What Keel's ISO 27001 rows are, and what they are not

This one is not an exclusion list. Every requirement of clauses 4 to 10 is in scope. What is declared instead is the grain Keel scores them at, and the two counts the total is built from.

116scored rows
23management-clause rows
93Annex A controls
3clauses out
3open verifications

The grain

Every requirement of clauses 4 to 10 is in scope. What is declared is the grain: Keel scores them at the standard’s second-level clause rather than at every sub-clause beneath it, while Annex A’s 93 controls are scored at the standard’s own leaf level. A readiness percentage here is a percentage of 116 rows at that depth, not of every sub-clause the standard states.

As it appears on the framework page. Keel scores ISO/IEC 27001 clauses 4-10 at the standard’s second-level clause (4.1, 6.1, 7.5 and so on) rather than at every sub-clause beneath them, while Annex A’s 93 controls are scored at the standard’s own leaf level. A readiness percentage here is therefore a percentage of 116 rows at that depth, not of every sub-clause the standard states.

A coarser grain is not a narrower scope. A coarser grain is not a narrower scope. Nothing in clauses 4 to 10 is left unscored, and a workspace at 100% here has answered for every management-system requirement the standard states. What it has not done is answer for each of them separately, and a certification body will ask at its own grain rather than at Keel’s.

What the coarser grain costs

The cost of the coarser grain is the denominator, not the coverage. Keel itself cites ISO 27001 sub-clauses this model does not contain as rows, and they are listed below so the gap between what Keel says elsewhere and what it scores here is visible rather than something a reader has to notice. Each of them sits inside a row that is authored, and that row’s summary carries the sub-clause content in aggregate.

Out entirely

What has not been verified

Keel does not hold a copy of ISO/IEC 27001:2022. These are the figures behind the 116 that rest on Keel's own inventory rather than on the published text, said out loud rather than left for someone to find.

The inconsistency with ISO 9001

ISO 9001:2015 is the same harmonized management-system skeleton and Keel models it to its own numbered leaf level: 7.5.1, 7.5.2, 7.5.3, 9.2.1, 9.2.2, 9.3.1 and so on. Two management-system standards, two different depth rules. That inconsistency is real, it is not resolved, and resolving it means acquiring ISO/IEC 27001:2022. It is published here rather than left for a reader to discover by comparing two framework pages.

Where this comes from

ISO/IEC 27001:2022, management clauses 4 to 10 plus Annex A. Clause numbers and the descriptions of what each clause is are factual references; no text of the standard is reproduced or paraphrased, and the clause descriptions below are Keel’s words rather than the standard’s published headings, because Keel does not hold a copy from which to quote them. Keel is not affiliated with, endorsed by, or acting for ISO or IEC.

Hold a copy of the standard and think one of these is wrong? That is the point of publishing it, so tell us which line. The full framework is at ISO/IEC 27001.