← All cheat sheets

ISO 27001:2022 CONTROLS MAPPING

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

- ISO/IEC 27001:2022 published October 2022
- Replaces ISO 27001:2013 (transition deadline: October 31, 2025)
- 93 controls in Annex A (down from 114 in 2013)
- 4 control themes replace the previous 14 domains
- 11 new controls added, several merged or restructured
- Requires an ISMS (Information Security Management System)

KEY CHANGES FROM 2013#

- 114 controls consolidated to 93 controls
- 14 control domains replaced by 4 themes
- 11 entirely new controls introduced
- 24 controls merged from existing ones
- 58 controls updated/revised
- Introduction of control attributes (types, properties, concepts, capabilities, domains)
- Stronger focus on cloud security, threat intelligence, and data masking

CONTROL ATTRIBUTES (NEW)#

Control Type:      Preventive, Detective, Corrective
Security Property: Confidentiality, Integrity, Availability
Cybersecurity:     Identify, Protect, Detect, Respond, Recover
Operational:       Governance, Asset Management, Protection, Defence, Resilience
Security Domain:   Governance & Ecosystem, Protection, Defence, Resilience

THEME 1: ORGANIZATIONAL CONTROLS (A.5) - 37 CONTROLS#

A.5.1   Policies for information security
A.5.2   Information security roles and responsibilities
A.5.3   Segregation of duties
A.5.4   Management responsibilities
A.5.5   Contact with authorities
A.5.6   Contact with special interest groups
A.5.7   Threat intelligence *NEW*
A.5.8   Information security in project management
A.5.9   Inventory of information and other associated assets
A.5.10  Acceptable use of information and other associated assets
A.5.11  Return of assets
A.5.12  Classification of information
A.5.13  Labelling of information
A.5.14  Information transfer
A.5.15  Access control
A.5.16  Identity management
A.5.17  Authentication information
A.5.18  Access rights
A.5.19  Information security in supplier relationships
A.5.20  Addressing information security within supplier agreements
A.5.21  Managing information security in the ICT supply chain
A.5.22  Monitoring, review and change management of supplier services
A.5.23  Information security for use of cloud services *NEW*
A.5.24  Information security incident management planning and preparation
A.5.25  Assessment and decision on information security events
A.5.26  Response to information security incidents
A.5.27  Learning from information security incidents
A.5.28  Collection of evidence
A.5.29  Information security during disruption
A.5.30  ICT readiness for business continuity
A.5.31  Legal, statutory, regulatory and contractual requirements
A.5.32  Intellectual property rights
A.5.33  Protection of records
A.5.34  Privacy and protection of PII
A.5.35  Independent review of information security
A.5.36  Compliance with policies, rules and standards for information security
A.5.37  Documented operating procedures

THEME 2: PEOPLE CONTROLS (A.6) - 8 CONTROLS#

A.6.1   Screening
A.6.2   Terms and conditions of employment
A.6.3   Information security awareness, education and training
A.6.4   Disciplinary process
A.6.5   Responsibilities after termination or change of employment
A.6.6   Confidentiality or non-disclosure agreements
A.6.7   Remote working
A.6.8   Information security event reporting

THEME 3: PHYSICAL CONTROLS (A.7) - 14 CONTROLS#

A.7.1   Physical security perimeters
A.7.2   Physical entry
A.7.3   Securing offices, rooms and facilities
A.7.4   Physical security monitoring *NEW*
A.7.5   Protecting against physical and environmental threats
A.7.6   Working in secure areas
A.7.7   Clear desk and clear screen
A.7.8   Equipment siting and protection
A.7.9   Security of assets off-premises
A.7.10  Storage media
A.7.11  Supporting utilities
A.7.12  Cabling security
A.7.13  Equipment maintenance
A.7.14  Secure disposal or re-use of equipment

