← All vlogs
Governance & Risk9 min · Script ready — not yet recorded
ISO 27001:2022 — What Actually Changed
The 2022 revision of ISO 27001 restructured the Annex A controls. This episode explains what actually changed, what didn't, and what it means for your ISMS.
Episode not yet live
This brief is script-ready. Subscribe to @cyberzonic on YouTube to be notified when it publishes.
Overview
ISO 27001:2022 is a significant revision of the international information security management system standard. The body of the standard changed less than people think; Annex A changed more. This episode walks through the control restructure, the new themes, and the implications for existing certifications.
Key takeaways
- The main body of ISO 27001 saw minor clarifications in 2022
- Annex A restructured from 14 domains to 4 themes — Organisational, People, Physical, Technological
- Control count dropped from 114 to 93, with 11 genuinely new controls
- New controls include threat intelligence, cloud services, ICT readiness for business continuity, physical security monitoring
- Certifications transition over a multi-year window — ISO 27001:2013 certificates expire on a staged schedule
Episode script
[OUTLINE — full script to be expanded before recording] Open: why ISO 27001:2022 matters, who it applies to. Section 1 — The body of the standard. Minor changes only. Context, leadership, planning, support, operation, performance evaluation, improvement. Section 2 — Annex A. From 14 domains to 4 themes. Mapping the old to the new. Section 3 — The 11 genuinely new controls. Threat intel, cloud services, ICT readiness, data masking, data leakage prevention, web filtering, secure coding, configuration management, physical security monitoring, monitoring activities, information deletion. Section 4 — What stayed. Most controls, in substance. Section 5 — Transition timelines. Certifications, re-certifications, Statement of Applicability updates. Section 6 — Practical action list for existing ISMS owners. Outro.


