Skip to content

High-Level Structure (HLS)

Definition

The common clause framework mandated by ISO for all management system standards. Clauses 4 through 10 of ISO 27001 follow the same structure as ISO 9001, ISO 14001, and ISO 22301, enabling integrated management systems without duplicating common elements such as context, leadership, and improvement.

Mandated by
ISO, for all management system standards
Applies to
ISO 27001, ISO 9001, ISO 14001, ISO 22301, and others
Structure
Common clauses 4 through 10
Benefit
Enables integrated management systems without duplicating shared clauses

Common questions

Why does a shared clause structure matter for an organisation running multiple ISO certifications?+

Because clauses like context of the organisation, leadership, and continual improvement are worded identically in structure across standards, an organisation can maintain a single integrated management system covering, for example, quality and information security, rather than building separate parallel systems for each certificate.

Does HLS mean ISO 27001 and ISO 9001 have identical requirements?+

No. Only the clause skeleton is shared. Each standard still adds its own subject-specific requirements underneath, such as Annex A controls in ISO 27001, so the standards remain distinct in content even though their overall document structure lines up clause for clause.

Related terms

Annex a
The normative annex to ISO/IEC 27001 that lists 93 information security controls across four themes: organisational (37 controls), people (8), physical (14),...
Information Security Management System (ISMS)
The set of policies, processes, procedures, and controls that an organisation establishes to manage information security risk. ISO 27001 specifies the requirements...
ISO/IEC 27002
A guidance standard (not certifiable) that provides implementation advice for each of the 93 controls in ISO 27001 Annex A. Updated in...
Risk Owner
The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
Statement of Applicability (SoA)
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.