HomeBlogCompliance

ISO 27001 Checklist: Requirements, Annex A Controls and Audit Readiness

Pixel-art illustration of a robot holding a tablet on a busy city sidewalk, with yellow taxis and pedestrians at a crosswalk behind it

An ISO 27001 checklist has two halves. The first is the management system in clauses 4 to 10, which you must meet in full: the standard says excluding any of those requirements is not acceptable when an organization claims conformity. The second is Annex A, a reference list of 93 controls in four themes, which you select through your risk assessment instead of adopting them all by default.

We help companies build and run these controls through our vCISO services; we are not a certification body. This checklist follows ISO/IEC 27001:2022, the current edition, together with ISO's free Amendment 1:2024, climate action changes. For budgeting, read our ISO 27001 cost guide, and for how Annex A relates to the separate guidance standard, see ISO 27001 vs 27002.

What are the ISO 27001 requirements, clause by clause?

The requirements are the clauses. Clauses 1 to 3 cover scope, references and terms; clauses 4 to 10 hold what the certification auditor tests. Use this table as the first half of your checklist. The middle column is our plain-language reading of what to have in place, not the standard's text, so check each line against your copy of the standard.

ClauseWhat to have in placeEvidence to keep
4.1 The organization and its contextThe internal and external issues that affect what your ISMS must achieveA dated context analysis
4.2 Interested partiesWho has a stake, such as customers, regulators, staff and suppliers, what they require, and which of those requirements the ISMS will addressAn interested parties register
4.3 Scope of the ISMSThe boundary: sites, teams, systems, services and the interfaces with outside partiesAn approved scope statement
4.4 The ISMSThe processes that make up the ISMS and how they connectA process map or short ISMS manual
5.1 Leadership and commitmentTop management sets direction, provides resources and follows resultsMinutes and resource decisions
5.2 PolicyAn information security policy, approved and communicatedThe signed policy and staff acknowledgments
5.3 Roles, responsibilities and authoritiesNamed owners for the ISMS and for security tasksRole descriptions or a responsibility matrix
6.1 Risks and opportunities, risk assessment and risk treatmentA repeatable risk method, a risk register with owners, treatment decisions and the controls chosenMethod, register, treatment plan and Statement of Applicability
6.2 ObjectivesMeasurable security objectives with plans, owners and datesAn objectives tracker
7.1 to 7.4 Resources, competence, awareness, communicationBudget and people, the skills each role needs, security awareness, and who communicates whatTraining and competence records, a communication plan
7.5 Documented informationControl of documents and records: versions, approvals, storage and accessA document register
8.1 Operational planning and controlThe ISMS processes run as plannedOperating records
8.2 and 8.3 Risk assessment and treatmentRisk assessments repeated on a schedule and after major change, and treatment plans carried outDated register updates and completed actions
9.1 Monitoring, measurement, analysis and evaluationWhat you measure, how and when, and who reviews the resultsMetrics reports
9.2 Internal auditAn internal audit programme that covers the ISMS over timeAudit plan, reports and findings
9.3 Management reviewTop management reviews the ISMS and records its decisionsReview minutes with actions
10.1 and 10.2 Improvement, nonconformity and corrective actionProblems fixed, causes found and corrective actions trackedA corrective action log

How many controls are in ISO 27001 Annex A?

Annex A lists 93 controls in four themes. They match the controls that ISO/IEC 27002:2022 explains one by one, and ISO aligned the 2022 edition of 27001 with it. This is the full controls list, by theme:

