Imperium Certific

ISO 27001 requirements through an auditor's eyes: what the certification audit covers

What the ISO 27001 certification audit examines: mandatory clauses 4 to 10, the Statement of Applicability, documentation, Annex A sampling and typical nonconformities.

In most companies, preparing for certification looks like writing paperwork. The audit team arrives for something else — the traces of a system at work. Here is what an Imperium Certific auditor examines at stage 2, in what order, and where the questions usually stop.

ISO 27001: requirements and controls are different things

The document has two parts with different status, and confusing them costs projects more time than anything else.

Clauses 4 to 10 are all mandatory: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. The moment an organisation claims conformity, it takes on every one of them — no exclusions are provided for.

Annex A works differently. It is a reference set of 93 controls in four themes: organisational, people, physical, technological. The company takes from it what its risks require and records the choice in the Statement of Applicability (SoA). The auditor does not insist that you "apply everything" — the auditor checks that the selection is justified.

Annex A 27001:2022 and the Statement of Applicability

The SoA is the central document of stage 2. It links risks to the chosen protective measures and explains why the rest were left aside. The auditor reads it first and works through the audit along its lines.

Two exclusion formulas look identical but land very differently:

  • "Not applicable, because we do not do that." A company without its own data centre legitimately excludes part of the physical controls. No questions arise.
  • "Not applicable, because it is expensive." Cost does not make a risk disappear. Here the auditor will ask to see how the risk was treated instead: transferred, accepted at management level, or reduced by other means.

ISO 27001, Annex A: what the auditor actually takes up

Checking 93 items in a few days is impossible, so sampling does the work. The sample is built deliberately from:

  • controls tied to high risks in the register;
  • anything that has changed since the previous visit;
  • areas where findings were raised last year;
  • items new in the 2022 edition — threat intelligence, cloud services, physical security monitoring, configuration management, information deletion and data masking, data leakage prevention, monitoring activities, web filtering, secure coding.

A key detail: every control carries a "purpose" line. What is verified is whether that purpose is achieved, not whether a particular product is installed.

How a stage 2 day unfolds

It starts with the opening meeting: the team confirms the programme, the boundaries of the audit and the confidentiality rules. Then come interviews with process owners — they, rather than the quality function, describe how things actually work. In parallel the team walks the site: the server room, restricted areas, workstations.

The second half is a sample review of records. The auditor asks for specific examples from recent months: an access request, an incident report, minutes of an access rights review, evidence that a new employee was trained.

ISO 27001 documentation: the mandatory minimum

The standard uses the term documented information for what an organisation must hold in writing. The minimum set is as follows:

Item Source clause
Scope of the system clause 4
Policy and objectives clauses 5 and 6
Risk assessment and treatment methodology clause 6
Risk assessment results and treatment plan clause 8
Statement of Applicability clause 6
Records of personnel competence clause 7
Monitoring and measurement results clause 9
Internal audit programme and results clause 9
Management review results clause 9
Records of nonconformities and corrective actions clause 10

Length is not prescribed: a two-page policy is perfectly acceptable. Format is free as well — a table in a task management tool works as well as a signed file, provided authorship, date and change history are visible.

The ISO 27002 list of controls explains, it does not replace

The second number in the family contains the same items, but with expanded commentary: why a control exists, how it is usually implemented, what to watch out for. No certificate is issued against it — conformity is assessed against the requirements of the first number.

What does not count as evidence

  • A screenshot with no date and no source.
  • An email saying "we plan to do this next quarter".
  • A presentation about the future security architecture.
  • A verbal mention of a rule that appears in no record whatsoever.

Evidence is something reproducible: a log entry, a dated ticket, signed minutes, an export from a system.

Implementing ISO 27001 and the impartiality boundary

This is the line a certification body does not cross. We do not design our clients' systems: policies, risk assessments, drafting the SoA and internal audits all sit outside our work. The rule comes from ISO/IEC 17021-1, and breaking it costs accreditation.

Five nonconformities we see most often

  • A risk register that never moves. The assessment was done a year ago; contractors, services and people have changed since, yet the table is identical.
  • Objectives without numbers. Wording such as "improve our security posture" cannot be verified: a year later nobody can say whether it was achieved.
  • A token internal audit. There is a report, but not a single finding in a whole year. Or the audit was carried out by the same specialist who built the system.
  • Management review as a formality. Half a page of minutes with no decisions and no deadlines. Clause 9 requires specific inputs to be considered and conclusions to be recorded.
  • No records of improvement. A log containing only "it broke, we fixed it" closes corrective action and leaves the improvement requirement open.

A self-check before applying

Readiness is easy to assess on your own. Take the SoA, pick five applied controls at random and try to find a record from the last three months for each. If four out of five turn up, you are ready for the team's visit.

Another useful exercise: ask two different employees to describe how they obtain access to a working system. A discrepancy in their answers means the rule lives only in the text of a document.

Planning an audit? Submit an application — we will review the scope, assess the system's readiness and calculate the audit effort.

Часті запитання

Повернутися до новин