Edition 2026.09 · Desk research from public vendor pages, last reviewed 29 September 2026

Lesson 2 of 10 · Track A · · Updated

ISO 27001 clauses 4 to 10, one at a time

Short answer

ISO/IEC 27001:2022 puts its requirements in clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation and improvement. Clauses 0 to 3 introduce the standard. Most platform features land in clauses 8 and 9; clauses 4 and 5 depend on decisions only your leadership can make.

G-01

Clause 4: what is the context of the organization?

Clause 4 asks you to understand your organisation and its environment, identify interested parties such as customers, regulators and staff, record what they require, and set the scope of the ISMS. The evidence is a short scope statement and a record of interested parties and requirements. No vendor on this site describes a workflow for this on its public pages, which is why the clause 4 column on our clause map is grey for everyone.

G-02

Clause 5: what does leadership have to show?

Top management has to show commitment: an information security policy they approved, roles and responsibilities that are assigned, and resources to run the ISMS. Platforms help by drafting policies. Vanta says its AI Agent drafts policies, Sprinto lists AI-assisted policies, Secureframe lists policy management, and Scrut describes a Policy Architect agent. Scytale lists an AI Policy Generator that is marked Coming soon. A drafted policy still needs a named approver.

G-03

Clause 6: how do planning and risk work?

Clause 6 is the core: a repeatable method for assessing information security risks, a risk treatment plan, the Statement of Applicability, and security goals with plans to reach them. Auditors look for a method you actually follow and results that match your environment. Vanta lists risk management on its Professional plan, Drata lists Risk Management Pro on GRC Enterprise, Secureframe and Sprinto list risk management on their entry plans, and Scrut describes a Risk Analyst agent.

G-04

Clause 7: what counts as support?

Support covers resources, competence, awareness, communication and documented information. In practice that means training records, onboarding and offboarding evidence, and document control. Sprinto lists training on its Foundation plan and Secureframe lists personnel management. Scytale lists HR system integrations such as BambooHR, Bob, Greenhouse and Lever, which supply people evidence; we mark that as partial on the map.

G-05

Clause 8: what happens in operation?

Operation means running what you planned: executing the risk treatment plan, operating the controls, and controlling suppliers and outsourced processes. This is where evidence collection lives, and every vendor here describes it. Supplier risk features also sit here: Scytale launched AI Third-Party Risk Management on 15 September 2026, and Vanta, Drata, Sprinto, Scrut and Secureframe each describe third-party or vendor risk features.

G-06

Clause 9: how is performance evaluated?

Clause 9 asks for monitoring and measurement, an internal audit programme and management review. Continuous monitoring from a platform covers the first part. Internal audit is a separate requirement: someone other than the control owner checks the ISMS against the standard. Scrut describes an Internal Auditor agent. Management review is a meeting with minutes and decisions, and no platform can hold it for you.

G-07

Clause 10: what does improvement require?

When something fails, you record the nonconformity, fix it, find the cause and check the fix worked, then keep improving the ISMS. Remediation features help here: Scytale lists AI Remediation, Vanta describes remediation snippets in Terraform, AWS CLI and CloudFormation, and Secureframe lists Comply AI for Remediation.