# Key Differences between ISO 27001:2022 and 27001:2013

<table id="bkmrk-annex-a-control-type"><thead><tr><th>Annex A Control Type</th><th>ISO/IEC 27001:2022 Annex A Identifier</th><th>ISO/IEC 27001:2013 Annex A Identifier</th><th>Annex A Name</th></tr></thead><tbody><tr><td>Organisational Controls</td><td>Annex A 5.1</td><td>Annex A 5.1.1 Annex A 5.1.2</td><td>Policies for Information Security</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.2</td><td>Annex A 6.1.1</td><td>Information Security Roles and Responsibilities</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.3</td><td>Annex A 6.1.2</td><td>Segregation of Duties</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.4</td><td>Annex A 7.2.1</td><td>Management Responsibilities</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.5</td><td>Annex A 6.1.3</td><td>Contact With Authorities</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.6</td><td>Annex A 6.1.4</td><td>Contact With Special Interest Groups</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.7</td><td>**NEW**</td><td>Threat Intelligence</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.8</td><td>Annex A 6.1.5 Annex A 14.1.1</td><td>Information Security in Project Management</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.9</td><td>Annex A 8.1.1 Annex A 8.1.2</td><td>Inventory of Information and Other Associated Assets</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.10</td><td>Annex A 8.1.3 Annex A 8.2.3</td><td>Acceptable Use of Information and Other Associated Assets</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.11</td><td>Annex A 8.1.4</td><td>Return of Assets</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.12</td><td>Annex A 8.2.1</td><td>Classification of Information</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.13</td><td>Annex A 8.2.2</td><td>Labelling of Information</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.14</td><td>Annex A 13.2.1 Annex A 13.2.2 Annex A 13.2.3</td><td>Information Transfer</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.15</td><td>Annex A 9.1.1 Annex A 9.1.2</td><td>Access Control</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.16</td><td>Annex A 9.2.1</td><td>Identity Management</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.17</td><td>Annex A 9.2.4 Annex A 9.3.1 Annex A 9.4.3</td><td>Authentication Information</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.18</td><td>Annex A 9.2.2 Annex A 9.2.5 Annex A 9.2.6</td><td>Access Rights</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.19</td><td>Annex A 15.1.1</td><td>Information Security in Supplier Relationships</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.20</td><td>Annex A 15.1.2</td><td>Addressing Information Security Within Supplier Agreements</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.21</td><td>Annex A 15.1.3</td><td>Managing Information Security in the ICT Supply Chain</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.22</td><td>Annex A 15.2.1 Annex A 15.2.2</td><td>Monitoring, Review and Change Management of Supplier Services</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.23</td><td>**NEW**</td><td>Information Security for Use of Cloud Services</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.24</td><td>Annex A 16.1.1</td><td>Information Security Incident Management Planning and Preparation</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.25</td><td>Annex A 16.1.4</td><td>Assessment and Decision on Information Security Events</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.26</td><td>Annex A 16.1.5</td><td>Response to Information Security Incidents</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.27</td><td>Annex A 16.1.6</td><td>Learning From Information Security Incidents</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.28</td><td>Annex A 16.1.7</td><td>Collection of Evidence</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.29</td><td>Annex