ISO/IEC 27001:2022
Is read here with the ISO/IEC 27002:2022 guidance beside each control. It requires an information security policy and topic-specific policies (control 5.1) and, control by control, the rules, procedures and plans the Annex A controls are implemented through; the ISO/IEC 27002:2022 guidance beside each control says what the document is expected to say.
Tick ISO/IEC 27001:2022 on the register and these documents are expected and these clauses attach. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here. Open the standard.
The documents it expects
35 documents expectedEach becomes a line on the gap list when the regime is ticked and no document on the paste resolves to it (or to the parent it may fold into).
Governance and the management system
- Document control procedure (procedure): ISO 27001 5.1, ISO 27001 5.37, ISO 27001 7.5named. Owner: The information security lead (CISO or ISMS manager). Template: Document control policy.
- Information security policy (policy): ISO 27001 5.1, ISO 27001 5.2named. Owner: Top management (the board or the CEO), with the information security lead drafting. Template: Information security policy.
- Information security roles and responsibilities (record; accepted folded into the information security policy): ISO 27001 5.2, ISO 27001 5.3named. Owner: The information security lead (CISO or ISMS manager). No template yet.
- Internal audit charter and programme (plan): ISO 27001 9.2named. Owner: The head of internal audit, independent of the functions audited. Template: Internal audit policy.
- Legal and regulatory register (record): ISO 27001 5.31. Owner: Legal or the compliance officer. Template: Legal and regulatory register template.
- Management review procedure (procedure): ISO 27001 9.3named. Owner: The information security lead (CISO or ISMS manager). Template: Management review policy.
- Nonconformity and corrective action procedure (procedure): ISO 27001 10.2named. Owner: The information security lead (CISO or ISMS manager). Template: Corrective action policy.
- Risk management policy (policy): ISO 27001 6.1.2named, ISO 27001 6.1.3named. Owner: The information security lead (CISO or ISMS manager). Template: Risk management policy.
People
- Acceptable use policy (policy): ISO 27001 5.10. Owner: The information security lead (CISO or ISMS manager). Template: Acceptable use policy.
- HR security policy (joiners, movers, leavers) (policy): ISO 27001 6.1, ISO 27001 6.2, ISO 27001 6.5. Owner: The head of HR. Template: Human resources security policy.
- Remote working policy (policy): ISO 27001 6.7. Owner: The information security lead (CISO or ISMS manager). Template: Remote work security policy.
- Security awareness and training policy (policy): ISO 27001 6.3, ISO 27001 7.3named. Owner: The information security lead (CISO or ISMS manager). Template: Security awareness training policy.
Access and identity
- Access control policy (policy): ISO 27001 5.15, ISO 27001 5.18. Owner: The information security lead (CISO or ISMS manager). Template: Access control policy.
Assets, data and classification
- Asset management policy (policy): ISO 27001 5.9, ISO 27001 5.11. Owner: The head of IT operations. Template: Asset management policy.
- Information classification and handling policy (policy): ISO 27001 5.12, ISO 27001 5.13. Owner: The information security lead (CISO or ISMS manager). Template: Data classification policy.
- Information transfer policy (policy; accepted folded into the information classification and handling policy): ISO 27001 5.14. Owner: The information security lead (CISO or ISMS manager). No template yet.
- Media handling and disposal policy (policy; accepted folded into the asset management policy): ISO 27001 7.10, ISO 27001 7.14, ISO 27001 8.10. Owner: The head of IT operations. Template: Media handling and disposal policy.
- Records retention schedule (record): ISO 27001 5.33. Owner: Legal or the compliance officer. Template: Data retention policy.
Operations and technology
- Backup policy (policy): ISO 27001 8.13. Owner: The head of IT operations. Template: Backup and recovery policy.
- Change management procedure (procedure): ISO 27001 8.32. Owner: The head of IT operations. Template: Change management policy.
- Cloud security policy (policy): ISO 27001 5.23. Owner: The information security lead (CISO or ISMS manager). Template: Cloud security policy.
- Configuration management policy (policy): ISO 27001 8.9. Owner: The head of IT operations. Template: Configuration management policy.
- Cryptography policy (policy): ISO 27001 8.24. Owner: The information security lead (CISO or ISMS manager). Template: Encryption policy.
- Documented operating procedures (procedure): ISO 27001 5.37. Owner: The head of IT operations. No template yet.
- Endpoint device policy (policy): ISO 27001 8.1, ISO 27001 8.7. Owner: The head of IT operations. Template: Endpoint protection policy.
- Logging and monitoring standard (standard): ISO 27001 8.15, ISO 27001 8.16. Owner: The head of IT operations. Template: Security monitoring and logging policy.
- Network security policy (policy): ISO 27001 8.20, ISO 27001 8.21, ISO 27001 8.22. Owner: The head of IT operations. Template: Network security policy.
- Physical security policy (policy): ISO 27001 7.1, ISO 27001 7.2, ISO 27001 7.4. Owner: Facilities or office management, with the information security lead. Template: Physical security policy.
- Secure development policy (policy): ISO 27001 8.25, ISO 27001 8.26, ISO 27001 8.28. Owner: The head of engineering or the CTO. Template: Secure development policy.
- Vulnerability management policy (policy): ISO 27001 8.8. Owner: The head of IT operations. Template: Vulnerability management policy.
Suppliers and third parties
- Supplier and third-party security policy (policy): ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.21, ISO 27001 5.22. Owner: Procurement or the vendor manager, with the information security lead. Template: Third party risk management policy.
Resilience and incidents
- Business continuity plan (plan): ISO 27001 5.29. Owner: The business continuity manager or COO. Template: Business continuity plan.
- Disaster recovery plan (plan; accepted folded into the business continuity plan): ISO 27001 5.30, ISO 27001 8.14. Owner: The head of IT operations. Template: Disaster recovery plan.
- Incident response plan (plan): ISO 27001 5.24, ISO 27001 5.26, ISO 27001 5.27. Owner: The information security lead (CISO or ISMS manager). Template: Incident response plan.
Privacy
- Data protection policy (policy): ISO 27001 5.34. Owner: The data protection officer or privacy lead. Template: Data protection policy.
Every document it reaches
73 types carry at least one of its clausesThe guidance beside every control
ISO/IEC 27002:2022 is quoted beside each ISO/IEC 27001:2022 control as what the guidance expects the document to say; control 5.1's guidance names the topic-specific policies an organisation commonly writes, which is where most of this regime's expected list comes from. Named and not quoted: SOC 2 (CC1 and CC5 name the same documents; not quoted here); PCI DSS Requirement 12 (the security policy and its topic documents; not quoted here).
The clauses, quoted
71 of 93 in the frameworkRequirement text quoted from the standards themselves, read clause by clause against the copy we hold: our statement of each clause, not the instrument verbatim.
ISO 27001 5.1 Policies for information securityWrite, approve and publish a top-level security policy plus topic-specific policies, and review them on a set cadence and after major change.
What the ISO 27002 guidance expects the document to say: Requires an information security policy together with supporting topic specific policies. These must be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed on a planned cycle and whenever significant change occurs.
Common gap: Policies not formally approved by senior management
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.10 Acceptable use of information and other associated assetsDefine and enforce rules for how information and assets may be used and handled.
What the ISO 27002 guidance expects the document to say: Requires rules for acceptable use, and procedures for handling information and its associated assets, to be identified, documented and put into effect.
Common gap: Policy not reviewed or updated regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.11 Return of assetsRecover all organizational assets on exit or role change.
What the ISO 27002 guidance expects the document to say: Requires personnel and other relevant interested parties to return all organisational assets in their possession when employment, a contract or an agreement changes or ends.
Common gap: Missing signatures on return forms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.12 Classification of informationClassify information by confidentiality, integrity, availability and interested-party requirements.
What the ISO 27002 guidance expects the document to say: Requires information to be classified according to the organisation's information security needs, judged on confidentiality, integrity and availability and on the requirements of relevant interested parties.
Common gap: Classification levels not aligned with business impact
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.13 Labelling of informationLabel information consistently with the classification scheme so handling rules can follow it.
What the ISO 27002 guidance expects the document to say: Requires a matching set of information labelling procedures to be developed and implemented, so that information carries markings consistent with the classification scheme the organisation has adopted.
Common gap: Labels applied inconsistently across departments
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.14 Information transferPut rules, procedures or agreements in place for every way information moves, inside and outside the organization.
What the ISO 27002 guidance expects the document to say: Requires transfer rules, procedures or agreements to be in place for every type of transfer facility, covering transfers within the organisation and between the organisation and outside parties.
Common gap: Reliance on informal verbal agreements
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.15 Access controlSet rules for physical and logical access based on business and security requirements.
What the ISO 27002 guidance expects the document to say: Requires rules governing access to information and the assets tied to it, covering both physical entry and logical access, to be established and implemented on the basis of business need and security requirements.
Common gap: Infrequent review of access rights
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.16 Identity managementManage the full life cycle of identities.
What the ISO 27002 guidance expects the document to say: Requires the full life cycle of identities to be managed, from creation through change to removal.
Common gap: relying on manual spreadsheets for provisioning
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.17 Authentication informationControl allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.
What the ISO 27002 guidance expects the document to say: Requires a management process to control how authentication information is issued and looked after over time, including guidance to personnel on handling it appropriately.
Common gap: Policies exist but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.18 Access rightsProvision, review, modify and remove access rights in line with the access control policy.
What the ISO 27002 guidance expects the document to say: Requires access rights to information and other associated assets to be provisioned, reviewed, modified and removed in accordance with the organisation's topic specific policy and rules on access control.
Common gap: Reviews lack documented corrective actions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
What the ISO 27002 guidance expects the document to say: Requires processes and procedures to be defined and implemented for managing the information security risks that arise from using suppliers' products or services.
Common gap: Treating all suppliers as low risk
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.2 Information security roles and responsibilitiesName who owns what in security and make the allocation explicit and traceable.
What the ISO 27002 guidance expects the document to say: Requires information security roles and responsibilities to be defined and allocated in line with what the organisation actually needs, so ownership of each security duty is explicit rather than assumed.
Common gap: Roles not updated after staff changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
What the ISO 27002 guidance expects the document to say: Requires the relevant information security requirements to be established and agreed with each supplier, scaled to the type of supplier relationship involved.
Common gap: missing explicit security clauses
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
What the ISO 27002 guidance expects the document to say: Requires processes and procedures to be defined and implemented to manage information security risk arising along the supply chain for ICT products and services.
Common gap: Treating supplier security as one-off check
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.22 Monitoring, review and change management of supplier servicesRegularly monitor, review and manage change in supplier security practice and service delivery.
What the ISO 27002 guidance expects the document to say: Requires supplier information security practice and service delivery to be monitored, reviewed and evaluated on a regular basis, and requires change within them to be managed.
Common gap: relying on informal verbal updates
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
What the ISO 27002 guidance expects the document to say: Requires processes for the acquisition, use, management and exit of cloud services to be established in line with the organisation's own information security requirements. Supporting material frames the aim as preserving confidentiality, integrity and availability of information assets held in cloud services.
Common gap: Relying solely on provider's security assurances
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.24 Information security incident management planning and preparationDefine incident roles, processes and readiness before an incident happens.
What the ISO 27002 guidance expects the document to say: Requires the organisation to plan and prepare for incident handling ahead of time. Incident management processes, plus the roles and responsibilities attached to them, must be defined, put in place and communicated.
Common gap: roles are defined but not formally assigned or approved
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.25 Assessment and decision on information security eventsTriage security events and decide which become incidents.
What the ISO 27002 guidance expects the document to say: Requires information security events to be assessed and a decision taken on whether each event is to be categorised as an information security incident.
Common gap: no documented triage steps
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.26 Response to information security incidentsRespond to incidents according to the documented procedures.
