← All vlogs
Governance & Risk9 min · Script ready — not yet recorded

ISO 27001:2022 — What Actually Changed

The 2022 revision of ISO 27001 restructured the Annex A controls. This episode explains what actually changed, what didn't, and what it means for your ISMS.

Episode not yet live

This brief is script-ready. Subscribe to @cyberzonic on YouTube to be notified when it publishes.

Overview

ISO 27001:2022 is a significant revision of the international information security management system standard. The body of the standard changed less than people think; Annex A changed more. This episode walks through the control restructure, the new themes, and the implications for existing certifications.

Key takeaways

  • The main body of ISO 27001 saw minor clarifications in 2022
  • Annex A restructured from 14 domains to 4 themes — Organisational, People, Physical, Technological
  • Control count dropped from 114 to 93, with 11 genuinely new controls
  • New controls include threat intelligence, cloud services, ICT readiness for business continuity, physical security monitoring
  • Certifications transition over a multi-year window — ISO 27001:2013 certificates expire on a staged schedule

Episode script

[OUTLINE — full script to be expanded before recording]

Open: why ISO 27001:2022 matters, who it applies to.

Section 1 — The body of the standard. Minor changes only. Context, leadership, planning, support, operation, performance evaluation, improvement.

Section 2 — Annex A. From 14 domains to 4 themes. Mapping the old to the new.

Section 3 — The 11 genuinely new controls. Threat intel, cloud services, ICT readiness, data masking, data leakage prevention, web filtering, secure coding, configuration management, physical security monitoring, monitoring activities, information deletion.

Section 4 — What stayed. Most controls, in substance.

Section 5 — Transition timelines. Certifications, re-certifications, Statement of Applicability updates.

Section 6 — Practical action list for existing ISMS owners.

Outro.

References