In short: The new edition of ISO/IEC 27001 aligns its Annex A controls with ISO/IEC 27002:2022, reorganized into four themes.
ISO and IEC have published ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements.
Main changes
- Annex A controls aligned with ISO/IEC 27002:2022
- Controls reorganized into four themes: organizational, people, physical and technological
- New controls, including threat intelligence, cloud services security, data leakage prevention and secure coding
- Minor updates to the management system clauses
Transition
Certified organizations have a transition period to move to the 2022 edition. Integrating information security with quality and business continuity management remains good practice.