A 17.1.1 Annex A 17.1.2 Annex A 17.1.3</td><td>Information Security During Disruption</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.30</td><td>**NEW**</td><td>ICT Readiness for Business Continuity</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.31</td><td>Annex A 18.1.1 Annex A 18.1.5</td><td>Legal, Statutory, Regulatory and Contractual Requirements</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.32</td><td>Annex A 18.1.2</td><td>Intellectual Property Rights</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.33</td><td>Annex A 18.1.3</td><td>Protection of Records</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.34</td><td>Annex A 18.1.4</td><td>Privacy and Protection of PII</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.35</td><td>Annex A 18.2.1</td><td>Independent Review of Information Security</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.36</td><td>Annex A 18.2.2 Annex A 18.2.3</td><td>Compliance With Policies, Rules and Standards for Information Security</td></tr><tr><td>Organisational Controls</td><td>Annex A 5.37</td><td>Annex A 12.1.1</td><td>Documented Operating Procedures</td></tr><tr><td>People Controls</td><td>Annex A 6.1</td><td>Annex A 7.1.1</td><td>Screening</td></tr><tr><td>People Controls</td><td>Annex A 6.2</td><td>Annex A 7.1.2</td><td>Terms and Conditions of Employment</td></tr><tr><td>People Controls</td><td>Annex A 6.3</td><td>Annex A 7.2.2</td><td>Information Security Awareness, Education and Training</td></tr><tr><td>People Controls</td><td>Annex A 6.4</td><td>Annex A 7.2.3</td><td>Disciplinary Process</td></tr><tr><td>People Controls</td><td>Annex A 6.5</td><td>Annex A 7.3.1</td><td>Responsibilities After Termination or Change of Employment</td></tr><tr><td>People Controls</td><td>Annex A 6.6</td><td>Annex A 13.2.4</td><td>Confidentiality or Non-Disclosure Agreements</td></tr><tr><td>People Controls</td><td>Annex A 6.7</td><td>Annex A 6.2.2</td><td>Remote Working</td></tr><tr><td>People Controls</td><td>Annex A 6.8</td><td>Annex A 16.1.2 Annex A 16.1.3</td><td>Information Security Event Reporting</td></tr><tr><td>Physical Controls</td><td>Annex A 7.1</td><td>Annex A 11.1.1</td><td>Physical Security Perimeters</td></tr><tr><td>Physical Controls</td><td>Annex A 7.2</td><td>Annex A 11.1.2 Annex A 11.1.6</td><td>Physical Entry</td></tr><tr><td>Physical Controls</td><td>Annex A 7.3</td><td>Annex A 11.1.3</td><td>Securing Offices, Rooms and Facilities</td></tr><tr><td>Physical Controls</td><td>Annex A 7.4</td><td>**NEW**</td><td>Physical Security Monitoring</td></tr><tr><td>Physical Controls</td><td>Annex A 7.5</td><td>Annex A 11.1.4</td><td>Protecting Against Physical and Environmental Threats</td></tr><tr><td>Physical Controls</td><td>Annex A 7.6</td><td>Annex A 11.1.5</td><td>Working In Secure Areas</td></tr><tr><td>Physical Controls</td><td>Annex A 7.7</td><td>Annex A 11.2.9</td><td>Clear Desk and Clear Screen</td></tr><tr><td>Physical Controls</td><td>Annex A 7.8</td><td>Annex A 11.2.1</td><td>Equipment Siting and Protection</td></tr><tr><td>Physical Controls</td><td>Annex A 7.9</td><td>Annex A 11.2.6</td><td>Security of Assets Off-Premises</td></tr><tr><td>Physical Controls</td><td>Annex A 7.10</td><td>Annex A 8.3.1 Annex A 8.3.2 Annex A 8.3.3 Annex A 11.2.5</td><td>Storage Media</td></tr><tr><td>Physical Controls</td><td>Annex A 7.11</td><td>Annex A 11.2.2</td><td>Supporting Utilities</td></tr><tr><td>Physical Controls</td><td>Annex A 7.12</td><td>Annex A 11.2.3</td><td>Cabling Security</td></tr><tr><td>Physical Controls</td><td>Annex A 7.13</td><td>Annex A 11.2.4</td><td>Equipment Maintenance</td></tr><tr><td>Physical Controls</td><td>Annex A 7.14</td><td>Annex A 11.2.7</td><td>Secure Disposal or Re-Use of Equipment</td></tr><tr><td>Technological Controls</td><td>Annex A 8.1</td><td>Annex A 6.2.1 Annex A 11.2.8</td><td>User Endpoint Devices</td></tr><tr><td>Technological Controls</td><td>Annex A 8.2</td><td>Annex A 9.2.3</td><td>Privileged