ISO/IEC 27001:2022 Information Security Management
The leading international standard for Information Security Management Systems — protecting the confidentiality, integrity, and availability of information assets through systematic risk management.
Everything you need to know about ISO/IEC 27001:2022
ISO/IEC 27001:2022 specifies requirements for an Information Security Management System (ISMS). It takes a risk-based approach — requiring organisations to assess information security risks in their context, select appropriate controls, and implement them systematically. Annex A provides 93 reference controls across four themes: organisational, people, physical, and technological. A Statement of Applicability (SoA) documents control selection decisions. The 2022 revision restructured Annex A and introduced 11 new controls addressing contemporary threats including threat intelligence, cloud security, and secure coding.
ISO/IEC 27001 applies to any organisation handling sensitive information — financial institutions, technology companies, healthcare providers, legal firms, government bodies, cloud service providers, data processors, and any organisation subject to GDPR, NIS2, or sector-specific cybersecurity regulation. It is scalable for organisations of any size and increasingly required in procurement processes across professional services and regulated sectors.
The Stage 2 audit evaluates the risk assessment and treatment process, implementation of selected Annex A controls against the SoA, information security incident management, monitoring and measurement activities, and the overall effectiveness of the ISMS. Interviews across IT, operations, HR, and management are a key element. View the full certification process.
ISO/IEC 27001:2022 certificates are valid for three years. The information security threat landscape evolves rapidly — surveillance audits assess how the organisation has responded to new threats, changes in information assets, and updates to regulatory requirements including GDPR and NIS2. Organisations that treat ISO 27001 as a living framework — regularly updating risk assessments and adapting to new threats — maintain robust security and sustained certification value.