# ISO 27001 Control Mapping: 2013 ↔ 2022

This file provides cross-reference mapping between ISO 27001:2013 (114 controls) and ISO 27001:2022 (93 controls).

## Summary of Changes
- Controls reduced from **114 → 93**
- Domains reduced from **14 → 4 themes**
- **11 new controls** added (marked ⭐)
- **Merged**: Many 2013 controls were consolidated into single 2022 controls
- **Renamed**: Several controls were renamed for clarity
- **Deleted**: No controls were fully removed — all 2013 concepts are still covered

---

## 2022 → 2013 Mapping

### A.5 Organisational Controls (2022) → 2013 Equivalents

| 2022 Control | 2022 Name | 2013 Equivalent(s) |
|-------------|-----------|-------------------|
| A.5.1 | Policies for information security | A.5.1.1, A.5.1.2 |
| A.5.2 | IS roles and responsibilities | A.6.1.1 |
| A.5.3 | Segregation of duties | A.6.1.2 |
| A.5.4 | Management responsibilities | A.7.2.1 |
| A.5.5 | Contact with authorities | A.6.1.3 |
| A.5.6 | Contact with special interest groups | A.6.1.4 |
| A.5.7 | Threat intelligence | ⭐ NEW |
| A.5.8 | IS in project management | A.6.1.5 |
| A.5.9 | Inventory of information and assets | A.8.1.1, A.8.1.2 |
| A.5.10 | Acceptable use of information and assets | A.8.1.3 |
| A.5.11 | Return of assets | A.8.1.4 |
| A.5.12 | Classification of information | A.8.2.1 |
| A.5.13 | Labelling of information | A.8.2.2 |
| A.5.14 | Information transfer | A.13.2.1, A.13.2.2, A.13.2.3 |
| A.5.15 | Access control | A.9.1.1, A.9.1.2 |
| A.5.16 | Identity management | A.9.2.1 |
| A.5.17 | Authentication information | A.9.2.4, A.9.3.1, A.9.4.3 |
| A.5.18 | Access rights | A.9.2.2, A.9.2.5, A.9.2.6 |
| A.5.19 | IS in supplier relationships | A.15.1.1 |
| A.5.20 | IS within supplier agreements | A.15.1.2 |
| A.5.21 | Managing IS in the ICT supply chain | A.15.1.3 |
| A.5.22 | Monitoring/review of supplier services | A.15.2.1, A.15.2.2 |
| A.5.23 | IS for use of cloud services | ⭐ NEW |
| A.5.24 | IS incident management planning | A.16.1.1 |
| A.5.25 | Assessment of IS events | A.16.1.4 |
| A.5.26 | Response to IS incidents | A.16.1.5 |
| A.5.27 | Learning from IS incidents | A.16.1.6 |
| A.5.28 | Collection of evidence | A.16.1.7 |
| A.5.29 | IS during disruption | A.17.1.1, A.17.1.2 |
| A.5.30 | ICT readiness for business continuity | ⭐ NEW |
| A.5.31 | Legal, statutory, regulatory requirements | A.18.1.1 |
| A.5.32 | Intellectual property rights | A.18.1.2 |
| A.5.33 | Protection of records | A.18.1.3 |
| A.5.34 | Privacy and protection of PII | A.18.1.4 |
| A.5.35 | Independent review of IS | A.18.2.1 |
| A.5.36 | Compliance with policies, rules, standards | A.18.2.2, A.18.2.3 |
| A.5.37 | Documented operating procedures | A.12.1.1 |

### A.6 People Controls (2022) → 2013 Equivalents

| 2022 Control | 2022 Name | 2013 Equivalent(s) |
|-------------|-----------|-------------------|
| A.6.1 | Screening | A.7.1.1 |
| A.6.2 | Terms and conditions of employment | A.7.1.2 |
| A.6.3 | IS awareness, education and training | A.7.2.2 |
| A.6.4 | Disciplinary process | A.7.2.3 |
| A.6.5 | Responsibilities after termination | A.7.3.1 |
| A.6.6 | Confidentiality or NDA agreements | A.13.2.4 |
| A.6.7 | Remote working | A.6.2.2 |
| A.6.8 | IS event reporting | A.16.1.2, A.16.1.3 |

