ISO 27001
Requirements Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Published | Oct 25, 2022 | ISO/IEC 27001:2022 released |
| Transition deadline | Oct 31, 2025 | Organizations must transition from 2013 version |
Provisions (2)
Information Security Controls (Annex A)
"ISO 27001:2022 restructured Annex A controls into **4 themes** (organizational, people, physical, technological) with **93 controls** replacing the previous 114."
Requirements
| Requirement | Details |
|---|---|
| Access control policy | Define and enforce access control rules |
| User access management | Formal registration and de-registration |
Sources: ISO 27001:2022
Data Quality Requirements (Clause 7.5)
"Clause 7.5 requires organizations to ensure documented information is **available, suitable, and adequately protected** throughout its lifecycle."
Requirements
| Requirement | Details |
|---|---|
| Documented information | Maintain quality and integrity of ISMS documentation |
| Information classification | Classify information according to sensitivity |
Sources: ISO 27001:2022