iso-iec-27002-2022-guide-controls-changes-and-2026-updates

ISO/IEC 27002:2022 Guide: Controls, Changes and 2026 Updates

  • ISO 27002
  • Gabriel Few-Wiegratz
  • Published: 24th Jul 2026

Share this

In Short
  • ISO 27001:2013 certification is no longer valid: The International Accreditation Forum's transition deadline closed on 31 October 2025, so a Statement of Applicability still mapped to the old 114-control structure is a live non-conformity.
  • ISO/IEC 27002:2022 reduced 114 controls to 93 across four themes (Organisational, People, Physical, Technological), merging 24 and introducing 11 entirely new controls covering cloud services, threat intelligence and secure coding.
  • Four existing controls now carry AI-era obligations: Auditors are interpreting controls 5.23, 8.10, 8.16 and 8.28 to cover AI model providers, prompt monitoring, AI-processed data deletion and AI-assisted development, even though the control wording itself is unchanged.
  • Amendment 1:2024 added a documented climate change assessment to ISO 27001:2022. Organisations must record whether climate change is relevant to their ISMS context, even when the answer is no.
  • Point-in-time audits only show what was true on the day they ran: Continuous controls monitoring closes the gap between cycles by keeping evidence current instead of collecting it in a pre-audit scramble.

So what: if your Statement of Applicability still reflects the 2013 control set, or hasn’t been reviewed for AI and climate change obligations, your next surveillance audit will find it. 

Introduction

ISO/IEC 27002:2022 sets out 93 controls across four themes, giving organisations practical guidance for implementing the controls required by ISO/IEC 27001. The 2022 revision cut the control count from 114, added 11 new controls, and reorganised the standard by control ownership rather than technology category. Auditors are now applying several of those controls to AI tools and prompt data in ways the 2022 wording never anticipated, and a compliance programme that hasn't adjusted for that will feel it at its next surveillance visit.

Expert View

Matt Davies

Matthew-Davies-1536x1022-Dec-11-2023-11-07-34-7484-AM

Chief Product Officer, SureCloud

LinkedIn

What our experts say about keeping your SoA audit ready year-round

 

"The SoA is where most ISO 27002 programmes lose credibility. It’s usually accurate the week after certification and stale by the second surveillance visit. We built Gracie AI Agents with Personas and Skills to flag control drift the moment evidence goes missing, well before the auditor arrives."

ISO/IEC 27001 vs ISO/IEC 27002: What's the Difference?

ISO/IEC 27001 and ISO/IEC 27002 work as a pair, each with a distinct job. Understanding the difference is the starting point for any implementation. Think of 27001 as the management system and 27002 as the control cookbook. Your Statement of Applicability (SoA) connects them: it records which of the 93 controls you've adopted, which you've excluded, and why.

Certification applies to ISO/IEC 27001. ISO/IEC 27002 supplies the implementation detail behind it, as set out in the official ISO/IEC 27002:2022 standard page.

Standard

Purpose

Certifiable?

ISO/IEC 27001

Defines the requirements for an Information Security Management System (ISMS). Governs how you build, run, and improve it.

Yes

ISO/IEC 27002

Provides implementation guidance for the controls that support your ISMS. Explains what each control means and how to apply it.

No

What Changed in ISO/IEC 27002:2022?

The 2022 revision, published on 15 February 2022, was the standard's most significant overhaul in nearly a decade. It cut the control count from 114 to 93, restructured 14 domains into 4 themes, and introduced 11 new controls reflecting how organisations operate today.

The headline numbers:

  1. 93 controls (down from 114 in the 2013 edition)
  2. 11 new controls introduced
  3. 24 controls merged to reduce duplication
  4. 58 controls updated with revised guidance
  5. 4 themes replace 14 domains
  6. 5 control attributes added to each control

Why the Restructure Matters

The old 14-domain model grouped controls by technology category. The new four-theme model groups them by who owns and operates them, a practical shift that makes it easier to assign accountability, map controls to your risk register, and explain coverage to auditors.

The five new control attributes, control type, information security properties, cybersecurity concepts, operational capabilities, and security domains, let you build different views of your control set. A CISO can filter by cybersecurity concept; a risk manager can filter by operational capability. One standard, several lenses.

The Four Themes at a Glance

Theme

Controls

What it covers

Organisational

37

Governance, policy, risk management, supplier oversight, business continuity

People

8

Screening, onboarding, training, joiner/mover/leaver, remote working

Physical

14

Secure areas, facility access, equipment, environmental safeguards

Technological

34

Identity, access, logging, configuration, development, vulnerability management

 

The 11 New Controls

These are the controls most likely to need fresh evidence at your next audit. Each one belongs in your SoA or needs a documented justification for exclusion.

