All Frameworks

Compliance Framework

ISO/IEC 27001:2022 Information Security Management

The internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

93 Annex A Controls · 4 Themes
Accredited certification bodies (ISO 17021)

Overview

ISO/IEC 27001:2022 is the latest revision of the world's best-known information security standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The 2022 update reorganized the Annex A controls from 14 categories into 4 themes and reduced the total from 114 to 93 controls (with 11 new additions). Certification is awarded by accredited third-party auditors after demonstrating that an ISMS meets all requirements. ISO 27001 is accepted globally and is often required for international business.

Who Needs This?

  • Organizations operating in international markets
  • Companies needing a globally recognized security certification
  • Enterprises with multi-standard compliance requirements
  • Government contractors in non-US jurisdictions
  • Organizations seeking a structured ISMS approach

Key Benefits

  • Achieve a globally recognized security certification
  • Streamline compliance across multiple frameworks (SOC 2, GDPR, etc.)
  • Demonstrate security commitment to international customers
  • Establish a systematic approach to managing information risks
  • Drive continuous improvement through the PDCA cycle

Key Domains

Organizational Controls

37

Policies, roles, threat intelligence, asset management, access control, supplier relationships, and business continuity.

People Controls

8

Screening, awareness, training, disciplinary processes, remote working, and confidentiality agreements.

Physical Controls

14

Secure areas, equipment security, storage media, utility services, cabling security, and monitoring.

Technological Controls

34

Endpoint security, access rights, authentication, cryptography, secure development, logging, and network security.

Related Frameworks

Need Help With ISO/IEC 27001:2022?

Our team can assess your current posture, identify gaps, and build a roadmap to compliance. Get expert guidance tailored to your organization.

Request a Compliance Assessment