ThemeControls
Organizational controls (37)5.1 Policies for information security; 5.2 Information security roles and responsibilities; 5.3 Segregation of duties; 5.4 Management responsibilities; 5.5 Contact with authorities; 5.6 Contact with special interest groups; 5.7 Threat intelligence; 5.8 Information security in project management; 5.9 Inventory of information and other associated assets; 5.10 Acceptable use of information and other associated assets; 5.11 Return of assets; 5.12 Classification of information; 5.13 Labelling of information; 5.14 Information transfer; 5.15 Access control; 5.16 Identity management; 5.17 Authentication information; 5.18 Access rights; 5.19 Information security in supplier relationships; 5.20 Addressing information security within supplier agreements; 5.21 Managing information security in the ICT supply chain; 5.22 Monitoring, review and change management of supplier services; 5.23 Information security for use of cloud services; 5.24 Information security incident management planning and preparation; 5.25 Assessment and decision on information security events; 5.26 Response to information security incidents; 5.27 Learning from information security incidents; 5.28 Collection of evidence; 5.29 Information security during disruption; 5.30 ICT readiness for business continuity; 5.31 Legal, statutory, regulatory and contractual requirements; 5.32 Intellectual property rights; 5.33 Protection of records; 5.34 Privacy and protection of PII; 5.35 Independent review of information security; 5.36 Compliance with policies, rules and standards for information security; 5.37 Documented operating procedures
People controls (8)6.1 Screening; 6.2 Terms and conditions of employment; 6.3 Information security awareness, education and training; 6.4 Disciplinary process; 6.5 Responsibilities after termination or change of employment; 6.6 Confidentiality or non-disclosure agreements; 6.7 Remote working; 6.8 Information security event reporting
Physical controls (14)7.1 Physical security perimeters; 7.2 Physical entry; 7.3 Securing offices, rooms and facilities; 7.4 Physical security monitoring; 7.5 Protecting against physical and environmental threats; 7.6 Working in secure areas; 7.7 Clear desk and clear screen; 7.8 Equipment siting and protection; 7.9 Security of assets off-premises; 7.10 Storage media; 7.11 Supporting utilities; 7.12 Cabling security; 7.13 Equipment maintenance; 7.14 Secure disposal or re-use of equipment
Technological controls (34)8.1 User endpoint devices; 8.2 Privileged access rights; 8.3 Information access restriction; 8.4 Access to source code; 8.5 Secure authentication; 8.6 Capacity management; 8.7 Protection against malware; 8.8 Management of technical vulnerabilities; 8.9 Configuration management; 8.10 Information deletion; 8.11 Data masking; 8.12 Data leakage prevention; 8.13 Information backup; 8.14 Redundancy of information processing facilities; 8.15 Logging; 8.16 Monitoring activities; 8.17 Clock synchronization; 8.18 Use of privileged utility programs; 8.19 Installation of software on operational systems; 8.20 Networks security; 8.21 Security of network services; 8.22 Segregation of networks; 8.23 Web filtering; 8.24 Use of cryptography; 8.25 Secure development life cycle; 8.26 Application security requirements; 8.27 Secure system architecture and engineering principles; 8.28 Secure coding; 8.29 Security testing in development and acceptance; 8.30 Outsourced development; 8.31 Separation of development, test and production environments; 8.32 Change management; 8.33 Test information; 8.34 Protection of information systems during audit testing

How do you implement ISO 27001 controls, step by step?

Start from risk, not from the list. ISO/IEC 27002 says determining controls depends on the decisions an organization makes after a risk assessment, and that controls can come from any source. A workable order for a small company:

  1. Set the scope and list the information and assets inside it, which is also control 5.9.
  2. Assess risk with a method you can repeat: what could go wrong, how likely it is, how bad it would be, and who owns each risk.
  3. Decide treatment for each risk and choose the controls that carry it out.
  4. Compare your choices with Annex A so nothing necessary is missed, and record which controls apply in your Statement of Applicability.
  5. Implement with owners. Every control gets an owner, a procedure and a record that proves it ran.
  6. Measure, audit and review under clauses 9.1 to 9.3, then correct what fails under clause 10.2.

For many small companies, much of Annex A maps onto systems they already run. Controls 5.15 to 5.18 and 8.5 become named accounts, multifactor authentication and joiner, mover and leaver steps with periodic access reviews. Controls 8.1 and 8.7 become managed devices with endpoint protection; 8.8 becomes patching and vulnerability scans; 8.13 becomes backups with restore tests; 8.15 and 8.16 become central logs that someone reviews. Controls 5.24 to 5.28 become a written incident response process, and 5.19 to 5.23 a supplier and cloud service review each year.

