ISO/IEC 27001:2022: the clauses the register cites
The 31 ISO/IEC 27001:2022 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The requirement lines are our statement of each clause, read against the copy we hold and cited to it.
31 clauses
the families they anchorISO 27001 5.1 Policies for information securityWrite, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
Where answers usually fall short: Policies not formally approved by senior management; No evidence of distribution or employee acknowledgment
Source: ISO/IEC 27001:2022
ISO 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
Where answers usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities
Source: ISO/IEC 27001:2022
ISO 27001 5.17 Authentication informationControl allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.
Where answers usually fall short: Policies exist but not enforced; No centralized inventory of secrets
Source: ISO/IEC 27001:2022
ISO 27001 5.18 Access rightsProvision, review, modify and remove access rights in line with the access control policy.
Where answers usually fall short: Reviews lack documented corrective actions; Access changes not tied to approved request workflow
Source: ISO/IEC 27001:2022
ISO 27001 5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Where answers usually fall short: Treating all suppliers as low risk; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Where answers usually fall short: Missing explicit security clauses; No documented risk assessment before onboarding
Source: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Where answers usually fall short: Treating supplier security as one-off check; Missing contractual security clauses
Source: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier servicesRegularly monitor, review and manage change in supplier security practice and service delivery.
Where answers usually fall short: Relying on informal verbal updates; Missing documented approval for supplier changes
Source: ISO/IEC 27001:2022
ISO 27001 5.24 Information security incident management planning and preparationDefine incident roles, processes and readiness before an incident happens.
Where answers usually fall short: Roles are defined but not formally assigned or approved; Plans are outdated and lack version control
Source: ISO/IEC 27001:2022
ISO 27001 5.25 Assessment and decision on information security eventsTriage security events and decide which become incidents.
Where answers usually fall short: No documented triage steps; Decisions not recorded or lack timestamps
Source: ISO/IEC 27001:2022
ISO 27001 5.26 Response to information security incidentsRespond to incidents according to the documented procedures.
Where answers usually fall short: Plans not tested regularly; Incident logs incomplete or inconsistent
Source: ISO/IEC 27001:2022
ISO 27001 5.29 Information security during disruptionPlan how to keep information security at the right level during disruption.
Where answers usually fall short: Plans not updated after tests; Missing documented approval for temporary control changes
Source: ISO/IEC 27001:2022
ISO 27001 5.30 ICT readiness for business continuityPlan, implement, maintain and test ICT readiness against business continuity objectives.
Where answers usually fall short: Testing frequency not aligned with risk; Plans not updated after infrastructure changes
Source: ISO/IEC 27001:2022
ISO 27001 5.31 Legal, statutory, regulatory and contractual requirementsIdentify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
Where answers usually fall short: Outdated legal register; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Where answers usually fall short: Missing documented consent for all data subjects; Incomplete inventory of PII across legacy systems
Source: ISO/IEC 27001:2022
ISO 27001 5.35 Independent review of information securityHave the security approach and its implementation reviewed independently on a cadence and after significant change.
Where answers usually fall short: Reviews performed by internal staff only; Infrequent or ad-hoc review cadence
Source: ISO/IEC 27001:2022
ISO 27001 6.1 ScreeningBackground-check candidates and personnel proportional to risk and classification, within the law.
Where answers usually fall short: One‑size‑fits‑all screening regardless of risk; Missing documentation of approvals for exceptions
Source: ISO/IEC 27001:2022
ISO 27001 6.3 Information security awareness, education and trainingGive personnel and relevant parties appropriate, current security training for their role.
Where answers usually fall short: Training not aligned to specific job functions; Content not updated on a regular basis
Source: ISO/IEC 27001:2022
ISO 27001 6.6 Confidentiality or non-disclosure agreementsIdentify, document, review and sign NDAs that reflect the organization's protection needs.
Where answers usually fall short: NDAs not refreshed when data classification changes; Contractor agreements missing required signatures
Source: ISO/IEC 27001:2022
ISO 27001 7.1 Physical security perimetersDefine and use security perimeters to protect areas holding information and assets.
Where answers usually fall short: Outdated floor plans; Inconsistent access log retention
Source: ISO/IEC 27001:2022
ISO 27001 8.2 Privileged access rightsRestrict and manage the allocation and use of privileged access.
Where answers usually fall short: Outdated privileged account inventory; Missing or informal approval documentation
Source: ISO/IEC 27001:2022
ISO 27001 8.5 Secure authenticationImplement authentication technologies and procedures based on access restrictions and policy.
Where answers usually fall short: Reliance on static passwords only; Inconsistent MFA enforcement across systems
Source: ISO/IEC 27001:2022
ISO 27001 8.7 Protection against malwareImplement malware protection backed by user awareness.
Where answers usually fall short: Outdated malware signatures not regularly updated; Training limited to annual sessions
Source: ISO/IEC 27001:2022
ISO 27001 8.8 Management of technical vulnerabilitiesObtain vulnerability information, evaluate exposure, and take appropriate remediation.
Where answers usually fall short: Relying on ad-hoc scans only; Missing documented risk ranking for vulnerabilities
Source: ISO/IEC 27001:2022
ISO 27001 8.10 Information deletionDelete information in systems, devices and media when no longer required.
Where answers usually fall short: Retaining data beyond approved period; No evidence of secure erase verification
Source: ISO/IEC 27001:2022
ISO 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
Where answers usually fall short: Infrequent restore testing; Missing retention documentation
Source: ISO/IEC 27001:2022
ISO 27001 8.15 LoggingProduce, store, protect and analyse logs of activities, exceptions and faults.
Where answers usually fall short: Inconsistent log collection across systems; Insufficient protection of log integrity
Source: ISO/IEC 27001:2022
ISO 27001 8.16 Monitoring activitiesMonitor networks, systems and applications for anomalies and act on potential incidents.
Where answers usually fall short: Alerts not correlated across sources; Lack of documented response procedures for anomalies
Source: ISO/IEC 27001:2022
ISO 27001 8.20 Networks securitySecure, manage and control networks and network devices.
Where answers usually fall short: Outdated topology diagrams; Inconsistent firewall rule documentation
Source: ISO/IEC 27001:2022
ISO 27001 8.24 Use of cryptographyDefine and implement rules for effective use of cryptography and key management.
Where answers usually fall short: Missing documented key lifecycle; Use of outdated or weak algorithms
Source: ISO/IEC 27001:2022
ISO 27001 8.25 Secure development life cycleEstablish and apply rules for secure development of software and systems.
Where answers usually fall short: Policy exists but not enforced; Threat models not updated for new features
Source: ISO/IEC 27001:2022