ISOQuality Systems MaturityStandard
ISO/IEC 27001:2022

Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements

Specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, including a risk-based process for selecting controls. Jointly published by ISO and IEC and certifiable by accredited bodies.

LAST REVISED
October 2022
PRODUCT AREAS
SterileSolid DoseBiotechApiDevicesClinicalDistribution
SOURCE & PROVENANCE
ISSUING BODY
International Organization for Standardization
JURISDICTION
International
DOCUMENT ID
ISO/IEC 27001:2022
Official site — International Organization for Standardization

Always verify against the current published text before relying on it for a submission or inspection.

Scope & applicability

Any organisation, of any size or sector. In regulated life sciences it is the recognised management-system framework for information security, and the one most often required contractually of suppliers, CROs, CDMOs and software vendors. It governs the security of information — not the integrity of GxP records specifically, which remains a quality-system obligation under Annex 11, Part 11 and the data-integrity guidance.

Key requirements

  • Defined ISMS scope, context, interested parties and leadership commitment
  • Information security risk assessment and risk treatment with a Statement of Applicability
  • Annex A control set selected and justified against assessed risk, not adopted wholesale
  • Competence, awareness and documented information proportionate to risk
  • Internal audit, management review, nonconformity handling and continual improvement
  • Amendment 1:2024 adds climate-action considerations to context and interested parties

Implementation tips

  • Certification covers the declared scope only — read a supplier certificate for what it excludes before relying on it.
  • The Statement of Applicability is the useful artefact in a supplier assessment; the certificate alone says little.
  • ISO/IEC 27001 does not discharge GxP data-integrity obligations. Map its controls onto Annex 11 and Part 11 expectations rather than substituting one for the other.

Revision notes

The 2022 edition restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes and introduced attributes for control selection. Amendment 1:2024 adds climate-action changes.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

ISO/IEC 27001:2022: frequently asked questions

Quick answers to common questions about ISO/IEC 27001:2022.

What is ISO/IEC 27001:2022?

ISO/IEC 27001:2022 — Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements — is a standard issued by the International Organization for Standardization. Specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, including a risk-based process for selecting controls. Jointly published by ISO and IEC and certifiable by accredited bodies.

Who does ISO/IEC 27001:2022 apply to?

Any organisation, of any size or sector. In regulated life sciences it is the recognised management-system framework for information security, and the one most often required contractually of suppliers, CROs, CDMOs and software vendors. It governs the security of information — not the integrity of GxP records specifically, which remains a quality-system obligation under Annex 11, Part 11 and the data-integrity guidance.

What are the key requirements of ISO/IEC 27001:2022?

ISO/IEC 27001:2022 requires, among other things: Defined ISMS scope, context, interested parties and leadership commitment; Information security risk assessment and risk treatment with a Statement of Applicability; Annex A control set selected and justified against assessed risk, not adopted wholesale; Competence, awareness and documented information proportionate to risk.

When was ISO/IEC 27001:2022 last updated?

The current version of ISO/IEC 27001:2022 dates from October 2022. The 2022 edition restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes and introduced attributes for control selection. Amendment 1:2024 adds climate-action changes.