News

ISO/IEC 27001:2022 updates information security requirements

Cybersecurity padlock on keyboard
In short: The new edition of ISO/IEC 27001 aligns its Annex A controls with ISO/IEC 27002:2022, reorganized into four themes.

ISO and IEC have published ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements.

Main changes

  • Annex A controls aligned with ISO/IEC 27002:2022
  • Controls reorganized into four themes: organizational, people, physical and technological
  • New controls, including threat intelligence, cloud services security, data leakage prevention and secure coding
  • Minor updates to the management system clauses

Transition

Certified organizations have a transition period to move to the 2022 edition. Integrating information security with quality and business continuity management remains good practice.

Related: CGRCP and CBCM certifications.