The 2022 revision was the first substantive update to ISO/IEC 27001 since 2013. It reorganised Annex A, introduced 11 new controls, and aligned the standard with the Annex SL harmonised management-system-standard structure shared with ISO 9001, ISO 14001, ISO 22301 and (later) ISO/IEC 42001. Amendment 1:2024, published February 2024, added a climate change dimension to Clauses 4.1 and 4.2. This lesson walks both changes.
What did not change
Start here because it is what most trainings skip. The ten-clause structure of ISO 27001 did not change. Clauses 4 (Context), 5 (Leadership), 6 (Planning), 7 (Support), 8 (Operation), 9 (Performance evaluation), 10 (Improvement) are the same shape as 2013. The four mandatory documented information items under Clause 7.5 are the same four (scope, ISMS policy, risk assessment and treatment process, Statement of Applicability). The fundamental logic of the ISMS (context and interested parties determine scope, top management commits, risks are assessed, controls are treated, evidence is monitored, internal audits check, management reviews, nonconformities are corrected) did not change.
If you had a working 2013 ISMS, the 2022 revision was a re-mapping exercise for Annex A plus attention to the 11 new controls. If your 2013 ISMS was not working, the 2022 revision did not fix it.
The Annex A restructure
Annex A of ISO 27001:2013 was organised as 14 numbered clauses (A.5 through A.18) containing 114 controls. Annex A of ISO 27001:2022 is organised as 4 themes containing 93 controls [L3-C1].
| Theme | Range | Count | New controls |
|---|---|---|---|
| A.5 Organizational | A.5.1 – A.5.37 | 37 | 3 (A.5.7 Threat intelligence, A.5.23 Cloud services, A.5.30 ICT readiness for business continuity) |
| A.6 People | A.6.1 – A.6.8 | 8 | 0 |
| A.7 Physical | A.7.1 – A.7.14 | 14 | 1 (A.7.4 Physical security monitoring) |
| A.8 Technological | A.8.1 – A.8.34 | 34 | 7 (A.8.9 Configuration management, A.8.10 Information deletion, A.8.11 Data masking, A.8.12 Data leakage prevention, A.8.16 Monitoring activities, A.8.23 Web filtering, A.8.28 Secure coding) |
| Total | 93 | 11 new |
The reduction from 114 to 93 controls came from merging overlapping controls. Nothing was removed as a security concept. If you had a working 2013 Statement of Applicability, the 2022 mapping exercise consolidates rather than trims your control set.
The 11 new controls
Each of the 11 new controls addresses a contemporary need that the 2013 standard did not cover cleanly. Modules 4 and 5 walk each in operational detail; a summary here for orientation.
- A.5.7 Threat intelligence. Collect and analyse threat intelligence to inform your risk assessment and defensive posture. Sources include commercial threat intel feeds, CERT-In sectoral CERTs, RBI IB-CART for banks, open-source intel and internal telemetry.
- A.5.23 Information security for use of cloud services. Formal processes for acquisition, use, management and exit of cloud services. Pairs with ISO 27017 for detailed cloud guidance.
- A.5.30 ICT readiness for business continuity. Distinguishes ICT continuity (RTO, RPO, tested failover) from general business continuity. Common gap in first-time filers.
- A.7.4 Physical security monitoring. CCTV and access-log monitoring across secure areas.
- A.8.9 Configuration management. Baseline configurations, change tracking, deviation detection. Anchors modern infrastructure-as-code practice.
- A.8.10 Information deletion. Secure deletion of information no longer required. Aligns with data-minimisation obligations under GDPR, DPDP Act 2023.
- A.8.11 Data masking. Test data, non-production data, PII protection through masking or synthetic generation.
- A.8.12 Data leakage prevention. DLP controls across endpoints, network, cloud services.
- A.8.16 Monitoring activities. SIEM, threat detection, alerting, anomaly detection. Distinguished from A.8.15 (logging) which is the raw log collection.
- A.8.23 Web filtering. Web content filtering to reduce exposure to malicious content.
- A.8.28 Secure coding. Secure coding standards, code review, security testing in the development lifecycle. Aligns with OWASP Top 10, CWE Top 25, language-specific secure coding guides.
