info@p2pdigitalservices.com London, United Kingdom
ISO 27001  ·  PCI DSS  ·  Cyber Essentials  ·  UK GDPR
Insights

ISO 27001:2022 — what changed and what it means for your ISMS

Home  /  Insights  /  Article

The 2022 revision of ISO/IEC 27001 restructured Annex A significantly. The 114 controls of the 2013 edition were consolidated into 93 controls organised across four themes: Organisational (37 controls), People (8), Physical (14), and Technological (34).

Eleven controls are genuinely new — including threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

What migrating organisations need to do

Organisations certified to the 2013 standard had a transition deadline to move to the 2022 edition. The work involved is usually less dramatic than the restructure suggests: most 2013 controls map directly to 2022 equivalents, and a well-maintained ISMS will already address many of the "new" controls informally.

The practical steps: update your Statement of Applicability against the new control set, refresh your risk treatment mapping, address the genuinely new controls (threat intelligence and DLP are the ones most often missing), and update internal audit checklists before your next surveillance audit.

Where organisations get caught out

The most common gap we find is control 5.7 (Threat Intelligence) — many SMEs have no structured process for collecting and analysing threat information. The second is 8.12 (Data Leakage Prevention), which requires demonstrable technical measures, not just policy statements.

If your surveillance audit is approaching and your SoA still references the 2013 control set, that conversation needs to happen now rather than in the audit opening meeting.

"Need help with your 2022 transition or a first-time implementation? We offer a free thirty-minute assessment of your current ISMS posture."
Book a free assessment →

More insights

Browse the rest of our articles or get advice specific to your organisation.