New Security Controls in ISO 27001:2022

The latest version of ISO 27001 was released on October 25, 2022, superseding the nine-year-old ISO 27001:2013. Designated as ISO 27001:2022, it has introduced 11 new security controls within its revised framework. However, the total number of controls has decreased from 114 to 93 due to the consolidation of some controls. Additionally, the former 14 control categories have been reorganized into four principal themes: Organizational, People, Physical, and Technological, offering greater alignment with the NIST CSF.

From a high-level understanding, below is the summary of the controls available under each theme of the new standard:

1. Organizational Controls
Number of controls:
37
Control numbers: ISO 27001 Annex A 5.1 to 5.37
Focus: These controls address the overall governance and management of information security within an organization, including policies, processes, and procedures that dictate the organization’s approach to regulations and data protection.

2. People Controls
Number of controls: 8
Control numbers: ISO 27001 Annex A 6.1 to 6.8
Focus: This theme encompasses controls related to human resources and personnel security, defining how employees interact with information and each other to maintain security.

3. Physical Controls
Number of controls: 14
Control numbers: ISO 27001 Annex A 7.1 to 7.13
Focus: Physical controls are designed to protect tangible assets and ensure the security of facilities, including access controls, environmental safeguards, and asset disposal processes. Such safeguards are essential for the preservation of confidential information.

4. Technological Controls
Number of controls: 34
Control numbers: ISO 27001 Annex A 8.1 to 8.34
Focus: This theme includes controls related to the technological aspects of information security, such as data protection measures, secure coding practices, and incident response protocols. Technological constraints help organizations establish a secure, compliant IT infrastructure, encompassing everything from authentication methods to configurations, backup and disaster recovery (BUDR) strategies, and information logging.

ISO27001 Standard

ISO/IEC 27001 is an internationally recognized standard for information security management systems (ISMS), created by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standard was first published in 2005 and has undergone several revisions, with the latest version being ISO/IEC 27001:2022.

Purpose and Importance

The primary purpose of ISO 27001 is to provide a framework for organizations to establish, implement, maintain, and continually improve their information security management systems. It aims to help organizations protect their information assets, manage risks effectively, and comply with legal and regulatory requirements. By adhering to this standard, organizations can demonstrate their commitment to information security and enhance their resilience against cyber threats.

Key Features

  • Risk Management: ISO 27001 emphasizes a risk-based approach, requiring organizations to identify, assess, and treat information security risks tailored to their specific context.
  • Comprehensive Framework: The standard outlines requirements for documentation, management responsibility, internal audits, and continual improvement, ensuring a systematic approach to information security.
  • Certification: Organizations can seek third-party certification to verify compliance with ISO 27001, which is recognized globally as a mark of effective information security management.

ISO 27001 was developed in response to the growing need for organizations to manage information security risks in a structured manner with management ownership an increasingly digital world, making it a critical tool for businesses of all sizes and sectors.