UNUS London  —  Compliance Architecture Division  |  UNCLASSIFIED // REGULATED INDUSTRIES
Home Solutions Legal & Professional Financial Services Manufacturing Healthcare Academy Blogs Ebooks About Book Discovery Call UNUS Govern
Standard Reference // ISO/IEC 27001:2022

Information Security
Management Systems

ISO/IEC 27001:2022 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). UNUS London deploys database-first ISMS infrastructure that evidences conformance across all 93 Annex A controls — with immutable audit trails, automated risk treatment records, and sub-30-second evidence retrieval.

Standard Metadata
Standard Reference
ISO/IEC 27001:2022
Previous Edition
ISO/IEC 27001:2013
Governing Body
ISO/IEC JTC 1/SC 27
Annex A Controls
93 Controls — 4 Domains
Regulatory Scope
Information Security · Risk · Privacy
UNUS Readiness Score
94/100
Deployment Tier
Enterprise — £18,500
Aligns With
ISO 9001 · ISO 19770 · ITIL 4
🔐
Standard Purpose
Specifies requirements for an ISMS — a systematic approach to managing sensitive organisational information through a risk-based framework of policies, processes, people, and technology controls.
📋
2022 Revision Scope
The 2022 edition reorganised Annex A from 114 controls across 14 domains to 93 controls across 4 themes. Eleven new controls were introduced, including threat intelligence, cloud security, and data masking. Transition deadline: October 2025.
⚖️
UK Regulatory Relevance
Required or strongly recommended for organisations subject to FCA operational resilience obligations, NHS DSPT, ICO GDPR accountability requirements, SRA technology governance, and MoD supply chain security standards.

The ISMS Standard
Clause Structure

ISO/IEC 27001:2022 follows the ISO High Level Structure (HLS/Annex SL), enabling integration with other management system standards. Clauses 4–10 are normative — organisations shall comply with every requirement to claim conformance. Prescriptive language follows ISO/IEC Directives, Part 2.

Clause 04
ISO/IEC 27001:2022 — §4
Context of the Organisation
The organisation shall determine the internal and external issues relevant to its purpose that affect its ability to achieve the intended outcomes of its ISMS. This includes identifying interested parties and their information security requirements, and establishing the ISMS scope with documented boundaries.
Scope Definition Stakeholder Mapping Boundary Documentation
Key Obligations
  • Cl. 4.1 — Shall identify internal and external issues relevant to the ISMS
  • Cl. 4.2 — Shall identify interested parties and their applicable requirements
  • Cl. 4.3 — Shall document the ISMS scope with justified exclusions
Clause 05
ISO/IEC 27001:2022 — §5
Leadership & Commitment
Top management shall demonstrate leadership and commitment to the ISMS by establishing an information security policy, assigning authority and responsibility, and ensuring the ISMS requirements are integrated into the organisation's processes. The policy shall be appropriate to the purpose of the organisation and shall include information security objectives.
Policy Governance Management Accountability Roles & Responsibilities
Key Obligations
  • Cl. 5.1 — Top management shall demonstrate leadership and commitment
  • Cl. 5.2 — Top management shall establish an information security policy
  • Cl. 5.3 — Shall assign and communicate ISMS roles and responsibilities
Clause 06
ISO/IEC 27001:2022 — §6
Planning — Risk & Objectives
The organisation shall define and apply an information security risk assessment process to identify risks, assess likelihood and consequence, and determine risk owners. The risk treatment process shall select appropriate options, determine necessary controls, and produce a Statement of Applicability (SoA) with justification for inclusions and exclusions of all Annex A controls.
Risk Assessment Statement of Applicability Risk Treatment Plan
Key Obligations
  • Cl. 6.1.2 — Shall define and apply an information security risk assessment process
  • Cl. 6.1.3 — Shall produce a Statement of Applicability (SoA)
  • Cl. 6.2 — Shall establish measurable information security objectives
Clause 07
ISO/IEC 27001:2022 — §7
Support — Resources & Documented Information
The organisation shall determine and provide the resources needed for the ISMS. Competence, awareness, and communication requirements shall be established. The standard requires extensive documented information to be maintained and retained, including the ISMS scope, risk assessment results, risk treatment plan, Statement of Applicability, and operational evidence.
Documented Information Competence Records Awareness Training
Key Obligations
  • Cl. 7.1–7.3 — Shall determine resources, competence, and awareness requirements
  • Cl. 7.5 — Shall maintain and retain documented information as evidence of conformance
Clause 09
ISO/IEC 27001:2022 — §9
Performance Evaluation & Internal Audit
The organisation shall monitor, measure, analyse, and evaluate information security performance. Internal ISMS audits shall be conducted at planned intervals to confirm conformance. Management reviews shall be conducted to ensure the continuing suitability, adequacy, and effectiveness of the ISMS. All results shall be retained as documented information.
Internal Audit Programme Management Review KPI Monitoring
Key Obligations
  • Cl. 9.1 — Shall monitor, measure, analyse, and evaluate ISMS performance
  • Cl. 9.2 — Shall conduct internal ISMS audits at planned intervals
  • Cl. 9.3 — Top management shall conduct management reviews
Clause 10
ISO/IEC 27001:2022 — §10
Improvement — Nonconformities & Corrective Action
When a nonconformity occurs, the organisation shall take action to control and correct it, evaluate the need for action to eliminate root causes, and implement corrective actions as appropriate. The results of corrective actions shall be documented. The organisation shall continually improve the suitability, adequacy, and effectiveness of the ISMS.
Nonconformity Register Corrective Action Continual Improvement
Key Obligations
  • Cl. 10.1 — Shall address nonconformities with documented corrective actions
  • Cl. 10.2 — Shall continually improve the suitability, adequacy, and effectiveness of the ISMS

