ISO
ISO 27001:2022: what changed and how to prepare
The key changes in the 2022 edition of ISO/IEC 27001, what they mean for your Information Security Management System and how to organize your preparation.
· 6 min
ISO/IEC 27001 sets the requirements for implementing, maintaining and improving an Information Security Management System (ISMS). Its third edition was published in October 2022, replacing the 2013 version. The transition period for certified organizations has ended, so every certification audit today is performed against the 2022 edition.
Whether your company is starting its ISMS or reviewing an existing one, it pays to understand what changed and where to focus.
The system requirements changed only slightly
Clauses 4 to 10 —context, leadership, planning, support, operation, performance evaluation and improvement— remain essentially the same. The most relevant adjustments are:
- Interested parties. You must determine which of their requirements will be addressed through the ISMS.
- Planning of changes. There is now an explicit requirement to plan changes to the system in a controlled way.
- Processes and their interaction. The ISMS must include the necessary processes and their interactions, in line with other management system standards.
In addition, a 2024 amendment asks organizations to consider whether climate change is a relevant issue when analyzing their context. It is a minor adjustment, but the auditor may ask about it.
Annex A was completely reorganized
The most visible change is in Annex A, the reference list of controls. The 2022 edition contains 93 controls grouped into four themes:
- Organizational: policies, roles, supplier management, incident management, continuity.
- People: screening, awareness, remote working, confidentiality.
- Physical: perimeters, physical access control, equipment protection.
- Technological: logical access control, cryptography, backups, logging, secure development.
Several controls were merged, and new ones were added to reflect current risks, including:
- Threat intelligence.
- Information security for the use of cloud services.
- ICT readiness for business continuity.
- Configuration management.
- Information deletion and data masking.
- Data leakage prevention.
- Monitoring activities and web filtering.
- Secure coding.
What it means for your company
For an organization getting started, the 2022 edition is simply the standard. For one with an ISMS built on the 2013 edition, the work usually centers on three documents:
- The risk methodology and assessment, to ensure new topics —cloud, data leakage, configuration— are analyzed.
- The Statement of Applicability, which must refer to the 93 current controls and justify which apply.
- Policies and procedures, which must reflect controls that did not exist before or were only partially addressed.
How to prepare, step by step
- Define the scope. Which processes, sites and assets the ISMS covers. A well-defined scope avoids unnecessary work.
- Perform a gap analysis against the standard and Annex A.
- Assess and treat risks with a documented, repeatable methodology.
- Implement controls with evidence: a policy is not enough; the auditor will ask for records.
- Train your staff. Many incidents start with human error.
- Run an internal audit and management review before the certification audit.
Remember that the certificate is issued by an accredited certification body. The role of a consulting firm such as Delour is to prepare the system, verify that it works and support you during the audit.
To find out where your organization stands, start with our self-assessment or request an assessment with a specialist.