C L A R E N T   3 6 0

Loading

ISO/IEC 27001:2022 Self-Assessment

Gauge your standard readiness, track real-time maturity, and review comprehensive administrative protocols aligned directly with security clauses.

Introducing ISO/IEC 27001:2022

Globally recognized best practice, ISO/IEC 27001, provides the robust framework and flexibility you need to manage and protect your information. It helps you continually review and refine your processes, building information security resilience today, while ensuring readiness for tomorrow.

The Benefits of Certification

Independent certification demonstrates your organization’s commitment to excellence.

By gaining third-party assurance that your information security management system (ISMS) meets the requirements of ISO/IEC 27001, you can inspire confidence in your ability to safeguard your information assets, mitigate risks, and build trust with an internationally recognized mark of excellence.

ISO 27001 GRC

Why Organizations Adopt ISO 27001

Establish a structured, internationally recognized framework to secure critical assets, mitigate systemic risks, and foster stakeholder trust.

Proactive Risk Management

Identify threats, assess vulnerabilities, evaluate potential impacts, and apply security controls. Build proactive resilience against data breaches, ransomware attacks, and insider threats.

Legal & Regulatory Compliance

Support regulatory, contractual, and privacy expectations. Certification provides verifiable proof that your information security practices are properly designed, implemented, and continuously monitored.

Trust & Competitive Advantage

Reassure customers, partners, and stakeholders that sensitive information is handled securely. Win enterprise contracts and tenders that require ISO 27001 certification as a prerequisite.

Governance & Continuity

Strengthen organizational governance by defining GRC roles and responsibilities. Build resilient recovery capabilities to protect assets and ensure business continuity during operational disruptions.

Are you ready to audit your security maturity?

Increasing reliance on digital services makes information security a necessity. Unlock your GRC score, gauge your ISO 27001 readiness range, and receive tailored action recommendations instantly.

How the Self-Assessment Works

By filling in the checklist below, you can gauge what stage of maturity your ISMS is currently at in relation to the main requirements of the standard, and what actions you can take next.

Check each box once you have validated the corresponding controls. Each completed item counts as one point towards your final score.

Clause 4 - Context of the Organization
0 / 4 Completed
1. Factors Influencing Information Security

Has the organization evaluated internal and external factors influencing information security, including stakeholder expectations, regulatory obligations, customer requirements, and the potential impact of climate change?

2. Stakeholder Expectations & Obligations

Has the organization determined which stakeholder expectations, legal obligations, and relevant requirements must be addressed by the Information Security Management System (ISMS)?

3. Establishing ISMS Scope

Has the organization clearly established the scope of its Information Security Management System, including organizational boundaries, outsourced activities, partner involvement, and any climate change–related considerations?

4. Defining Required ISMS Processes

Has the organization defined and implemented the necessary processes, roles, responsibilities, and continual improvement mechanisms required to ensure the ongoing effectiveness of the Information Security Management System?

Clause 5 - Leadership
0 / 3 Completed
5. Policies, Objectives & Communication

Has your organization established an information security policy and defined objectives that align with its strategic direction, and have these been effectively communicated to employees and relevant stakeholders?

6. Roles, Responsibilities & Authorities

Have roles, responsibilities, and authorities been clearly defined and assigned to ensure effective management, operation, and reporting of the information security management system (ISMS)?

7. Achieving Objectives & Personal Duties

Has leadership ensured that a structured plan exists to achieve information security objectives, and that personnel understand their importance and their individual responsibilities in supporting them?

Clause 6 - Planning
0 / 8 Completed
8. Risks and Opportunities Identification

Has the organization identified key risks and opportunities that may impact the effectiveness of the Information Security Management System (ISMS), and established appropriate actions to address them?

9. Repeatable Risk Assessment Methodology

Is there a defined, consistent, and repeatable methodology for conducting information security risk assessments, including evaluation of risk likelihood and potential impact?

10. Risk Acceptance Criteria & Priorities

Have risk acceptance criteria been formally established, and are identified risks evaluated and prioritized according to these criteria?

11. Assigned Risk Owners

Are risk owners assigned for each identified risk, with defined responsibilities to review, approve, and oversee risk treatment activities?

12. Controls Verification (Annex A Alignment)

Have suitable risk treatment options and security controls been selected and implemented, and verified against ISO/IEC 27001 Annex A to ensure no applicable controls have been overlooked?

13. Statement of Applicability (SoA)
Has a Statement of Applicability (SoA) been developed that:
  • identifies selected security controls,
  • specifies applicable Annex A controls,
  • justifies inclusion or exclusion decisions,
  • documents any additional controls implemented, and
  • confirms implementation status?
14. Risk Treatment Plan & Residual Risks

Is a formal risk treatment plan maintained, and are any residual risks explicitly reviewed and accepted by authorized management?

