Latest alerts
  1. Home
  2. Insights
  3. Compliance
// compliance · 6 min read

ISO 27001:2022 in practice: the 93 controls without the jargon

Four themes, eleven new controls and what auditors actually look for. Lessons from moving an ISMS from 114 to 93 controls.

Published 21 May 2026 · Dravincon Security Team

ISO/IEC 27001:2022 replaced the 2013 edition, and the transition period for existing certificates ended on 31 October 2025. Annex A was reorganised from 114 controls in 14 domains into 93 controls in four themes.

The four themes

  • Organisational (37): policies, roles, supplier relationships, incident management, compliance.
  • People (8): screening, awareness, remote working, reporting events.
  • Physical (14): perimeters, equipment, clear desk, secure disposal.
  • Technological (34): access, cryptography, logging, secure development, backups.

The 11 new controls

Threat intelligence · Information security for cloud services · ICT readiness for business continuity · Physical security monitoring · Configuration management · Information deletion · Data masking · Data leakage prevention · Monitoring activities · Web filtering · Secure coding.

What auditors look for

  1. Evidence over documents. A beautiful policy without access-review records is a finding.
  2. A living risk assessment. Risks that reflect your business, owners who know they own them.
  3. A justified Statement of Applicability. Every excluded control needs a reason.
  4. Management involvement. Management reviews with real decisions, minuted.

We have taken organisations — including a global data-centre provider — through this exact transition. See how we work.

// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check