93 Information Security
Controls Across 4 Themes

The 2022 revision reorganised controls from 114 across 14 domains into 93 controls across four thematic groupings — Organisational, People, Physical, and Technological. Eleven controls are new to the 2022 edition. All controls are referenced in the Statement of Applicability (SoA) with implementation justification.

Theme A.5
🏻️
Organisational Controls
37 controls
Theme A.6
👤
People Controls
8 controls
Theme A.7
🏢
Physical Controls
14 controls
Theme A.8
💻
Technological Controls
34 controls
A.5.7 — Threat Intelligence
A.5.23 — Information Security for Cloud Services
A.5.30 — ICT Readiness for Business Continuity
A.7.4 — Physical Security Monitoring
A.8.9 — Configuration Management
A.8.10 — Information Deletion
A.8.11 — Data Masking
A.8.12 — Data Leakage Prevention
A.8.16 — Monitoring Activities
A.8.23 — Web Filtering
A.8.28 — Secure Coding

ISMS Compliance
Requirements Mapping

The table below maps key ISO/IEC 27001:2022 clauses to their mandatory requirements, prescriptive language, and UNUS London's fulfilment status. Conformance language follows ISO/IEC Directives, Part 2 — "shall" denotes a requirement; "should" a recommendation.

Clause Ref. Requirement (shall) ISMS Domain UNUS Status
Cl. 4.2 The organisation shall determine the interested parties that are relevant to the ISMS and their requirements relevant to information security. Context Fully Met
Cl. 4.3 The organisation shall determine the boundaries and applicability of the ISMS and shall document the scope, including justified exclusions. Scope Fully Met
Cl. 5.2 Top management shall establish an information security policy that is appropriate to the purpose of the organisation, includes information security objectives, and is available as documented information. Policy Fully Met
Cl. 6.1.2 The organisation shall define and apply an information security risk assessment process that identifies risks associated with the loss of confidentiality, integrity, and availability of information. Risk Assessment Fully Met
Cl. 6.1.3 The organisation shall produce a Statement of Applicability that includes the necessary controls, justification for inclusions, and justification for exclusions of Annex A controls. Statement of Applicability Fully Met
Cl. 7.5 The organisation shall maintain and retain documented information required by this standard, including evidence of the results of risk assessments and the risk treatment plan. Documented Information Fully Met
Cl. 8.2 The organisation shall perform information security risk assessments at planned intervals or when significant changes occur, and shall retain documented information of the risk assessment results. Operational Risk Fully Met
Cl. 8.3 The organisation shall implement the information security risk treatment plan and retain documented information of the results of the risk treatment. Risk Treatment Fully Met
Cl. 9.1 The organisation shall evaluate the information security performance and the effectiveness of the ISMS, and shall retain documented information as evidence of the monitoring and measurement results. Performance Evaluation Fully Met
Cl. 9.2 The organisation shall conduct internal ISMS audits at planned intervals to determine whether the ISMS conforms to the requirements of this standard and is effectively implemented and maintained. Internal Audit Fully Met
