ISO 27001 Requirements: Clauses 4-10 Explained

ISO 27001 requirements: the mandatory clauses 4 to 10 explained
ISO 27001 Requirements: Clauses 4-10 Explained | Osto

ISO 27001 requirements explained: the mandatory management clauses, 4 to 10, that define the ISMS and decide whether you pass, in plain language for founders.

Osto Security Team9 min readCompliance & Trust

TL;DR

Most ISO 27001 guides obsess over the 93 Annex A controls, but those are selectable. The real, mandatory requirements are Clauses 4 to 10, which define the ISMS itself: context, leadership, planning, support, operation, evaluation, and improvement.

You cannot exclude these. Get the clauses right and the controls fall into place; skip them and no amount of tooling will pass the audit.

ISO 27001 requirements: why the clauses matter more than the controls

Here is the distinction that trips up most first-time teams. ISO 27001 has two parts. Annex A is a catalogue of 93 controls you select from based on risk. Clauses 4 to 10 are the mandatory management-system requirements, and they are not optional. An auditor can accept that a given Annex A control does not apply to you. An auditor will never accept that you skipped a clause.

The core point
The certificate is awarded for running a working Information Security Management System, and the clauses are what define that system. The controls are how the system does its job; the clauses are the system itself.

The clauses at a glance

The seven mandatory clauses form a cycle. They set up the system, run it, measure it, and improve it, then repeat.

The mandatory clauses
Clauses 4 to 10: what the ISMS must contain
Annex A controls are selectable. These seven clauses are not, they are required for every certification.
4. Contextscope + stakeholders 5. Leadershiptop-level ownership 6. Planningrisk + objectives 7. Supportpeople + resources 8. Operationrun the controls 9. Evaluationaudit + review 10. Improvementfix + get better Clauses 6, 9 and 10 form the continual-improvement loop that keeps the ISMS alive

What each clause actually asks for

In plain terms, here is what an auditor is looking for under each clause.

4

Context

  • Define the ISMS scope
  • Identify interested parties and their needs
5

Leadership

  • Demonstrate genuine top-level ownership
  • Set a security policy and assign roles
6

Planning

7

Support

  • Provide resources, competence, awareness
  • Control documented information
8

Operation

9

Evaluation

  • Monitor, run an internal audit
  • Hold a management review
Clause 10: Improvement
The final clause requires you to handle nonconformities with corrective action and to continually improve the ISMS. Auditors look for evidence that when something went wrong, you caught it, fixed the root cause, and adjusted the system, not just patched the symptom.

The improvement loop that keeps the ISMS alive

Clauses 6, 9, and 10 are not one-time steps. Together they form a loop: plan based on risk, evaluate how it is working, improve, then plan again. This is what auditors mean when they say ISO 27001 is a living system rather than a project with an end date. A startup that treats certification as a one-off scramble will struggle at the first surveillance audit; one that runs the loop stays ready.

The lean-team path through the clauses

The clauses are about management and process, but several depend directly on real security operating underneath. Clause 6 needs a genuine risk assessment, Clause 8 needs controls that actually run, and Clause 9 needs monitoring and evidence to evaluate. When those live across scattered tools, satisfying the clauses becomes a coordination burden.

Build an ISMS that stands up to every clause.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the controls the clauses depend on, with monitoring and evidence in one place, and map it all to ISO 27001 automatically. No security team required.

Book a Demo →

Frequently asked questions

What are the ISO 27001 requirements?

The mandatory requirements are Clauses 4 to 10: context of the organisation, leadership, planning, support, operation, performance evaluation, and improvement. Together they define the Information Security Management System. The Annex A controls are selected separately based on your risk assessment.

Are the ISO 27001 clauses mandatory?

Yes. Unlike Annex A controls, which you select based on risk, Clauses 4 to 10 are required for every certification. You cannot exclude a clause; an auditor will check each one.

What is the difference between the clauses and Annex A?

Clauses 4 to 10 are the mandatory management-system requirements that define the ISMS. Annex A is a menu of 93 controls you select from based on your risks. The clauses are the system; the controls are how the system protects information.

Which clause do startups most often get wrong?

Clause 5, leadership. Auditors look for genuine top-level ownership, not a policy signed and forgotten. In a small company this is straightforward to demonstrate, but it has to be real involvement, not a formality.

What is the continual improvement loop?

Clauses 6, 9, and 10 form a cycle: plan based on risk, evaluate through monitoring and internal audit, then improve by fixing nonconformities at the root. It is what makes ISO 27001 a living system rather than a one-time project.