Answers to the questions practitioners most commonly ask about Four Themes.
Do the four themes replace ISO 27001's mandatory clauses 4 through 10?
No. The four themes (Organizational, People, Physical, and Technological) are the grouping structure for the reference controls in Annex A of ISO/IEC 27001:2022. They do not replace the certifiable ISMS requirements in clauses 4 through 10, which remain the requirements against which certification is granted. Annex A controls are selected via the Statement of Applicability and informed by risk assessment, whereas the clause requirements must be met to achieve certification.
Does adopting the four themes mean I must implement all controls within every theme?
No. The themes are simply a categorization of reference controls; they are not a mandate to implement everything. Applicability of individual controls is determined through your risk assessment and documented in the Statement of Applicability. Depending on scope, an organization may justify excluding controls that are not relevant to its ISMS, so the four themes describe how controls are organized rather than dictating which apply.
How do the four themes affect an existing Statement of Applicability built on the 2013 version?
When transitioning to the 2022 revision, organizations typically remap their Statement of Applicability to the restructured Annex A, which reorganizes the reference controls into the four themes and reduces the total control count relative to the 2013 edition. In most transitions this involves reconciling previously listed controls against the new structure, addressing any newly introduced controls, and confirming that each inclusion or exclusion remains justified by the risk assessment. Specific control counts and mappings depend on the version, so cite the edition when documenting the change.
How should I reference the four themes when scoping my ISMS?
The four themes can serve as an organizing lens when reviewing which reference controls are relevant to your defined scope. In most engagements, teams work through each theme to consider organizational, people-related, physical, and technological controls, then record applicability decisions in the Statement of Applicability. The scope of the ISMS ultimately governs which controls are in play, so the themes support, rather than determine, scoping decisions.
Where can I find implementation guidance for controls within each theme?
ISO/IEC 27001:2022 lists the reference controls in Annex A, while the companion standard ISO/IEC 27002:2022 provides more detailed implementation guidance organized under the same four-theme structure. Depending on your environment, sector-specific guidance such as ISO/IEC 27017 (cloud services) or ISO/IEC 27018 (protection of PII in public clouds) may supplement this. Note that 27002 is guidance and is not itself certifiable.
Does the four-theme structure map cleanly to the SOC 2 Trust Services Criteria?
Only partially. The four themes organize ISO 27001 Annex A reference controls, whereas SOC 2 is structured around the Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. Mapping between the two is possible for planning or efficiency purposes, but it is incomplete, and satisfying the four themes in an ISO 27001 ISMS does not automatically satisfy the criteria examined in a SOC 2 engagement.