On February 15, 2022, a revision of the ISO/IEC 27002 standard is published and available to all.

You can get it here:
https://www.iso.org/standard/75652.html
This is really good news, as the standard really needed a refresh and modernization.
Here’s a reminder of the changes
- Number of safety measures.
- Theme reorganization
- Adding tag properties to controls
- Closer ties with NIST CSF
- The 11 new safety measures
1.number of inspections
Number of safety measures reduced from 114 à 93. Those that remain are much more detailed than in the previous version, i.e. with better explanations and more depth to better understand the objectives of the security measures.
35 safety measures unchanged
23 safety measures have changed a little, apart from the name or definition, simply to make them simpler and more consistent.
11 new safety measures
57 safety measures have been merged into 24 new safety measures.
2. Theme reorganization
Safety measures, which were grouped into 14 themes, have been reduced to just 4:
- Organizational measures
- Personal measurements
- Physical measurements
- Technical / technological measures
3. Adding properties(Tag) to controls
Each safety measure now has its own property in the form of:
- 3 types of control: #Preventive, #Detective, #Corrective
- 3 Security criteria: #Confidentiality, #Integrity, #Availability
- 5 Cybersecurity concepts: #Identify, #Protect, #Detect, #Respond, #Recover
- 15 Operational capabilities : #Governance, #Asset_management, #Information_protection, #Human_resource_security, #Physical_security, #System_and_network_security, #Application_security, #Secure_configuration, #Identity_and_access_management, #Threat_and_vulnerability_ management, #Continuity, #Supplier_relationships_security, #Legal_and_compliance, #Information_security_event_management, #Information_security_assurance
- 4 Safety Domains: #Governance_and_Ecosystem, #Protection, #Defence, #Resilience
4. Reconciliation with the NIST CSF standard
You can understand that with these #tags, it’s possible to group together security measures and no longer duplicate information from one control to another.
What’s more, this move towards the NIST CyberSecurity Framework opens up the standard to other standards available today.
5. What are the 11 new safety measures?
5.7 Threat intelligence5.23 Information security for use of cloud services5.30 ICT readiness for business continuity7.4 Physical security monitoring8.9 Configuration management8.10 Information deletion8.11 Data masking8.12 Data leakage prevention8.16 Monitoring activities8.23 Web Filtering8.28 Secure coding
If you already have ISO27001 certification, you should start updating your information security management system (ISMS), as the next re-certification cycle will require you to comply with the new standard.
So the next steps are :
- Review the applicability statement
- Perform risk analysis to include new safety measures and adjust them.
- Review policies and directives to add new safety measures.