Auditors are spending the most time in 2026 on controls 5.21 (ICT supply chain security) and 8.28 (secure coding). They expect demonstrable, risk-based oversight of your software supply chain, not just your contracted ICT vendors. Control 5.23 (cloud services) matters most for SaaS-heavy organisations; auditors now expect a formal exit process documented for each significant provider.

Control

What it requires

5.7 Threat intelligence

Gather, assess and use threat data to inform prevention and response

5.23 Information security for cloud services

Formal process for selecting, using and exiting cloud services, with documented risk acceptance

5.30 ICT readiness for business continuity

Translate business impact analyses into ICT continuity strategies

7.4 Physical security monitoring

Surveillance systems that are tamper-proof and privacy-compliant

8.9 Configuration management

Secure configuration baselines with drift detection

8.10 Information deletion

Secure deletion of data when no longer needed, with evidence

8.11 Data masking

Pseudonymisation and anonymisation to limit sensitive data exposure

8.12 Data leakage prevention

Classify, monitor and prevent unauthorised data movement

8.16 Monitoring activities

Continuous monitoring for anomalies across networks and systems

8.23 Web filtering

Block malicious content; train staff on acceptable use

8.28 Secure coding

Embed security into the software development lifecycle

The 2026 Context: What’s Changed Since the Transition

ISO/IEC 27002:2022 has been the operative standard since 2022, and the compliance environment around it has moved on in two important ways since the transition deadline. Here's where things stand in July 2026.

The Transition Deadline Has Closed

The International Accreditation Forum required all ISO 27001:2013 certifications to transition to the 2022 edition by 31 October 2025. That window is now closed. Any organisation that didn't complete the transition has to restart certification from scratch, and every active certificate now refers to ISO/IEC 27001:2022 and its 93 controls in ISO/IEC 27002:2022.

The practical implication: an SoA still mapped to the old 114-control structure is non-conformant, and your next surveillance audit will surface it as a major finding.

Amendment 1:2024 and Climate Change

In February 2024, ISO published Amendment 1 to ISO/IEC 27001:2022. It adds a sentence to Clause 4.1 requiring organisations to determine whether climate change is a relevant issue for their ISMS, and a note to Clause 4.2 recognising that customers, regulators and other interested parties can have requirements related to climate change.

This is a single documented determination, and auditors will ask for it directly. If your ISMS context review hasn't addressed climate change, even to record that it's not relevant, add that determination before your next audit cycle.

Key takeaway: the 2022 standard is the only operative version, and climate change is now a documented ISMS obligation. Two things to check before your next surveillance audit.

ISO 27002 Controls Through an AI Lens

Generative AI adoption between 2024 and 2026 has changed how auditors interpret several existing controls. The controls themselves haven't been rewritten, but the evidence auditors expect has shifted, and this is the area of ISO 27002 implementation most programmes haven't caught up with yet.

Four Controls That Now Mean Something Different

5.23 (Information security for cloud services) now extends to AI model providers. When your teams use OpenAI, Anthropic, Google Gemini or similar services, auditors ask what those providers do with your prompts, whether they meet your data residency requirements, and whether you have a documented exit strategy. The same cloud governance logic applies to AI as to any other cloud service.

8.16 (Monitoring activities) used to focus on network and system logs. It now requires observability over human-AI interactions, including prompts submitted to and outputs received from AI systems. A SIEM that doesn't capture AI tool usage has a monitoring gap.

8.10 (Information deletion) has become more complex. Regulators and auditors are asking how you'd evidence that an AI model has “forgotten” personal data included in a prompt. The right to erasure under UK GDPR runs up against how large language models work, so your deletion policy needs to address AI-processed data explicitly.

8.28 (Secure coding) now applies to prompt engineering and AI-assisted development pipelines. If your developers use AI coding assistants such as GitHub Copilot or Cursor, the secure coding control extends to how those tools are governed, what data they access, and how their outputs get reviewed before deployment.

What This Means for Your SoA and Risk Register

A separate AI standard isn't required to close these gaps, though ISO/IEC 42001 provides a dedicated AI management system standard with an explicit mapping to ISO 27001 and ISO 27701 in its Annex D. Review your existing control implementations and ask whether the evidence you've collected reflects how your organisation actually uses AI today.

