Theme comparison · iso-27001-editions
ISO 27001:2013 vs 2022
ISO 27001:2013 vs ISO 27001:2022: compare clauses, 114-to-93 Annex A controls, new cloud and threat controls, attributes, and migration work.
Frameworks covered: ISO/IEC 27001
Key differences
| Dimension | Approach A | Approach B |
|---|---|---|
| Annex A structure | 114 controls were arranged in 14 security domains from A.5 through A.18. | 93 controls are grouped into organizational, people, physical, and technological themes. |
| Control changes | The 2013 set used older control wording and distributed related topics across domain sections. | The 2022 set adds 11 controls, merges 24, and updates 58 to reflect current technology and practices. |
| New topics | Threat intelligence, cloud-service security, data masking, DLP, monitoring activities, configuration management, and secure coding were not standalone controls. | A.5.7, A.5.23, A.8.11, A.8.12, A.8.16, A.8.9, and A.8.28 make those topics explicit. |
| Control taxonomy | Controls were primarily navigated by domain and objective. | Five attribute families—control type, information-security properties, cybersecurity concepts, operational capabilities, and security domains—support tailored views. |
| Clause updates | Clause 6.1.3(d) framed the Statement of Applicability against Annex A controls; planning language predated harmonized amendments. | Clause wording clarifies planned changes, process interactions, stakeholder communication, and comparison of controls with Annex A. |
| SoA impact | Organizations recorded applicability and implementation status against 114 reference controls. | Organizations remap controls, justify the revised 93-control reference set, and add organization-specific controls where risk treatment requires them. |
| Certification status | 2013 certificates followed the transition window and are no longer the current certification basis. | Certification and surveillance now use ISO/IEC 27001:2022, including the applicable climate-change amendment to management-system clauses. |
Control overlap
The core ISMS did not disappear: context, leadership, risk assessment, treatment, competence, documented information, internal audit, management review, corrective action, and continual improvement remain recognizable. Most 2013 operating evidence still supports 2022 after remapping. For example, old A.9 access-control practices map into A.5.15–A.5.18 and technological controls; old A.12 operations topics map into controls such as /controls/iso-27001/a-8-6, /controls/iso-27001/a-8-13, and /controls/iso-27001/a-8-17. Migration requires more than renumbering: assess the 11 new controls, revised wording, changed risk context, SoA structure, attributes, and whether cloud, DLP, monitoring, or secure coding creates new evidence needs.
Sequencing advice
A SaaS team migrating an established ISMS should freeze neither engineering nor the risk program. Start with a documented 2013-to-2022 crosswalk, then update context, interested parties, risk assessment, treatment plan, and SoA. Assign owners for cloud-service governance A.5.23, configuration A.8.9, monitoring A.8.16, data leakage A.8.12, and secure coding A.8.28; collect operational evidence from cloud, CI/CD, endpoint, and SIEM systems. Update policies only where control intent changed, train affected owners, run an internal audit against the 2022 criteria, and complete management review before the certification-body visit. New applicants should implement 2022 directly rather than building a legacy 2013 control library.