Direct definition
What are ISO 27001 Clauses 4–10?
They are the core requirements for an information security management system: understand the organisation, establish leadership, plan how risk will be managed, provide support, operate the plan, evaluate results and improve the system. Clauses 1–3 cover the standard's scope, references and terms; Annex A supplies a reference set of controls. Neither is interchangeable with Clauses 4–10.
Frame
4 Context · 5 Leadership
Plan
6 Risks · objectives · change
Do
7 Support · 8 Operation
Check and act
9 Evaluate · 10 Improve
Purpose: use the map to learn relationships, not to replace the standard with a checklist. Context and leadership frame every cycle; Clause 6 plans; Clauses 7 and 8 enable and operate; Clause 9 checks; Clause 10 improves.
All requirements in Clauses 4–10 apply and cannot be excluded from the ISMS. Annex A serves a different purpose: it is a reference control set used to check that no necessary control was overlooked, not a claim that every one of its 93 controls is mandatory for every organisation.
Visible preview
Follow the evidence handoff
Read down once to understand the structure, then read the handoffs to see why the system loops. A weak input upstream usually appears as a weak record or finding downstream.
Context of the organisation
What are we protecting, for whom and inside which boundary?
Understand internal and external issues, identify relevant interested parties and their requirements, set the ISMS scope and establish the processes the system needs.
Evidence you may see
- Context and interested-party records
- Approved ISMS scope statement
- ISMS process and interface overview
Handoff
The boundary and applicable requirements become inputs to leadership decisions and risk planning.
Leadership
Who is accountable, what direction have they set and who owns each role?
Make top management accountable for the ISMS, align information security with the organisation, approve the policy and assign clear responsibilities and authorities.
Evidence you may see
- Information security policy
- Named roles and accountabilities
- Management decisions, resources and communications
Handoff
Leadership supplies direction, authority and resources for planning, operation and improvement.
Planning
What could affect the intended outcomes, and what will we do about it?
Address risks and opportunities, define a repeatable information security risk method, plan risk treatment, set measurable objectives and plan significant ISMS changes.
Evidence you may see
- Risk criteria and assessment method
- Risk register and treatment plan
- Statement of Applicability and security objectives
Handoff
Approved treatments, objectives and changes tell support and operations what must be enabled and performed.
Support
What people, skills, awareness, communication and information does the ISMS need?
Provide resources and competence, build awareness, decide what to communicate and control the documented information used as instructions and evidence.
Evidence you may see
- Competence and awareness records
- Communication plan
- Controlled policies, procedures and retained records
Handoff
Support makes the planned controls and operational processes capable of working consistently.
Operation
Are the planned risk and control activities actually being performed?
Plan and control ISMS operations, manage relevant external processes and changes, perform risk assessments when planned or when significant changes occur, and carry out the approved risk treatment plan.
Evidence you may see
- Operating records from controls and processes
- Updated risk assessments
- Completed treatment actions and approvals
Handoff
Operational records provide the evidence that Clause 9 measures, audits and reviews.
Performance evaluation
Is the ISMS effective, conforming and producing the intended results?
Monitor and evaluate performance, conduct objective internal audits and have top management review the continuing suitability, adequacy and effectiveness of the ISMS.
Evidence you may see
- Metrics, analysis and evaluation results
- Internal audit programme and reports
- Management review inputs, decisions and actions
Handoff
Findings, trends and management decisions become the improvement work in Clause 10.
Improvement
What must be corrected, prevented from recurring or made more effective?
Respond to nonconformities, correct their immediate effects, address causes where needed and continually improve the suitability, adequacy and effectiveness of the ISMS.
Evidence you may see
- Nonconformity and correction records
- Cause analysis and corrective actions
- Verified improvements and lessons learned
Handoff
Improvement changes the next view of context, risk, objectives, support and operation; the cycle continues.
Amendment 1:2024 adds climate-action considerations to Clause 4: determine whether climate change is relevant to the organisation's context, and recognise that relevant interested parties may have climate-related requirements. It does not turn every ISMS into an environmental-management system.
Worked example · fictional
One privileged-access risk through all seven clauses
Paperbark Payroll is a fictional 45-person Australian SaaS provider. The example follows one risk so the connections are visible. It is not a model scope, control selection or audit conclusion for another organisation.
