Security Questionnaire Mapper
Clause text

ISO/IEC 27001:2022: the clauses the register cites

The 31 ISO/IEC 27001:2022 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The requirement lines are our statement of each clause, read against the copy we hold and cited to it.

31 clauses

the families they anchor
ISO 27001 5.1 Policies for information security

Write, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.

Evidence an assessor expects: Security policy document; Policy approval records; Policy distribution log; Policy review schedule; Policy change records
Where answers usually fall short: Policies not formally approved by senior management; No evidence of distribution or employee acknowledgment
Source: ISO/IEC 27001:2022
ISO 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

Evidence an assessor expects: Role definitions; Responsibility matrix; Assignment records; Authority delegation
Where answers usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities
Source: ISO/IEC 27001:2022
ISO 27001 5.17 Authentication information

Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.

Evidence an assessor expects: Password policy; Secret inventory; User training records; Access review logs
Where answers usually fall short: Policies exist but not enforced; No centralized inventory of secrets
Source: ISO/IEC 27001:2022
ISO 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

Evidence an assessor expects: Access provision records; Access review reports; Access revocation logs; Role definition documents
Where answers usually fall short: Reviews lack documented corrective actions; Access changes not tied to approved request workflow
Source: ISO/IEC 27001:2022
ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an assessor expects: Supplier risk assessment; Contractual security requirements; Supplier security monitoring; Supplier incident management
Where answers usually fall short: Treating all suppliers as low risk; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an assessor expects: Contract security clauses; Supplier risk assessment; Security incident reporting; Performance monitoring reports; Contract termination provisions
Where answers usually fall short: Missing explicit security clauses; No documented risk assessment before onboarding
Source: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an assessor expects: Supplier security requirements; Contractual security clauses; Supply chain risk assessments; Supplier audit reports; Incident response collaboration
Where answers usually fall short: Treating supplier security as one-off check; Missing contractual security clauses
Source: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an assessor expects: Supplier security monitoring reports; Supplier service review meetings; Supplier change management records; Supplier contractual compliance evidence
Where answers usually fall short: Relying on informal verbal updates; Missing documented approval for supplier changes
Source: ISO/IEC 27001:2022
ISO 27001 5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Evidence an assessor expects: Incident response plan; Role assignment matrix; Training and awareness records; Exercise and testing reports; Communication procedure documents
Where answers usually fall short: Roles are defined but not formally assigned or approved; Plans are outdated and lack version control
Source: ISO/IEC 27001:2022
ISO 27001 5.25 Assessment and decision on information security events

Triage security events and decide which become incidents.

Evidence an assessor expects: Event triage workflow; Incident decision log; Classification criteria; Escalation procedure
Where answers usually fall short: No documented triage steps; Decisions not recorded or lack timestamps
Source: ISO/IEC 27001:2022
ISO 27001 5.26 Response to information security incidents

Respond to incidents according to the documented procedures.

Evidence an assessor expects: Incident response plan; Incident handling records; Post incident analysis; Stakeholder communication
Where answers usually fall short: Plans not tested regularly; Incident logs incomplete or inconsistent
Source: ISO/IEC 27001:2022
ISO 27001 5.29 Information security during disruption

Plan how to keep information security at the right level during disruption.

Evidence an assessor expects: Disruption security plan; Business continuity test reports; Security control adjustment log; Incident communication records
Where answers usually fall short: Plans not updated after tests; Missing documented approval for temporary control changes
Source: ISO/IEC 27001:2022
ISO 27001 5.30 ICT readiness for business continuity

Plan, implement, maintain and test ICT readiness against business continuity objectives.

Evidence an assessor expects: ICT continuity plan; Readiness test results; Resource allocation records; Simulation exercise reports
Where answers usually fall short: Testing frequency not aligned with risk; Plans not updated after infrastructure changes
Source: ISO/IEC 27001:2022
ISO 27001 5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an assessor expects: Legal register; Contractual obligations; Regulatory filing records; Privacy impact assessments
Where answers usually fall short: Outdated legal register; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an assessor expects: Privacy policy; Data inventory; Processing agreements; Breach records
Where answers usually fall short: Missing documented consent for all data subjects; Incomplete inventory of PII across legacy systems
Source: ISO/IEC 27001:2022
ISO 27001 5.35 Independent review of information security

Have the security approach and its implementation reviewed independently on a cadence and after significant change.

Evidence an assessor expects: Review schedule; Review reports; Reviewer independence; Change trigger log
Where answers usually fall short: Reviews performed by internal staff only; Infrequent or ad-hoc review cadence
Source: ISO/IEC 27001:2022
ISO 27001 6.1 Screening

Background-check candidates and personnel proportional to risk and classification, within the law.

