ISO has published ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection – Information security management systems – Requirements.
Key changes
- Annex A is replaced to align with ISO/IEC 27002:2022: 93 controls in four themes, including 11 new controls.
- Minor changes to the management system clauses, including a new clause 6.3 on planning of changes and clarification that processes needed for the ISMS must be determined.
- Greater emphasis on monitoring, and on the needs of interested parties being addressed through the ISMS.
Transition: certified organisations have until 31 October 2025 to transition, and certification bodies will stop issuing certificates against the 2013 edition before then. Start with a gap analysis, then update your risk treatment, Statement of Applicability and supporting procedures.
Source: ISO/IEC 27001:2022 (ISO)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.