Optional and mandatory clauses
Overview of ISO 27001 requirements
Clauses 4-10 of ISO 27001 are mandatory and non-negotiable. They are the core structure of the ISO 27001 standard and must be implemented by every organization.
Clause 4: Context of the organization
Clause 5: Leadership
Clause 6: Planning
Clause 7: Support
Clause 8: Operation
Clause 9: Performance evaluation
Clause 10: Improvement
Annex A controls are, however, optional and contain 93 controls categorized into four themes. You select controls based on your organization’s specific risks and needs, then document your decisions in the Statement of Applicability (SoA).
Clause 4: Context of the organization
Clause 5: Leadership
Clause 6: Planning
Clause 7: Support
Clause 8: Operation
Clause 9: Performance evaluation
Clause 10: Improvement
Annex A controls are, however, optional and contain 93 controls categorized into four themes. You select controls based on your organization’s specific risks and needs, then document your decisions in the Statement of Applicability (SoA).
ISO 27001 Controls: A Guide to Implementing Annex A Controls
ISO 27001 Mandatory Documents [Free Template]
ISO 27001 Requirements – A Comprehensive List [+Free Template]
ISO 27001 Series
Basics
Certification Process
Policies & Management
Risk Management
Resources & Templates
Sprinto: Your ally for all things compliance, risk, governance