Cl. 10.1 When a nonconformity occurs, the organisation shall take action to control and correct it, evaluate the need for corrective action, and retain documented information as evidence of results. Corrective Action Partial — Config Req.
A.5.7 Information relating to information security threats shall be collected and analysed to produce threat intelligence. This intelligence shall be used in the risk assessment process. Threat Intelligence Advisory Review
A.8.8 Information about technical vulnerabilities of information systems in use shall be obtained in a timely fashion. The organisation's exposure to such vulnerabilities shall be evaluated and appropriate measures taken. Vulnerability Mgmt Fully Met

How Our Systems Satisfy
ISO/IEC 27001:2022

Each component of the UNUS London compliance infrastructure maps directly to one or more clauses or Annex A controls of the standard. The following cards detail exact system capabilities and the requirements they address.

Cl. 6.1.2 — Risk Assessment
⚠️
Information Security Risk Register — PostgreSQL Layer

Structured IS Risk Register

A production PostgreSQL schema implements the information security risk register required under Clause 6.1.2. Every identified risk is stored with asset reference, threat source, vulnerability, likelihood, impact, risk score, risk owner, and treatment decision.

  • Risk scoring via probability × impact matrix: likelihood_score × impact_score = risk_rating
  • Risk owner assignment with role-based accountability tracking
  • Automated risk recalculation triggers on control status changes
  • Full audit log of every risk record mutation — immutable via database trigger
Cl. 6.1.3 — Statement of Applicability
📋
Statement of Applicability — Automated Generation

SoA Engine & Control Register

The SoA module maintains a database record for every Annex A control — all 93 — with inclusion/exclusion status, implementation justification, implementation evidence reference, and responsible owner. The SoA document is generated on-demand as a timestamped output from the database.

  • All 93 Annex A controls pre-loaded with 2022 edition metadata
  • SoA generation workflow produces a timestamped, formatted document in under 60 seconds
  • Exclusion justification fields with mandatory text entry before exclusion is accepted
  • Control status ENUM: implemented | partial | planned | excluded | not_applicable
Cl. 8.3 — Risk Treatment
🛡️
Risk Treatment Plan — Tracked Implementation

Risk Treatment Record System

The risk treatment module links each identified risk to its treatment decision (accept, mitigate, transfer, avoid), the specific Annex A controls applied, implementation status, target completion date, and evidence of treatment. Treatment records satisfy Clause 8.3 documented information requirements.

  • Treatment decisions logged with approving authority and timestamp
  • Control mapping: risk record → Annex A control reference → implementation evidence
  • Overdue treatment alerts via scheduled n8n workflow notification
  • Treatment effectiveness reviews linked to Cl. 9.1 monitoring schedule
Cl. 7.5 — Documented Information
🗄️
Evidence Repository — Immutable Audit Trail

ISMS Evidence Store

All documented information required by ISO/IEC 27001:2022 is stored in the PostgreSQL evidence repository with version control, access logging, and immutable change history. This satisfies Clause 7.5 requirements for maintaining and retaining documented information as conformance evidence.