THEME 4: TECHNOLOGICAL CONTROLS (A.8) - 34 CONTROLS#

A.8.1   User endpoint devices
A.8.2   Privileged access rights
A.8.3   Information access restriction
A.8.4   Access to source code
A.8.5   Secure authentication
A.8.6   Capacity management
A.8.7   Protection against malware
A.8.8   Management of technical vulnerabilities
A.8.9   Configuration management *NEW*
A.8.10  Information deletion *NEW*
A.8.11  Data masking *NEW*
A.8.12  Data leakage prevention *NEW*
A.8.13  Information backup
A.8.14  Redundancy of information processing facilities
A.8.15  Logging
A.8.16  Monitoring activities *NEW*
A.8.17  Clock synchronization
A.8.18  Use of privileged utility programs
A.8.19  Installation of software on operational systems
A.8.20  Networks security
A.8.21  Security of network services
A.8.22  Segregation of networks
A.8.23  Web filtering *NEW*
A.8.24  Use of cryptography
A.8.25  Secure development life cycle
A.8.26  Application security requirements
A.8.27  Secure system architecture and engineering principles
A.8.28  Secure coding *NEW*
A.8.29  Security testing in development and acceptance
A.8.30  Outsourced development
A.8.31  Separation of development, test and production environments
A.8.32  Change management
A.8.33  Test information
A.8.34  Protection of information systems during audit testing

ALL 11 NEW CONTROLS SUMMARY#

A.5.7   Threat intelligence - gather and analyze threat info
A.5.23  Cloud services security - manage cloud-specific risks
A.5.30  ICT readiness for business continuity - ensure ICT supports BCP
A.7.4   Physical security monitoring - surveillance and detection
A.8.9   Configuration management - establish and maintain secure configs
A.8.10  Information deletion - delete data when no longer required
A.8.11  Data masking - mask PII/sensitive data per policy
A.8.12  Data leakage prevention - apply DLP measures to sensitive data
A.8.16  Monitoring activities - monitor systems for anomalous behavior
A.8.23  Web filtering - manage access to external websites
A.8.28  Secure coding - apply secure coding principles in development

MAPPING: ISO 27001:2022 TO NIST CSF 2.0#

ISO 27001         NIST CSF 2.0
---------         ------------
A.5.1-5.4         GV.PO, GV.RR
A.5.7             ID.RA
A.5.9-5.10        ID.AM
A.5.15-5.18       PR.AA
A.5.19-5.22       GV.SC
A.5.24-5.28       RS.MA, RS.AN
A.5.29-5.30       RC.RP
A.6.3             PR.AT
A.8.2-8.3         PR.AA
A.8.7-8.8         PR.PS
A.8.12            PR.DS
A.8.15-8.16       DE.CM
A.8.25-8.28       PR.PS

ISMS REQUIREMENTS (CLAUSES 4-10)#

Clause 4: Context of the Organization
  - Understanding the organization and its context
  - Understanding needs and expectations of interested parties
  - Determining the scope of the ISMS

Clause 5: Leadership
  - Leadership and commitment
  - Information security policy
  - Organizational roles, responsibilities and authorities

Clause 6: Planning
  - Actions to address risks and opportunities
  - Information security objectives and planning

Clause 7: Support
  - Resources, competence, awareness
  - Communication and documented information

Clause 8: Operation
  - Operational planning and control
  - Information security risk assessment and treatment

Clause 9: Performance Evaluation
  - Monitoring, measurement, analysis and evaluation
  - Internal audit and management review

Clause 10: Improvement
  - Continual improvement
  - Nonconformity and corrective action

CERTIFICATION TIPS#

- Stage 1 Audit: documentation review (ISMS scope, policies, SoA)
- Stage 2 Audit: implementation effectiveness (evidence, interviews)
- Statement of Applicability (SoA) must justify included/excluded controls
- Risk assessment methodology must be documented and repeatable
- Internal audits must cover the full ISMS scope over the cycle
- Management review must include defined inputs and outputs
- Transition from 2013 to 2022 requires updated SoA and risk treatment plan
- Surveillance audits occur annually; recertification every 3 years

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.