ISO/IEC 27001:2022 — Information Security Management Systems
ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Based on the Plan-Do-Check-Act cycle, it provides a systematic approach to managing information security risks. The 2022 revision reorganised Annex A from 114 controls (14 domains) to 93 controls across 4 themes.
93
Annex A Controls
4
Control Themes
3-Year
Certification Cycle
48,671
Certificates Worldwide (2023)
Core management system requirements: context of the organisation, leadership, planning, support, operation, performance evaluation, and improvement. Approximately 140-150 requirements.
Policies, procedures, governance, roles, and responsibilities for information security management across the organisation.
Awareness, training, competence, screening, and behaviour management for personnel involved in information security.
Protection of physical assets, premises, equipment, and facilities from environmental and physical threats.
Digital security controls covering encryption, network security, access management, malware protection, and system development security.
Define the scope of your ISMS: which parts of the organisation, which information assets, and which locations to include in the certification boundary.
Identify information security risks, evaluate their likelihood and impact, and determine risk treatment options aligned with your risk appetite.
Select applicable Annex A controls based on your risk assessment. Document your Statement of Applicability (SoA) explaining control inclusion or exclusion.
Implement selected controls across all four themes (Organisational, People, Physical, Technological). Document policies, procedures, and evidence.
Conduct internal audits and management reviews to verify ISMS effectiveness before engaging an external certification body.
Complete Stage 1 and Stage 2 audits. Maintain certification through annual surveillance audits and continuous improvement per the PDCA cycle.