Skip to content

Fundamentals

ISO 27001:2022: what an ISMS actually has to deliver

The standard does not demand a museum of documents. It demands a steerable system for information risks, responsibilities and improvement.

Back to ISO 27001

7 minute read · Content as of 21.07.2026

The management system is what is actually audited

ISO/IEC 27001 describes requirements for an information security management system. What gets certified is therefore not a single firewall or a set of policies, but the organisation's ability to identify, treat and monitor information risks systematically.

Technical controls matter. But they only become defensible through a defined scope, clear responsibilities, documented decisions and a recurring improvement process.

Clauses 4 to 10 form a chain of steering

Context and scope set the frame. Leadership provides mandate and resources. Planning translates risks into objectives and controls. Support and operation bring these decisions into daily work. Evaluation and improvement close the loop.

  • Define the scope and interested parties in a traceable way
  • Assess and treat risks with a consistent method
  • Verify effectiveness through metrics, audits and management review
  • Close deviations with cause, correction and evidence of effectiveness

The best starting point is a defensible scope

Many programmes start with a list of controls. It is more practical to first determine the service context that needs protection: products, processes, information, sites, platforms and dependencies. Only then can you decide which risks and controls are relevant.

Sources used

Back to ISO 27001