The major change to ISO 27001, with the publication of the 2022 version, was the incorporation of the control set from ISO 27002:2022 into Annex A of ISO 27001:2022.  With ISO 27002:2022, there was a a significant revision of the set of information security controls with the previous 114 being reduced to 93.   Of those 93 controls:

  • 58 have been updated
  • 24 controls represent merging of 57 of the previous controls
  • 11 new controls have been introduced.

More information on ISO 27002:2022 can be found here.

A number of changes to the management system clauses were made in ISO/IEC 27001:2022 with the goal of making some of the requirements more explicit and improving the alignment with other Annex SL standards, such as ISO 9001 and ISO 22301, e.g. sub clause titles, terms and definitions.

Excellent presentation, thank you!
Contact the ISO 27001 Experts Today

ISO 27001 Clause 9.1: Monitoring, Measurement, Analysis and Evaluation Explained

Published on
13 Aug
2026

URM’s blog explores ISO 27001 Clause 9.1, what it requires and practical guidance on how to implement this Clause in full conformance with the Standard.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
7/8/2026
5 Must-Dos of Effective ISO 27001 Risk Management

URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
7/8/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
4/8/2026
ISO 27001 Clause 10.2: Nonconformity and corrective action

URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more

Read more
"
We are immensely grateful to URM for their unwavering support, professionalism, and expertise throughout our ISO 27001 and Cyber Essentials Plus journey. Their guidance and strategic insights have been invaluable. With URM's continued partnership and support, we are confident in our ability to proactively address emerging threats and keep our business secure.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.