Fundamentals
ISO 27001:2022: what an ISMS actually has to deliver
The standard does not demand a museum of documents. It demands a steerable system for information risks, responsibilities and improvement.
7 minute read · Content as of 21.07.2026
The management system is what is actually audited
ISO/IEC 27001 describes requirements for an information security management system. What gets certified is therefore not a single firewall or a set of policies, but the organisation's ability to identify, treat and monitor information risks systematically.
Technical controls matter. But they only become defensible through a defined scope, clear responsibilities, documented decisions and a recurring improvement process.
Clauses 4 to 10 form a chain of steering
Context and scope set the frame. Leadership provides mandate and resources. Planning translates risks into objectives and controls. Support and operation bring these decisions into daily work. Evaluation and improvement close the loop.
- Define the scope and interested parties in a traceable way
- Assess and treat risks with a consistent method
- Verify effectiveness through metrics, audits and management review
- Close deviations with cause, correction and evidence of effectiveness
The best starting point is a defensible scope
Many programmes start with a list of controls. It is more practical to first determine the service context that needs protection: products, processes, information, sites, platforms and dependencies. Only then can you decide which risks and controls are relevant.
Sources used
- ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
- ISMS practice patterns · KaitoSec