News in ISO 01 Jan 2024

ISO 27001:2022: Updates and the ISO 27001 certification maintenance process (Transition)

ISO 27001:2022 is an important update to the standard for maintaining a certified Information Security Management System.

Revision of ISO 27001:2013 – What Changes Will 2022 Bring?

After nine years, the International Organization for Standardization (ISO) updated its ISO 27001:2013 standard. It has been replaced by ISO 27001:2022, which was published on October 25, 2022.

ISO 27001 is a globally recognized information security standard designed to provide requirements for implementing, maintaining, and continuously improving an Information Security Management System (ISMS).

ISO 27001 Updates

ISO 27001:2022 introduces several key changes, the most significant being its alignment with the so-called High-Level Structure (HLS). The new standard emphasizes a process-oriented approach, marking a significant step toward a more effective and integrated Information Security Management System (ISMS).

Normative Changes in ISO 27001:2022

Key changes in ISO 27001:2022 include:

  • Clause 4.4 – Context of the Organization and ISMS Processes: It requires the identification and interaction of key processes in the ISMS, in line with management best practices under the HLS. This requirement emphasizes the need to build the ISMS on identifiable processes and their interactions.
  • Clause 8.1 – Operational Planning and Control: This stresses the importance of processes in operational planning and control, requiring the definition and application of process criteria.
  • Additional clauses, such as Clauses 5.3, 7.4, 9.2, 9.3, 10.1, and 10.2, have been supplemented with minor clarifications and specifications, improving information security management in organizations.

Revision of Annex A

Annex A of ISO 27001:2022 underwent a significant revision, reflecting changes in ISO 27002:2022. The number of information security controls has been reduced from 114 to 93, incorporating new challenges in information security. Eleven new controls have been added to the annex, including information security in cloud services and ICT readiness for business continuity. These controls are now organized into four main categories:

  • A.5 Organizational Controls (37 controls)
  • A.6 People Controls (8 controls)
  • A.7 Physical Controls (14 controls)
  • A.8 Technological Controls (34 controls)

Annex A in the new version of ISO 27001:2022 contains 93 controls in total, including the following 11 new ones:

  • A.5.7 Threat Intelligence
  • A.5.23 Information Security for Cloud Services
  • A.5.30 ICT Readiness for Business Continuity
  • A.7.4 Physical Security Monitoring
  • A.8.9 Configuration Management
  • A.8.10 Information Deletion
  • A.8.11 Data Masking
  • A.8.12 Data Leakage Prevention
  • A.8.16 Activity Monitoring
  • A.8.23 Web Filtering
  • A.8.28 Secure Coding

While Annex A of ISO 27001:2022 only lists the controls, the ISO 27002:2022 implementation guide provides further opportunities for categorization. Each control is assigned five attributes, enabling different views and perspectives on them. The attributes or their values can be used to filter, sort, or display controls for various organizational views.

Transition Requirements for ISO 27001:2022

All organizations currently certified under ISO 27001:2013 have until October 31, 2025, to transition to the new version.

New applicants for certification or renewal (i.e., recertification) can still be audited under the 2013 version of ISO 27001 until April 30, 2024—an update from the original deadline of October 31, 2023.

All organizations wishing to maintain their ISO 27001 certification must transition to the new ISO 27001:2022 standard by October 31, 2025, regardless of the original registration date. All remaining ISO 27001:2013 certificates will be withdrawn and considered expired on October 25, 2023, regardless of their expiration date.

The transition process involves the certification body adding additional time to the basic audit duration to conduct the so-called transition audit. After a successful result, the ISO 27001 certificate is updated, and the organization is subject to further audits according to the certificate validity cycle. The transition audit is charged additionally.

Article author


Lukasz Kowalski

Managing Director

Certiget.

Lukasz Kowalski is an expert in the certification body market and management system certification processes. He is the founder of Certiget – the world's first platform created to increase transparency in the certification market and help organizations make informed decisions when selecting a certification body. He gained his experience both by implementing and improving management systems within organizations and at British Standards Institution (BSI) – one of the world's most renowned certification bodies. This unique background enables him to understand the certification process from the perspective of both organizations seeking certification and certification bodies. He specializes in ISO management systems and the certification market. His articles are based on practical experience as well as the latest international standards and accreditation requirements.


Share this article