Practical actions: document every AI tool or service used in security operations and business processes; define review rules for AI-generated content before anyone acts on it; add AI tool usage to your monitoring scope under control 8.16; update your deletion and retention policy to address AI-processed data under control 8.10; include AI coding assistants in your secure development policy under control 8.28.

Metrics to track: the percentage of high-risk workflows with human-in-the-loop review steps, AI-assisted change requests with documented reviewer sign-off, and AI tool inventory completeness as a percentage of known tools in use.

Deep Dive: The Four Control Themes

Each theme has a distinct ownership model and a distinct set of failure modes. What follows is a practical guide to what good looks like, where teams commonly fail, and which metrics matter.

Organisational Controls (37 controls)

This is the largest theme, and the one auditors use to judge whether governance is real or decorative. What good looks like: a risk-based control set that matches your business model and threat profile rather than a copy-paste from a template; policies that define what must happen and procedures that define how; named owners for every control with documented review cycles; an SoA that's current, scoped, and traceable to evidence; supplier oversight from onboarding through exit, tiered by risk; continuity plans that account for upstream vendor failure.

Common mistakes: an SoA written at certification and never updated; one-off vendor due diligence with no ongoing monitoring; continuity plans that miss single points of failure in SaaS dependencies; policies too broad to enforce or too narrow to scale.

Metrics: percentage of in-scope suppliers with completed due diligence this quarter; percentage of controls with named owners and on-time reviews; mean time to close security exceptions; percentage of business units with up-to-date business impact analyses.

People Controls (8 controls)

What good looks like: background screening and role-based access confirmed before day one; joiner, mover, leaver flows tied to HR events; security awareness training tailored to job function and risk level; enhanced training for privileged users; documented, versioned sign-offs for critical policies.

Common mistakes: delayed access revocation on leavers or role changes; generic annual training that doesn't shift behaviour; treating privileged users the same as standard users; no proof of policy acknowledgement.

Metrics: access revocation SLA on terminations and role changes; training completion and pass rates by role; phishing simulation fail rate trend; percentage of privileged users who've completed enhanced training.

Physical Controls (14 controls)

The smallest theme by control count, and the easiest one to under-invest in once a team's attention shifts to cloud and AI risk. What good looks like: layered access controls for secure areas; visitor management with escorts, logs, and visible badges; camera coverage with retention schedules and tamper checks; environmental safeguards such as power, HVAC, and fire detection; clean desk and clear screen policies with spot checks.

Common mistakes: shared credentials or unchallenged tailgating; CCTV systems without health checks or retention compliance; inconsistent asset return at offboarding; disposal without certified data destruction records.

Metrics: percentage of secure areas audited on schedule; physical access review completion rate; CCTV and log retention compliance against policy; percentage of incidents with complete physical evidence attached.

Technological Controls (34 controls)

This is where the most audit attention falls in 2026, particularly around identity, supply chain, and AI tool governance.

What good looks like: least-privilege identity management with MFA enforced on every account including service accounts; secure configuration baselines with automated drift detection; centralised logging tuned to reduce alert fatigue; risk-based vulnerability SLAs; secure development lifecycle including AI tool governance; cloud controls mapped to shared responsibility lines.

Common mistakes: MFA enforced for standard users but skipped for admins or service accounts; configuration drift without detection; patch SLAs that treat every vulnerability the same; secrets committed to code repositories; assuming the cloud provider covers every obligation.

Metrics: percentage of identities with MFA enforced; percentage of systems meeting baseline, and mean time to remediate drift; percentage of critical assets with full log coverage; mean time to remediate high-severity vulnerabilities.

ISO 27002 Implementation: A Phased Roadmap

ISO 27002 implementation fails when teams treat it as a documentation exercise. The standard is a control framework, and controls need owners, evidence, and ongoing monitoring, not just policies written once and filed away.

The roadmap below works for first-time implementations and for programmes refreshing after the 2022 transition.