  • Evidence records linked to specific clause or Annex A control references
  • Version history maintained — any historical version retrievable in under 30 seconds
  • Access log: who retrieved which document at what time — satisfies A.8.15 (Logging)
  • Document review schedule with automated expiry alerts
Cl. 9.2 — Internal Audit
🔍
Internal Audit Programme — Scheduled Automation

ISMS Internal Audit System

Scheduled n8n workflows execute ISMS internal audit queries at configured intervals, producing conformance evidence packs and audit findings records that satisfy Clause 9.2. Every audit execution is logged with scope, methodology, findings, and corrective actions raised.

  • Quarterly ISMS audit programme with automated scheduling and reminder notifications
  • Audit findings stored in isms_audit_findings table with severity and owner
  • Nonconformity records linked from finding to corrective action to closure evidence
  • Audit programme history fully retrievable — systematic programme evidenced for certification
A.8.8 — Vulnerability Management
🔬
Vulnerability Register — Technical Control Tracking

Vulnerability Management Record

The vulnerability management module satisfies Annex A control A.8.8 by maintaining a structured register of known technical vulnerabilities, their severity scores (CVSS-aligned), affected assets, remediation status, and evidence of remediation. Scheduled scans feed automated database records.

  • Vulnerability records linked to asset register entries from the ISO 19770 ITAM layer
  • CVSS severity bands: Critical / High / Medium / Low with SLA-driven remediation targets
  • Remediation workflow: vulnerability raised → owner assigned → remediation logged → closed
  • Overdue vulnerability alerts with escalation path to Information Security Manager

Critical ISMS Gaps
UNUS London Resolves

The following represent the three most prevalent and highest-risk failures identified during ISO/IEC 27001 certification audits. Each is a common reason organisations fail external certification or receive major nonconformities. UNUS London's database-first architecture resolves all three structurally.

Cl. 6.1.3 — Statement of Applicability
Resolved by UNUS
No Current Statement of Applicability
Clause 6.1.3 mandates a Statement of Applicability that references all 93 Annex A controls with documented inclusion or exclusion justification. The SoA is one of the first documents requested by certification auditors. Organisations that maintain SoAs in Word documents or spreadsheets routinely present versions that are months out of date, contain incomplete justifications, or reference the superseded 2013 control set — constituting a major nonconformity in all three cases.
UNUS Resolution The UNUS SoA engine maintains a live database record for every Annex A control. When the SoA document is generated, it pulls current status, justification text, and evidence references directly from the database. The output is always current, always complete, and always traceable to clause requirements. Generation takes under 60 seconds. Auditors receive a timestamped document that reflects the state of the ISMS at the moment of generation — not six months ago.
Cl. 7.5 — Documented Information
Resolved by UNUS
Evidence Cannot Be Retrieved at Audit
Clause 7.5 requires that documented information be available and suitable for use, where and when needed. Certification auditors routinely request specific evidence — the result of a risk assessment conducted 18 months ago, the access control review from last quarter, the supplier security review for a named vendor. Organisations storing ISMS evidence in email threads, shared drives, or unlinked document management systems routinely fail to produce this evidence in audits, resulting in observation findings or, in cases where the absence is systematic, major nonconformities.
UNUS Resolution The ISMS evidence store links every piece of documented information to the clause or control it evidences. When an auditor requests evidence for Cl. 8.2 risk assessment results, the database query returns a timestamped record set in under 30 seconds. The retrieval itself is logged — demonstrating to the auditor not only that the evidence exists, but that the access control over it (A.5.15) is also functioning.
Cl. 9.2 — Internal Audit Programme
Resolved by UNUS
No Systematic Internal Audit Programme
Clause 9.2 requires internal ISMS audits to be conducted at planned intervals, with results retained as documented information. Most organisations attempting ISO/IEC 27001 certification for the first time can evidence at most one internal audit, conducted in the weeks before the external audit. Certification bodies treat this as evidence of a reactive rather than systematic programme — a nonconformity under Cl. 9.2 because the requirement is for audits at planned intervals, not a single pre-certification exercise.
UNUS Resolution The ISMS audit programme module schedules quarterly internal audits from Day 1. Each execution generates an isms_audit_record row with scope, methodology, findings, auditor identity, and timestamp. After three consecutive quarters, the organisation has an evidenced systematic programme — a pattern of conformance, not a single data point. The audit schedule is itself a documented information artefact, satisfying the planning sub-requirement of Cl. 9.2.

