Alastor InfoSec
← All Checklists

ISO 27001 Compliance Checklist

A working checklist for building or auditing an Information Security Management System (ISMS) against ISO/IEC 27001:2022. Pair this with our full ISO 27001 compliance program for implementation detail.

ISMS Foundations

  • ISMS scope formally defined and documented
  • Information security policy approved by leadership and communicated organization-wide
  • Risk assessment methodology defined and consistently applied
  • Statement of Applicability (SoA) drafted, covering all 93 Annex A controls with justification for exclusions

Risk Treatment

  • Risk register maintained and reviewed on a recurring cycle
  • Risk treatment plan in place with owners and deadlines for each identified risk
  • Residual risk formally accepted by an accountable owner, not left implicit

Organizational & People Controls

  • Roles and responsibilities for information security clearly assigned
  • Security awareness training delivered to all staff, with records kept
  • Background checks and confidentiality agreements in place for relevant roles
  • Asset inventory maintained, covering hardware, software, and data

Technical Controls

  • Access control policy enforced with least privilege and periodic review
  • Cryptographic controls applied to data at rest and in transit
  • Continuous vulnerability management and penetration testing program in place
  • Logging and monitoring cover access, changes, and anomalies, with defined retention
  • Secure development lifecycle practices applied to in-house software

Supplier & Incident Management

  • Supplier relationships risk-assessed and contractually bound to security requirements
  • Incident response plan documented, tested, and includes post-incident review
  • Business continuity and disaster recovery plans exist and are tested

Internal Audit & Management Review

  • Internal audit program covers the full ISMS scope on a defined cycle
  • Nonconformities are tracked to corrective action, not just logged
  • Management review meetings held and documented at planned intervals

Where Alastor InfoSec Fits

Alastor Shield maps continuous evidence collection to Annex A controls and keeps your Statement of Applicability current between audits. Alastor Pulse supplies the ongoing penetration testing evidence ISO 27001 auditors expect to see as a continuous program, not a once-a-year checkbox.

Talk to our team about an ISO 27001 readiness assessment scored against this checklist.

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.