Guide · Information Security

Introduction to ISO 27001:2022

A plain-English guide to the world’s leading information security standard — what it is, its key benefits, the mandatory clauses, the Annex A controls, who needs it, and how organisations achieve certification.

4–10Mandatory clauses
93Annex A controls
4Control themes
3-yrCertification cycle

What is ISO/IEC 27001:2022?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a risk-based framework for protecting the confidentiality, integrity and availability of information. The 2022 edition (published October 2022, replacing ISO 27001:2013) modernises the standard’s security controls. It is the only ISMS standard against which an organisation can be independently certified, giving customers and regulators assurance that information is managed to a recognised global benchmark.

ISO/IEC 27001:2022

Key benefits of ISO 27001:2022

An information-security standard trusted worldwide.
01

Globally recognised

An internationally recognised certification that supports overseas clients, partners and cross-border business.

02

Protect critical information

A structured, risk-based way to safeguard customer, employee and business data against loss, misuse and unauthorised access.

03

Win trust & tenders

Certification is increasingly required in contracts and vendor reviews — it opens doors and shortens security questionnaires.

04

Build a security culture

Clear roles, training and accountability embed information security into day-to-day operations, not just IT.

05

Lower long-term costs

Fewer incidents, less rework and faster security reviews reduce the true cost of managing information risk.

06

Reduce breach & downtime risk

Identifying and treating risks systematically lowers the likelihood and impact of incidents and outages.

07

Support legal & regulatory alignment

Helps demonstrate good practice that supports obligations under privacy and data-protection laws across NZ, Australia and beyond.

08

Continual improvement

Built-in monitoring, internal audit and management review keep your security posture improving over time.

09

Supply-chain confidence

Reassure customers and meet supplier security requirements throughout your supply chain.

The mandatory clauses (Clauses 4–10)

Clauses 4 to 10 are the auditable requirements — every certified organisation must meet them. They define the management system itself.

Clause 4

Context of the organisation

Understand internal and external issues, interested parties and their needs, and define the scope of your ISMS.

Clause 5

Leadership

Top-management commitment, an information security policy, and clearly assigned roles and responsibilities.

Clause 6

Planning

Risk assessment and risk treatment, the Statement of Applicability, and measurable security objectives.

Clause 7

Support

Resources, competence, awareness, communication and control of documented information.

Clause 8

Operation

Putting the plans into action — operational controls and carrying out risk assessment and treatment.

Clause 9

Performance evaluation

Monitoring, measurement, analysis, internal audit and management review of the ISMS.

Clause 10

Improvement

Managing nonconformities, taking corrective action and continually improving the system.

The Annex A controls

Annex A is a catalogue of 93 security controls, reorganised in the 2022 edition into four themes (down from 114 controls in 14 domains, with 11 new controls such as threat intelligence, cloud security and data masking).

37

A.5 Organisational

Policies, roles, supplier and cloud security, incident management, continuity.

8

A.6 People

Screening, awareness & training, responsibilities, remote working, reporting.

14

A.7 Physical

Secure areas, equipment protection, clear desk & screen, secure disposal.

34

A.8 Technological

Access control, cryptography, logging, secure development, malware protection.

How the clauses and Annex A work together

The mandatory clauses (4–10) build the engine — the processes for running, monitoring and improving information security. Annex A is the toolbox of specific safeguards.

During Clause 6 (Planning) you assess your risks, then select the Annex A controls needed to treat them and record your decisions — and any exclusions, with justification — in your Statement of Applicability (SoA). So the clauses are always mandatory and define how you manage security; the Annex A controls are chosen based on your risks and define what specific protections you put in place. The two are assessed together at certification.

Who needs ISO 27001?

Any organisation that handles sensitive or valuable information — regardless of size or sector. It is especially relevant for SaaS and technology companies, financial and professional services, healthcare, government suppliers, and any business that stores customer data or is asked by clients to prove strong security. Common triggers include winning enterprise contracts, meeting tender or regulatory requirements, moving to the cloud, or responding to a security incident.

How to achieve ISO 27001:2022

Certification follows a well-trodden path. These are the steps organisations typically work through.

Secure leadership commitment & define scope

Get top-management buy-in, assign roles, and decide which parts of the business the ISMS will cover.

Assess your risks

Identify information assets and threats, and evaluate risks to confidentiality, integrity and availability.

Select controls & write your Statement of Applicability

Choose the Annex A controls that treat your risks, and document what applies (and what doesn’t, with reasons).

Implement controls, policies & procedures

Put the selected safeguards in place and create the documentation your ISMS needs.

Train staff & operate the ISMS

Build awareness, run the processes, and generate the records that show the system is working.

Internal audit & management review

Check the ISMS against the standard, fix any gaps, and have management review its performance.

Certification audit (Stage 1 & Stage 2)

An accredited, independent certification body — such as Cianaa — audits your ISMS and, if it conforms, issues your certificate. This is kept separate from implementation to preserve impartiality.

Frequently asked questions

What changed in ISO 27001:2022 vs 2013?
The management clauses (4–10) are largely unchanged. The big change is Annex A: controls were reorganised into four themes and reduced from 114 to 93, with 11 new controls covering areas like threat intelligence, cloud services, data masking and secure coding.
How long does ISO 27001 certification take?
It depends on your size, complexity and starting maturity — commonly a few months to build and operate the ISMS before the certification audit. An accredited certification body can give you a realistic timeline once your scope is known.
Is ISO 27001 certification mandatory?
It’s voluntary, but it is frequently required by customers, tenders and regulators as evidence of strong information security — so in practice many organisations treat it as essential.
How long is an ISO 27001 certificate valid?
Certification runs on a three-year cycle: an initial certification audit, then annual surveillance audits, and recertification at the end of the cycle.

Pursuing ISO 27001:2022?

Talk to Cianaa’s independent ISO 27001 lead auditors about certification — conflict-free assessment across New Zealand & Australia.

Explore our ISO 27001 service →