Insights Into The Revised ISO/IEC 27001:2022

Insights Into The Revised ISO/IEC 27001:2022

Share this article

Altenar, a sportsbook software provider, is excited to share an overview of the new ISO/IEC 27001:2022 standard — published on October 25, 2022 — and how it improves the ability to address the ever-evolving security challenges facing organizations today.


ISO 27001 defines the framework for an information security management system (ISMS). As cyber threats and vulnerabilities continue to evolve, so do the risks to confidentiality, integrity, and availability. The new version of the standard enhances the focus on managing these risks more effectively.


One of the key benefits of using the updated controls outlined in ISO/IEC 27001:2022 is that they are clearly defined and easily identifiable. This simplification helps streamline control selection, potentially reducing the effort required to achieve compliance. It can also enhance the overall efficiency and effectiveness of your ISMS by allowing for better integration of security processes.


The core mandatory requirements outlined in clauses 4 to 10 of the 2013 version have undergone minor changes and include a few new additions. However, the most significant update lies in the Annex A control set, which has now been aligned with the latest ISO 27002 publication. The number of controls has been reduced from 114 to 93. Of these, 11 are entirely new, 24 have been merged, and 58 have updated descriptions and guidance.


The 93 controls have been consolidated into four primary categories:


1. A.5 Organizational controls

2. A.6 People controls

3. A.7 Physical controls

4. A.8 Technological controls


Organizations are encouraged to review and compare the new information security controls against their existing ones. This evaluation will guide updates to risk management plans and adjustments to the Statement of Applicability (SoA) to reflect any new or revised controls.


Information About the Transition to the New Published Standard


Since ISO/IEC 27001:2022 is not considered a “fully revised edition,” the International Accreditation Forum (IAF) does not require immediate transition for organizations already certified under or currently pursuing ISO/IEC 27001:2013. Certified organizations will need to complete the transition to the 2022 revision within 36 months of its publication — by October 31, 2025.


IAF MD 26 outlines the following minimum objectives for certification bodies, along with a requirement of at least 0.5 auditor days to validate the transition plan for certified organizations:


  • Conducting a gap assessment of the organization’s ISMS against the 2022 revision of ISO 27001
  • Reviewing the updated Statement of Applicability, including the new set of 93 controls
  • Reviewing risk treatment plans — particularly where existing plans are based on Annex A controls used to mitigate identified risks
  • Assessing the implementation and effectiveness of newly adopted controls


You can learn more about the transition process by referring to the official IAF MD 26 document.



Previous Next

Related articles

  • Design Is Not Just Pictures: Marat Garipov, Art Director at Altenar

    Design Is Not Just Pictures: Marat Garipov, Art Director at Altenar

  • Getting to know you - Diego Salas

    Getting to know you - Diego Salas

  • Sportsbook Guide: Fully Customizable Front-End Solution

    Sportsbook Guide: Fully Customizable Front-End Solution

  • Gambling laws and regulation in Peru

    Gambling laws and regulation in Peru

  • Getting to know you - Keith Barbara

    Getting to know you - Keith Barbara

  • Altenar signs sportsbook deal with Gamblr

    Altenar signs sportsbook deal with Gamblr

  • Gambling Laws & Compliance in France: An Operator’s Guide to Entering the Market

    Gambling Laws & Compliance in France: An Operator’s Guide to Entering the Market

  • Personalization Tactics – Is Your Platform Smart Enough to Compete?

    Personalization Tactics – Is Your Platform Smart Enough to Compete?

  • Gambling Laws and Regulations in the US State of Florida

    Gambling Laws and Regulations in the US State of Florida

  • Sportsbook features guide: Player props

    Sportsbook features guide: Player props

  • Sportsbook features guide: Bonus engine

    Sportsbook features guide: Bonus engine

  • Altenar powering Vegas.hu’s sportsbook success

    Altenar powering Vegas.hu’s sportsbook success

Fill out the form and we’ll be in touch as soon as possible

Follow 3 simple steps to fill out the form

  • 1

    Details

    Step 1
  • 2

    Contacts

    Step 2
  • 3

    Info

    Step 3

Choose enquiry and fill details

1 / 3
Enquiry Type

This form collects your data so that we can correspond with you. Read our Privacy Policy for more information

  • 1

    Details

    Step 1
  • 2

    Contacts

    Step 2
  • 3

    Info

    Step 3

Contact info

2 / 3
How can we reach you?

This form collects your data so that we can correspond with you. Read our Privacy Policy for more information

  • 1

    Details

    Step 1
  • 2

    Contacts

    Step 2
  • 3

    Info

    Step 3

More information you want to tell us

3 / 3
How did you hear about us?
Region of Operation
Do you already have a sportsbook?

This form collects your data so that we can correspond with you. Read our Privacy Policy for more information