← Standards
ISO/IEC 27001:2022 CertifiableISO/IEC
Information security, cybersecurity and privacy protection — Information security management systems — Requirements
The certifiable ISMS. The 2022 edition reorganised Annex A into 93 controls across four themes and added eleven new ones, including threat intelligence and ICT readiness for business continuity — the direct junction with ISO 22301.
Official textWho it applies to
- CISOs
- Providers evidencing their security posture
- Entities in scope of NIS2 or DORA
Structuring points
- A.5.29 and A.5.30 bring continuity into the ISMS
- The Statement of Applicability justifies every control retained or excluded
- An ISMS and a BCMS share 70% of their structure: auditing them jointly saves a third of the time
Protecting the confidentiality, integrity and availability of information.