The 11 new controls are where most 2013-heritage ISMS programmes fail their first 2022-basis audit. The technical controls (A.8.9, A.8.10, A.8.11, A.8.12, A.8.16, A.8.23, A.8.28) require engineering discipline that many pre-2022 ISMS programmes never established formally.
The Annex SL alignment
The 2022 revision aligned ISO/IEC 27001's Clauses 4 through 10 with the Annex SL harmonised management-system-standard structure. This is the same skeleton used by ISO 9001, ISO 14001, ISO 22301, ISO/IEC 42001 and other MSS standards. Practical consequence: if your organisation already has ISO 9001 or ISO 14001 or ISO 22301 certification, the Clauses 4 through 10 language and structure are already familiar. Integrated management systems (IMS) combining ISO 9001 + 27001 + 14001 + 45001 are standard for large Indian IT services companies (Infosys, TCS, Wipro, HCLTech). The shared Clauses 4 through 10 make IMS integration cheaper.
The Clause 6.3 addition
Clause 6.3 Planning of changes is new in the 2022 revision [L3-C2]. Short clause with a large operational implication: when the organisation determines a need for changes to the ISMS, the changes must be carried out in a planned manner. Applied to Annex A control changes, scope changes, methodology changes, ISMS policy changes. Sub-clause supports the risk-based approach and dovetails with A.8.32 Change management.
The Amendment 1:2024 climate change addition
ISO/IEC 27001:2022/Amd 1:2024 was published February 2024 [L3-C3]. Two textual changes to two clauses. This is not a rewrite of the standard. It is the ISO family-wide climate change amendment issued simultaneously across ISO 9001, 14001, 22301, 45001, 42001 and more than thirty other management-system standards.
Clause 4.1 gained a mandatory note: "The organization shall determine whether climate change is a relevant issue." This sits alongside the existing requirement to determine internal and external issues. You are not required to conclude climate change is relevant. You are required to make the determination, in either direction, with documented reasoning.
Clause 4.2 gained a note: "Relevant interested parties can have requirements related to climate change." This sits alongside the existing requirement to determine interested parties and their requirements. If a relevant interested party (customer, regulator, investor) has climate-related requirements affecting information security (data centre cooling under heat stress, physical security under flood scenarios, supply chain resilience under climate transition), you must consider them.
Practical implication for an Indian ISMS. Your Clause 4.1 determination should now document your consideration of climate change as an internal or external issue for information security. Examples:
- Data centres in Chennai, Mumbai, Kolkata exposed to cyclone or flood risk affecting availability of information systems (A.7.11 Supporting utilities, A.7.5 Protecting against physical and environmental threats)
- Delivery centres in Bengaluru, Hyderabad, Pune exposed to heat stress affecting data centre cooling and equipment operating temperatures
- Supply chain suppliers (cloud service providers, hardware vendors) with climate-related operational risks
Your Clause 4.2 documentation should identify interested parties with climate-related requirements. Examples: European enterprise customers subject to CSRD (Corporate Sustainability Reporting Directive), Indian regulated financial services customers subject to SEBI BRSR, investors with ESG mandates.
You are permitted to conclude climate change is not a relevant issue for information security if the determination is documented. Amendment 1:2024 does not force conclusions; it forces the determination.
No recertification is required. The amendment is picked up at your next scheduled surveillance or recertification audit. If you were already certified before February 2024, your next surveillance audit will check whether your Clauses 4.1 and 4.2 documented information reflects the amendment.
The transition from 27001:2013
IAF Mandatory Document 22 governed the 27001:2013 to 27001:2022 transition. Deadline: 31 October 2025 [L3-C4]. That window is now closed. Any organisation still certified to 27001:2013 after 31 October 2025 has an invalid certificate. If your CB missed the deadline, you need a new Stage 1 + Stage 2 audit against 27001:2022 to re-establish certification.
If you are reading this course in August 2026 or later, your certification programme starts at 27001:2022. The 2013 material is historical only.
Next lesson: the certification lifecycle. Stage 1, Stage 2, surveillance, recertification. The three-year cycle every certified organisation runs.