The 2022 revision of ISO/IEC 27001 restructured Annex A significantly. The 114 controls of the 2013 edition were consolidated into 93 controls organised across four themes: Organisational (37 controls), People (8), Physical (14), and Technological (34).
Eleven controls are genuinely new — including threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
Organisations certified to the 2013 standard had a transition deadline to move to the 2022 edition. The work involved is usually less dramatic than the restructure suggests: most 2013 controls map directly to 2022 equivalents, and a well-maintained ISMS will already address many of the "new" controls informally.
The practical steps: update your Statement of Applicability against the new control set, refresh your risk treatment mapping, address the genuinely new controls (threat intelligence and DLP are the ones most often missing), and update internal audit checklists before your next surveillance audit.
The most common gap we find is control 5.7 (Threat Intelligence) — many SMEs have no structured process for collecting and analysing threat information. The second is 8.12 (Data Leakage Prevention), which requires demonstrable technical measures, not just policy statements.
If your surveillance audit is approaching and your SoA still references the 2013 control set, that conversation needs to happen now rather than in the audit opening meeting.
"Need help with your 2022 transition or a first-time implementation? We offer a free thirty-minute assessment of your current ISMS posture."Book a free assessment →
Browse the rest of our articles or get advice specific to your organisation.