Evidence an assessor expects: Screening policy; Risk based screening procedures; Candidate check records; Employee screening logs; Third party screening reports
Where answers usually fall short: One‑size‑fits‑all screening regardless of risk; Missing documentation of approvals for exceptions
Source: ISO/IEC 27001:2022
ISO 27001 6.3 Information security awareness, education and training

Give personnel and relevant parties appropriate, current security training for their role.

Evidence an assessor expects: Training program plan; Role based training records; Attendance logs; Training effectiveness reports
Where answers usually fall short: Training not aligned to specific job functions; Content not updated on a regular basis
Source: ISO/IEC 27001:2022
ISO 27001 6.6 Confidentiality or non-disclosure agreements

Identify, document, review and sign NDAs that reflect the organization's protection needs.

Evidence an assessor expects: NDA policy; NDA templates; Signed NDA registry; NDA review process; Third party NDA records
Where answers usually fall short: NDAs not refreshed when data classification changes; Contractor agreements missing required signatures
Source: ISO/IEC 27001:2022
ISO 27001 7.1 Physical security perimeters

Define and use security perimeters to protect areas holding information and assets.

Evidence an assessor expects: Perimeter design; Access point controls; Visitor management; Surveillance records
Where answers usually fall short: Outdated floor plans; Inconsistent access log retention
Source: ISO/IEC 27001:2022
ISO 27001 8.2 Privileged access rights

Restrict and manage the allocation and use of privileged access.

Evidence an assessor expects: Privileged account inventory; Privileged access approval; Privileged access review; Privileged access logging
Where answers usually fall short: Outdated privileged account inventory; Missing or informal approval documentation
Source: ISO/IEC 27001:2022
ISO 27001 8.5 Secure authentication

Implement authentication technologies and procedures based on access restrictions and policy.

Evidence an assessor expects: Authentication policy; Credential provisioning; MFA implementation; Access log monitoring; Privileged account controls
Where answers usually fall short: Reliance on static passwords only; Inconsistent MFA enforcement across systems
Source: ISO/IEC 27001:2022
ISO 27001 8.7 Protection against malware

Implement malware protection backed by user awareness.

Evidence an assessor expects: Anti malware policy; Endpoint protection; User awareness program; Malware incident handling
Where answers usually fall short: Outdated malware signatures not regularly updated; Training limited to annual sessions
Source: ISO/IEC 27001:2022
ISO 27001 8.8 Management of technical vulnerabilities

Obtain vulnerability information, evaluate exposure, and take appropriate remediation.

Evidence an assessor expects: Vulnerability feed logs; Risk assessment reports; Remediation ticket records; Patch deployment evidence
Where answers usually fall short: Relying on ad-hoc scans only; Missing documented risk ranking for vulnerabilities
Source: ISO/IEC 27001:2022
ISO 27001 8.10 Information deletion

Delete information in systems, devices and media when no longer required.

Evidence an assessor expects: Deletion policy; Media disposal log; System deletion audit; Data retention schedule
Where answers usually fall short: Retaining data beyond approved period; No evidence of secure erase verification
Source: ISO/IEC 27001:2022
ISO 27001 8.13 Information backup

Maintain and regularly test backups of information, software and systems per the backup policy.

Evidence an assessor expects: Backup policy; Backup schedule; Backup test reports; Retention records; Access logs
Where answers usually fall short: Infrequent restore testing; Missing retention documentation
Source: ISO/IEC 27001:2022
ISO 27001 8.15 Logging

Produce, store, protect and analyse logs of activities, exceptions and faults.

Evidence an assessor expects: Log collection policy; Log storage and protection; Log review and analysis; Log retention and disposal
Where answers usually fall short: Inconsistent log collection across systems; Insufficient protection of log integrity
Source: ISO/IEC 27001:2022
ISO 27001 8.16 Monitoring activities

Monitor networks, systems and applications for anomalies and act on potential incidents.

Evidence an assessor expects: Network anomaly detection logs; System integrity monitoring reports; Application behavior alerts; Incident response records
Where answers usually fall short: Alerts not correlated across sources; Lack of documented response procedures for anomalies
Source: ISO/IEC 27001:2022
ISO 27001 8.20 Networks security

Secure, manage and control networks and network devices.

Evidence an assessor expects: Network topology diagrams; Firewall rule sets; Network access control lists; Wireless security configurations
Where answers usually fall short: Outdated topology diagrams; Inconsistent firewall rule documentation
Source: ISO/IEC 27001:2022
ISO 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

Evidence an assessor expects: Encryption policy; Key management procedures; Algorithm inventory; Key usage records
Where answers usually fall short: Missing documented key lifecycle; Use of outdated or weak algorithms
Source: ISO/IEC 27001:2022
ISO 27001 8.25 Secure development life cycle

Establish and apply rules for secure development of software and systems.

Evidence an assessor expects: Secure dev policy; Threat modeling artifacts; Code review logs; Security testing reports
Where answers usually fall short: Policy exists but not enforced; Threat models not updated for new features
Source: ISO/IEC 27001:2022