ISO 27001 Compliance Checklist
A working checklist for building or auditing an Information Security Management System (ISMS) against ISO/IEC 27001:2022. Pair this with our full ISO 27001 compliance program for implementation detail.
ISMS Foundations
- ISMS scope formally defined and documented
- Information security policy approved by leadership and communicated organization-wide
- Risk assessment methodology defined and consistently applied
- Statement of Applicability (SoA) drafted, covering all 93 Annex A controls with justification for exclusions
Risk Treatment
- Risk register maintained and reviewed on a recurring cycle
- Risk treatment plan in place with owners and deadlines for each identified risk
- Residual risk formally accepted by an accountable owner, not left implicit
Organizational & People Controls
- Roles and responsibilities for information security clearly assigned
- Security awareness training delivered to all staff, with records kept
- Background checks and confidentiality agreements in place for relevant roles
- Asset inventory maintained, covering hardware, software, and data
Technical Controls
- Access control policy enforced with least privilege and periodic review
- Cryptographic controls applied to data at rest and in transit
- Continuous vulnerability management and penetration testing program in place
- Logging and monitoring cover access, changes, and anomalies, with defined retention
- Secure development lifecycle practices applied to in-house software
Supplier & Incident Management
- Supplier relationships risk-assessed and contractually bound to security requirements
- Incident response plan documented, tested, and includes post-incident review
- Business continuity and disaster recovery plans exist and are tested
Internal Audit & Management Review
- Internal audit program covers the full ISMS scope on a defined cycle
- Nonconformities are tracked to corrective action, not just logged
- Management review meetings held and documented at planned intervals
Where Alastor InfoSec Fits
Alastor Shield maps continuous evidence collection to Annex A controls and keeps your Statement of Applicability current between audits. Alastor Pulse supplies the ongoing penetration testing evidence ISO 27001 auditors expect to see as a continuous program, not a once-a-year checkbox.
Talk to our team about an ISO 27001 readiness assessment scored against this checklist.