The major change to ISO 27001, with the publication of the 2022 version, was the incorporation of the control set from ISO 27002:2022 into Annex A of ISO 27001:2022. With ISO 27002:2022, there was a a significant revision of the set of information security controls with the previous 114 being reduced to 93. Of those 93 controls:
- 58 have been updated
- 24 controls represent merging of 57 of the previous controls
- 11 new controls have been introduced.
More information on ISO 27002:2022 can be found here.
A number of changes to the management system clauses were made in ISO/IEC 27001:2022 with the goal of making some of the requirements more explicit and improving the alignment with other Annex SL standards, such as ISO 9001 and ISO 22301, e.g. sub clause titles, terms and definitions.

Critical Cyber Security Practices to Defend Against Ransomware Attacks
URM’s blog examines how ransomware occur, and highlights practical cyber security measures you can implement to reduce your exposure and mitigate security risk.

URM’s blog breaks down the ISO 27001 certification process, the roles of certification bodies and UKAS, what auditors look for during assessments, and more.

URM’s blog explores the ISO 27001 business continuity controls, why they matter, & how they can be effectively implemented to ensure conformance to the Standard

A question which comes up time and time again is ‘How do I approach asset identification within my information security risk assessment’.