ISO Compliance Governance Knowledge Hub

ISO 27001 Clauses 4-10: The Requirements Behind the Controls

Maciej
ISO 27001 Clauses 4-10: The Requirements Behind the Controls
TL;DR

ISO 27001 has two parts, and most content covers the wrong one first. Annex A's 93 controls are applied selectively through your risk treatment — you justify inclusions and exclusions in the Statement of Applicability. Clauses 4–10 are different: every requirement is mandatory, none can be excluded, and this is where certification is actually decided. The seven clauses form one loop: Clause 4 defines your context and ISMS scope; Clause 5 puts obligations directly on top management; Clause 6 runs risk assessment and treatment and produces the SoA; Clause 7 supplies resources, competence, awareness, and document control; Clause 8 is where controls operate day to day; Clause 9 checks the system through metrics, internal audit, and management review; Clause 10 fixes what those checks find. It's the Plan-Do-Check-Act cycle in standards form. Auditors test the loop's connections — context feeding risks, findings reaching management review, corrective actions closing — which is why a template-bought ISMS with perfect documents and no working loop fails, and a modest ISMS that genuinely cycles passes. Each clause has its own detailed post in this series.

Search for ISO 27001 content and you'll drown in Annex A — the 93 controls, the four themes, the checklists. We've written plenty of it ourselves, including the complete Annex A guide. But here's the structural fact most of that content skips: Annex A is not where certification is decided. The decision happens in clauses 4 through 10 of the standard — the management-system requirements — and they work differently from controls in one crucial way.

Annex A controls apply through your risk treatment: you select what your risks demand and justify every exclusion in the Statement of Applicability. Clauses 4–10 offer no such negotiation. Every "shall" in those seven clauses is mandatory for every certified organization, from a five-person startup to a bank. You can exclude a physical-media control you have no use for; you cannot exclude management review, internal audit, or risk assessment. Annex A is what you implement; clauses 4–10 are why you pass or fail.

This hub maps the seven clauses and how they interlock. Each one has a dedicated post in this series going requirement by requirement, with the evidence auditors expect and the nonconformities they actually raise.

The loop, clause by clause

Clause 4 — Context of the organization. The foundations: the external and internal issues that shape your ISMS (4.1 — including, since the February 2024 amendment, determining whether climate change is relevant), your interested parties and their requirements (4.2), the documented scope of the ISMS (4.3), and the ISMS itself as connected processes (4.4). Everything downstream inherits what you decide here — especially the scope.

Clause 5 — Leadership. The clause your executives can't delegate: top management must demonstrably lead the ISMS (5.1), own the information security policy (5.2), and assign roles and authorities — including who reports ISMS performance upward (5.3). Audited by interviewing your leadership, which is exactly why it can't be faked.

Clause 6 — Planning. The decision engine: a defined risk assessment process with owners and acceptance criteria (6.1.2), risk treatment that determines your controls and verifies them against Annex A — producing the Statement of Applicability and a treatment plan with formally accepted residual risk (6.1.3), measurable security objectives (6.2), and, new in 2022, planned management of ISMS changes (6.3).

Clause 7 — Support. The plumbing: resources (7.1), competence defined per role and evidenced (7.2), genuine staff awareness — tested by interview, not by email receipts (7.3), a communication plan (7.4), and document control with versions, approvals, and retention (7.5). Home of the most frequently rejected audit evidence in the standard.

Clause 8 — Operation. The shortest clause and the one your daily security work formally hangs from: run the planned processes with criteria and records (8.1 — including control of externally provided services, meaning your cloud and SaaS vendors), reassess risk at planned intervals and on significant change (8.2), and actually implement the risk treatment plan (8.3). This is where Annex A controls plug into the management system.

Clause 9 — Performance evaluation. The system checks itself: defined metrics with comparable, reproducible methods (9.1), an impartial internal audit programme testing conformity to the standard and to your own rules (9.2), and management review with prescribed inputs and recorded decisions (9.3). In certification practice, the most finding-dense clause of the seven.

Clause 10 — Improvement. The repair loop: continual improvement of the ISMS (10.1) and the nonconformity process — correct the instance, find the cause, check for similar cases, verify the fix worked (10.2). The clause startups most often fake with an empty log, and the easiest fake for an auditor to catch.

One cycle, not seven silos

If the structure feels familiar, it should: it's Plan-Do-Check-Act. Clauses 4–7 plan and provision, Clause 8 does, Clause 9 checks, Clause 10 acts on what checking found — feeding changes back into planning. The standard is built so each clause consumes the previous ones' outputs: context (4) feeds risk assessment (6), whose treatment plan runs in operation (8), whose records are tested by audit (9), whose findings become corrective actions (10), which surface in management review (9.3) attended by leadership (5), resourced through support (7), and reflected in an updated context when the business changes (4). Auditors test those connections more than any single document — a folder of perfect templates with no working loop between them is precisely what stage-2 audits are designed to expose.

