How to update your ISMS to the ISO 27001:2022 standard
Follow these steps to successfully transfer your Information Security Management System (ISMS) from ISO 27001:2013 to ISO 27001:2022
Written By Micah
Organizations certified to ISO 27001:2013 have until October 2025 to transition to the 2022 version, but it's important to develop a plan for these changes so your organization can maintain its certification.
To update an Information Security Management System (ISMS) from the ISO 27001:2013 standard to the new ISO 27001:2022 standard, the following activities should be undertaken.
Stage 1: Certification Planning
First and foremost, it's important that your organization engages a certification body (or Assessor) for transitioning the ISMS certification to the 2022 version before the transition period ends in October 2025.
This step ensures that your certification remains on track and provides a timeline for the preparation steps below.
Stage 2: Account Configuration
Once you've confirmed your transition timeline with your certification body, contact your CSM and request that these changes be reflected in your Strike Graph account.
Your CSM will handle the necessary configuration to transfer your account content from ISO 27001:2013 to ISO 27001:2022. Changes you'll see reflected in your Strike Graph account include:
The ISO:27001 framework tree will be updated to align with the 2022 version of the standard.
11 new Strike Graph Suggested Controls will be activated in your Control Library to address the updated Annex A requirements. A list of these controls can be found below.
Your CSM will notify you when this step is complete and your team can move to the next stage.
Stage 3: Internal Preparation
As your team takes the following preparation steps, it's important to note that all below activities should be documented in your ISMS Status Meetings as Agenda Items.
Step 1: Review Clause Updates
To start, we suggest reviewing your ISMS documentation against the management system clauses (Clauses 4-10) to gain an understanding of the updates. As you review the updated requirements, be sure to update processes, procedures, and documentation accordingly.
Key changes include:
Clause 4.2 Understanding the Needs and Expectations of Interested Parties: A new subclause has been added, requiring an analysis of which interested party requirements will be addressed through the ISMS.
Clause 4.4 Information Security Management System: New language has been added, requiring organizations to identify necessary processes and their interactions within the ISMS. The ISMS must now include all processes that support it, not just those specifically mentioned in the Standard.
Clause 6.2 Information Security Objectives and Planning to Achieve Them: Now includes additional guidance on information security objectives, providing more clarity on how these objectives should be regularly monitored and formally documented.
Clause 6.3 Planning of Changes: This new clause sets a standard for planning changes to the ISMS. It states that any necessary changes must be adequately planned.
Clause 8.1 Operational Planning and Control: Additional guidance has been added for operational planning and control. The ISMS must now establish criteria for the actions identified in Clause 6 and control those actions according to these criteria.
Step 2: Review New Annex A Controls
Take time to review the newly activated controls in your Control Library. These new suggested controls are designed to satisfy the updated 2022 Annex A requirements. β
New Annex A Controls:
A.5.7 Threat Intelligence
A.5.23 Information Security for Use of Cloud Services
A.5.30 ICT Readiness for Business Continuity
A.7.4 Physical Security Monitoring
A.8.9 Configuration Management
A.8.10 Information Deletion
A.8.11 Data Masking
A.8.12 Data Leakage Prevention
A.8.16 Monitoring Activities
A.8.23 Web Filtering
A.8.28 Secure Coding
We recommend reviewing the control descriptions and frequencies, assigning control owners, and assigning progress flags.
Step 3: Update Your Statement of Applicability Document
After you've identified the new Annex A controls in your Control Library, it's important to integrate these controls in your Statement of Applicability.
To update your Statement of Applicability, feel free to use Strike Graph's updated SoA template. The new template has columns for both 2013 and 2022 to easily reflect your updated content. More SoA guidance is available here.
Step 4: Update Risk Assessment
It's important that all new controls are reflected as mitigating controls within your Risk Register document. Your organization also has the ability to create new risks as needed within your Risk Register to address any new risk areas.
Step 5: Operationalize New Controls
Now it's time to operationalize the new Annex A controls listed above. This includes updating policies, procedures, and other documentation as necessary to satisfy the linked evidence items.
Tip: For any new or existing documentation, make sure that any reference to 27001:2013 is updated to 27001:2022.
Tip: Remember to retrain employees on your updated ISMS processes and procedures as needed!
Step 6: Conduct Internal Audit
As a final step, your organization will conduct an internal audit to verify the effective implementation of the updated ISMS based on ISO 27001:2022 requirements. This will allow your team to remediate as needed to prepare for your eventual certification audit.