Skip to main content
Guide · Updated

ISO 27001 Clauses 4–10 study map

Clauses 4–10 are the seven requirement sections that turn ISO/IEC 27001 into a working information security management system. This map shows the question each clause answers, the evidence it can produce and how its output feeds the next part of the cycle.
Prepared by Aegentra Academy · Version 1.0 · Substantively reviewed by Harry Sidhu on 2 September 202611 min read

Direct definition

What are ISO 27001 Clauses 4–10?

They are the core requirements for an information security management system: understand the organisation, establish leadership, plan how risk will be managed, provide support, operate the plan, evaluate results and improve the system. Clauses 1–3 cover the standard's scope, references and terms; Annex A supplies a reference set of controls. Neither is interchangeable with Clauses 4–10.

Frame

4 Context · 5 Leadership

Plan

6 Risks · objectives · change

Do

7 Support · 8 Operation

Check and act

9 Evaluate · 10 Improve

Purpose: use the map to learn relationships, not to replace the standard with a checklist. Context and leadership frame every cycle; Clause 6 plans; Clauses 7 and 8 enable and operate; Clause 9 checks; Clause 10 improves.

All requirements in Clauses 4–10 apply and cannot be excluded from the ISMS. Annex A serves a different purpose: it is a reference control set used to check that no necessary control was overlooked, not a claim that every one of its 93 controls is mandatory for every organisation.

Visible preview

Follow the evidence handoff

Download the CSV map

Read down once to understand the structure, then read the handoffs to see why the system loops. A weak input upstream usually appears as a weak record or finding downstream.

4Frame the system

Context of the organisation

What are we protecting, for whom and inside which boundary?

Understand internal and external issues, identify relevant interested parties and their requirements, set the ISMS scope and establish the processes the system needs.

Evidence you may see

  • Context and interested-party records
  • Approved ISMS scope statement
  • ISMS process and interface overview

Handoff

The boundary and applicable requirements become inputs to leadership decisions and risk planning.

5Steer the system

Leadership

Who is accountable, what direction have they set and who owns each role?

Make top management accountable for the ISMS, align information security with the organisation, approve the policy and assign clear responsibilities and authorities.

Evidence you may see

  • Information security policy
  • Named roles and accountabilities
  • Management decisions, resources and communications

Handoff

Leadership supplies direction, authority and resources for planning, operation and improvement.

6Plan

Planning

What could affect the intended outcomes, and what will we do about it?

Address risks and opportunities, define a repeatable information security risk method, plan risk treatment, set measurable objectives and plan significant ISMS changes.

Evidence you may see

  • Risk criteria and assessment method
  • Risk register and treatment plan
  • Statement of Applicability and security objectives

Handoff

Approved treatments, objectives and changes tell support and operations what must be enabled and performed.

7Enable

Support

What people, skills, awareness, communication and information does the ISMS need?

Provide resources and competence, build awareness, decide what to communicate and control the documented information used as instructions and evidence.

Evidence you may see

  • Competence and awareness records
  • Communication plan
  • Controlled policies, procedures and retained records

Handoff

Support makes the planned controls and operational processes capable of working consistently.

8Do

Operation

Are the planned risk and control activities actually being performed?

Plan and control ISMS operations, manage relevant external processes and changes, perform risk assessments when planned or when significant changes occur, and carry out the approved risk treatment plan.

Evidence you may see

  • Operating records from controls and processes
  • Updated risk assessments
  • Completed treatment actions and approvals

Handoff

Operational records provide the evidence that Clause 9 measures, audits and reviews.

9Check

Performance evaluation

Is the ISMS effective, conforming and producing the intended results?

Monitor and evaluate performance, conduct objective internal audits and have top management review the continuing suitability, adequacy and effectiveness of the ISMS.

Evidence you may see

  • Metrics, analysis and evaluation results
  • Internal audit programme and reports
  • Management review inputs, decisions and actions

Handoff

Findings, trends and management decisions become the improvement work in Clause 10.

10Act

Improvement

What must be corrected, prevented from recurring or made more effective?

Respond to nonconformities, correct their immediate effects, address causes where needed and continually improve the suitability, adequacy and effectiveness of the ISMS.

Evidence you may see

  • Nonconformity and correction records
  • Cause analysis and corrective actions
  • Verified improvements and lessons learned

Handoff

Improvement changes the next view of context, risk, objectives, support and operation; the cycle continues.

Amendment 1:2024 adds climate-action considerations to Clause 4: determine whether climate change is relevant to the organisation's context, and recognise that relevant interested parties may have climate-related requirements. It does not turn every ISMS into an environmental-management system.

Worked example · fictional

One privileged-access risk through all seven clauses

Paperbark Payroll is a fictional 45-person Australian SaaS provider. The example follows one risk so the connections are visible. It is not a model scope, control selection or audit conclusion for another organisation.

