ISO27001 2013 vs ISO27001 2022 Explained

Stuart And Fay High Table

ISO27001 2013 vs ISO27001 2022

It took 9 years for ISO 27001, the information security standard, to be updated with ISO 27001:2022 being released on October 25 2022. If you’re involved in managing or implementing ISO 27001, you might be wondering what these changes mean for you. Let’s break it down.

Key Takeaways

  • ISO 27001:2022 focusses on wording changes and simplification
  • Clarification is provided on Management Reviews and Internal Audits
  • Planning for changes to the management system was introduced
  • Minor word changes
  • 1 new clause
  • 5 new sub clauses
  • the numbering of 2 clauses has swapped

Changes to the management system

The changes to clauses 4 through 10 were put in place to align the standard with other ISO management standards such as ISO 9001, ISO 14001 and with Annex SL.

A summary of the management system changes in ISO 27001:2022

ISO 27001 Clause 4.2

ISO/IEC 27001:2022 Clause 4.2 Understanding the needs and expectations of interested parties clarified that you will now determine which of the identified requirements will be addressed through the information security management system rather than implying it.

ISO 27001 Clause 4.3

ISO/IEC 27001:2022 Clause 4.3 Determining the scope of the information security management system removed the word ‘and’ from 4.3 b.

ISO 27001 Clause 4.4

ISO/IEC 27001:2022 Clause 4.4 Information security management system they now refer through the standard to this ‘document’ rather than this ‘international standard’. So replacement of the words ‘international standard’ with the word ‘document’. They have added into the sentence the term – ‘including the processes needed and their interactions’ to be absolutely crystal clear that processes are included, rather than implying it. In essence, nothing has changed. It is clarification of wording.

ISO 27001 Clause 5.3

ISO/IEC 27001:2022 Clause 5.3 Organisational roles, responsibilities and authorities added clarification that communication of roles is done within the organisation as was always implied but never said out right. Nothing material.

ISO 27001 Clause 6.1

ISO/IEC 27001:2022 Clause 6.1.3 Information security risk treatment The changes to ISO 27001 Clause 6.1.3 are minor but important

  • Changing the wording of 6.1.3 c to now reference Annex A as containing a list of possible information security controls. This is a change from it containing a comprehensive list of control objectives
  • Removing the wording that control objectives are implicitly included in the controls chosen.
  • Changing from the control objectives listed in Annex A as being not exhaustive with additional controls may being needed to the wording of Information Security Controls listed in Annex.
  • Change the word control objectives to controls
  • Changing the sentence of 6.1.3 d into a list for ease of reading
  • Changing the words ‘International Standard’ to the word ‘document’ 
  • Overall these are clarification changes and not material.

ISO 27001 Clause 6.2

ISO/IEC 27001:2022 Clause 6.2 Information security objectives and planning to achieve them ISO 27001 clause 6.2 had minor changes in the 2022 update with the changes being focussed on clarity. It introduced that information security objectives should be monitored and be available as documented information. This was always implied but is made explicit. As a result the numbering of the sub parts shifted but this is not material.

ISO 27001 Clause 6.3

ISO 27001:2022 Clause 6.3 Planning Of Changes was added and is new. When you make changes to the ISMS it requires that you do it in a planned manner. 

ISO 27001 Clause 7.4

ISO/IEC 27001:2022 Clause 7.4 Communication There are minor changes to ISO 27001 Clause 7.4 in the 2022 update. The changes can be seen as a simplification. It removes who shall communicate and replaces it with how to communicate and it completely removes the need to show the processes by which communication shall be done. It is our opinion that keeping who and the process of how is good practice but you can, if you wish, not account for it directly.

ISO 27001 Clause 8.1

ISO/IEC 27001:2022 Clause 8.1 Operational planning and control The changes to ISO 27001 Clause 8.1 in the 2022 update are clarification changes and nothing material. 

  • The wording on planning and implementing and controlling processes is widened to the more general wording of ‘meet requirements’ rather than before which was ‘meet information security requirements’. 
  • It now talks to establishing cirtieria for the processes and implementing control of processes in line with those criteria.
  • Rather than keep documented information it is changed to documented information shall be available. 
  • Outsourced processes are determined and controlled is changed to externally provided processes, products or services that are relevant to the information security management system are controlled

ISO 27001 Clause 9.1

ISO/IEC 27001:2022 Clause 9.1 Monitoring, measurement, analysis and evaluation There are clarification changes to the ISO 27001 Clause 9.1 in the 2022 update. 

  • The words about how the organisation evaluates the information security performance and the effectiveness of the management system have been removed. They are covered to a greater or lesser degree elsewhere in the clause.
  • 9.1 b has been updated to give guidance on the methods of monitoring, measurement, analysis and evaluation and provides that they should produce comparable results and reproducible results to be considered valid. This was previously a footnote so no material change. 
  • 9.1 e has had the word ‘and’ removed with little to no consequence.
  • A requirement for documented information to be available to evidence results has been included making it an explicit rather than implied requirement.
  • Rather than retain appropriate documentation as evidence the line has been replaced with the requirement to evaluate the information security performance and effectiveness of the information security management system. 
  • It says pretty much the same thing, with the same requirement with a change to the wording of how it says it.

ISO 27001 Clause 9.2

ISO/IEC 27001:2022 Clause 9.2 Internal audit This clause has now had the wording removed and wording shifted to two new separate sub clauses.

ISO 27001 Clause 9.3

ISO/IEC 27001:2022 Clause 9.3 Management review This clause has now had the wording removed and wording shifted to three new separate sub clauses.

ISO 27001 Clause 10.1

ISO/IEC 27001:2022 Clause 10.1 Continual improvement – no changed but used to be Clause 10.2 and now is renumbered to 10.1

ISO 27001 Clause 10.2

ISO/IEC 27001:2022 Clause 10.2 Nonconformity and corrective action – no changed but used to be Clause 10.1 and now is renumbered to 10.2

Changes to Annex A security controls

A summary of the Annex A Security controls changes in ISO 27001:2022

  • 11 New controls were added
  • 57 controls were merged
  • 1 control was split
  • 23 controls were renamed
  • 35 controls stayed the same.

We cover this in depth in The complete guide to ISO/IEC 27002:2022

Although no controls have been removed, ISO 27001:2022 lists only 93 controls compared to the 114 controls in ISO 27001:2013’s. This is due to the large number of merged controls (57 into 24).

The controls are grouped into 4 ‘themes’ rather than 14 clauses. The themes are:

  • People (8 controls)
  • Organisational (37 controls)
  • Technological (34 controls)
  • Physical (14 controls)

The update also introduced ISO 27001 attributes. Used to view, report on and categorise controls they are:

  • Control type (preventive, detective, corrective)
  • Information security properties (confidentiality, integrity, availability)
  • Cyber security concepts (identify, protect, detect, respond, recover)
  • Operational capabilities (governance, asset management, etc.)
  • Security domains (governance and ecosystem, protection, defence, resilience)

When was ISO 27001:2013 withdrawn?

ISO 27001:2013 was valid until October 2025.

The transition period

For companies that are already certified against ISO 27001:2013, the transition to the ISO 27001:2022 needed to be completed by October 31, 2025.

ISO 27002:2022 a more significant update to the guidance

While ISO 27001 saw minor tweaks, ISO 27002, which provides guidance on implementing the controls listed in Annex A of ISO 27001, underwent a more substantial update. This is where most of the changes you’ll need to consider reside.

  • Consolidation and Restructuring of Controls: The number of controls in Annex A was reduced from 114 to 93. This was achieved through consolidation, removal of some controls, and restructuring. The controls are now organised into simpler domains.
  • Introduction of New Controls: Eleven new controls were added, addressing areas like threat intelligence, information security during development, ICT readiness for business continuity, and physical security monitoring.
  • Focus on Guidance: The update aims to provide more comprehensive and up-to-date guidance on implementing these controls.

For a breakdown of the changes to ISO 27001 Annex A / ISO 27002:2022 read The complete guide to ISO/IEC 27002:2022

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top