ISO 27001 Requirements Explained: Clauses 4–10 and 93 Controls
ISO 27001 requirements explained clearly: the management system, risk process, clauses 4 to 10 and the 93 Annex A controls.
ISO/IEC 27001 combines mandatory management-system requirements in clauses 4 to 10 with a reference set of 93 information-security controls in Annex A. The controls are not a universal shopping list. Each organisation selects necessary controls from risks, legal duties and customer requirements and records its reasoning in the Statement of Applicability.
How the standard works
The standard connects leadership, planning, operations and improvement with a risk-based security process. It covers far more than firewalls and passwords: roles, suppliers, people, physical security, documented decisions and system effectiveness are equally important.
Clauses 4 to 10 at a glance
| Clause | Core question |
|---|---|
| 4 Context | Which internal and external issues and interested parties affect the ISMS? |
| 5 Leadership | Who owns the system, approves policy and provides resources? |
| 6 Planning | How are risks, opportunities, objectives and treatment managed? |
| 7 Support | Which competence, communication and documented information are needed? |
| 8 Operation | How are risk assessment and treatment carried out? |
| 9 Evaluation | How are monitoring, internal audit and management review used? |
| 10 Improvement | How are nonconformities corrected and the ISMS improved? |
What the 93 controls mean
Annex A groups controls into organisational, people, physical and technological themes. Detailed implementation guidance is mainly provided by ISO/IEC 27002. For each control, the organisation decides whether it is necessary, how it is implemented and what evidence demonstrates effectiveness.
Controls outside Annex A may also be needed. The goal is a traceable link between risk, treatment, controls and evidence, rather than mechanically ticking a list.
Evidence auditors commonly expect
- Approved scope and information-security policy
- Traceable risk assessment and treatment plan
- Statement of Applicability with clear rationale
- Roles, competence and training records
- Operational evidence such as tickets, logs, tests and reviews
- Internal audit, management review and corrective actions
How Sternberg Consulting supports you
We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.
Frequently asked questions
Are all 93 controls mandatory?
All must be considered. Applicability depends on risks, obligations and requirements and is justified in the SoA.
Is a document library enough?
No. Auditors test whether described processes are implemented and effective.
How is ISO 27002 different?
ISO 27001 contains certifiable requirements, while ISO 27002 gives more detailed guidance for information-security controls.