| Clause | What Paperbark does | Example evidence |
|---|---|---|
| 4 | Paperbark Payroll identifies customer payroll data, its cloud service and support process as in scope. Customers, staff, regulators and its hosting provider are relevant interested parties. | A scope statement names the service, teams, systems, interfaces and justified exclusions. |
| 5 | The managing director approves the information security policy. The security lead coordinates the ISMS; system owners remain responsible for risks in their services. | Approved policy, role descriptions and a recorded resource decision. |
| 6 | The team assesses unauthorised privileged access to payroll exports, sets acceptance criteria and approves stronger authentication plus quarterly access review as treatment. | Risk entry, treatment owner, due date, objective and Statement of Applicability rationale. |
| 7 | Administrators receive role-specific training. The access procedure is version-controlled and staff know how to report a suspected account compromise. | Competence record, awareness evidence, communication route and controlled procedure. |
| 8 | IT enrols administrators in phishing-resistant MFA, performs the scheduled access review and reassesses risk after a major identity-platform change. | MFA enrolment output, approved access review and updated risk assessment. |
| 9 | The team monitors enrolment coverage and overdue reviews. An independent internal auditor samples accounts, and management reviews results and unresolved risk. | Metric report, audit evidence and management review decisions. |
| 10 | An audit finds one former contractor account still active. IT disables it immediately, then fixes the HR-to-IT offboarding workflow and checks that the change works. | Correction, cause analysis, corrective action, owner, due date and effectiveness check. |
Adaptation instructions
Turn the map into your organisation's system
- Replace the fictional scope with the products, services, teams, locations, systems, interfaces and exclusions your organisation can defend.
- Identify your interested parties and decide which of their legal, regulatory, contractual and business requirements are relevant to the ISMS.
- Define risk criteria before scoring risks. Use your own assets, threats, vulnerabilities, consequences, likelihood scales and acceptance authority.
- Select necessary controls from risk, legal and contractual needs, then compare that set with Annex A and record the decision in your Statement of Applicability.
- Name owners, frequencies and evidence for each process. A policy alone does not demonstrate that an activity operates.
- Set an audit and management-review cadence, then feed findings and decisions back into risk, objectives, resources and operations.
Common mistakes
Where the mental map usually breaks
Treating Annex A as Clauses 4–10
Clauses 4–10 set the ISMS requirements. Annex A is a reference control set used when determining and checking necessary controls.
Choosing controls before defining scope and risk criteria
Context and scope shape the risk assessment; risk and applicable requirements shape the control set.
Handing the whole ISMS to IT
Top management remains accountable, while legal, HR, procurement, engineering and service owners contribute evidence and decisions.
Calling a document evidence of operation
A procedure explains what should happen. Logs, approvals, tickets, reviews and records show what did happen.
Having the process owner audit their own work
Internal audit needs objectivity and impartiality; plan assignments so the auditor is not simply approving their own process.
Using correction and corrective action as synonyms
Correction deals with the detected problem. Corrective action deals with its cause to reduce recurrence.
Running the cycle once for certification
The ISMS continues after an audit. Changes, results and findings must keep feeding the next planning and improvement cycle.
Version, author and review status
- Resource version
- 1.0
- Published
- 2 September 2026
- Author
- Aegentra Academy
- Standards basis
- ISO/IEC 27001:2022 and Amendment 1:2024
- Substantive reviewer
- Harry Sidhu · Director and Principal Consultant, Aegentra
- Substantive review date
- 2 September 2026
Substantively reviewed for source accuracy, clause mapping, limitations and learner-facing presentation. Source links were checked when this version was prepared; source availability and standards status can change.
Limitations and use boundary
- This is Aegentra-authored educational material, not official PECB course material and not a reproduction of ISO/IEC 27001.
- It does not replace an authorised copy of the standard, organisation-specific risk work, legal advice, an internal audit or certification-body assessment.
- The evidence examples are illustrative. ISO 27001 does not prescribe one universal document set, template, technology or control implementation.
- The fictional worked example must not be copied as evidence. Your scope, interested parties, risks, controls, owners and retained records must reflect your organisation.
- Certification applies to an organisation’s defined ISMS scope. Completing an individual course or using this map does not certify an organisation.
Sources and further study
The descriptions above are plain-English paraphrases. Use the published ISO sources for the authoritative requirements and terms.
- [1]ISO/IEC 27001:2022 — Information security management systems — Requirements
Current requirements edition and the purpose of an ISMS.
- [2]ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes
Current amendment affecting the context and interested-party requirements.
- [3]ISO management system standards
Management-system purpose, leadership, evaluation and continual-improvement context.
- [4]ISO/IEC 27005:2022 — Guidance on managing information security risks
Risk assessment, treatment, communication, monitoring and review context.
- [5]ISO/IEC 27001 Auditing Practices Group — Statement of Applicability note
An educational practices note hosted in the SC 27 resource library on necessary controls, Annex A comparison and SoA completeness. The note states that it has not been endorsed by ISO or SC 27.
FAQs
No. Clauses 4–10 contain the requirements for establishing, operating, evaluating and improving the ISMS. Annex A is a reference set of information security controls. The organisation determines necessary controls from its risks and applicable requirements, then compares that set with Annex A and records the result in its Statement of Applicability.
The numbers are a useful learning order, but an operating ISMS is iterative. Context and leadership frame the system, planning directs support and operation, performance evaluation tests results, and improvement feeds changes back into the next cycle.
No. It is an Aegentra-authored educational map, not the standard and not a statement of conformity. Use an authorised copy of ISO/IEC 27001 and obtain competent advice for implementation, audit or certification decisions.