What the ISO 27002 guidance expects the document to say: Requires information security incidents to be responded to in accordance with documented procedures, rather than improvised case by case.
Common gap: Plans not tested regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.27 Learning from information security incidentsFeed lessons from incidents back into stronger controls.
What the ISO 27002 guidance expects the document to say: Requires knowledge gained from information security incidents to be fed back into strengthening and improving the information security controls.
Common gap: Root cause analysis limited to symptoms
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.28 Collection of evidenceHave procedures to identify, collect, acquire and preserve evidence related to security events.
What the ISO 27002 guidance expects the document to say: Requires procedures to be established and used for identifying evidence relating to information security events, then collecting, acquiring and preserving it.
Common gap: Procedures not aligned with legal requirements
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.29 Information security during disruptionPlan how to keep information security at the right level during disruption.
What the ISO 27002 guidance expects the document to say: Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.
Common gap: Plans not updated after tests
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.30 ICT readiness for business continuityPlan, implement, maintain and test ICT readiness against business continuity objectives.
What the ISO 27002 guidance expects the document to say: Requires ICT readiness to be planned, implemented, maintained and tested against business continuity objectives and ICT continuity requirements. Supporting material frames this as ICT infrastructure and resources being resilient enough to carry business operations through disruption.
Common gap: Testing frequency not aligned with risk
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.31 Legal, statutory, regulatory and contractual requirementsIdentify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
What the ISO 27002 guidance expects the document to say: Requires the legal, statutory, regulatory and contractual requirements bearing on information security, and the organisation's approach to meeting them, to be identified, documented and kept up to date.
Common gap: outdated legal register
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.33 Protection of recordsProtect records from loss, destruction, falsification, unauthorized access and unauthorized release.
What the ISO 27002 guidance expects the document to say: Requires records to be protected against loss, destruction, falsification, unauthorised access and unauthorised release.
Common gap: retention schedules not aligned with legal requirements
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
What the ISO 27002 guidance expects the document to say: Requires the requirements for preserving privacy and protecting personally identifiable information to be identified and met, in line with applicable laws, regulations and contractual requirements.
Common gap: Missing documented consent for all data subjects
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.37 Documented operating proceduresDocument operating procedures for information processing facilities and make them available to those who need them.
What the ISO 27002 guidance expects the document to say: Requires the operating procedures used to run information processing facilities to be written down and made available to the personnel who need them.
Common gap: outdated procedures still in use
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.7 Threat intelligenceCollect and analyse threat information and turn it into decisions, not just unread feeds.
What the ISO 27002 guidance expects the document to say: Requires information about information security threats to be collected and analysed so that it becomes usable threat intelligence. Supporting material frames this as gathering and applying intelligence proactively, to identify, assess and mitigate emerging threats before they are realised.
Common gap: Collecting feeds without validation
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 5.9 Inventory of information and other associated assetsMaintain a current asset inventory with owners.
What the ISO 27002 guidance expects the document to say: Requires an inventory of information and of the other assets associated with it to be developed and kept current, and requires that inventory to record ownership of each entry.
Common gap: Outdated entries in inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.1 ScreeningBackground-check candidates and personnel proportional to risk and classification, within the law.
What the ISO 27002 guidance expects the document to say: Requires background verification checks on all candidates for personnel before they join and on an ongoing basis afterwards, within the bounds of applicable laws, regulations and ethics, and proportionate to business requirements, the classification of information to be accessed and the perceived risk.
Common gap: One‑size‑fits‑all screening regardless of risk
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.2 Terms and conditions of employmentState the security responsibilities of both the person and the organization in the employment agreement.
What the ISO 27002 guidance expects the document to say: Requires employment contractual agreements to state what the individual and the organisation are each responsible for with respect to information security.
Common gap: missing security clauses in standard contracts
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.3 Information security awareness, education and trainingGive personnel and relevant parties appropriate, current security training for their role.