15. Measurable ISMS Objectives

Have measurable ISMS objectives been defined, communicated, and aligned with organizational information security goals?

Clause 7 - Support
0 / 4 Completed
16. Structured Change Management

Does the organization follow a controlled and structured process to plan, evaluate, and manage changes affecting the ISMS?

17. Resource Provisioning

Are adequate resources—including personnel, technology, infrastructure, and operational environment—provided to establish, operate, maintain, and continually improve the ISMS?

18. Competency, Awareness & Training
Are individuals performing ISMS-related roles competent through appropriate education, training, or experience, and aware of:
  • their responsibilities,
  • the information security policy, and
  • the significance of their contributions to ISMS effectiveness?
19. Documented Information Control

Is documented information properly created, maintained, protected, and controlled, and are internal and external communication requirements clearly defined and managed?

Clause 8 - Operation
0 / 4 Completed
20. Integrating Risks into Operations

Have risk and opportunity management actions been integrated into operational processes, and are these processes consistently executed as planned?

21. Controlling Planned & Unplanned Changes

When organizational or system changes occur, are they planned, reviewed, and controlled to minimize potential impacts on information security?

22. Outsourcing & Third-Party Governance

Are outsourced activities and third-party service providers effectively governed to ensure compliance with established information security requirements?

23. Periodic Risk Assessments

Are information security risks periodically assessed, with documented records maintained for risk evaluations, treatment decisions, and management approvals?

Clause 9 - Performance Evaluation
0 / 5 Completed
24. Monitoring & Measurement Criteria

Have measurement criteria been established, including what is monitored, the methods used, the frequency of measurement, responsible personnel, and the maintenance of documented results?

25. Independent Internal Audits

Are internal audits conducted by independent and impartial auditors, with findings properly documented and communicated to management?

26. Resolving Audit & Monitoring Nonconformities

Is a formal process established to identify, manage, and resolve issues or nonconformities detected through monitoring activities or audit outcomes?

27. Qualified Audit Reports

Are internal audits performed objectively by qualified auditors, and are audit results recorded and reported to relevant management stakeholders?

28. Performance Records Retention

Has the organization defined monitoring and measurement requirements, including responsibilities, timing, methodologies, and retention of performance records?

Clause 10 - Improvement
0 / 1 Completed
29. Corrective Actions & Root Cause Analysis

When an issue occurs, do you take corrective action, identify and address the root cause, verify the effectiveness of the fix, and document the outcome?

0 / 29 Points Developing
Developing
0 - 13 Points

Initial Stage

Managed
14 - 21 Points

Defined Program

Optimized
22 - 29 Points

Audit Ready

Action Recommended: Implement Information Security Training

Based on your organization’s maturity score, we’d recommend exploring information security training and qualifications for you and your team.

Our bespoke information security training courses aligned to professional certifications provide the most relevant and up-to-date skills and knowledge. Our courses can help you to interpret and understand the standard requirements and how to audit the management system. We also offer customized courses focused on key skills that bolster your abilities and knowledge as a security professional, such as cybersecurity, data and privacy, AI, cloud security, and more. Wherever you are on your journey, whatever your role, we have a training solution to help you succeed.

Action Recommended: Schedule Clarent360 GAP Assessment

Based on your organization’s maturity score, you may benefit from a Gap Assessment from our experts to improve your organization’s security posture.

A Gap Assessment with CLARENT360 provides you with a method of assessing your current situation against future goals, pinpointing areas where your existing program does not meet the requirements of ISO/IEC 27001. Our specialists are uniquely positioned to help you, thanks to their significant experience and expertise in information security management across many industry sectors. Following your assessment, you’ll have actionable metrics to act upon, progressing your organization towards achieving ISO/IEC 27001 certification.

Congratulations: Ready for ISO/IEC 27001 Certification!

Based on your organization’s maturity score, you may be ready to achieve ISO/IEC 27001 certification.

Certification with ISO 27001:2022 comes with the confidence of partnering with an independent, trusted, global organization. Our expert and qualified auditors have deep knowledge of information security management across industries, so they understand your needs and challenges. CLARENT360 can provide you with internal certification audits and support you with external audit preparations, acknowledging your organization’s commitment to driving growth, risk management, and regulatory compliance.

Ready to take the next step in your GRC journey?

Based on your Developing status, contact our experts to get professional training and establish your ISMS baseline.

ISO/IEC 27001:2022 Official Standard

Access the official ISO publication directory to review standard clauses, mandatory guidelines, and full certification requisites.

Visit ISO Directory

ISO/IEC 27701:2025 Privacy Standard

Access the official ISO publication directory to review Privacy Information Management System (PIMS) standard requirements, guidelines, and PII protection controls.

Visit ISO Directory

Reset Assessment?

This will clear all 29 self-assessment checklist selections and reset your maturity score. This action cannot be undone.