Phase 1: Assess

  1. Scope your ISMS: define the boundaries, assets, and data flows in scope
  2. Map existing controls against the four 27002 themes; log gaps against each of the 93 controls
  3. Review your SoA: is it mapped to the 2022 edition, and are all 11 new controls addressed?
  4. Prioritise gaps by risk and regulatory driver (DORA, NIS2, UK GDPR, sector-specific requirements)

Phase 2: Prioritise

  1. Sequence remediation work into time-boxed sprints
  2. Assign a named owner, due date, and success metric to each gap
  3. Define what “done” looks like before work starts: what evidence will prove the control's operating?
  4. Identify compensating controls for any gaps that can't close immediately

Phase 3: Implement

  1. Update policies and procedures; integrate approval and exception workflows with your ticketing system
  2. Configure technical controls and instrument logging
  3. Train staff by role; test joiner, mover, leaver flows end to end
  4. Address the 11 new controls explicitly; they need fresh SoA entries and fresh evidence

Phase 4: Monitor

  1. Track the metrics from this guide in a compliance dashboard
  2. Review exceptions; retest high-risk controls on a defined cycle
  3. Tune alerts and adjust vulnerability SLAs based on real operational data
  4. Monitor AI tool usage under the updated scope of controls 8.16, 8.10, and 8.28

Phase 5: Review

  1. Run internal audits; close findings with root cause analysis
  2. Update the SoA and risk treatment plan to reflect changes in the business and threat landscape
  3. Feed lessons learned into the next planning cycle
  4. Complete your Amendment 1:2024 climate change determination at the next management review

Spreadsheets can support a small programme, but they don't scale as controls, owners, and evidence multiply. SureCloud's Compliance Management connects risks to controls to owners to evidence, automates evidence collection, and generates audit-ready reports. Teams using the platform reduce audit preparation time for ISO 27001 and SOC 2 certifications by 75%.

How ISO 27002 Connects with Other Frameworks

ISO 27002 doesn't operate in isolation. Most organisations under it also carry obligations under DORA (the EU's Digital Operational Resilience Act), NIS2 (the EU's Network and Information Security Directive 2), UK GDPR, or sector-specific regulation. The 2022 standard was designed with cross-framework mapping in mind.

ISO 27002 and ISO 27001

This is the pairing everything else in this guide sits on top of. 27002 is the implementation guide for 27001's Annex A controls; your SoA is the bridge, since risk treatment decisions drive which controls you adopt, 27002 explains how to implement them, and evidence proves they're working.

ISO 27002 and NIST CSF 2.0

NIST's Cybersecurity Framework 2.0 sets strategic outcomes across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. ISO 27002 supplies the detailed “how” behind the Protect, Detect, and Respond functions. Organisations using both can avoid duplicate effort by mapping 27002 controls to CSF subcategories.

ISO 27002 and DORA

DORA is in enforcement now, and its ICT risk management requirements overlap significantly with ISO 27002's Technological and Organisational controls, particularly incident management (5.24 to 5.28), supplier oversight (5.19 to 5.22), and ICT continuity (5.30). A mature 27002 programme closes much of the gap to DORA compliance.

ISO 27002 and NIS2

NIS2's transposition deadline for EU member states was 17 October 2024. Enforcement action against member states that missed it is ongoing, so implementation timelines still vary by country. NIS2's ten baseline security measures under Article 21 map closely to ISO 27002 controls across all four themes; organisations with a current 27002-aligned programme are well placed for NIS2, though incident reporting timelines and supply chain obligations need their own review.

ISO 27002 and UK GDPR

Where does data protection law meet a security controls standard? ISO 27002 controls underpin the “appropriate technical and organisational measures” requirement under UK GDPR Article 32. Controls covering access management, logging, data masking, deletion, and encryption directly support privacy obligations. A well-implemented 27002 programme provides the security backbone a privacy management system relies on.

ISO 27002 and ISO 42001

ISO/IEC 42001:2023 is the AI management system standard, with 38 AI-specific controls in its Annex A and an explicit mapping to ISO 27001 and ISO 27701 in Annex D. For organisations deploying AI systems, 42001 extends 27002's coverage into AI impact assessment, training data governance, and human oversight obligations that sit outside 27002's scope.

Common Pitfalls and How to Avoid Them

Most ISO 27002 programmes run into trouble at the execution stage. These are the patterns that consistently produce major findings at audit.

Over-Implementation and Control Inflation

Implementing every control regardless of risk creates noise, cost, and a false sense of assurance. Every control in your SoA needs evidence, and every control without a named owner and a working metric is a liability at audit. Tie every control to a risk or a documented regulatory requirement, and if you can't articulate why a control is in scope, cut it.

The “Set and Forget” SoA

An SoA written at certification and left unchanged is one of the most common audit findings. The business changes, suppliers change, technology changes, and your SoA has to reflect the current control environment. Review it at least annually, and after any significant change to your ISMS scope.

Myths That Cost Organisations Time and Money

Myth

Reality

"We can get certified to ISO 27002"

Certification applies to ISO/IEC 27001; 27002 supplies the implementation guidance behind it.

"Once controls are in, we're done"

Controls drift and people change, so ongoing monitoring is mandatory.

