Live Founding Cohort open, limited seats remaining Back to main site →

The 2022 revision plus Amendment 1:2024

ISO/IEC 27001:2022 restructured Annex A from 14 clauses / 114 controls into 4 themes / 93 controls and added 11 new controls. Amendment 1:2024 folded climate change into Clauses 4.1 and 4.2. This lesson walks what actually changed and why.

Free preview 10 min read Verified
Legal basis
ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.

The 2022 revision was the first substantive update to ISO/IEC 27001 since 2013. It reorganised Annex A, introduced 11 new controls, and aligned the standard with the Annex SL harmonised management-system-standard structure shared with ISO 9001, ISO 14001, ISO 22301 and (later) ISO/IEC 42001. Amendment 1:2024, published February 2024, added a climate change dimension to Clauses 4.1 and 4.2. This lesson walks both changes.

What did not change

Start here because it is what most trainings skip. The ten-clause structure of ISO 27001 did not change. Clauses 4 (Context), 5 (Leadership), 6 (Planning), 7 (Support), 8 (Operation), 9 (Performance evaluation), 10 (Improvement) are the same shape as 2013. The four mandatory documented information items under Clause 7.5 are the same four (scope, ISMS policy, risk assessment and treatment process, Statement of Applicability). The fundamental logic of the ISMS (context and interested parties determine scope, top management commits, risks are assessed, controls are treated, evidence is monitored, internal audits check, management reviews, nonconformities are corrected) did not change.

If you had a working 2013 ISMS, the 2022 revision was a re-mapping exercise for Annex A plus attention to the 11 new controls. If your 2013 ISMS was not working, the 2022 revision did not fix it.

The Annex A restructure

Annex A of ISO 27001:2013 was organised as 14 numbered clauses (A.5 through A.18) containing 114 controls. Annex A of ISO 27001:2022 is organised as 4 themes containing 93 controls [L3-C1].

ThemeRangeCountNew controls
A.5 OrganizationalA.5.1 – A.5.37373 (A.5.7 Threat intelligence, A.5.23 Cloud services, A.5.30 ICT readiness for business continuity)
A.6 PeopleA.6.1 – A.6.880
A.7 PhysicalA.7.1 – A.7.14141 (A.7.4 Physical security monitoring)
A.8 TechnologicalA.8.1 – A.8.34347 (A.8.9 Configuration management, A.8.10 Information deletion, A.8.11 Data masking, A.8.12 Data leakage prevention, A.8.16 Monitoring activities, A.8.23 Web filtering, A.8.28 Secure coding)
Total9311 new

The reduction from 114 to 93 controls came from merging overlapping controls. Nothing was removed as a security concept. If you had a working 2013 Statement of Applicability, the 2022 mapping exercise consolidates rather than trims your control set.

The 11 new controls

Each of the 11 new controls addresses a contemporary need that the 2013 standard did not cover cleanly. Modules 4 and 5 walk each in operational detail; a summary here for orientation.

  • A.5.7 Threat intelligence. Collect and analyse threat intelligence to inform your risk assessment and defensive posture. Sources include commercial threat intel feeds, CERT-In sectoral CERTs, RBI IB-CART for banks, open-source intel and internal telemetry.
  • A.5.23 Information security for use of cloud services. Formal processes for acquisition, use, management and exit of cloud services. Pairs with ISO 27017 for detailed cloud guidance.
  • A.5.30 ICT readiness for business continuity. Distinguishes ICT continuity (RTO, RPO, tested failover) from general business continuity. Common gap in first-time filers.
  • A.7.4 Physical security monitoring. CCTV and access-log monitoring across secure areas.
  • A.8.9 Configuration management. Baseline configurations, change tracking, deviation detection. Anchors modern infrastructure-as-code practice.
  • A.8.10 Information deletion. Secure deletion of information no longer required. Aligns with data-minimisation obligations under GDPR, DPDP Act 2023.
  • A.8.11 Data masking. Test data, non-production data, PII protection through masking or synthetic generation.
  • A.8.12 Data leakage prevention. DLP controls across endpoints, network, cloud services.
  • A.8.16 Monitoring activities. SIEM, threat detection, alerting, anomaly detection. Distinguished from A.8.15 (logging) which is the raw log collection.
  • A.8.23 Web filtering. Web content filtering to reduce exposure to malicious content.
  • A.8.28 Secure coding. Secure coding standards, code review, security testing in the development lifecycle. Aligns with OWASP Top 10, CWE Top 25, language-specific secure coding guides.

