What changed between ISO 27001:2013 and ISO 27001:2022?
The primary change between ISO/IEC 27001:2013 and ISO/IEC 27001:2022 is the update to Annex A, which now references ISO/IEC 27002:2022. This revision consolidates the previous 114 controls into 93 controls across four thematic categories: Organisational, People, Physical, and Technological. Additionally, the main body of ISO/IEC 27001 received minor updates to align with the harmonised structure for management system standards and to clarify certain requirements, though the core principles of the Information Security Management System (ISMS) remain consistent.
The most significant alteration lies within Annex A, which enumerates the information security controls. ISO/IEC 27001:2022 now references ISO/IEC 27002:2022, which fundamentally reorganises and updates the control set. The previous 14 control domains and 114 controls have been streamlined into 93 controls, categorised under four themes: Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). This consolidation includes the introduction of 11 new controls addressing emerging threats and technologies, such as threat intelligence, information security for cloud services, and data masking. Each control is also accompanied by five attributes (control type, information security properties, cybersecurity concepts, operational capabilities, and security domains) to facilitate better categorisation and implementation.
Beyond Annex A, the main body of ISO/IEC 27001:2022, comprising clauses 4 to 10, received relatively minor updates. These revisions primarily aim to align the standard with the harmonised structure for management system standards (Annex SL) and to improve clarity, rather than introducing substantial new requirements for the Information Security Management System (ISMS). Key changes include minor wording adjustments in clauses such as 4.2 (Understanding the needs and expectations of interested parties), 6.1 (Actions to address risks and opportunities), and 6.2 (Information security objectives and planning to achieve them). The fundamental requirement for organisations to define their ISMS scope, conduct risk assessments, and produce a Statement of Applicability (SoA) remains central to the certification process.
Sources
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection — Information security controls