Access Rights</td></tr><tr><td>Technological Controls</td><td>Annex A 8.3</td><td>Annex A 9.4.1</td><td>Information Access Restriction</td></tr><tr><td>Technological Controls</td><td>Annex A 8.4</td><td>Annex A 9.4.5</td><td>Access to Source Code</td></tr><tr><td>Technological Controls</td><td>Annex A 8.5</td><td>Annex A 9.4.2</td><td>Secure Authentication</td></tr><tr><td>Technological Controls</td><td>Annex A 8.6</td><td>Annex A 12.1.3</td><td>Capacity Management</td></tr><tr><td>Technological Controls</td><td>Annex A 8.7</td><td>Annex A 12.2.1</td><td>Protection Against Malware</td></tr><tr><td>Technological Controls</td><td>Annex A 8.8</td><td>Annex A 12.6.1 Annex A 18.2.3</td><td>Management of Technical Vulnerabilities</td></tr><tr><td>Technological Controls</td><td>Annex A 8.9</td><td>NEW</td><td>Configuration Management</td></tr><tr><td>Technological Controls</td><td>Annex A 8.10</td><td>NEW</td><td>Information Deletion</td></tr><tr><td>Technological Controls</td><td>Annex A 8.11</td><td>NEW</td><td>Data Masking</td></tr><tr><td>Technological Controls</td><td>Annex A 8.12</td><td>NEW</td><td>Data Leakage Prevention</td></tr><tr><td>Technological Controls</td><td>Annex A 8.13</td><td>Annex A 12.3.1</td><td>Information Backup</td></tr><tr><td>Technological Controls</td><td>Annex A 8.14</td><td>Annex A 17.2.1</td><td>Redundancy of Information Processing Facilities</td></tr><tr><td>Technological Controls</td><td>Annex A 8.15</td><td>Annex A 12.4.1 Annex A 12.4.2 Annex A 12.4.3</td><td>Logging</td></tr><tr><td>Technological Controls</td><td>Annex A 8.16</td><td>**NEW**</td><td>Monitoring Activities</td></tr><tr><td>Technological Controls</td><td>Annex A 8.17</td><td>Annex A 12.4.4</td><td>Clock Synchronization</td></tr><tr><td>Technological Controls</td><td>Annex A 8.18</td><td>Annex A 9.4.4</td><td>Use of Privileged Utility Programs</td></tr><tr><td>Technological Controls</td><td>Annex A 8.19</td><td>Annex A 12.5.1 Annex A 12.6.2</td><td>Installation of Software on Operational Systems</td></tr><tr><td>Technological Controls</td><td>Annex A 8.20</td><td>Annex A 13.1.1</td><td>Networks Security</td></tr><tr><td>Technological Controls</td><td>Annex A 8.21</td><td>Annex A 13.1.2</td><td>Security of Network Services</td></tr><tr><td>Technological Controls</td><td>Annex A 8.22</td><td>Annex A 13.1.3</td><td>Segregation of Networks</td></tr><tr><td>Technological Controls</td><td>Annex A 8.23</td><td>**NEW**</td><td>Web filtering</td></tr><tr><td>Technological Controls</td><td>Annex A 8.24</td><td>Annex A 10.1.1 Annex A 10.1.2</td><td>Use of Cryptography</td></tr><tr><td>Technological Controls</td><td>Annex A 8.25</td><td>Annex A 14.2.1</td><td>Secure Development Life Cycle</td></tr><tr><td>Technological Controls</td><td>Annex A 8.26</td><td>Annex A 14.1.2 Annex A 14.1.3</td><td>Application Security Requirements</td></tr><tr><td>Technological Controls</td><td>Annex A 8.27</td><td>Annex A 14.2.5</td><td>Secure System Architecture and Engineering Principles</td></tr><tr><td>Technological Controls</td><td>Annex A 8.28</td><td>**NEW**</td><td>Secure Coding</td></tr><tr><td>Technological Controls</td><td>Annex A 8.29</td><td>Annex A 14.2.8 Annex A 14.2.9</td><td>Security Testing in Development and Acceptance</td></tr><tr><td>Technological Controls</td><td>Annex A 8.30</td><td>Annex A 14.2.7</td><td>Outsourced Development</td></tr><tr><td>Technological Controls</td><td>Annex A 8.31</td><td>Annex A 12.1.4 Annex A 14.2.6</td><td>Separation of Development, Test and Production Environments</td></tr><tr><td>Technological Controls</td><td>Annex A 8.32</td><td>Annex A 12.1.2 Annex A 14.2.2 Annex A 14.2.3 Annex A 14.2.4</td><td>Change Management</td></tr><tr><td>Technological Controls</td><td>Annex A 8.33</td><td>Annex A 14.3.1</td><td>Test Information</td></tr><tr><td>Technological Controls</td><td>Annex A 8.34</td><td>Annex A 12.7.1</td><td>Protection of Information Systems During Audit Testing</td></tr></tbody></table>