What evidence will the certification auditor ask for?

  • The scope statement, the information security policy and the roles.
  • The risk method, the risk register, the treatment plan and the Statement of Applicability.
  • Security objectives and how you measure them.
  • Training and awareness records.
  • Records that controls operated: access reviews, change tickets, backup and restore tests, patch reports, incident logs and supplier reviews.
  • Internal audit reports, management review minutes and the corrective action log.

Date every record and keep final versions. An undated screenshot or a draft policy proves little to an auditor sampling across months.

What should an ISO 27001 internal audit checklist include?

Clause 9.2 requires internal audits, and clause 9.2.2 an internal audit programme. ISO 19011, updated in 2026, gives guidance on managing audit programmes and conducting management system audits. A checklist for each internal audit:

  • Define the audit's scope and criteria: which clauses, which Annex A controls, which sites.
  • Choose an auditor who did not build or run the controls being audited.
  • Over the audit cycle, cover every clause from 4 to 10 and every control in the Statement of Applicability.
  • Sample records from across the period, not just the latest month.
  • Interview the people who run each process and watch at least one control operate.
  • Record each finding against the requirement it breaches, with the evidence.
  • Report results to the managers responsible and feed nonconformities into corrective action.

Are you ready for the certification audit?

  • The scope is approved and stable.
  • The risk assessment and treatment are complete, and the Statement of Applicability is approved.
  • Policies are approved and acknowledged by staff.
  • Controls have run long enough to produce records.
  • At least one full internal audit is complete.
  • A management review has been held and minuted.
  • Every open nonconformity has an owner and a date.
  • You have compared several certification bodies and checked their accreditation.

Who maintains the ISO 27001 checklist?

The ISMS owner keeps it current and reports to top management through the management review. Update it whenever the scope, a system or a supplier changes, after every internal audit and after any security incident. Treat it as a working document, not a one-time project.

How does NetSys help with ISO 27001?

We align client environments to frameworks including ISO 27001, the NIST Cybersecurity Framework and CIS Controls. Through our vCISO service, a senior security lead sets risk priorities, writes the policies, handles vendor and insurer questions and reports to leadership, while your IT team, another provider or NetSys engineers carry out the fixes. For managed clients, much of the control evidence comes from identity, devices, email and backups we already run. Certification comes from an independent certification body; mapping your program to ISO 27001 is not a certification, and NetSys claims none.

Want a second opinion on your gap list? Book a call and we will go through your scope and risk register with you.

Frequently asked questions

What are the ISO 27001 requirements?

They are clauses 4 to 10 of ISO/IEC 27001:2022: context and scope, leadership, planning including risk assessment and treatment, support, operation, performance evaluation including internal audit and management review, and improvement. An organization claiming conformity cannot exclude any of them. The Annex A controls are selected through risk treatment.

How do you implement ISO 27001 controls?

Assess risk first, decide how to treat each risk, then choose controls from Annex A or elsewhere to carry out that treatment. Give each control an owner, a written procedure and a record it produces, and use ISO/IEC 27002 for detailed guidance on each control. Check them through internal audits and the management review.

Do we have to implement all 93 Annex A controls?

Not automatically. Annex A is a reference list that you compare against your risk treatment, and your Statement of Applicability records which controls apply. A company that writes no software, for example, has little use for the secure coding controls. Exclusions need a defensible reason, because the auditor will ask.

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 states the requirements you are certified against, including the Annex A reference list of controls. ISO/IEC 27002 is guidance: 152 pages explaining each of the same 93 controls, with attributes to help you sort them. You are certified to 27001, not 27002.

Is there an ISO 27001 checklist in Excel?

Copy the two tables above into a spreadsheet: one row per clause and one row per Annex A control, with columns for owner, status, evidence location and next review date. That sheet becomes the working draft of your Statement of Applicability and your internal audit plan.

Can NetSys certify us to ISO 27001?

No. ISO does not certify anyone either; certification comes from an external certification body, ideally an accredited one. We help build and run the controls and the evidence, and an independent certification body performs the audit.

Sources and further reading

vCISO Services

Discuss vciso services for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.