"The cloud provider covers it"

Shared responsibility means you retain a significant share of the security obligations; map the line for each service.

"Our SoA maps to the old 114 controls"

The transition deadline closed in October 2025, so a 2013-mapped SoA is now a major non-conformity.

"AI tools are out of scope"

Controls 5.23, 8.10, 8.16, and 8.28 now extend to AI services and AI-assisted development.

Ownership Without Accountability

Controls fail when no one owns them in practice. A name on a spreadsheet isn't ownership. Real ownership means the person understands what the control requires, has the authority to act, receives the metric, and is accountable when it fails.

Continuous Monitoring Versus Point-in-Time Compliance

Point-in-time audits show what was true on a given day; they don't capture what happens between audits. Continuous controls monitoring (CCM) replaces snapshot testing with ongoing evidence collection. SureCloud's CCM reduces audit preparation time by 75% by keeping a live, evidence-backed control status rather than scrambling to collect it at audit time.

What to Do This Quarter

ISO 27002 turns intent into action: the standard supplies the control language, and execution is what separates organisations that pass audits from those that are genuinely secure.

Four things worth doing before your next surveillance audit: audit your SoA against the 93 controls and fix gaps now, not two weeks before the auditor arrives; add AI to your control scope under 5.23, 8.10, 8.16, and 8.28; complete your Amendment 1:2024 climate change determination, an hour's work whose absence is a finding; and move from point-in-time to continuous monitoring.

Get these four right, and your next audit becomes a formality instead of a scramble. Baseline frameworks like Cyber Essentials map cleanly alongside ISO 27002, and Gracie AI Agents with Personas and Skills keep the evidence current between audits, not just the week before one. Either way, the goal is the same: control status you can state with confidence on any given day.

Ready to Move from Point-in-Time to Continuous?

SureCloud's Compliance Management platform supports ISO 27001:2022 out of the box, with Gracie AI Agents with Personas and Skills that perform compliance activities at scale and reduce manual evidence collection by 50 to 65%. Book a demo to see how SureCloud keeps your ISO 27002 controls audit-ready year-round.
Recommended Compliance Resources
  • DORA
  • ISO 27001
  • NIS2
  • Compliance

DORA vs NIS-2 vs ISO 27001: Where They Overlap & How to Combine Them

  • ISO 27001

How to Become ISO 27001 Certified: A Step-by-Step UK Guide

  • ISO 27001

ISO 27001 Compared to Other Information Security Standards: What’s the Difference?

FAQ's

Can you get certified to ISO/IEC 27002?

No, certification applies to ISO/IEC 27001, which defines the requirements for an Information Security Management System. ISO/IEC 27002 supplies implementation guidance for the controls that support that ISMS. Your auditor certifies you against 27001, using 27002 to judge whether each control is implemented properly.

How many controls are in ISO/IEC 27002:2022?

ISO/IEC 27002:2022 contains 93 controls, down from 114 in the 2013 edition. The reduction came from merging 24 overlapping controls, and 11 new controls were added to address cloud services, threat intelligence, configuration management, data protection, and secure coding.

Is ISO 27001:2013 still valid in 2026?

No. The International Accreditation Forum (IAF) required all ISO 27001:2013 certifications to transition to the 2022 edition by 31 October 2025, and that deadline has now passed. Any organisation that didn't complete the transition has to restart certification from scratch. IAF itself merged into the Global Accreditation Cooperation Incorporated on 1 January 2026, which now oversees the requirement it set.

What is Amendment 1:2024 to ISO 27001:2022?

Published in February 2024, Amendment 1 adds a requirement to Clause 4.1 that organisations determine whether climate change is a relevant issue for their ISMS, plus a note to Clause 4.2 on interested parties' climate-related requirements. Organisations must document this determination even when they conclude climate change isn't relevant to their scope.

What do the new AI-era interpretations mean for my SoA?

Controls 5.23, 8.10, 8.16, and 8.28 now carry broader scope than their original 2022 wording suggests, covering AI model providers, AI tool usage monitoring, AI-processed data deletion, and AI-assisted development pipelines. Your SoA doesn't need rewriting, but your control implementation evidence should reflect how your organisation actually uses AI tools today.

 

What are the biggest risks of getting ISO 27002 wrong?

The most common failure modes are implementing controls without named owners, letting the SoA go stale after certification, treating cloud and AI tools as out of scope, and running point-in-time audits with no monitoring between cycles. Each of these produces major non-conformities and weakens the assurance value of the programme.