ISMS Evidence
Retrieval in Under 30 Seconds

When a certification body auditor or regulator requests evidence of information security conformance, the UNUS London system produces structured, timestamped records in seconds. The following illustrates a live ISMS evidence retrieval session against the compliance database.

unus@isms-db:~$ psql -d unus_isms -c "SELECT * FROM vw_soa_current_status ORDER BY control_ref;"
-- ISO/IEC 27001:2022 Cl.6.1.3 | Statement of Applicability | Generated: 2026-03-12 10:22:41 UTC
control_ref | title | status | justification_present | evidence_linked
--------------+-------------------------------------+---------------+-----------------------+----------------
A.5.1 | Policies for Information Security | implemented | TRUE | TRUE
A.5.7 | Threat Intelligence | implemented | TRUE | TRUE
A.5.23 | IS for Cloud Services | implemented | TRUE | TRUE
A.8.8 | Management of Technical Vulnerabilities | implemented | TRUE | TRUE
A.8.11 | Data Masking | partial | TRUE | TRUE
-- SoA Coverage: 93/93 controls addressed. 0 controls with missing justification.
unus@isms-db:~$ SELECT * FROM isms_risk_register WHERE risk_rating >= 12 ORDER BY risk_rating DESC LIMIT 5;
-- Cl.6.1.2 Risk Assessment | High Risk Items | Cl.8.2 Operational Review
risk_id | asset | threat | risk_score | treatment | owner
-----------+---------------------+-----------------------+------------+-------------+--------------------
RISK-0041 | Client Data (DB) | Unauthorised Access | 16 | mitigate | j.smith@firm
RISK-0038 | Email System | Phishing / BEC | 15 | mitigate | a.jones@firm
RISK-0055 | Cloud Storage (SaaS) | Data Exfiltration | 12 | transfer | ciso@firm
unus@isms-db:~$ SELECT * FROM isms_audit_log ORDER BY audit_date DESC LIMIT 3;
-- Cl.9.2 Internal Audit Programme | Systematic Evidence — 4 Consecutive Quarters
audit_ref | scope | findings | nonconformities | auditor | audit_date
--------------+--------------+----------+-----------------+-----------------+---------------
AUD-2026-Q1 | Cl.6–Cl.10 | 2 | 0 | ext.auditor | 2026-03-01
AUD-2025-Q4 | Annex A A.5–A.8 | 4 | 1 | int.auditor | 2025-12-05
AUD-2025-Q3 | Cl.4–Cl.8 | 3 | 0 | int.auditor | 2025-09-11
-- Elapsed: 0.022s | Systematic audit programme confirmed across 4 quarters. Evidence pack ready.
unus@isms-db:~$ _

ISO/IEC 27001:2022 Compliance
Assessment

The UNUS London ISMS system achieves a composite readiness score of 94/100 against ISO/IEC 27001:2022. Scores are calculated across seven assessment dimensions using weighted clause and Annex A control coverage.

