ISO/IEC 27001:2022: the clauses the checker cites
The 8 ISO/IEC 27001:2022 clauses behind the findings, each with the evidence an auditor asks for where it is held.
Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording.
8 clauses
ISO 27001 8.32 Change managementPut changes to facilities and systems through change management procedures.
Where it usually falls short: Missing formal approval; No rollback plan documented
Source: ISO/IEC 27001:2022
ISO 27001 5.3 Segregation of dutiesSplit conflicting duties so no single person can run a sensitive process end to end unchecked.
Where it usually falls short: Combining conflicting roles in small teams; Lack of documented exceptions
Source: ISO/IEC 27001:2022
ISO 27001 8.25 Secure development life cycleEstablish and apply rules for secure development of software and systems.
Where it usually falls short: Policy exists but not enforced; Threat models not updated for new features
Source: ISO/IEC 27001:2022
ISO 27001 8.31 Separation of development, test and production environmentsSeparate and secure development, test and production environments.
Where it usually falls short: Policies exist but are not enforced; Shared credentials across environments
Source: ISO/IEC 27001:2022
ISO 27001 8.4 Access to source codeAppropriately manage read and write access to source code, development tools and libraries.
Where it usually falls short: Shared accounts used for source code repositories; Permissions not reviewed on a regular basis
Source: ISO/IEC 27001:2022
ISO 27001 8.9 Configuration managementEstablish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
Where it usually falls short: Outdated baselines; Missing change approvals
Source: ISO/IEC 27001:2022
ISO 27001 8.19 Installation of software on operational systemsSecurely manage software installation on production systems.
Where it usually falls short: Missing formal approval for installations; No evidence of post‑install verification
Source: ISO/IEC 27001:2022
ISO 27001 8.29 Security testing in development and acceptanceDefine and run security testing across the development life cycle.
Where it usually falls short: Testing only after release; Inconsistent test coverage across modules
Source: ISO/IEC 27001:2022