What the ISO 27002 guidance expects the document to say: Requires personnel and relevant interested parties to receive appropriate information security awareness, education and training, plus regular updates on the security policy, topic specific policies and procedures relevant to their job function. Supporting SME guidance separates merely informing people from making them aware and from training those holding specific roles, and treats repetition as necessary because objectives, threats and available measures keep changing.
Common gap: Training not aligned to specific job functions
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.4 Disciplinary processHave a formal, communicated disciplinary process for security policy violations.
What the ISO 27002 guidance expects the document to say: Requires a formalised disciplinary process, communicated in advance, so that action can be taken where personnel or other relevant parties have breached information security policy.
Common gap: Policy exists but not communicated to staff
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.5 Responsibilities after termination or change of employmentDefine and enforce security responsibilities that remain valid after an exit or role change.
What the ISO 27002 guidance expects the document to say: Requires the security duties and responsibilities that survive the end of employment, or a move to a different role, to be defined, communicated to the people concerned and enforced.
Common gap: Delayed revocation of privileged accounts
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.6 Confidentiality or non-disclosure agreementsIdentify, document, review and sign NDAs that reflect the organization's protection needs.
What the ISO 27002 guidance expects the document to say: Requires confidentiality or non-disclosure agreements matching the organisation's need to protect information to be identified, documented, reviewed on a regular basis and signed by personnel and by other relevant parties.
Common gap: NDAs not refreshed when data classification changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.7 Remote workingApply security measures when people access, process or store information outside the organization's premises.
What the ISO 27002 guidance expects the document to say: Requires security measures to be implemented when personnel work remotely, protecting information that is accessed, processed or stored outside the organisation's premises.
Common gap: Missing MFA for remote access
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 6.8 Information security event reportingGive people an easy, timely channel to report observed or suspected security events.
What the ISO 27002 guidance expects the document to say: Requires a mechanism through which personnel can report security events they have observed or suspect, using appropriate channels and without delay.
Common gap: no anonymous reporting option
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.1 Physical security perimetersDefine and use security perimeters to protect areas holding information and assets.
What the ISO 27002 guidance expects the document to say: Requires security perimeters to be defined and used to protect any area holding information and the assets associated with it.
Common gap: outdated floor plans
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.10 Storage mediaManage storage media across acquisition, use, transport and disposal per classification and handling rules.
What the ISO 27002 guidance expects the document to say: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.
Common gap: No documented classification for media
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.14 Secure disposal or re-use of equipmentVerify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.
What the ISO 27002 guidance expects the document to say: Requires items of equipment containing storage media to be verified before disposal or re-use, confirming that sensitive data and licensed software have been removed or securely overwritten.
Common gap: Relying on visual inspection only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.2 Physical entryProtect secure areas with appropriate entry controls and access points.
What the ISO 27002 guidance expects the document to say: Requires secure areas to be protected by appropriate entry controls and by control over the access points themselves.
Common gap: Use of informal sign-in sheets instead of controlled logs
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.4 Physical security monitoringContinuously monitor premises for unauthorized physical access.
What the ISO 27002 guidance expects the document to say: Requires premises to be monitored continuously for unauthorised physical access. Supporting material frames this as continuous monitoring of physical security controls so that unauthorised entry and other physical security incidents are detected and responded to.
Common gap: logs not retained for required period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.5 Protecting against physical and environmental threatsDesign and apply protection against natural disasters and other physical and environmental threats.
What the ISO 27002 guidance expects the document to say: Requires designed and implemented protection against physical and environmental threats. These include natural disasters as well as other physical threats to infrastructure, whether deliberate or accidental.
Common gap: risk assessments not updated after infrastructure changes
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.7 Clear desk and clear screenEnforce clear-desk rules for papers and media and clear-screen rules for processing facilities.
What the ISO 27002 guidance expects the document to say: Requires defined and enforced rules for clearing papers and removable storage media from desks, and for clearing the screens of facilities used to process information.
Common gap: Policy exists but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.1 User end point devicesProtect information stored on, processed by or reachable through user endpoints.
