ISO 27001:2022 updated the management-system clauses modestly and restructured Annex A controls (now aligned with ISO 27002:2022). Organizations certified to 2013 have a transition window they cannot ignore.
The work is not renaming controls. It is confirming that the Statement of Applicability still matches the risk assessment, and that new or re-grouped controls (threat intelligence, cloud, data masking, secure coding, ICT readiness) are evidenced if they apply.
WCH implements 2022 ISMS programs and audits both 2013 and 2022. We also add ISO 27701 when privacy is in the customer contract.
Integrated with ISO 9001, the ISMS shares leadership, internal audit, and management review so information security does not become a second bureaucracy in IT.
