Skip to content

Operationalizing ISO/IEC 27001:2022 in Modulos

ISO 27001 becomes manageable when the ISMS is treated as an operating model — scope, risk assessment, control execution, evidence, continual improvement, repeated. This page is the implementation playbook for running the ISMS on Modulos using the OFF-9 + MFF-9 framework templates.

Quick decision

  • You are starting a fresh ISMS rollout → one organization project with OFF-9, plus AI-system projects with MFF-9.
  • You already run ISO 42001 (AIMS) or 27701 (PIMS) → add OFF-9 to the existing organization project; reuse the shared Annex SL management-system processes (document control, internal audit, management review, corrective action); only stand up information-security-specific work.
  • You are building the Statement of Applicability → the SoA is mandatory under Clause 6.1.3 d. Store as control-level evidence on ORF-205. Every Annex A control gets a position.
  • You need to scope the AI-system MFF-9 work → MFF-9 records the per-AI-system information-security risk overlap (operational Clause 8.2 risk assessment + 8.3 risk treatment) and the 93 Annex A controls under four theme requirements (MRF-390MRF-393). One MFF-9 project per AI system in scope.

TL;DR

  • Two framework templates map ISO 27001: OFF-9 (org, 28 ORF requirements) + MFF-9 (app, 6 MRF requirements — two information-security risk requirements plus four Annex A theme requirements).
  • Two project layers: organization project for the ISMS spine; AI-system projects for per-system overlap.
  • ISMS spine on the org project: scope, policy, risk method + SoA, internal audit, management review, corrective action.
  • Per-AI-system work on the app project: information-security risk assessment + treatment for each AI deployment, plus the 93 Annex A controls tracked individually under four theme requirements.
  • Statement of Applicability = mandatory under Clause 6.1.3 d. Owner-authored documentation stored as evidence on ORF-205.
  • IMS integration with ISO 42001 / 27701: share Clauses 4–10 processes; keep standard-specific risk and control work explicit.

Primary source

ISO/IEC 27001:2022Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Modulos framework templates: OFF-9 and MFF-9 in modulos_platform/content/templates/frameworks/. Available via the ISO Online Browsing Platform. © ISO.

ProjectTemplateWhen to use
One organization projectOFF-9 (add to existing org project if you already run ISO 42001 / 27701)Scope statement, information-security policy, Annex SL processes, Statement of Applicability, internal audit, management review, corrective action
AI-system projectsMFF-9Per-AI-system information-security risk assessment + treatment, plus the Annex A controls (four theme requirements, 93 controls)

The split mirrors the standard's logic: organization-wide ISMS spine on one side; per-system operational work on the other.

Set up: a sequence that works

How to operationalize ISO 27001 in Modulos

OFF-9 (org-level) mapping:

ISMS elementOFF-9 requirementClause
Organizational contextORF-1964.1
Interested partiesORF-1974.2
ISMS scopeORF-1984.3
ISMS itselfORF-1994.4
Leadership commitmentORF-2005.1
Information-security policyORF-2015.2
Roles and responsibilitiesORF-2025.3
Risk and opportunities — generalORF-2036.1.1
Information-security risk assessmentORF-2046.1.2
Information-security risk treatment + Statement of ApplicabilityORF-2056.1.3 (incl. 6.1.3 d)
Information-security objectivesORF-2066.2
Planning of changesORF-2076.3
Resources / competence / awareness / communicationORF-208ORF-2117.1–7.4
Documented informationORF-212 / ORF-213 / ORF-2147.5.1–7.5.3
Operational planning and controlORF-2158.1
Monitoring + measurementORF-2169.1
Internal audit + audit programORF-217 / ORF-2189.2.1 / 9.2.2
Management review (process / inputs / outputs)ORF-219 / ORF-220 / ORF-2219.3.1 / 9.3.2 / 9.3.3
Continual improvementORF-22210.1
Nonconformity and corrective actionORF-22310.2

MFF-9 (app-level) mapping:

RequirementClause / AnnexTopic
MRF-2218.2Information-security risk assessment (per AI system)
MRF-2228.3Information-security risk treatment (per AI system)
MRF-390Annex A.5Organizational controls (37 controls)
MRF-391Annex A.6People controls (8 controls)
MRF-392Annex A.7Physical controls (14 controls)
MRF-393Annex A.8Technological controls (34 controls)

Operating rules:

  • Scope, policy, risk method, SoA, internal audit, management review live on OFF-9. One organization project per organization.
  • Per-AI-system information-security risk + treatment and the Annex A controls live on MFF-9. One MFF-9 project per AI system in scope; each applicable Annex A control is tracked individually under its theme requirement (MRF-390MRF-393).
  • The Statement of Applicability is owner-authored documentation stored as control-level evidence on ORF-205 — the org-level applicability record. The SoA carries the ISMS-wide inclusion/exclusion decisions; the per-control work itself is tracked on the MFF-9 theme requirements.

What is first-class UI vs evidence-attached

  • First-class — Modulos exposes the OFF-9 / MFF-9 framework template on the project (Settings → Frameworks), the requirement readiness signal on each ORF / MRF requirement, and — on MFF-9 — each of the 93 Annex A controls as an individually tracked control under its theme requirement.
  • Evidence-attached (no dedicated UI) — Statement of Applicability, risk-assessment method document, risk register, control execution records, internal-audit program + reports, management-review minutes, corrective-action records, supplier assessments. Each is owner-authored documentation stored as control-level evidence on the relevant requirement.

ISO 27001 doesn't prescribe the form of these artifacts — only that they exist, are current and are reviewable. Locking them into a prescribed workflow would defeat the standard's risk-driven intent.

Cross-framework mapping (preview)

ISO 27001 elementAdjacent provision
Clause 4.3 ISMS scopeISO 42001 Clause 4.3 AIMS scope; ISO 27701 Clause 4.3 PIMS scope
Clause 5.2 information-security policyISO 42001 Clause 5.2 AI policy; ISO 27701 Clause 5.2 privacy policy
Clause 6.1.2 information-security risk assessmentISO 42001 Clause 6.1.2 AI risk assessment; ISO 31000
Clause 6.1.3 risk treatment + SoAISO 42001 Clause 6.1.3; EU AI Act Article 9 RMS
Annex A theme 5 (supplier relationships)EU AI Act Article 25 value chain; NIS2 Article 21(2)(d); ISO 42001 Annex A.10
Annex A theme 5 (incident management)EU AI Act Article 73 serious-incident reporting; GDPR Article 33
Annex A theme 8 (cryptography, logging)EU AI Act Article 12 logging; Article 15(5) cybersecurity
Clauses 7.5 / 9.2 / 9.3 / 10.2 (shared Annex SL)ISO 42001 / 27701 same clauses — implement once, share evidence

IMS integration — ISO 27001 + 42001 + 27701

ISO management-system standards share the Annex SL backbone, which makes IMS integration realistic. In Modulos the org-level Clause 4–10 controls are one shared set, written to read correctly under whichever management system applies. The shared layer includes document control (Clause 7.5), internal audit (Clause 9.2), management review (Clause 9.3), corrective action (Clause 10.2), competence (Clause 7.2) and communication (Clause 7.4) — implement a shared control once and it satisfies all three standards. Every ISO requirement panel names its exact clause reference and links to the matching requirement in the sibling standards ("Harmonized with"), so the reuse is explicit.

Where one standard imposes work the others do not, that obligation is its own control mapped only to that standard, so it never appears in another framework's checklist. Climate-change relevance (Clause 4.1) and communication methods (Clause 7.4) are shared by all three; information-security policy establishment (Clause 5.2) and the monitoring/measurement assignee determination (Clause 9.1) are ISO 27001-only; risk-owner identification (Clause 6.1.2) is shared by ISO 27001 and ISO 27701; information-security-program documentation (Clause 6.1.3) is ISO 27701-only; AI-policy alignment and AIMS documentation are ISO 42001-only.

What stays standard-specific overall:

  • ISO 27001: information-security risk + treatment + Annex A (normative) information-security controls.
  • ISO 42001: AI policy, AI risk + impact (6.1.2/3/4), Annex A (informative) AI lifecycle and data controls.
  • ISO 27701: privacy risk, PII controller / processor distinctions, and the PII controller, processor and joint controls (Tables A.1–A.3 of the 2025 edition).

Practical pattern in Modulos: add the relevant OFF templates to the same organization project; share evidence across them where a single shared control satisfies multiple obligations (e.g., a single internal-audit program that covers ISMS + AIMS + PIMS).

Related: Integration with AI governance · ISO 42001 vs ISO 27001 comparison.

Common pitfalls

  • Treating Annex A as a checklist. "We have all Annex A controls" with thin evidence does not pass Stage 2.
  • Stale SoA. Controls remain "implemented" after the system or vendor has changed. The SoA needs to live with the ISMS.
  • Internal audit as document review. Auditors expect operational sampling — control execution records, decisions, evidence — not just policy completeness.
  • Mixing ISMS work with product execution. The org project holds the management-system spine; per-AI-system MFF projects hold the operational evidence. Keeping them separate keeps review queues legible.
  • Reproducing Annex A control text. © ISO. Reference Annex A controls by theme and reference number; describe the implementation in your own words.

Source attribution

ISO/IEC 27001:2022Information security, cybersecurity and privacy protection — Information security management systems — Requirements, Clauses 4–10 + Annex A. © ISO/IEC. Available via the ISO Online Browsing Platform. Modulos framework templates OFF-9 and MFF-9 in modulos_platform/content/templates/frameworks/.

Disclaimer

This page is for general informational purposes and does not constitute legal or certification advice.