Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements
Specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, including a risk-based process for selecting controls. Jointly published by ISO and IEC and certifiable by accredited bodies.
Always verify against the current published text before relying on it for a submission or inspection.
Scope & applicability
Any organisation, of any size or sector. In regulated life sciences it is the recognised management-system framework for information security, and the one most often required contractually of suppliers, CROs, CDMOs and software vendors. It governs the security of information — not the integrity of GxP records specifically, which remains a quality-system obligation under Annex 11, Part 11 and the data-integrity guidance.
Key requirements
- Defined ISMS scope, context, interested parties and leadership commitment
- Information security risk assessment and risk treatment with a Statement of Applicability
- Annex A control set selected and justified against assessed risk, not adopted wholesale
- Competence, awareness and documented information proportionate to risk
- Internal audit, management review, nonconformity handling and continual improvement
- Amendment 1:2024 adds climate-action considerations to context and interested parties
Implementation tips
- Certification covers the declared scope only — read a supplier certificate for what it excludes before relying on it.
- The Statement of Applicability is the useful artefact in a supplier assessment; the certificate alone says little.
- ISO/IEC 27001 does not discharge GxP data-integrity obligations. Map its controls onto Annex 11 and Part 11 expectations rather than substituting one for the other.
Revision notes
The 2022 edition restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes and introduced attributes for control selection. Amendment 1:2024 adds climate-action changes.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
ISO/IEC 27001:2022: frequently asked questions
Quick answers to common questions about ISO/IEC 27001:2022.
What is ISO/IEC 27001:2022?
ISO/IEC 27001:2022 — Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements — is a standard issued by the International Organization for Standardization. Specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system, including a risk-based process for selecting controls. Jointly published by ISO and IEC and certifiable by accredited bodies.
Who does ISO/IEC 27001:2022 apply to?
Any organisation, of any size or sector. In regulated life sciences it is the recognised management-system framework for information security, and the one most often required contractually of suppliers, CROs, CDMOs and software vendors. It governs the security of information — not the integrity of GxP records specifically, which remains a quality-system obligation under Annex 11, Part 11 and the data-integrity guidance.
What are the key requirements of ISO/IEC 27001:2022?
ISO/IEC 27001:2022 requires, among other things: Defined ISMS scope, context, interested parties and leadership commitment; Information security risk assessment and risk treatment with a Statement of Applicability; Annex A control set selected and justified against assessed risk, not adopted wholesale; Competence, awareness and documented information proportionate to risk.
When was ISO/IEC 27001:2022 last updated?
The current version of ISO/IEC 27001:2022 dates from October 2022. The 2022 edition restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes and introduced attributes for control selection. Amendment 1:2024 adds climate-action changes.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.