Many organisations approach ISO/IEC 27001:2022 as a documentation exercise. They write a stack of policies, drop them in a shared drive, and expect a certificate. Auditors see straight through this. An Information Security Management System (ISMS) is a living system, and certification is granted on evidence that it operates, improves and is led from the top.
This article explains what the ISMS actually consists of, how the management system clauses fit together, and how to build one that an external auditor will trust. For broader context on the standard, see our ISO 27001 service page.
The ISMS is the clauses, not just the controls
ISO/IEC 27001:2022 has two distinct parts. The mandatory requirements live in clauses 4 through 10. Annex A is a reference set of 93 controls you draw on as treatments. Organisations fixate on Annex A and underbuild the clauses, then fail certification on the management system itself. The clauses are what make it a system rather than a list of safeguards.
The seven mandatory clause areas are context (clause 4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9), and improvement (10). Each produces evidence an auditor will request. Understanding how they connect is the difference between a coherent ISMS and a pile of disconnected documents.
Clause 4: Context and scope
Everything starts with context. You must identify the internal and external issues relevant to your information security, the interested parties (customers, regulators, staff, partners) and their requirements, and then define the scope of the ISMS. Scope is a deliberate decision: which business units, locations, services and information assets are in, and what is excluded and why.
Auditors scrutinise scope because a vague or self-serving boundary undermines the whole certificate. If you exclude a system that clearly handles in-scope data, that is a red flag. Define scope honestly, document the rationale, and make sure it reflects how the business actually operates.
Clause 5: Leadership that is visible
Clause 5 is where many ISMS implementations quietly fail. The standard requires top management to demonstrate leadership and commitment, establish an information security policy, assign roles and responsibilities, and ensure the ISMS achieves its intended outcomes. This cannot be delegated entirely to IT.
Auditors look for tangible evidence: an approved information security policy signed off at the right level, resourcing decisions, and senior participation in management reviews. If the executive cannot describe the ISMS or their role in it, the auditor concludes leadership is absent, however good the paperwork looks. A Virtual CISO can bridge this by translating security risk into board language and providing the senior accountability the standard expects.
Clause 6: Planning, risk and objectives
Clause 6 is the engine of the ISMS. It requires you to assess and treat information security risks, produce a Statement of Applicability, and set measurable information security objectives. The risk assessment drives which Annex A controls you apply, and the Statement of Applicability records every control with its justification for inclusion or exclusion.
This is the most consequential part of the system, and it deserves dedicated attention. We cover the methodology in detail in our companion articles on the ISO 27001 risk assessment and treatment process and the Statement of Applicability. Objectives, meanwhile, must be measurable so that performance evaluation under clause 9 has something to measure against.
Clause 7: Support
Clause 7 covers the resources, competence, awareness, communication and documented information that keep the ISMS running. Practically, this means:
- Allocating people, budget and tooling to information security.
- Ensuring those operating controls are competent, with evidence such as training records.
- Running security awareness so staff understand their responsibilities.
- Controlling documents and records so versions are managed and evidence is retained.
Document control sounds bureaucratic, but it is how auditors verify that the policy they are reading is the current, approved one and that records have not been quietly backdated.
Clause 8: Operation
Clause 8 requires you to actually carry out the plans from clause 6. You operate the controls, perform risk assessments at planned intervals or when significant change occurs, and implement risk treatments. This is where the ISMS stops being theoretical. Operational evidence, such as completed access reviews, incident records and supplier assessments, is what proves the system runs day to day.
A common failure at this stage is the gap between a documented process and what staff actually do. Auditors test this deliberately by interviewing the people who operate controls rather than the people who wrote the policies. If your access review procedure says reviews happen quarterly but the last completed review is eighteen months old, the operation clause fails regardless of how polished the procedure looks. Build operational routines that produce evidence as a by-product, so that running the control and proving it are the same activity.
Clause 8 also requires you to control planned changes and review the consequences of unintended ones. In practice this means your change management process should consider information security impact, and significant changes should trigger a fresh look at the relevant risks. Outsourced processes that fall within scope must be identified and controlled too; you remain accountable for security even when a third party performs the work.
