Standards
ISO/IEC 27001:2022 CertifiableISO/IEC

Information security, cybersecurity and privacy protection — Information security management systems — Requirements

The certifiable ISMS. The 2022 edition reorganised Annex A into 93 controls across four themes and added eleven new ones, including threat intelligence and ICT readiness for business continuity — the direct junction with ISO 22301.

Official text

Who it applies to

  • CISOs
  • Providers evidencing their security posture
  • Entities in scope of NIS2 or DORA

Structuring points

  • A.5.29 and A.5.30 bring continuity into the ISMS
  • The Statement of Applicability justifies every control retained or excluded
  • An ISMS and a BCMS share 70% of their structure: auditing them jointly saves a third of the time

Protecting the confidentiality, integrity and availability of information.