Don’t do SECURITY. Do business SECURELY.

ISO/IEC 27002:2022 published: a new structure for security controls

The revised code of practice for information security controls restructures 114 controls into 93, organised in four themes.

ISO has published ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection – Information security controls.

What’s changed?

  • The 114 controls in 14 domains are restructured into 93 controls in four themes: organisational, people, physical and technological.
  • 11 new controls, including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.
  • Each control now has attributes (such as control type, security properties and cybersecurity concepts) to help organisations filter and view controls in different ways.

A revised ISO/IEC 27001, with an updated Annex A aligned to these controls, is expected later this year.

Source: ISO/IEC 27002:2022 (ISO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights