Logo webu

Transitioning with Confidence: Embracing ISO/IEC 27001:2022

16. 8. 2023 | 5 min read | author: Karolína Kubínová

ISO 27001, an international standard for information security management systems (ISMS), provides a framework to establish, implement, and continually improve security practices. Recently, ISO/IEC 27001:2022 was released, superseding the previous 2013 edition. So what's new?

Karolína Kubínová works at axelum as a Security Analyst specializing in preparing companies for security certifications, conducting internal audits and improving security processes (mainly based on ISO 27K, KB Act and best practices). She also works on social engineering, especially phishing and vishing campaigns, and security awareness.

The Latest in ISO/IEC 27001:2022

The ISO/IEC 27001:2022 updates bring noteworthy changes, mainly showcased in Annex A. But it's not just about Annex A – the new version also brings subtle enhancements. Terminology has been clarified, sentences have been revamped for better understanding, and paragraphs restructured for clarity.

So, what's different? ISO/IEC 27001:2022 now places a greater spotlight on documenting information security objectives and evaluating performance (think monitoring and measurement). There's also a call for methodical, controlled adjustments to the information security management system.

In the realm of Operational Planning and Control, organisations are now tasked with planning, executing, and managing processes to hit their information security objectives. This involves setting up process criteria and implementing controls that align with those criteria. It's all part of the evolving landscape of ISO/IEC 27001:2022.

Revamping Annex A

Annex A's controls have transformed. The total number of controls has been slimmed down from 114 to 93 with a blend of merging and adding. And while the control family has become leaner, it's also become smarter. This streamlined approach means a more effective and succinct set of controls. And speaking of controls, ISO 27002, the security control guru, has also had a 2022 update.

Out of those 93 controls, 35 remain unchanged, 23 have been given a fresh name, 56 have cosied up into 24 pairs, and one has turned into a dynamic duo. Not stopping there, 11 newcomers have joined the control party.

2013: 114 controls in 14 sections
  1. Information security policies
  2. Organisation of information security
  3. Human resources security
  4. Asset management
  5. Access control
  6. Cryptography
  7. Physical and environmental security
  8. Operational security
  9. Communications security
  10. System acquisition, development and maintenance
  11. Supplier relationships
  12. Information security incident management
  13. Information security aspects of business continuity management
  14. Compliance 



2022: 93 controls in 4 sections
  1. People controls
  2. Organizational controls
  3. Technological controls
  4. Physical controls

and 11 new controls

  1. Threat intelligence
  2. Information security for the use of cloud services
  3. ICT readiness for business continuity
  4. Physical security monitoring
  5. Configuration management
  6. Information deletion
  7. Data masking
  8. Data leakage prevention
  9. Monitoring activities
  10. Web filtering
  11. Secure coding

Attributes for Control Clarity

Now each control has several attributes assigned to it. Including control attributes in the standard provides a standardised method for organising and categorising controls that allow efficient sorting and filtering. This facilitates the identification of specific requirements for different departments or groups within an organisation.

The standard provides a clear representation of control attributes:

  1. Control type: preventive, detective, corrective.
  2. Information security properties: confidentiality, integrity, availability.
  3. Cyber security concepts: identify, detect, protect, respond, recover.
  4. Operational capabilities: application security, asset management, continuity, governance, human resource security, identity and access management, information protection, information security assurance, information security event management, legal and compliance, physical security, secure configuration, system and network security, supplier relationships security, threat and vulnerability management.
  5. Security domains: defence, governance and ecosystem, protection and resilience.

Smooth Transition to ISO/IEC 27001:2022

Please note that the new update does not affect your current certification. ISO 27001:2013 certification is still valid until October 31, 2025. However, it is advisable for companies to start updating their controls and processes to comply with the requirements of the new revision as soon as possible.

Here's the timeline breakdown:

What Needs to Be Done?

Analysis of compliance with the updated ISO/IEC 27001:2022 and ISO/IEC 27002:2022 standards.
Planning and implementation of necessary changes in the information security management system.
Providing risk analyses according to ISO/IEC 27005:2022 and updating the Statement of Applicability.

Don’t Be Afraid to Ask for Assistance!

Whether youre adapting existing ISMS or implementing the standard from scratch, were here to help you every step of the way! At axelum, we understand the importance of a seamless transition to ISO/IEC 27001:2022, and we are dedicated to providing you with the necessary support and expertise.

With our team of experts and extensive experience with information security management, we offer comprehensive support tailored to meet your specific needs. Our services include conducting thorough gap analyses, developing customised transition plans, and providing expert guidance on updating policies, procedures, and documentation to align with the new ISO/IEC 27001:2022 requirements.

Right in Your Inbox

Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.

All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.