Back to blogFrameworks & Standards

ISO 27001:2022 — Implement Your ISMS Step by Step

Aranis· Plataforma de inteligência de risco
July 6, 20267 min read

ISO/IEC 27001 is the most widely adopted international standard for information security management. The 2022 update modernized the Annex A control structure, reducing it from 114 to 93 controls, now organized into 4 themes: Organizational, People, Physical, and Technological.

What actually changed

11 brand-new controls were added — threat intelligence, cloud security, ICT readiness for business continuity, monitoring activities, among others — 24 controls were consolidated, and 58 were updated. New control attributes (tags) for control type, security concept, and operational capability make filtering and cross-mapping to other frameworks easier.

The 7 steps to implementing an ISMS

Define the scope (not too broad, not so narrow it creates gaps); analyze context (stakeholders, legal requirements like LGPD or GDPR); assess risk with a documented, repeatable methodology; build the treatment plan and Statement of Applicability (SoA); implement controls with documented evidence; monitor with KPIs and internal audits; and close the PDCA cycle with continuous improvement.

Certification: two stages, not a single event

Stage 1 assesses whether the ISMS documentation is ready for the field audit; Stage 2 verifies on-site that the controls work as documented. After certification, expect annual surveillance audits and a full recertification every 3 years — certification is an ongoing management style, not a project with an end date.

Where ISO 27001 connects to the rest of your program

Annex A controls rarely stand alone: they overlap significantly with NIST CSF, CIS Controls, and specific TPRM and privacy requirements. That's why, in Aranis's control catalog, every ISO 27001 control ships with documented applicability and a crosswalk to the other frameworks your company likely also needs to meet — instead of treating each certification as an isolated project.

ISO 27001 isn't a project with an end date — it's an ongoing risk management process that evolves alongside the business and the threat landscape.

ISO 27001ISMScertificationframeworks