How the audit covers these clauses

Certification runs in two stages, and clauses 4–10 dominate both. Stage 1 is largely a documentation review: scope, policy, risk methodology, SoA, and evidence that internal audit and management review exist — Clause 4–7 territory plus the Clause 9 mechanisms. Stage 2 tests operation: records from Clause 8, results and follow-through from Clauses 9 and 10, and interviews up and down the org chart — executives for Clause 5, random staff for Clause 7.3 awareness. A useful planning fact: your certification body expects a full internal audit cycle and at least one management review completed before stage 2, which sets your minimum timeline more often than any control does.

Where to start

Read the clause posts in order if you're building an ISMS from scratch — the sequence mirrors the build. If you're diagnosing an existing ISMS before an audit, start from the back: Clause 9 and Clause 10 are where findings concentrate and where fixes pay off fastest. And when the clauses send you back to the controls they operate, the Annex A guide picks up from there.

Ready to Streamline Your Compliance?

Discover how AuditBadger can simplify your compliance management process.

The bottom line

ISO 27001 certification isn't a controls test with paperwork attached — it's a management-system test with controls attached. The seven mandatory clauses form one loop: define your world, commit your leadership, decide your risks, support the work, run it, check it, fix it. Build the loop honestly at whatever size you are, and Annex A becomes the easy part.

FAQ

Frequently asked questions

What are clauses 4-10 of ISO 27001? +

Clauses 4–10 are the mandatory management-system requirements of ISO/IEC 27001 — the part of the standard where certification is actually decided. Clause 4 (Context) defines your organization's issues, interested parties, and ISMS scope; Clause 5 (Leadership) places obligations directly on top management; Clause 6 (Planning) covers risk assessment, risk treatment, the Statement of Applicability, and security objectives; Clause 7 (Support) covers resources, competence, awareness, communication, and document control; Clause 8 (Operation) is where controls run day to day; Clause 9 (Performance evaluation) covers monitoring, internal audit, and management review; Clause 10 (Improvement) covers continual improvement and corrective action. Together they form a Plan-Do-Check-Act loop. Clauses 1–3 (scope, references, definitions) contain no requirements, which is why the auditable standard effectively starts at 4.

Can ISO 27001 clauses be excluded like Annex A controls? +

No — and this is the fundamental structural difference in the standard. Annex A controls apply through your risk treatment: you select what your risks require and justify every exclusion in the Statement of Applicability. Clauses 4–10 offer no such negotiation: every "shall" in the seven management-system clauses is mandatory for every certified organization regardless of size or industry. You can legitimately exclude a physical-media control you have no use for; you cannot exclude risk assessment, management review, internal audit, competence records, or corrective action. Any organization claiming conformity to ISO 27001 must meet all the requirements of clauses 4 through 10 — the standard says so explicitly, which is why certification is decided there rather than in Annex A.

What is the difference between ISO 27001 clauses and Annex A controls? +

The clauses (4–10) define the management system: the mandatory, non-excludable requirements for how you understand your context, lead, assess and treat risk, resource the work, operate, check yourself, and improve. Annex A is a reference catalogue of 93 security controls in four themes, applied selectively: Clause 6.1.3 requires you to determine the controls your risk treatment needs and compare them against Annex A to verify nothing necessary was overlooked, documenting inclusions and exclusions in the Statement of Applicability. A useful shorthand: Annex A is what you implement; clauses 4–10 are why you pass or fail. Most ISO 27001 content covers only the controls — but a certification audit spends its interviews and its findings disproportionately on the clauses.

What is stage 1 vs stage 2 in an ISO 27001 certification audit? +

Certification runs in two stages, both dominated by clauses 4–10. Stage 1 is primarily a documentation and readiness review: the auditor examines your ISMS scope, security policy, risk assessment methodology, Statement of Applicability, and evidence that internal audit and management review exist and have run — mostly Clause 4–7 territory plus the Clause 9 mechanisms. Stage 2 tests operation: records showing processes ran as planned (Clause 8), results and follow-through from monitoring, internal audit, and management review (Clause 9), the corrective-action loop (Clause 10), and interviews across the organization — executives for Clause 5, randomly selected staff for Clause 7.3 awareness. Certification bodies expect a full internal audit cycle and at least one management review completed before stage 2, which often sets your minimum timeline.

Keep reading

More implementation notes and operator context from the same topic area.

Next step

Ready to replace scattered compliance work?

See how AuditBadger turns policies, evidence, risks, and audit prep into one operating system for lean teams.

Start Subscription