Skip to content
Log inRegister

ISO/IEC 27001:2022 Explained

Dr. Abeer Alshammari · Published 7/29/2026

BeginnerProfessionalsGeneral audience

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) -- a systematic, documented approach to managing information security risk. The current version, published in October 2022, replaced the 2013 version, and organizations certified under 2013 had a transition deadline to migrate.

Structure

The standard has two main parts: the main clauses (4-10), which define ISMS requirements an organization must meet to be certified, and Annex A, a reference list of security controls an organization selects from based on its risk assessment. See ISO 27001 Clauses Explained and Annex A Controls Explained for each in detail.

What changed in the 2022 revision

  • Annex A was restructured from 14 categories/114 controls (2013) into 4 themes/93 controls (2022) -- largely a consolidation, not a wholesale rewrite
  • 11 new controls were introduced, including threat intelligence, cloud security, and data masking, reflecting how the threat and technology landscape shifted since 2013
  • Controls gained "attributes" (control type, security properties, cybersecurity concepts, operational capabilities, security domains) to support filtering and mapping to other frameworks

Why the ISMS approach matters

ISO 27001 does not mandate a fixed list of controls for every organization -- it mandates a risk-based process for deciding which controls apply, documenting that decision, and continually improving. This is why two ISO 27001-certified organizations can have meaningfully different control sets and both be legitimately compliant.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights