What are the Major Changes in ISO/IEC 27001:2022?

The updated version of ISO 27001 has been restructured and revised. There is slight changes in Mandatory clauses from 4 to 10.

New requirements in main part of the standards are in clause 4.2c) , 6.3 , 8.1 & 9.3.2 c) The number of controls has decreased from 114 to 93 in the new version of ISO 27001. These security controls are now divided into 4 'Themes' instead of the previous 14 domain. The new domains:

Organizational (37 controls)
  • Organizational (37 controls)
  • People (8 controls)
  • Physical (14 controls)
  • Technology (34 controls)
The completely new controls are:
  • Threat Intelligence
  • Physical security monitoring
  • Data masking
  • Information security for cloud services
  • Monitoring activities
  • ICT readiness for business continuity
  • Data leakage prevention
  • Configuration management
  • Web filtering
  • Information deletion
  • Secure coding

The changes in Annex A are only moderate because most of the controls have either stayed the same (35 of them) or have only been renamed (23).

Another 57 controls were merged, which has reduced the number of controls, but the requirements within those controls remained almost the same.


Enquiry Now


For ISO Certifications!!
Enquiry or Whatsapp

ISO Certification Training in Mumbai • List of ISO Certification Courses in Mumbai • ISO Certification Classes in Mumbai • ISO Certification Institutes in Mumbai • ISO Consultants Nearby your Locality • ISO Certification Course Fees • ISO Training Fees

Submit your Enquiry