What the ISO 27002 guidance expects the document to say: Requires information stored on, processed by or accessible through user endpoint devices to be protected.
Common gap: Incomplete device inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.10 Information deletionDelete information in systems, devices and media when no longer required.
What the ISO 27002 guidance expects the document to say: Requires information held in information systems, devices or any other storage media to be deleted once it is no longer required. Supporting material frames this as procedures for secure deletion at the point the information ceases to be needed.
Common gap: Retaining data beyond approved period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.11 Data maskingUse data masking in line with access policy, business need and applicable law.
What the ISO 27002 guidance expects the document to say: Requires data masking to be used in accordance with the topic specific policy on access control, other related topic specific policies and business requirements, taking applicable legislation into account. Supporting material notes the common case of protecting sensitive data used for testing or development.
Common gap: Masking applied inconsistently across data stores
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.13 Information backupMaintain and regularly test backups of information, software and systems per the backup policy.
What the ISO 27002 guidance expects the document to say: Requires backup copies of information, software and systems to be maintained and regularly tested, in line with the agreed topic specific policy on backup. Supporting SME guidance treats regular creation of backups together with tested recovery as the substance of the control, not the copy on its own.
Common gap: infrequent restore testing
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.14 Redundancy of information processing facilitiesBuild enough redundancy into processing facilities to meet availability requirements.
What the ISO 27002 guidance expects the document to say: Requires information processing facilities to be implemented with redundancy sufficient to meet the availability requirements placed on them.
Common gap: reliance on undocumented manual backups
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.15 LoggingProduce, store, protect and analyse logs of activities, exceptions and faults.
What the ISO 27002 guidance expects the document to say: Requires logs to be produced, stored, protected and analysed, covering activities, exceptions, faults and any other event of relevance. Older source material adds that records of user activity, exceptions and security events should be retained for an agreed period to support later investigation and access control monitoring, and that faults should be logged, analysed and acted on.
Common gap: Inconsistent log collection across systems
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.16 Monitoring activitiesMonitor networks, systems and applications for anomalies and act on potential incidents.
What the ISO 27002 guidance expects the document to say: Requires networks, systems and applications to be monitored for anomalous behaviour, with appropriate action taken to evaluate whether what is observed constitutes an information security incident. Secondary commentary notes the deliberate shift to anomalous behaviour as the trigger, responding to cloud era risk.
Common gap: alerts not correlated across sources
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.19 Installation of software on operational systemsSecurely manage software installation on production systems.
What the ISO 27002 guidance expects the document to say: Requires procedures and measures to be implemented to manage software installation on operational systems securely. Secondary commentary notes that this replaces a narrower restriction on software installation and is oriented to remote working and mobile devices.
Common gap: Missing formal approval for installations
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.2 Privileged access rightsRestrict and manage the allocation and use of privileged access.
What the ISO 27002 guidance expects the document to say: Requires the allocation and use of privileged access rights to be restricted and actively managed.
Common gap: Outdated privileged account inventory
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.20 Networks securitySecure, manage and control networks and network devices.
What the ISO 27002 guidance expects the document to say: Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.
Common gap: outdated topology diagrams
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.21 Security of network servicesIdentify, implement and monitor security mechanisms and service levels for network services.
What the ISO 27002 guidance expects the document to say: Requires the security mechanisms for network services, along with their service levels and the requirements placed on them, to be identified, implemented and monitored, whether provision is in house or outsourced.
Common gap: Out‑of‑date service inventory missing recent cloud assets
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.22 Segregation of networksSegregate groups of services, users and systems in the network.
What the ISO 27002 guidance expects the document to say: Requires segregation within the organisation's networks, keeping groups of information services, of users and of systems apart from one another.
Common gap: Informal or outdated network maps used instead of documented diagrams
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.23 Web filteringManage access to external websites to reduce exposure to malicious content.
What the ISO 27002 guidance expects the document to say: Requires access to external websites to be managed so as to reduce exposure to malicious content.
Common gap: Outdated URL category lists
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.24 Use of cryptographyDefine and implement rules for effective use of cryptography and key management.
