The major change to ISO 27001, with the publication of the 2022 version, was the incorporation of the control set from ISO 27002:2022 into Annex A of ISO 27001:2022.  With ISO 27002:2022, there was a a significant revision of the set of information security controls with the previous 114 being reduced to 93.   Of those 93 controls:

  • 58 have been updated
  • 24 controls represent merging of 57 of the previous controls
  • 11 new controls have been introduced.

More information on ISO 27002:2022 can be found here.

A number of changes to the management system clauses were made in ISO/IEC 27001:2022 with the goal of making some of the requirements more explicit and improving the alignment with other Annex SL standards, such as ISO 9001 and ISO 22301, e.g. sub clause titles, terms and definitions.

We would like to pass on our gratitude to our consultant for all his hard work and advice during our 3-year re-certification and assessment against the new Standard. After seven days of auditing, we have two OFIs that the assessors have put forward from the audits. This pays testament to our URM consultant, his hard work, eye for detail and advice given, both during the audits and during all the works beforehand.
Waste management company
Contact the ISO 27001 Experts Today

Information Risk Assessment and Treatment in ISO 27001

Published on
5 Jun
2025

URM’s blog explains how to conduct information security risk assessments and implement risk treatments that are both efficient and ISO 27001 conformant.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
29/5/2025
Implementing Technological Controls in ISO 27001

URM’s blog offers key guidance on how to effectively implement technological controls in your organisation, the common challenges & how these can be overcome.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
23/5/2025
ISO 27001:2022 - A.5 Organisational Controls (Legal, Regulatory and Contractual)

URM’s blog explains the legal, regulatory & contractual controls in ISO 27001 & how they can be implemented in full conformance with the Standard.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
19/5/2025
ISO 27001:2022 - A.5 Organisational Controls (Information Security Management)

URM explains the 8 information security management controls included within the ‘Organisational controls’ theme and how to prepare for an audit of each control

Read more
"
Our consultant was very thorough and knowledgeable when delivering the ISO 27001 pre-stage-2 internal audit.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.