Fictional worked example applying ISO 27001 Clauses 4 to 10
ClauseWhat Paperbark doesExample evidence
4Paperbark Payroll identifies customer payroll data, its cloud service and support process as in scope. Customers, staff, regulators and its hosting provider are relevant interested parties.A scope statement names the service, teams, systems, interfaces and justified exclusions.
5The managing director approves the information security policy. The security lead coordinates the ISMS; system owners remain responsible for risks in their services.Approved policy, role descriptions and a recorded resource decision.
6The team assesses unauthorised privileged access to payroll exports, sets acceptance criteria and approves stronger authentication plus quarterly access review as treatment.Risk entry, treatment owner, due date, objective and Statement of Applicability rationale.
7Administrators receive role-specific training. The access procedure is version-controlled and staff know how to report a suspected account compromise.Competence record, awareness evidence, communication route and controlled procedure.
8IT enrols administrators in phishing-resistant MFA, performs the scheduled access review and reassesses risk after a major identity-platform change.MFA enrolment output, approved access review and updated risk assessment.
9The team monitors enrolment coverage and overdue reviews. An independent internal auditor samples accounts, and management reviews results and unresolved risk.Metric report, audit evidence and management review decisions.
10An audit finds one former contractor account still active. IT disables it immediately, then fixes the HR-to-IT offboarding workflow and checks that the change works.Correction, cause analysis, corrective action, owner, due date and effectiveness check.

Adaptation instructions

Turn the map into your organisation's system

  1. Replace the fictional scope with the products, services, teams, locations, systems, interfaces and exclusions your organisation can defend.
  2. Identify your interested parties and decide which of their legal, regulatory, contractual and business requirements are relevant to the ISMS.
  3. Define risk criteria before scoring risks. Use your own assets, threats, vulnerabilities, consequences, likelihood scales and acceptance authority.
  4. Select necessary controls from risk, legal and contractual needs, then compare that set with Annex A and record the decision in your Statement of Applicability.
  5. Name owners, frequencies and evidence for each process. A policy alone does not demonstrate that an activity operates.
  6. Set an audit and management-review cadence, then feed findings and decisions back into risk, objectives, resources and operations.

Common mistakes

Where the mental map usually breaks

Treating Annex A as Clauses 4–10

Clauses 4–10 set the ISMS requirements. Annex A is a reference control set used when determining and checking necessary controls.

Choosing controls before defining scope and risk criteria

Context and scope shape the risk assessment; risk and applicable requirements shape the control set.

Handing the whole ISMS to IT

Top management remains accountable, while legal, HR, procurement, engineering and service owners contribute evidence and decisions.

Calling a document evidence of operation

A procedure explains what should happen. Logs, approvals, tickets, reviews and records show what did happen.

Having the process owner audit their own work

Internal audit needs objectivity and impartiality; plan assignments so the auditor is not simply approving their own process.

Using correction and corrective action as synonyms

Correction deals with the detected problem. Corrective action deals with its cause to reduce recurrence.

Running the cycle once for certification

The ISMS continues after an audit. Changes, results and findings must keep feeding the next planning and improvement cycle.

Version, author and review status

Resource version
1.0
Published
2 September 2026
Author
Aegentra Academy
Standards basis
ISO/IEC 27001:2022 and Amendment 1:2024
Substantive reviewer
Harry Sidhu · Director and Principal Consultant, Aegentra
Substantive review date
2 September 2026

Substantively reviewed for source accuracy, clause mapping, limitations and learner-facing presentation. Source links were checked when this version was prepared; source availability and standards status can change.

Limitations and use boundary

  • This is Aegentra-authored educational material, not official PECB course material and not a reproduction of ISO/IEC 27001.
  • It does not replace an authorised copy of the standard, organisation-specific risk work, legal advice, an internal audit or certification-body assessment.
  • The evidence examples are illustrative. ISO 27001 does not prescribe one universal document set, template, technology or control implementation.
  • The fictional worked example must not be copied as evidence. Your scope, interested parties, risks, controls, owners and retained records must reflect your organisation.
  • Certification applies to an organisation’s defined ISMS scope. Completing an individual course or using this map does not certify an organisation.

Sources and further study

The descriptions above are plain-English paraphrases. Use the published ISO sources for the authoritative requirements and terms.

  1. [1]
    ISO/IEC 27001:2022 — Information security management systems — Requirements

    Current requirements edition and the purpose of an ISMS.

  2. [2]
    ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes

    Current amendment affecting the context and interested-party requirements.

  3. [3]
    ISO management system standards

    Management-system purpose, leadership, evaluation and continual-improvement context.

  4. [4]
    ISO/IEC 27005:2022 — Guidance on managing information security risks

    Risk assessment, treatment, communication, monitoring and review context.

  5. [5]
    ISO/IEC 27001 Auditing Practices Group — Statement of Applicability note

    An educational practices note hosted in the SC 27 resource library on necessary controls, Annex A comparison and SoA completeness. The note states that it has not been endorsed by ISO or SC 27.

FAQs

No. Clauses 4–10 contain the requirements for establishing, operating, evaluating and improving the ISMS. Annex A is a reference set of information security controls. The organisation determines necessary controls from its risks and applicable requirements, then compares that set with Annex A and records the result in its Statement of Applicability.

The numbers are a useful learning order, but an operating ISMS is iterative. Context and leadership frame the system, planning directs support and operation, performance evaluation tests results, and improvement feeds changes back into the next cycle.

No. It is an Aegentra-authored educational map, not the standard and not a statement of conformity. Use an authorised copy of ISO/IEC 27001 and obtain competent advice for implementation, audit or certification decisions.

Continue from the map

Learn the ISO 27001 foundations, then choose the role you need

Foundation builds the vocabulary and management-system map. Lead Implementer develops implementation capability; Lead Auditor focuses on planning, conducting and following up audits.