Clause 9: Performance evaluation
Clause 9 is where trust is won or lost. It requires monitoring and measurement, internal audit, and management review. Internal audit is mandatory and must be conducted by people independent of the area they are auditing. Management review is a scheduled meeting where top management examines the ISMS performance, audit results, risk status and improvement opportunities, and makes decisions.
Auditors ask for dated internal audit reports and management review minutes as a matter of course. If these have never happened, the ISMS is not operating, no matter what the policies say. Run internal audits well before your certification audit, and treat management review as a genuine decision-making forum, not a formality.
Clause 10: Improvement
Clause 10 closes the loop. When nonconformities are identified, you must take corrective action, address the cause, and demonstrate continual improvement. Auditors review your corrective action log. Open actions with no progress, or the same issues recurring, signal an ISMS that records problems but does not fix them. A healthy log shows issues raised, root causes addressed, and actions closed.
How the clauses reinforce each other
The reason ISO 27001 works is that the clauses form a cycle rather than a checklist. This is the familiar Plan-Do-Check-Act loop. Clauses 4 to 7 are Plan: understand context, commit leadership, assess risk and resource the work. Clause 8 is Do: operate the controls. Clause 9 is Check: measure, audit and review. Clause 10 is Act: correct and improve, feeding back into the next cycle of planning.
Auditors assess maturity partly by how well this loop turns. An organisation that plans and operates but never genuinely checks and improves has a static ISMS that will drift out of date. The cycle is what makes the system continually relevant as your business, threats and obligations change. When you present evidence, present it as a turning loop: here is the risk we found, the control we applied, the audit that tested it, and the improvement we made.
Scoping the ISMS sensibly
A practical decision that shapes the whole programme is how broadly to scope the ISMS. A narrow scope (a single product, team or data centre) is faster to certify but covers less of the business. A broad scope is more work but gives customers and regulators wider assurance. The right answer depends on why you are certifying. If a major client requires certification for a specific service, scope to that service plus its supporting infrastructure. If certification is a board-level assurance objective, a broader scope serves better. Whatever you choose, the scope must be coherent: you cannot exclude systems that are integral to delivering the in-scope service, and auditors will test the boundary for exactly that.
What makes an ISMS auditors actually trust
The common thread is evidence that the system is alive. A trustworthy ISMS has recent, dated artefacts across every clause: a current risk assessment, an internal audit conducted this cycle, management review minutes with real decisions, and corrective actions being worked. The documentation matches what staff actually do when you ask them.
Equally important is proportionality. Auditors do not reward bureaucracy for its own sake; they reward a system that is sized to the organisation and the risk. A small business does not need the same documentation weight as a bank, and over-engineering the ISMS often makes it harder to keep current, which ironically undermines trust. The aim is a system people can actually run.
Building this takes discipline, and most organisations benefit from external guidance to avoid the common traps. CISO Advisory helps Australian organisations across the private sector and government build certification-ready management systems and provides ongoing ISMS ownership through our Virtual CISO service. To discuss your path to ISO 27001, call 07 2112 8502 or contact us.
Frequently asked questions
What is an ISMS in ISO 27001?
An Information Security Management System is the framework of policies, processes, roles and controls an organisation uses to manage information security risk systematically. ISO 27001 specifies the requirements for an ISMS in clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation and improvement.
How long does ISO 27001 certification take?
For most Australian SMEs, building an ISMS to certification readiness takes six to twelve months, followed by a two-stage certification audit. The timeline depends on existing maturity, scope size, and whether you have dedicated resources or use external support to drive the programme.
What is the difference between ISO 27001 and Annex A?
Clauses 4 to 10 of ISO 27001 are the mandatory management system requirements you must meet to certify. Annex A is a reference catalogue of 93 controls you select from based on your risk assessment. The clauses are the system; Annex A controls are treatments you apply within it.
Do we need a full-time person to run an ISMS?
Not necessarily. Smaller organisations often appoint a part-time ISMS manager or use a Virtual CISO to own the system, supported by control owners across the business. What matters to auditors is clear accountability, demonstrated leadership commitment, and that the system is genuinely operated, not just documented.
What makes auditors lose confidence in an ISMS?
Auditors lose confidence when documentation describes activities that are not actually happening: risk assessments with no recent review, internal audits that were never run, corrective actions left open, and management reviews that never occurred. A trustworthy ISMS shows recent, dated evidence of the system operating as designed.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.