The 11 new controls are where most 2013-heritage ISMS programmes fail their first 2022-basis audit. The technical controls (A.8.9, A.8.10, A.8.11, A.8.12, A.8.16, A.8.23, A.8.28) require engineering discipline that many pre-2022 ISMS programmes never established formally.

The Annex SL alignment

The 2022 revision aligned ISO/IEC 27001's Clauses 4 through 10 with the Annex SL harmonised management-system-standard structure. This is the same skeleton used by ISO 9001, ISO 14001, ISO 22301, ISO/IEC 42001 and other MSS standards. Practical consequence: if your organisation already has ISO 9001 or ISO 14001 or ISO 22301 certification, the Clauses 4 through 10 language and structure are already familiar. Integrated management systems (IMS) combining ISO 9001 + 27001 + 14001 + 45001 are standard for large Indian IT services companies (Infosys, TCS, Wipro, HCLTech). The shared Clauses 4 through 10 make IMS integration cheaper.

The Clause 6.3 addition

Clause 6.3 Planning of changes is new in the 2022 revision [L3-C2]. Short clause with a large operational implication: when the organisation determines a need for changes to the ISMS, the changes must be carried out in a planned manner. Applied to Annex A control changes, scope changes, methodology changes, ISMS policy changes. Sub-clause supports the risk-based approach and dovetails with A.8.32 Change management.

The Amendment 1:2024 climate change addition

ISO/IEC 27001:2022/Amd 1:2024 was published February 2024 [L3-C3]. Two textual changes to two clauses. This is not a rewrite of the standard. It is the ISO family-wide climate change amendment issued simultaneously across ISO 9001, 14001, 22301, 45001, 42001 and more than thirty other management-system standards.

Clause 4.1 gained a mandatory note: "The organization shall determine whether climate change is a relevant issue." This sits alongside the existing requirement to determine internal and external issues. You are not required to conclude climate change is relevant. You are required to make the determination, in either direction, with documented reasoning.

Clause 4.2 gained a note: "Relevant interested parties can have requirements related to climate change." This sits alongside the existing requirement to determine interested parties and their requirements. If a relevant interested party (customer, regulator, investor) has climate-related requirements affecting information security (data centre cooling under heat stress, physical security under flood scenarios, supply chain resilience under climate transition), you must consider them.

Practical implication for an Indian ISMS. Your Clause 4.1 determination should now document your consideration of climate change as an internal or external issue for information security. Examples:

  • Data centres in Chennai, Mumbai, Kolkata exposed to cyclone or flood risk affecting availability of information systems (A.7.11 Supporting utilities, A.7.5 Protecting against physical and environmental threats)
  • Delivery centres in Bengaluru, Hyderabad, Pune exposed to heat stress affecting data centre cooling and equipment operating temperatures
  • Supply chain suppliers (cloud service providers, hardware vendors) with climate-related operational risks

Your Clause 4.2 documentation should identify interested parties with climate-related requirements. Examples: European enterprise customers subject to CSRD (Corporate Sustainability Reporting Directive), Indian regulated financial services customers subject to SEBI BRSR, investors with ESG mandates.

You are permitted to conclude climate change is not a relevant issue for information security if the determination is documented. Amendment 1:2024 does not force conclusions; it forces the determination.

No recertification is required. The amendment is picked up at your next scheduled surveillance or recertification audit. If you were already certified before February 2024, your next surveillance audit will check whether your Clauses 4.1 and 4.2 documented information reflects the amendment.

The transition from 27001:2013

IAF Mandatory Document 22 governed the 27001:2013 to 27001:2022 transition. Deadline: 31 October 2025 [L3-C4]. That window is now closed. Any organisation still certified to 27001:2013 after 31 October 2025 has an invalid certificate. If your CB missed the deadline, you need a new Stage 1 + Stage 2 audit against 27001:2022 to re-establish certification.

If you are reading this course in August 2026 or later, your certification programme starts at 27001:2022. The 2013 material is historical only.

