Book

ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements

by ISO/IEC · 2022 · 7 reading cards

7 cards

  1. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    Annex A is a checklist, not a shopping list.

    The 2022 edition restructured the annex: from 114 controls in 14 clauses there are now 93, grouped in four themes — organizational (37), people (8), physical (14) and technological (34). Eleven are entirely new: threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28). The implementation guidance lives in ISO/IEC 27002:2022, which gives every control five attributes for filtering: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. The attributes are a sorting tool, not extra requirements. And 27002 is guidance: nobody gets certified against it.

    The information security controls listed in Annex A are not exhaustive and additional information security controls can be included if needed.

    Open the card

  2. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    Clause 6 writes the method, clause 8 proves it was used.

    Clause 8 is where the system actually runs. At 8.1 the organization plans, implements and controls the processes needed to meet requirements and to implement the actions determined in clause 6, retains documented information showing the processes were carried out as planned, controls planned changes and reviews the consequences of unintended ones. This is also where outsourcing sits: externally provided processes, products or services relevant to the system must be determined and controlled. They do not have to be certified, they have to be controlled. The classic exam confusion is between 6.1.2 and 8.2. The first requires that a risk assessment process exist, defined and applied; the second requires that the process actually be run, at planned intervals and on significant changes, with the results retained. The same pair exists for treatment: 6.1.3 defines the process, while 8.3 requires the plan to be implemented and the results to be retained.

    The organization shall perform information security risk assessments at planned intervals or when significant changes are proposed or occur, taking account of the criteria established in 6.1.2 a).

    Open the card

  3. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    An objective that cannot be measured is an intention on letterhead.

    Clause 6.2 asks for objectives that can be checked: consistent with the policy, measurable if practicable, taking account of applicable requirements and of the results of risk assessment and treatment, monitored, communicated, updated and available as documented information. Their planning answers five questions on top of that: what will be done, with what resources, who is responsible, when it will be completed and how the results will be evaluated. "Raise the level of security" does not survive that filter. Clause 6.3 is new in the 2022 edition and is a single sentence, but it is auditable: a change to the system — a new site, a new cloud provider, a reorganization — carried out in a rush becomes a finding. Clause 7 supplies the rest: resources (7.1), competence determined, ensured and evidenced with the effectiveness of actions evaluated (7.2), awareness of the policy, of one's own contribution and of the consequences of not conforming (7.3), planned communication (7.4) and control of documented information (7.5).

    When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.

    Open the card

  4. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    Annex A is the safety net under your list of controls, not its source.

    Almost every beginner reads the order of 6.1.3 backwards. It does not start from Annex A. First the treatment options are chosen, taking account of the assessment results; then all controls necessary to implement the chosen options are determined — the standard says plainly that they may be designed by the organization or identified from any source; only then is the resulting list compared with Annex A, as a cross-check that nothing necessary has been omitted. The outcome is recorded in the Statement of Applicability, the one document that ties risks to controls. It says four things about each control: that it is necessary, why it was included, whether it is implemented or not, and why any Annex A control was excluded. A necessary control that is not yet implemented is allowed to appear there; what is not allowed is silence. Finally, the treatment plan and the acceptance of residual risk are approved by the risk owners.

    produce a Statement of Applicability that contains: the necessary controls (see 6.1.3 b) and c)); justification for their inclusion; whether the necessary controls are implemented or not; and the justification for excluding any of the Annex A controls.

    Open the card

  5. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    Clause 5 is audited in the executive office, not in the server room.

    Clause 5 has three subclauses and every one of them starts with "top management", not with "the organization". The wording is deliberate: at 5.1 the auditor asks for evidence that the people who decide budget and direction did something checkable — made sure the policy and the objectives exist and fit the strategic direction, integrated the requirements into the organization's ordinary processes, made resources available, promoted continual improvement. At 5.2 the policy has to suit the purpose of the organization, contain objectives or the framework for setting them, and carry two commitments: to satisfy applicable requirements and to improve continually. It exists as documented information, is communicated internally and is made available to interested parties as appropriate. At 5.3 roles are assigned and communicated, and two responsibilities are named outright: that the system conforms to the standard and that its performance is reported to top management. This is why stage 2 interviews are not held with the technical team alone.

    Top management shall demonstrate leadership and commitment with respect to the information security management system by: ensuring the information security policy and the information security objectives are established and are compatible with the strategic direction of the organization.

    Open the card

  6. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    A scope too narrow passes the audit but convinces no customer, and one too broad never gets finished.

    Clause 4 asks for three things before any control. First, the internal and external issues relevant to the organisation's purpose and to the intended outcomes of the system. Then the interested parties and their requirements — customers, regulators, employees, suppliers — because a contractual requirement nobody identified becomes a nonconformity at the first audit. Only then comes the scope, at 4.3: the boundaries and applicability of the system, taking into account the issues from 4.1, the requirements from 4.2, and the interfaces with activities performed by other organisations. The classic mistake sits at 4.3, in both directions. A scope that is too narrow, one team or one product, passes the audit easily but convinces no customer who asks what exactly is certified. A scope that is too broad, declared before the processes exist, turns certification into a project that never ends. Amendment 1:2024, published in February 2024, added to 4.1 and 4.2 the duty to consider climate change as a possibly relevant issue.

    The organization shall determine the boundaries and applicability of the information security management system to establish its scope.

    Open the card

  7. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022

    Annex A is the consequence of the risk assessment, not the starting point of the implementation.

    An ISMS — information security management system — is not a list of controls but the machinery that decides which controls are needed, puts them to work and checks whether they still fit. The standard says so directly in its introduction: the system preserves the confidentiality, integrity and availability of information by applying a risk management process. The Annex A controls, 93 of them, grouped in the 2022 edition into four themes — organisational, people, physical, technological — are the consequence of the risk assessment, not the starting point. The auditable requirements are clauses 4 to 10: context, leadership, planning, support, operation, performance evaluation, improvement. That structure is shared by every management system standard written since 2012, which has a practical upshot: ISO 9001, ISO 22301 or ISO/IEC 42001 for artificial intelligence use the same framing clauses. An organisation already running one of them adds the second scheme without rebuilding its policy, internal audit or management review.

    The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.

    Open the card