0
Overall Readiness Score
StandardISO/IEC 27001:2022
SoA Coverage93/93 Controls
2022 Edition✓ Fully Aligned
Certification Ready✓ Yes
Statement of Applicability Completeness
99%
Risk Register Coverage (Cl. 6.1.2)
96%
Documented Information Integrity (Cl. 7.5)
99%
Risk Treatment Execution (Cl. 8.3)
94%
Internal Audit Programme (Cl. 9.2)
97%
Annex A Control Implementation
91%
Corrective Action Closure Rate
88%

From Zero to
27001-Compliant in 21 Days

UNUS London delivers a production-ready ISMS aligned to ISO/IEC 27001:2022 within a 21-day structured deployment programme. All deliverables — including database schemas, workflow automations, and documentation templates — are transferred with full code ownership.

D1–3
Phase 1 — Context & Scoping (Cl. 4)
ISMS Scope Definition & Stakeholder Mapping
Discovery session to define the ISMS scope, identify interested parties and their information security requirements, and document internal and external issues. Scope statement drafted and approved. Satisfies Clauses 4.1, 4.2, and 4.3 documentation requirements.
ISMS Scope Document Stakeholder Register Context Analysis
D4–7
Phase 2 — Risk Assessment & SoA (Cl. 6)
Risk Register Build & Statement of Applicability
Information security risk assessment conducted. Risk register populated with identified risks, owners, scores, and treatment decisions. All 93 Annex A controls reviewed. Statement of Applicability generated from database with inclusion/exclusion justification for every control. Satisfies Clauses 6.1.2 and 6.1.3.
IS Risk Register Statement of Applicability Risk Treatment Plan
D8–12
Phase 3 — Policy Suite & Documentation (Cl. 5 & 7)
Information Security Policy Suite & Evidence Repository
Information security policy produced and approved. Supporting policies created: access control, acceptable use, cryptography, supplier security, incident response. ISMS evidence repository deployed. All documented information linked to clause references. Satisfies Clauses 5.2 and 7.5.
IS Policy Suite Evidence Repository Documented Information Index
D13–17
Phase 4 — Control Implementation & Automation (Cl. 8)
Annex A Control Deployment & n8n Workflow Automation
Priority Annex A controls implemented with database evidence records created. n8n automation workflows deployed for scheduled risk reviews, vulnerability tracking, supplier review alerts, access review reminders, and audit scheduling. Satisfies Clause 8 operational control requirements.
Control Implementation Evidence Automation Workflows Vulnerability Register
D18–21
Phase 5 — Audit, Handover & Code Transfer
Internal Audit, Evidence Pack & Full Code Ownership
Internal ISMS audit conducted against all normative clauses. Audit findings documented. Corrective actions raised where applicable. Full code ownership transferred. Staff training session delivered. Initial evidence pack generated demonstrating clause conformance. System is in production operation on Day 21.
Internal Audit Report ISMS Evidence Pack Full Code Ownership Certification-Ready Pack

Continuous ISMS Evidence.
Not A One-Time Audit Pack.

ISO/IEC 27001:2022 requires a continuously maintained Information Security Management System — not a one-time evidence pack you generate for the audit and forget. UNUS Govern is the operational wrapper that turns your ISMS from a point-in-time deliverable into a continuously-evidenced system. Statement of Applicability stays current. Risk treatment plan tracks drift in real time. Annex A controls remain mapped to your live schema. The 27001 evidence layer is always audit-ready — not just before surveillance.

  • Continuous Annex A control mapping (live)
  • Statement of Applicability drift detection
  • Risk treatment plan monitoring (0–100)
  • Annual surveillance audit pack (auto-generated)

Part of UNUS Govern's continuous evidence layer.
Available as a monthly subscription. Cancel anytime.

Ready to build an
ISO/IEC 27001:2022-compliant ISMS?

A 60-minute discovery call establishes your current information security posture, identifies your critical nonconformities against the 2022 edition, and scopes exactly what will be built and transferred to you — including the Statement of Applicability, risk register, and internal audit programme. No sales pitch — a structured technical assessment.