Introduction to ISO 27001:2022
A plain-English guide to the world’s leading information security standard — what it is, its key benefits, the mandatory clauses, the Annex A controls, who needs it, and how organisations achieve certification.
What is ISO/IEC 27001:2022?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a risk-based framework for protecting the confidentiality, integrity and availability of information. The 2022 edition (published October 2022, replacing ISO 27001:2013) modernises the standard’s security controls. It is the only ISMS standard against which an organisation can be independently certified, giving customers and regulators assurance that information is managed to a recognised global benchmark.
Key benefits of ISO 27001:2022
Globally recognised
An internationally recognised certification that supports overseas clients, partners and cross-border business.
Protect critical information
A structured, risk-based way to safeguard customer, employee and business data against loss, misuse and unauthorised access.
Win trust & tenders
Certification is increasingly required in contracts and vendor reviews — it opens doors and shortens security questionnaires.
Build a security culture
Clear roles, training and accountability embed information security into day-to-day operations, not just IT.
Lower long-term costs
Fewer incidents, less rework and faster security reviews reduce the true cost of managing information risk.
Reduce breach & downtime risk
Identifying and treating risks systematically lowers the likelihood and impact of incidents and outages.
Support legal & regulatory alignment
Helps demonstrate good practice that supports obligations under privacy and data-protection laws across NZ, Australia and beyond.
Continual improvement
Built-in monitoring, internal audit and management review keep your security posture improving over time.
Supply-chain confidence
Reassure customers and meet supplier security requirements throughout your supply chain.
The mandatory clauses (Clauses 4–10)
Clauses 4 to 10 are the auditable requirements — every certified organisation must meet them. They define the management system itself.
Context of the organisation
Understand internal and external issues, interested parties and their needs, and define the scope of your ISMS.
Leadership
Top-management commitment, an information security policy, and clearly assigned roles and responsibilities.
Planning
Risk assessment and risk treatment, the Statement of Applicability, and measurable security objectives.
Support
Resources, competence, awareness, communication and control of documented information.
Operation
Putting the plans into action — operational controls and carrying out risk assessment and treatment.
Performance evaluation
Monitoring, measurement, analysis, internal audit and management review of the ISMS.
Improvement
Managing nonconformities, taking corrective action and continually improving the system.
The Annex A controls
Annex A is a catalogue of 93 security controls, reorganised in the 2022 edition into four themes (down from 114 controls in 14 domains, with 11 new controls such as threat intelligence, cloud security and data masking).
A.5 Organisational
Policies, roles, supplier and cloud security, incident management, continuity.
A.6 People
Screening, awareness & training, responsibilities, remote working, reporting.
A.7 Physical
Secure areas, equipment protection, clear desk & screen, secure disposal.
A.8 Technological
Access control, cryptography, logging, secure development, malware protection.
How the clauses and Annex A work together
The mandatory clauses (4–10) build the engine — the processes for running, monitoring and improving information security. Annex A is the toolbox of specific safeguards.
During Clause 6 (Planning) you assess your risks, then select the Annex A controls needed to treat them and record your decisions — and any exclusions, with justification — in your Statement of Applicability (SoA). So the clauses are always mandatory and define how you manage security; the Annex A controls are chosen based on your risks and define what specific protections you put in place. The two are assessed together at certification.
Who needs ISO 27001?
Any organisation that handles sensitive or valuable information — regardless of size or sector. It is especially relevant for SaaS and technology companies, financial and professional services, healthcare, government suppliers, and any business that stores customer data or is asked by clients to prove strong security. Common triggers include winning enterprise contracts, meeting tender or regulatory requirements, moving to the cloud, or responding to a security incident.
How to achieve ISO 27001:2022
Certification follows a well-trodden path. These are the steps organisations typically work through.
Secure leadership commitment & define scope
Get top-management buy-in, assign roles, and decide which parts of the business the ISMS will cover.
Assess your risks
Identify information assets and threats, and evaluate risks to confidentiality, integrity and availability.
Select controls & write your Statement of Applicability
Choose the Annex A controls that treat your risks, and document what applies (and what doesn’t, with reasons).
Implement controls, policies & procedures
Put the selected safeguards in place and create the documentation your ISMS needs.
Train staff & operate the ISMS
Build awareness, run the processes, and generate the records that show the system is working.
Internal audit & management review
Check the ISMS against the standard, fix any gaps, and have management review its performance.
Certification audit (Stage 1 & Stage 2)
An accredited, independent certification body — such as Cianaa — audits your ISMS and, if it conforms, issues your certificate. This is kept separate from implementation to preserve impartiality.
Frequently asked questions
What changed in ISO 27001:2022 vs 2013?
How long does ISO 27001 certification take?
Is ISO 27001 certification mandatory?
How long is an ISO 27001 certificate valid?
Pursuing ISO 27001:2022?
Talk to Cianaa’s independent ISO 27001 lead auditors about certification — conflict-free assessment across New Zealand & Australia.
Explore our ISO 27001 service →