ISO 27001:2022
What is ISO 27001:2022?
International standard for establishing, implementing, maintaining and continually improving an information security management system (ISMS). It comprises 93 controls organised across 6 domains, published by ISO/IEC, and applies in International.
How ISO 27001:2022 maps to other frameworks
All 93 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 6 domains ISO 27001:2022 groups its controls into
Frameworks that share controls with ISO 27001:2022
Each of these has at least one control mapped to a control in ISO 27001:2022. The number is how many ISO 27001:2022 controls are shared, counted from the mapping graph.
Where ISO 27001:2022 overlaps with the standards you already hold
Implementation guides for frameworks that overlap ISO 27001:2022
Step-by-step implementation of ISO 27001:2022
More ISO 27001:2022 comparisons
Analysis of ISO 27001:2022
Training that covers ISO 27001:2022
Where to get trained on ISO 27001:2022
4 courses in the catalogue cover ISO 27001:2022 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What ISO 27001:2022 means in your sector
What ISO 27001:2022 means for your job
Questions people ask about ISO 27001:2022
What is ISO 27001:2022?
How many controls does ISO 27001:2022 have?
Where does ISO 27001:2022 apply?
What frameworks does ISO 27001:2022 map to?
How do I get started with ISO 27001:2022 compliance?
Query ISO 27001:2022 programmatically
ISO 27001:2022, its 93 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO 27001:2022 API reference and MCP config →What ISO 27001:2022 requires, control by control
Each page carries the requirement text for one ISO 27001:2022 control and what an assessor expects to see as evidence.
- 5-1 Policies for information security
- 5-10 Acceptable use of information and other associated assets
- 5-12 Classification of information
- 5-13 Labelling of information
- 5-14 Information transfer
- 5-15 Access control
- 5-17 Authentication information
- 5-18 Access rights
- 5-19 Information security in supplier relationships
- 5-2 Information security roles and responsibilities
How much of another standard ISO 27001:2022 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to ISO 27001:2022 crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to ISO 27001:2022 crosswalk
- APRA CPS 230 Operational Risk Management to ISO 27001:2022 crosswalk
- APRA CPS 234 to ISO 27001:2022 crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to ISO 27001:2022 crosswalk
- Australia Consumer Data Right - Banking (CDR) to ISO 27001:2022 crosswalk
- Australia My Health Records Act 2012 to ISO 27001:2022 crosswalk
- AWS Well-Architected Security Pillar to ISO 27001:2022 crosswalk
How ready are you for ISO 27001:2022?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.