1Introduction
ISO/IEC 27001 is the best-known international standard for information security management systems. The 2022 edition, published in October 2022, aligned its control annex with ISO/IEC 27002:2022.
2Discussion
Controls fell from 114 to 93, grouped into organisational, people, physical and technological themes. Eleven new controls were added, including threat intelligence, cloud services security, ICT readiness for business continuity, monitoring, configuration management, information deletion, data masking and data leakage prevention.
3Conclusion
Organisations certified to the 2013 edition had until October 2025 to transition. For firms handling customer financial data, certification is among the first questions banks and large enterprises ask.
Sources
همفکران فناوری شریفThis article summarises the official sources cited, prepared by the Hamfekran Fanavari Sharif team for finance leaders.
Want to see these solutions in your organisation?Book a free demo
همفکران فناوری شریف

