Why You Need an ISO 27001 Checklist
Achieving ISO 27001 certification involves hundreds of requirements across documentation, controls, processes, and governance. A structured checklist ensures nothing falls through the cracks during implementation and audit preparation.
Mandatory Documentation Checklist
The following documents are explicitly required by ISO 27001:
Clause 4 – Context of the Organization
- Scope of the ISMS (Clause 4.3)
- List of interested parties and their requirements (Clause 4.2)
- Internal and external issues affecting the ISMS (Clause 4.1)
Clause 5 – Leadership
- Information Security Policy (Clause 5.2)
- Roles, responsibilities, and authorities (Clause 5.3)
- Evidence of management commitment (Clause 5.1)
Clause 6 – Planning
- Risk assessment methodology (Clause 6.1.2)
- Risk assessment results (Clause 6.1.2)
- Risk treatment plan (Clause 6.1.3)
- Statement of Applicability (Clause 6.1.3 d)
- Information security objectives (Clause 6.2)
Clause 7 – Support
- Evidence of competence (Clause 7.2)
- Security awareness program records (Clause 7.3)
- Document control procedure (Clause 7.5)
Clause 8 – Operation
- Operational planning and control records (Clause 8.1)
- Risk assessment results (Clause 8.2)
- Risk treatment results (Clause 8.3)
Clause 9 – Performance Evaluation
- Monitoring and measurement results (Clause 9.1)
- Internal audit program and results (Clause 9.2)
- Management review minutes (Clause 9.3)
Clause 10 – Improvement
- Nonconformity and corrective action records (Clause 10.1)
- Continual improvement evidence (Clause 10.2)
Annex A Controls Checklist
ISO 27001:2022 contains 93 controls across four themes. Use our Annex A Selector Tool to determine which apply to your organization.
Organizational Controls (A.5) – 37 Controls
- Information security policies (A.5.1)
- Information security roles (A.5.2)
- Segregation of duties (A.5.3)
- Management responsibilities (A.5.4)
- Threat intelligence (A.5.7)
- Information security in project management (A.5.8)
- Inventory of information assets (A.5.9)
- Acceptable use of assets (A.5.10)
People Controls (A.6) – 8 Controls
- Screening (A.6.1)
- Terms and conditions of employment (A.6.2)
- Information security awareness and training (A.6.3)
- Disciplinary process (A.6.4)
- Responsibilities after termination (A.6.5)
- Remote working (A.6.7)
Physical Controls (A.7) – 14 Controls
- Physical security perimeters (A.7.1)
- Physical entry controls (A.7.2)
- Securing offices and facilities (A.7.3)
- Clear desk and clear screen (A.7.7)
- Equipment siting and protection (A.7.8)
Technological Controls (A.8) – 34 Controls
- User endpoint devices (A.8.1)
- Privileged access rights (A.8.2)
- Information access restriction (A.8.3)
- Secure authentication (A.8.5)
- Malware protection (A.8.7)
- Management of technical vulnerabilities (A.8.8)
- Information backup (A.8.13)
- Logging (A.8.15)
- Network security (A.8.20)
- Secure coding (A.8.28)
Pre-Audit Readiness Checklist
Before your certification audit, verify these critical items:
Stage 1 Audit Preparation
- All mandatory documents are approved and distributed
- Statement of Applicability is complete and justified
- Risk assessment is documented and current
- Internal audit has been conducted
- Management review has been performed
- Corrective actions from internal audit are closed
Stage 2 Audit Preparation
- All controls in the SoA are implemented
- Staff are aware of security policies
- Evidence of control effectiveness exists
- Incident management process is tested
- Business continuity plans are tested
- Supplier security requirements are documented
Using Our Free Tools
Streamline your checklist completion with our tools:
- Gap Analysis Tool – Assess your current compliance status
- SoA Generator – Build your Statement of Applicability
- Risk Assessment Tool – Create your risk register
- Internal Audit Checklist – Prepare for internal audits
- Implementation Roadmap – Plan your timeline
Common Gaps Found During Audits
Based on industry data, the most common nonconformities are:
- Incomplete risk assessments – Not covering all assets or threats
- Missing evidence of awareness training – No records of employee training
- Outdated documents – Policies not reviewed or updated annually
- Weak access control – No formal access provisioning process
- No incident response testing – Plans exist but are never tested
Conclusion
Use this checklist as your roadmap to ISO 27001 certification. Start with our Gap Analysis to identify your current position, then work through each section systematically.
Found this article helpful?
Share it with your colleagues.
