Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›ISO standards
ISO standards

ISO 27002:2022: 93 controls and the five attributes most people skip

The 2022 revision cut 114 controls to 93 and reorganised them into four themes instead of fourteen clauses. The bigger change is the attributes - and they are why an old Statement of Applicability cannot simply be renumbered.

Daniel Bara, PhD5 May 20266 min read

Migration to ISO/IEC 27002:2022 is usually executed as a renumbering exercise: take the old Statement of Applicability, map the controls into the new numbering, done. It formally passes. It also misses the only part of the revision that genuinely changes how you work.

What changed in numbers

ISO 27002:2013ISO 27002:2022
Controls11493
Structure14 clauses4 themes
New controls-11
Merged-57 into 24
Attributesnone5 per control

The four themes are organisational, people, physical and technological. The reduction in control count is not a reduction in scope - most of it comes from merging controls that were implemented together in practice anyway.

The eleven new controls

This is the list worth reviewing before concluding that everything is covered:

  • Threat intelligence - collecting and using information on threats relevant to you.
  • Information security for use of cloud services - from procurement through to exit.
  • ICT readiness for business continuity - the bridge to ISO 22301.
  • Physical security monitoring - surveillance of premises, not just entry control.
  • Configuration management - secure baselines and drift detection.
  • Information deletion - at your end and at your processors'.
  • Data masking - particularly in test environments.
  • Data leakage prevention - as a control, not as a product.
  • Monitoring activities - networks, systems and applications, for anomaly detection.
  • Web filtering - control of access to external sites.
  • Secure coding - rules that also apply to acquired software.

In most organisations at least four of these eleven exist technically but have no document describing them and no record evidencing them. That is the difference between a control that works and a control that passes an audit.

The attributes are the real novelty

Every control in the new standard carries five attributes: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities and security domains.

Why that is useful

Attributes let you re-sort the same set of controls according to the question being asked. The board asks "how capable are we of detecting an attack?" - filter on the detect concept. A regulator wants evidence on availability - filter on that property. Without attributes, every such question means walking the whole list by hand.

Attributes are also the fastest route to mapping against other frameworks. The cybersecurity concepts correspond directly to the NIST framework functions, so an organisation working to both the Croatian rules and NIST does not need two unconnected spreadsheets.

How to migrate without losing your evidence

  1. Map old into new, not the other way round. Start from your 114 controls and find each a home among the 93. What has no counterpart has usually been merged, not withdrawn.
  2. Keep the trail. Retain a column with the old identifier in the Statement of Applicability for at least one cycle. Auditors and internal staff will think in the old numbering for another year.
  3. Treat the eleven new controls separately. That is the only place where genuinely new work arises.
  4. Populate the attributes. Not because the standard mandates it, but because this is the one moment when you will be going through the controls one by one anyway.
  5. Check the links to other obligations. The new controls on cloud, monitoring and continuity feed directly into the measures of the Croatian Cybersecurity Regulation.

ISO/IEC 27001:2022 is the standard you certify against; 27002 is the implementation guidance for the Annex A controls. You do not get certified against 27002, but you write your evidence with its help.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.