{
  "code": "ISO27001-2022",
  "name": "ISO/IEC 27001:2022",
  "version": "2022",
  "issuing_body": "ISO/IEC",
  "description": "Information security management systems — Requirements",
  "regions": ["global"],
  "industries": ["all"],
  "effective_date": "2022-10-25",
  "is_global": true,
  "requirements": [
    {
      "reference_code": "4",
      "title": "Context of the Organization",
      "requirement_type": "mandatory",
      "category": "Organizational Context",
      "children": [
        { "reference_code": "4.1", "title": "Understanding the organization and its context", "description": "Determine external and internal issues relevant to the purpose of the organization and that affect its ability to achieve the intended outcomes of its ISMS.", "guidance": "Consider PEST analysis, SWOT analysis, regulatory landscape.", "requirement_type": "mandatory" },
        { "reference_code": "4.2", "title": "Understanding the needs and expectations of interested parties", "description": "Determine the interested parties relevant to the ISMS and their requirements.", "requirement_type": "mandatory" },
        { "reference_code": "4.3", "title": "Determining the scope of the ISMS", "description": "Determine the boundaries and applicability of the ISMS.", "requirement_type": "mandatory" },
        { "reference_code": "4.4", "title": "Information security management system", "description": "Establish, implement, maintain and continually improve an ISMS.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "5",
      "title": "Leadership",
      "requirement_type": "mandatory",
      "category": "Leadership & Commitment",
      "children": [
        { "reference_code": "5.1", "title": "Leadership and commitment", "description": "Top management shall demonstrate leadership and commitment with respect to the ISMS.", "requirement_type": "mandatory" },
        { "reference_code": "5.2", "title": "Policy", "description": "Top management shall establish an information security policy.", "requirement_type": "mandatory" },
        { "reference_code": "5.3", "title": "Organizational roles, responsibilities and authorities", "description": "Ensure roles, responsibilities and authorities relevant to information security are assigned and communicated.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "6",
      "title": "Planning",
      "requirement_type": "mandatory",
      "category": "Risk Planning",
      "children": [
        { "reference_code": "6.1", "title": "Actions to address risks and opportunities", "description": "Determine risks and opportunities that need to be addressed.", "requirement_type": "mandatory",
          "children": [
            { "reference_code": "6.1.1", "title": "General", "description": "Consider the context and interested parties requirements.", "requirement_type": "mandatory" },
            { "reference_code": "6.1.2", "title": "Information security risk assessment", "description": "Define and apply an information security risk assessment process.", "requirement_type": "mandatory" },
            { "reference_code": "6.1.3", "title": "Information security risk treatment", "description": "Define and apply an information security risk treatment process.", "requirement_type": "mandatory" }
          ]
        },
        { "reference_code": "6.2", "title": "Information security objectives and planning to achieve them", "description": "Establish information security objectives at relevant functions and levels.", "requirement_type": "mandatory" },
        { "reference_code": "6.3", "title": "Planning of changes", "description": "Changes to the ISMS shall be carried out in a planned manner.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "7",
      "title": "Support",
      "requirement_type": "mandatory",
      "category": "Resources & Support",
      "children": [
        { "reference_code": "7.1", "title": "Resources", "description": "Determine and provide the resources needed for the establishment, implementation, maintenance and improvement of the ISMS.", "requirement_type": "mandatory" },
        { "reference_code": "7.2", "title": "Competence", "description": "Determine the necessary competence of persons doing work under the organization's control.", "requirement_type": "mandatory" },
        { "reference_code": "7.3", "title": "Awareness", "description": "Persons doing work under the organization's control shall be aware of the information security policy.", "requirement_type": "mandatory" },
        { "reference_code": "7.4", "title": "Communication", "description": "Determine the need for internal and external communications relevant to the ISMS.", "requirement_type": "mandatory" },
        { "reference_code": "7.5", "title": "Documented information", "description": "Maintain documented information required by the standard.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "8",
      "title": "Operation",
      "requirement_type": "mandatory",
      "category": "Operational Controls",
      "children": [
        { "reference_code": "8.1", "title": "Operational planning and control", "description": "Plan, implement, control, monitor and review processes needed to meet requirements.", "requirement_type": "mandatory" },
        { "reference_code": "8.2", "title": "Information security risk assessment", "description": "Perform information security risk assessments at planned intervals.", "requirement_type": "mandatory" },
        { "reference_code": "8.3", "title": "Information security risk treatment", "description": "Implement the information security risk treatment plan.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "9",
      "title": "Performance Evaluation",
      "requirement_type": "mandatory",
      "category": "Monitoring & Review",
      "children": [
        { "reference_code": "9.1", "title": "Monitoring, measurement, analysis and evaluation", "description": "Evaluate the performance and effectiveness of the ISMS.", "requirement_type": "mandatory" },
        { "reference_code": "9.2", "title": "Internal audit", "description": "Conduct internal audits at planned intervals.", "requirement_type": "mandatory" },
        { "reference_code": "9.3", "title": "Management review", "description": "Top management shall review the organization's ISMS at planned intervals.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "10",
      "title": "Improvement",
      "requirement_type": "mandatory",
      "category": "Continual Improvement",
      "children": [
        { "reference_code": "10.1", "title": "Continual improvement", "description": "Continually improve the suitability, adequacy and effectiveness of the ISMS.", "requirement_type": "mandatory" },
        { "reference_code": "10.2", "title": "Nonconformity and corrective action", "description": "React to nonconformity, take corrective actions and review effectiveness.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "A.5",
      "title": "Organizational controls",
      "requirement_type": "mandatory",
      "category": "Annex A Controls",
      "children": [
        { "reference_code": "A.5.1", "title": "Policies for information security", "description": "Information security policy and topic-specific policies shall be defined, approved, published, communicated, acknowledged.", "requirement_type": "mandatory" },
        { "reference_code": "A.5.2", "title": "Information security roles and responsibilities", "description": "Roles and responsibilities for information security shall be defined and allocated.", "requirement_type": "mandatory" },
        { "reference_code": "A.5.7", "title": "Threat intelligence", "description": "Information relating to information security threats shall be collected and analysed.", "requirement_type": "mandatory" },
        { "reference_code": "A.5.15", "title": "Access control", "description": "Rules for physical and logical access to information and associated assets shall be established and implemented.", "requirement_type": "mandatory" },
        { "reference_code": "A.5.23", "title": "Information security for use of cloud services", "description": "Processes for acquisition, use, management and exit from cloud services shall be established.", "requirement_type": "mandatory" },
        { "reference_code": "A.5.30", "title": "ICT readiness for business continuity", "description": "ICT readiness shall be planned, implemented, maintained and tested.", "requirement_type": "mandatory" }
      ]
    }
  ]
}
