ISO 27001 was first published in 2005 and then revised on September 25, 2013, as ISO/IEC 27001:2013. The most recent revision was published on October 25, 2022, as ISO/IEC 27001:2022 “Information security, cybersecurity and privacy protection — Information security management systems”. ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. It also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in ISO/IEC 27001 are generic and are intended to be applicable to all organizations, regardless of type, size or nature.
The purpose of ISO/IEC 27001 is to help organizations to establish and maintain an information security management system (ISMS). An ISMS is a set of interrelated elements that organizations use to manage and control information security risks and to protect and preserve the confidentiality, integrity, and availability of information. These elements include all of the policies, procedures, processes, plans, practices, roles, responsibilities, resources, and structures that are used to manage security risks and to protect information.

What are the main changes?
1. There are editorial changes, including:
- “International standard” replaced with “document” throughout
- Re-arranging of some English phrases to allow for easier translation
2. There are also changes to align with the ISO harmonized approach:
- Numbering re-structure
- Requirement to define processes needed for implementing the ISMS and their interactions
- Explicit requirement to communicate organizational roles relevant to information security within in the organization
- New clause 6.3 – Planning of Changes
- New requirement to ensure the organization determines how to communicate as part of clause 7.4
- New requirements to establish criteria for operational processes and implementing control of the processes
3. The main control changes in Annex A Controls are:
The major changes to ISO 27002, include restructuring the original 14 control domains into 4 categories. As a result, the total number of controls has decreased from the original 114 to 93. This decrease has come mainly due to merging 57 controls into 24 controls. 58 controls remain mostly unchanged, with minor contextual updates, and 11 controls are brand new (not available in ISO/IEC 27001:2013).
The controls are restructured into 4 clauses:
- A.5 Organizational – contains 37 controls
- A.6 People – contains 8 controls
- A.7 Physical – contains 14 controls
- A.8 Technological – contains 34 controls
The 11 new controls added to Annex A include:
- A.5.7 Threat intelligence
- A.5.23 Information security for the use of cloud services
- A.5.30 ICT readiness for business continuity
- A.7.4 Physical security monitoring
- A.8.9 Configuration management
- A.8.10 Information deletion
- A.8.11 Data masking
- A.8.12 Data leakage prevention
- A.8.16 Monitoring activities
- A.8.23 Web filtering
- A.8.28 Secure coding
The controls also have five types of ‘attribute’ to make them easier to categories:
- Control type (preventive, detective, corrective)
- Information security properties (confidentiality, integrity, availability)
- Cyber security concepts (identify, protect, detect, respond, recover)
- Operational capabilities (governance, asset management, etc.)
- Security domains (governance and ecosystem, protection, defence, resilience)

Benefits of Implementing ISO/IEC 27001
The benefits of using the standards are as follows:
- Keeps confidential information secure.
- Provides customers and stakeholders with confidence in how you manage risk.
- Allows for secure exchange of information.
- Provide you with a competitive advantage.
- Enhanced customer satisfaction that improves client retention.
- Consistency in the delivery of your service or product.
- Manages and minimizes risk exposure.
- Builds a culture of security.
How can we help?
IQMS consists of full-time trainers and consultants having huge international experience and exposure in ISO 27001:2013 ISMS consulting, implementation and training.
ISO 27001 Consulting
We offer expert consulting services for effective implementation of ISO27001.
IQMS consultants can guide you through the process of gaining certification. They will assist with final preparations to your ISMS, and also act on your behalf when organizing the audit progress. Many clients have found our close involvement to be extremely advantageous during this decisive stage of the process.
Our experts can help us to gain effective implementation of ISMS in your organisation
- Gap Analysis
- Risk Assessment
- Implementation Services
- ISMS Awareness Training
- Pre Audit Service
For every standard, we provide customized documents like manuals, procedures, formats & standard operating procedures etc.
