---
title: "ISO 27001 Compliance Checklist"
description: "A practical checklist for ISO 27001 certification readiness — ISMS scope, Annex A controls, risk treatment, and audit evidence."
keywords:
  - ISO 27001 checklist
  - ISO 27001 certification checklist
  - ISMS checklist
  - Annex A controls checklist
---

# ISO 27001 Compliance Checklist

A working checklist for building or auditing an Information Security Management System (ISMS) against ISO/IEC 27001:2022. Pair this with our full [ISO 27001 compliance program](/compliance/iso-27001) for implementation detail.

## ISMS Foundations

- [ ] ISMS scope formally defined and documented
- [ ] Information security policy approved by leadership and communicated organization-wide
- [ ] Risk assessment methodology defined and consistently applied
- [ ] Statement of Applicability (SoA) drafted, covering all 93 Annex A controls with justification for exclusions

## Risk Treatment

- [ ] Risk register maintained and reviewed on a recurring cycle
- [ ] Risk treatment plan in place with owners and deadlines for each identified risk
- [ ] Residual risk formally accepted by an accountable owner, not left implicit

## Organizational & People Controls

- [ ] Roles and responsibilities for information security clearly assigned
- [ ] Security awareness training delivered to all staff, with records kept
- [ ] Background checks and confidentiality agreements in place for relevant roles
- [ ] Asset inventory maintained, covering hardware, software, and data

## Technical Controls

- [ ] Access control policy enforced with least privilege and periodic review
- [ ] Cryptographic controls applied to data at rest and in transit
- [ ] Continuous vulnerability management and penetration testing program in place
- [ ] Logging and monitoring cover access, changes, and anomalies, with defined retention
- [ ] Secure development lifecycle practices applied to in-house software

## Supplier & Incident Management

- [ ] Supplier relationships risk-assessed and contractually bound to security requirements
- [ ] Incident response plan documented, tested, and includes post-incident review
- [ ] Business continuity and disaster recovery plans exist and are tested

## Internal Audit & Management Review

- [ ] Internal audit program covers the full ISMS scope on a defined cycle
- [ ] Nonconformities are tracked to corrective action, not just logged
- [ ] Management review meetings held and documented at planned intervals

## Where Alastor InfoSec Fits

[Alastor Shield](/products/alastor-shield) maps continuous evidence collection to Annex A controls and keeps your Statement of Applicability current between audits. [Alastor Pulse](/products/alastor-pulse) supplies the ongoing penetration testing evidence ISO 27001 auditors expect to see as a continuous program, not a once-a-year checkbox.

[Talk to our team](/about-us) about an ISO 27001 readiness assessment scored against this checklist.
