The major change to ISO 27001, with the publication of the 2022 version, was the incorporation of the control set from ISO 27002:2022 into Annex A of ISO 27001:2022. With ISO 27002:2022, there was a a significant revision of the set of information security controls with the previous 114 being reduced to 93. Of those 93 controls:
- 58 have been updated
- 24 controls represent merging of 57 of the previous controls
- 11 new controls have been introduced.
More information on ISO 27002:2022 can be found here.
A number of changes to the management system clauses were made in ISO/IEC 27001:2022 with the goal of making some of the requirements more explicit and improving the alignment with other Annex SL standards, such as ISO 9001 and ISO 22301, e.g. sub clause titles, terms and definitions.

5 Must-Dos of Effective ISO 27001 Risk Management
URM’s blog explores five key actions organisations can take to strengthen their ISO 27001 information risk management processes.
URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more
URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more
URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