Next lesson: the certification lifecycle. Stage 1, Stage 2, surveillance, recertification. The three-year cycle every certified organisation runs.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 27002:2022, ISO/IEC 27002:2022 (Feb 2022, 93 controls) (The 93 Annex A controls across 4 themes) L3-C1
ISO/IEC 27002:2022 published February 2022 as the companion controls standard to ISO/IEC 27001:2022. Contains 93 controls (down from 114 in 2013 edition) organised across four themes: A.5 Organizational (37 controls), A.6 People (8 controls), A.7 Physical (14 controls), A.8 Technological (34 controls). Introduces 11 new controls. Each control is now tagged with attributes (control type, information security properties, cybersecurity concepts, operational capability, security domain) to aid mapping to other frameworks.
ISO/IEC 27001:2022, Clause 6.3 Planning of changes (Change planning (new in 2022)) L3-C2
Clause 6.3 Planning of changes is new in the 2022 revision. Requires that when the organisation determines a need for changes to the ISMS, the changes are carried out in a planned manner.
ISO/IEC 27001:2022/Amd 1:2024, Amendment 1:2024 (climate action changes) (February 2024 climate change amendment) L3-C3
ISO/IEC 27001:2022/Amd 1:2024 published February 2024. Two textual changes to two clauses. Clause 4.1 gains a mandatory NOTE requiring the organisation to determine whether climate change is a relevant issue. Clause 4.2 gains a NOTE that relevant interested parties may have climate-related requirements. No recertification required; amendment is picked up at the next scheduled surveillance or recertification audit. Organisation is permitted to conclude climate change is not relevant provided the determination is documented.
IAF Mandatory Document, IAF MD 22 (management system transitions) (Transition to new standard editions) L3-C4
IAF MD 22 governs how CBs handle transitions between editions of management system standards. Applied to the ISO/IEC 27001:2013 to 2022 transition that closed 31 October 2025 and (in future) to any next-edition transition.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The ISO 27001 story
Module 2: Clauses 4 to 6: Context, Leadership, Planning
  • Clause 4 Context of the organisation (including Amendment 1:2024 climate change)
  • Clause 5 Leadership and the ISMS Policy
  • Clause 6.1 Actions to address risks and opportunities
  • Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology
  • Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes
Module 3: Clauses 7 to 10: Support, Operation, Evaluation, Improvement
  • Clause 7 Support — Resources, competence, awareness, communication
  • Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC
  • Clause 8 Operation — Executing the plan
  • Clause 9 — Monitoring, Internal Audit, Management Review
  • Clause 10 Improvement — Nonconformity and CAPA
Module 4: Annex A controls Part 1: Organizational + People
  • A.5 Organizational controls Part 1 (A.5.1 through A.5.20)
  • A.5 Organizational controls Part 2 (A.5.21 through A.5.37)
  • A.6 People controls (8 controls, A.6.1 through A.6.8)
  • The 11 new controls in ISO/IEC 27002:2022 walkthrough
  • Building the Statement of Applicability (all 93 controls)
Module 5: Annex A controls Part 2: Physical + Technological
  • A.7 Physical controls (14 controls, A.7.1 through A.7.14)
  • A.8 Technological controls Part 1 (A.8.1 through A.8.17)
  • A.8 Technological controls Part 2 (A.8.18 through A.8.34)
  • Cloud-specific controls and ISO 27017 / 27018 alignment
  • Control Ownership Matrix and evidence sources
Module 6: The risk assessment operating layer
  • Choosing a risk methodology (asset-based, scenario-based, hybrid)
  • Asset inventory and information classification
  • Threat identification, vulnerability identification, likelihood + impact scoring
  • Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan
  • GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer)
Module 7: Certification body selection + Stage 1 + Stage 2 audits
  • What NABCB accreditation means (and why IAF MLA matters)
  • CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS)
  • Stage 1 audit — documentation review
  • Stage 2 audit — operating effectiveness testing
  • Handling nonconformities, CAPA closure, certificate issuance
Module 8: Post-certification + adjacent standards
  • Surveillance Years 1 + 2, and recertification Year 3
  • Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires
  • ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk
  • ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions
  • ISO/IEC 42001 AI Management System as the next horizon