What the ISO 27002 guidance expects the document to say: Requires defined and implemented rules on using cryptography effectively, including how cryptographic keys are managed.
Common gap: Missing documented key lifecycle
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.25 Secure development life cycleEstablish and apply rules for secure development of software and systems.
What the ISO 27002 guidance expects the document to say: Requires rules covering the secure development of both software and systems to be established and applied.
Common gap: Policy exists but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.26 Application security requirementsIdentify, specify and approve security requirements when developing or acquiring applications.
What the ISO 27002 guidance expects the document to say: Requires information security requirements to be identified, specified and approved when applications are being developed or acquired.
Common gap: Security requirements not formally approved
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.27 Secure system architecture and engineering principlesEstablish and apply secure engineering principles to system development.
What the ISO 27002 guidance expects the document to say: Requires principles for engineering secure systems to be established, documented and maintained, then applied across all information system development work.
Common gap: Design reviews not documented
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.28 Secure codingApply secure coding principles to software development.
What the ISO 27002 guidance expects the document to say: Requires secure coding principles to be applied to software development.
Common gap: inconsistent application of coding standards
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.29 Security testing in development and acceptanceDefine and run security testing across the development life cycle.
What the ISO 27002 guidance expects the document to say: Requires security testing processes to be defined and implemented within the development life cycle.
Common gap: testing only after release
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.3 Information access restrictionRestrict access to information and assets per the access control policy.
What the ISO 27002 guidance expects the document to say: Requires access to information and other associated assets to be restricted in accordance with the established topic specific policy on access control.
Common gap: infrequent or missing access reviews
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.30 Outsourced developmentDirect, monitor and review outsourced system development.
What the ISO 27002 guidance expects the document to say: Requires the organisation to direct, monitor and review the activities involved in outsourced system development. Secondary commentary notes that explicit direction and review were added in the 2022 revision in response to third party risk.
Common gap: contracts lack specific security obligations
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.32 Change managementPut changes to facilities and systems through change management procedures.
What the ISO 27002 guidance expects the document to say: Requires change management procedures to govern changes made to information systems and to the facilities that process information. Older source material adds that changes should be controlled by formal, documented and enforced procedures, with risk assessed as part of the process.
Common gap: missing formal approval
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.33 Test informationSelect, protect and manage test information appropriately.
What the ISO 27002 guidance expects the document to say: Requires test information to be appropriately selected, protected and managed.
Common gap: Treating test data like production data without classification
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.5 Secure authenticationImplement authentication technologies and procedures based on access restrictions and policy.
What the ISO 27002 guidance expects the document to say: Requires secure authentication technologies and procedures to be implemented, driven by the information access restrictions and the topic specific policy on access control.
Common gap: Reliance on static passwords only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.7 Protection against malwareImplement malware protection backed by user awareness.
What the ISO 27002 guidance expects the document to say: Requires malware protection to be put in place and reinforced by suitable awareness among users.
Common gap: Outdated malware signatures not regularly updated
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.8 Management of technical vulnerabilitiesObtain vulnerability information, evaluate exposure, and take appropriate remediation.
What the ISO 27002 guidance expects the document to say: Requires information about technical vulnerabilities in the information systems in use to be obtained, the organisation's exposure to them to be evaluated, and appropriate measures to be taken. Older source material sets out the surrounding process: named roles and responsibilities, identified information sources, a defined reaction timeline, assessment of the risk posed by the vulnerability against the risk of applying the patch, testing before deployment, alternative measures where no patch exists, an audit log of actions taken, and highest risk systems addressed first.
Common gap: Relying on ad-hoc scans only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.9 Configuration managementEstablish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
What the ISO 27002 guidance expects the document to say: Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a standing process that keeps systems configured securely and consistently.
Common gap: outdated baselines
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
See what it expects of your list
Paste the policy list, tick the regime, and every document it reaches carries its clauses, with the ones it expects and the list does not carry named. Eight documents free, no account.
Build a register