ISO 27001 for IS Auditors
93 controls in four themes, not 114 in 14 domains. Here's the 2022 standard as an auditor uses it.
ISO/IEC 27001 sets the requirements for an information security management system (ISMS): the policies, risk process, controls and review cycle an organisation uses to manage information security risk. It is the one standard in Module 2 that an organisation can be certified against.
The current edition is ISO/IEC 27001:2022, published October 2022, with one amendment in 2024 on climate action. ISO lists the 2013 edition as withdrawn. The ISA 3.0 background material still describes the 2013 version with 114 controls in 14 domains, so expect to unlearn that count.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Management System Clauses (4-10)
These are the mandatory requirements. A certification auditor tests all of them; Annex A controls are selected through the risk process.
4
Title
Context of the organisation
What the auditor looks for
Defined ISMS scope, interested parties and their requirements
5
Title
Leadership
What the auditor looks for
Top management commitment, an approved information security policy, assigned roles
6
Title
Planning
What the auditor looks for
Risk assessment and treatment approach, security objectives
7
Title
Support
What the auditor looks for
Resources, competence, awareness, communication, documented information
8
Title
Operation
What the auditor looks for
Risk assessments and risk treatment actually carried out
9
Title
Performance evaluation
What the auditor looks for
Monitoring and measurement, internal audit, management review
10
Title
Improvement
What the auditor looks for
Nonconformities handled, corrective action, continual improvement
| Clause | Title | What the auditor looks for |
|---|---|---|
| 4 | Context of the organisation | Defined ISMS scope, interested parties and their requirements |
| 5 | Leadership | Top management commitment, an approved information security policy, assigned roles |
| 6 | Planning | Risk assessment and treatment approach, security objectives |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | Risk assessments and risk treatment actually carried out |
| 9 | Performance evaluation | Monitoring and measurement, internal audit, management review |
| 10 | Improvement | Nonconformities handled, corrective action, continual improvement |
Annex A in the 2022 Edition: 93 Controls, Four Themes
Annex A of ISO/IEC 27001:2022 is a reference list of controls that mirrors ISO/IEC 27002:2022, where each control has implementation guidance.
Organisational
Controls
37
Examples
Policies (5.1), segregation of duties (5.3), threat intelligence (5.7), cloud services (5.23), ICT readiness for business continuity (5.30)
People
Controls
8
Examples
Screening (6.1), awareness and training (6.3), remote working (6.7), event reporting (6.8)
Physical
Controls
14
Examples
Physical security monitoring (7.4), storage media (7.10), secure disposal or reuse (7.14)
Technological
Controls
34
Examples
Configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring (8.16), web filtering (8.23), secure coding (8.28), change management (8.32)
| Theme | Controls | Examples |
|---|---|---|
| Organisational | 37 | Policies (5.1), segregation of duties (5.3), threat intelligence (5.7), cloud services (5.23), ICT readiness for business continuity (5.30) |
| People | 8 | Screening (6.1), awareness and training (6.3), remote working (6.7), event reporting (6.8) |
| Physical | 14 | Physical security monitoring (7.4), storage media (7.10), secure disposal or reuse (7.14) |
| Technological | 34 | Configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring (8.16), web filtering (8.23), secure coding (8.28), change management (8.32) |
Terms Worth Getting Right
- ISMS
- The whole management system, not just the controls: scope, policy, risk process, controls, monitoring, audit and review.
- Statement of Applicability (SoA)
- The document listing each Annex A control, whether it is included or excluded, and why. Exclusions must be justified by the risk assessment. It is usually the auditor's first request after the scope.
- Risk treatment plan
- How each assessed risk will be treated, with owners and timelines. The SoA and the treatment plan should agree.
- ISO/IEC 27002
- The guidance standard for the controls. Organisations are certified to 27001, never to 27002.
- Attributes
- New in 27002:2022: each control is tagged with attributes (for example operational capabilities and security domains) so it can be filtered and mapped to other frameworks.
Quick practice on audit concepts. No signup.
How an IS Auditor Uses a Client's ISO 27001 Certificate
Example: a GST-era ERP hosted by a certified data centre provider.
- check_circleRead the certificate scope. A certificate covering one data centre says nothing about the provider's application support team in another city.
- check_circleCheck validity dates and the certifying body's accreditation.
- check_circleAsk for the SoA. A control you plan to rely on may be excluded.
- check_circleA certificate is not a substitute for testing the specific controls your audit relies on; treat it as one source of evidence.
How the DISA Assessment Test Tests This
- check_circleControl counts: 93 controls in four themes is the current answer. 114 controls in 14 domains is the 2013 edition the course material describes.
- check_circleCertification: organisations are certified to 27001, not 27002, and not to COBIT or ISO 31000.
- check_circleStarting point: an ISMS starts with scope and risk assessment, not with buying controls.
- check_circleExcluded controls: valid only when justified in the SoA by the risk assessment.
FAQs
How many controls are in ISO 27001:2022 Annex A?expand_more
93, in four themes: organisational (37), people (8), physical (14) and technological (34). The 2013 edition had 114 controls in 14 domains.
What is the difference between ISO 27001 and ISO 27002?expand_more
ISO/IEC 27001 sets the requirements for an ISMS and is certifiable. ISO/IEC 27002 gives guidance on implementing the controls listed in 27001's Annex A.
What is a Statement of Applicability in ISO 27001?expand_more
The document that lists every Annex A control, says whether it applies, and justifies each inclusion and exclusion based on the risk assessment.
Is ISO 27001:2013 still valid?expand_more
ISO lists ISO/IEC 27001:2013 as withdrawn; the current edition is ISO/IEC 27001:2022. Study material that predates 2022 describes the old control set.
Next steps
- COBIT vs ISO vs ITILarrow_forward
- Security Policyarrow_forward
- NIST CSF 2.0arrow_forward
- Logical Accessarrow_forward
Assessment Test format, timed and scored.