### A.7 Physical Controls (2022) → 2013 Equivalents

| 2022 Control | 2022 Name | 2013 Equivalent(s) |
|-------------|-----------|-------------------|
| A.7.1 | Physical security perimeters | A.11.1.1 |
| A.7.2 | Physical entry | A.11.1.2, A.11.1.6 |
| A.7.3 | Securing offices, rooms and facilities | A.11.1.3 |
| A.7.4 | Physical security monitoring | ⭐ NEW |
| A.7.5 | Protecting against physical/environmental threats | A.11.1.4 |
| A.7.6 | Working in secure areas | A.11.1.5 |
| A.7.7 | Clear desk and clear screen | A.11.2.9 |
| A.7.8 | Equipment siting and protection | A.11.2.1 |
| A.7.9 | Security of assets off-premises | A.11.2.6 |
| A.7.10 | Storage media | A.8.3.1, A.8.3.2, A.8.3.3, A.11.2.5 |
| A.7.11 | Supporting utilities | A.11.2.2 |
| A.7.12 | Cabling security | A.11.2.3 |
| A.7.13 | Equipment maintenance | A.11.2.4 |
| A.7.14 | Secure disposal or re-use of equipment | A.11.2.7 |

### A.8 Technological Controls (2022) → 2013 Equivalents

| 2022 Control | 2022 Name | 2013 Equivalent(s) |
|-------------|-----------|-------------------|
| A.8.1 | User end point devices | A.6.2.1, A.11.2.8 |
| A.8.2 | Privileged access rights | A.9.2.3 |
| A.8.3 | Information access restriction | A.9.4.1 |
| A.8.4 | Access to source code | A.9.4.5 |
| A.8.5 | Secure authentication | A.9.4.2 |
| A.8.6 | Capacity management | A.12.1.3 |
| A.8.7 | Protection against malware | A.12.2.1 |
| A.8.8 | Management of technical vulnerabilities | A.12.6.1, A.12.6.2 |
| A.8.9 | Configuration management | ⭐ NEW |
| A.8.10 | Information deletion | ⭐ NEW |
| A.8.11 | Data masking | ⭐ NEW |
| A.8.12 | Data leakage prevention | ⭐ NEW |
| A.8.13 | Information backup | A.12.3.1 |
| A.8.14 | Redundancy of information processing facilities | A.17.2.1 |
| A.8.15 | Logging | A.12.4.1, A.12.4.2, A.12.4.3 |
| A.8.16 | Monitoring activities | ⭐ NEW |
| A.8.17 | Clock synchronisation | A.12.4.4 |
| A.8.18 | Use of privileged utility programs | A.9.4.4 |
| A.8.19 | Installation of software on operational systems | A.12.5.1 |
| A.8.20 | Networks security | A.13.1.1 |
| A.8.21 | Security of network services | A.13.1.2 |
| A.8.22 | Segregation of networks | A.13.1.3 |
| A.8.23 | Web filtering | ⭐ NEW |
| A.8.24 | Use of cryptography | A.10.1.1, A.10.1.2, A.18.1.5 |
| A.8.25 | Secure development life cycle | A.14.2.1 |
| A.8.26 | Application security requirements | A.14.1.1, A.14.1.2, A.14.1.3 |
| A.8.27 | Secure system architecture and engineering principles | A.14.2.5 |
| A.8.28 | Secure coding | ⭐ NEW |
| A.8.29 | Security testing in development and acceptance | A.14.2.8, A.14.2.9 |
| A.8.30 | Outsourced development | A.14.2.7 |
| A.8.31 | Separation of dev, test and production environments | A.12.1.4, A.14.2.6 |
| A.8.32 | Change management | A.12.1.2, A.14.2.2, A.14.2.3, A.14.2.4 |
| A.8.33 | Test information | A.14.3.1 |
| A.8.34 | Protection of IS during audit testing | A.12.7.1 |

---

## Controls Only in 2013 (removed/merged in 2022)
No controls were deleted outright. All were merged:
- A.8.2.3 (Handling of assets) → merged into A.5.10 (Acceptable use)
- A.16.1.3 (Reporting weaknesses) → merged into A.6.8 (IS event reporting)
- A.17.1.3 (Verify IS continuity) → merged into A.5.29

---

## 11 New Controls in 2022 (not in 2013)
| 2022 ID | Name |
|---------|------|
| A.5.7 | Threat intelligence |
| A.5.23 | Information security for use of cloud services |
| A.5.30 | ICT readiness for business continuity |
| A.7.4 | Physical security monitoring |
| A.8.9 | Configuration management |
| A.8.10 | Information deletion |
| A.8.11 | Data masking |
| A.8.12 | Data leakage prevention |
| A.8.16 | Monitoring activities |
| A.8.23 | Web filtering |
| A.8.28 | Secure coding |
