News

ISO/IEC 27002:2022 restructures information security controls

Cybersecurity padlock on keyboard
In short: ISO/IEC 27002:2022 provides guidance on information security controls. It reorganizes controls into four themes — organizational, people, physical and technological — merges many controls, adds 11 new ones and introduces attributes to filter and map controls.

What are the main changes?

  • 93 controls instead of 114
  • Four themes replace 14 domains
  • 11 new controls, including threat intelligence and data masking
  • Attributes such as control type and cybersecurity concepts

What does it mean for ISO/IEC 27001 users?

ISO/IEC 27001:2022 Annex A was aligned with these controls, so certified organizations must update their Statement of Applicability.

Key takeaways

  • ISO/IEC 27002:2022 has 93 controls in four themes.
  • New controls address modern threats.
  • Annex A of ISO/IEC 27001:2022 follows this structure.

Frequently asked questions

Is ISO/IEC 27002 certifiable?

No. Organizations certify to ISO/IEC 27001, which references these controls.

What is a Statement of Applicability?

A document listing which controls apply and why.

What are control attributes?

Tags that help organizations view and select controls from different perspectives.