The latest version of ISO 27001 was released on October 25, 2022, superseding the nine-year-old ISO 27001:2013. Designated as ISO 27001:2022, it has introduced 11 new security controls within its revised framework. However, the total number of controls has decreased from 114 to 93 due to the consolidation of some controls. Additionally, the former 14 control categories have been reorganized into four principal themes: Organizational, People, Physical, and Technological, offering greater alignment with the NIST CSF.
From a high-level understanding, below is the summary of the controls available under each theme of the new standard:
1. Organizational Controls
Number of controls: 37
Control numbers: ISO 27001 Annex A 5.1 to 5.37
Focus: These controls address the overall governance and management of information security within an organization, including policies, processes, and procedures that dictate the organization’s approach to regulations and data protection.
2. People Controls
Number of controls: 8
Control numbers: ISO 27001 Annex A 6.1 to 6.8
Focus: This theme encompasses controls related to human resources and personnel security, defining how employees interact with information and each other to maintain security.
3. Physical Controls
Number of controls: 14
Control numbers: ISO 27001 Annex A 7.1 to 7.13
Focus: Physical controls are designed to protect tangible assets and ensure the security of facilities, including access controls, environmental safeguards, and asset disposal processes. Such safeguards are essential for the preservation of confidential information.
4. Technological Controls
Number of controls: 34
Control numbers: ISO 27001 Annex A 8.1 to 8.34
Focus: This theme includes controls related to the technological aspects of information security, such as data protection measures, secure coding practices, and incident response protocols. Technological constraints help organizations establish a secure, compliant IT infrastructure, encompassing everything from authentication methods to configurations, backup and disaster recovery (BUDR) strategies, and information logging.