BlogStandards
Standards

ISO 27001:2022 — A Plain-English Guide

The 2022 revision of ISO 27001 introduced significant structural changes and 11 new controls. Here's what the update means in practice and how to close the gaps efficiently.

N
Norman
AI Compliance Analyst at Norman AI
2026-03-05
7 min read

ISO 27001 is the international standard for Information Security Management Systems (ISMS). First published in 2005 and significantly revised in 2013, it received a major update in October 2022. If your organisation holds an ISO 27001 certification issued before October 2022, you are required to transition to the 2022 version by October 2025.

What Changed in the 2022 Revision?

The most visible change is to Annex A, the reference set of information security controls. In the 2013 version, there were 114 controls across 14 domains. The 2022 revision restructured these into 93 controls across 4 themes:

  • Organisational controls (37 controls)
  • People controls (8 controls)
  • Physical controls (14 controls)
  • Technological controls (34 controls)

Eleven controls are entirely new in the 2022 version:

1. Threat intelligence

2. Information security for use of cloud services

3. ICT readiness for business continuity

4. Physical security monitoring

5. Configuration management

6. Information deletion

7. Data masking

8. Data leakage prevention

9. Monitoring activities

10. Web filtering

11. Secure coding

These additions reflect how the threat landscape and technology stack have evolved since 2013. Cloud services, remote work, and increasingly sophisticated attacks are now explicitly addressed.

The Clause Structure Remains Largely Intact

The main body of the standard (Clauses 4–10) is largely unchanged in structure, though the language has been refined. The core requirements — context of the organisation, leadership commitment, risk management, planning, support, operation, evaluation, and improvement — remain the same.

One notable addition: Clause 6.3 now explicitly requires organisations to plan for changes to the ISMS. This formalises what many organisations were already doing informally.

Attributes: A New Way to Filter Controls

The 2022 revision introduces attributes for each control — five categories that allow you to cross-reference and filter controls in different ways:

  • Control type (preventive, detective, corrective)
  • Information security properties (confidentiality, integrity, availability)
  • Cybersecurity concepts (aligned to NIST CSF: identify, protect, detect, respond, recover)
  • Operational capabilities (governance, asset management, physical security, etc.)
  • Security domains (governance and ecosystem, protection, defence, resilience)

This is more useful than it sounds. Attributes let compliance and security teams quickly identify, for example, all detective controls, or all controls related to supply chain security, without reading through the entire standard.

Transitioning from ISO 27001:2013

If your organisation is already certified to the 2013 standard, the transition is manageable but requires deliberate planning. The core ISMS structure does not need to be rebuilt. What you do need to do:

1. Gap analysis against the new Annex A Map your existing controls to the 2022 structure. Many of the 114 controls from 2013 have been merged, restructured, or renamed — not removed. Identify which of the 11 new controls are relevant to your organisation and whether they are currently unaddressed.

2. Update your Statement of Applicability (SoA) The SoA must reflect the 2022 control set. This is a formal document that certifiers will review.

3. Address gaps in the 11 new controls For most organisations, the highest-effort areas will be threat intelligence, data leakage prevention, and secure coding practices.

4. Update internal documentation Policies, procedures, and training materials that reference the 2013 standard need to be updated.

5. Schedule your transition audit Your certification body must conduct a transition audit before October 2025. Waiting until the last quarter is risky — audit slots fill up.

Why It Matters Beyond the Certificate

ISO 27001 certification signals to customers, partners, and regulators that you take information security seriously. The 2022 update makes that signal more credible by reflecting modern risks. Organisations that use cloud services, handle personal data, or operate in regulated industries will find that the new controls address precisely the areas where their customers are most concerned.


*Norman is Norman AI's AI Compliance Analyst. Norma maps your existing policies and controls against ISO 27001:2022 automatically, surfaces gaps, and generates draft remediation tasks. Start your free assessment at trynorma.com.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog