{"id":2887,"date":"2025-04-29T07:44:46","date_gmt":"2025-04-29T07:44:46","guid":{"rendered":"https:\/\/www.overtsoftware.id\/?p=2887"},"modified":"2025-04-29T07:44:49","modified_gmt":"2025-04-29T07:44:49","slug":"iso-270012022-vs-2013-whats-new-and-why-it-matters","status":"publish","type":"post","link":"https:\/\/www.overtsoftware.id\/index.php\/iso-270012022-vs-2013-whats-new-and-why-it-matters\/","title":{"rendered":"ISO 27001:2022 VS 2013 \u2013 WHAT\u2019S NEW AND WHY IT MATTERS\u00a0"},"content":{"rendered":"<p lang=\"EN-GB\"><span data-contrast=\"auto\" lang=\"EN-GB\">With cyber threats advancing at a rapid pace, organisations must adopt robust frameworks to safeguard their information assets. ISO\/IEC 27001 is a globally recognised standard for managing information security risks systematically. Its origins trace back to the British Standard BS 7799-2, first published in 1999, which laid the groundwork for formal information security management systems (ISMS). The first international version, ISO\/IEC 27001:2005, was published in 2005, replacing BS 7799-2. A major revision came with ISO\/IEC 27001:2013, followed by the latest update in 2022, which addresses modern challenges such as cloud computing, remote working, and sophisticated cyberattacks, aligning its structure and Annex A controls with ISO\/IEC 27002:2022.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/p>\n<p lang=\"EN-GB\"><span data-contrast=\"auto\" lang=\"EN-GB\">&nbsp;<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">At Overt Software Solutions, we are proud to announce our successful upgrade from ISO 27001:2013 to ISO 27001:2022, reinforcing our commitment to delivering secure, cutting-edge IT services to our customers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/p>\n<p><span><img decoding=\"async\" alt=\"\" data-id=\"15394\" width=\"602\" data-init-width=\"1440\" height=\"339\" data-init-height=\"810\" title=\"evolution of ISO27001\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/59.jpg\" data-width=\"602\" data-height=\"339\" style=\"aspect-ratio: auto 1440 \/ 810;\"><\/span><\/p>\n<h3 id=\"t-1742986096429\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Background of ISO 27001:2013 vs 2022 Versions<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:319,&quot;335559739&quot;:319}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">ISO 27001:2013 provided a solid foundation for establishing, implementing, maintaining, and improving an Information Security Management System (ISMS). Its purpose was to help organisations identify risks, implement controls, and ensure continual improvement in security practices. However, by the late 2010s, the cybersecurity landscape had shifted dramatically. The rise of cloud services, Internet of Things (IoT) devices, remote workforces, and advanced threats like ransomware exposed limitations in the 2013 version. These gaps necessitated an update to keep the standard relevant.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">Published in October 2022, ISO 27001:2022 builds on its predecessor while introducing refinements and new controls. The update reflects the evolution of technology and organisational needs, ensuring that the standard remains a practical tool for managing modern risks. For instance, the 2013 version offered little guidance on cloud security or threat intelligence, areas now critical to most businesses. The 2022 revision addresses these shortcomings, making it a forward-looking framework suited to today\u2019s digital environment.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p style=\"text-align: center;\"><strong>Want to learn more about ISO 27001? We have the content you need. Click below to read.<\/strong><\/p>\n<p><span><img decoding=\"async\" alt=\"Iso27001 Certification_ The best way to protect your data blogpost Feature image by Overt Software Solution\" data-id=\"4749\" width=\"248\" data-init-width=\"1920\" height=\"140\" data-init-height=\"1080\" title=\"Iso27001 Certification_ The best way to protect your data blogpost Feature image by Overt Software Solution\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/Iso27001-Certification_-The-best-way-to-protect-your-data-blogpost-Feature-image-by-Overt-Software-Solution.jpg\" data-width=\"248\" data-height=\"140\" style=\"aspect-ratio: auto 1920 \/ 1080;\"><\/span><\/p>\n<p style=\"text-align: center;\">Learn what ISO 27001 certification means and how it strengthens your security.<\/p>\n<p><span><img decoding=\"async\" alt=\"How ISO 27001 Certification Boosts Customer Trust and Business Success - feature image_ How ISO 27001 Certification Boosts Customer Trust and Business Success\" data-id=\"10986\" width=\"248\" data-init-width=\"1920\" height=\"140\" data-init-height=\"1080\" title=\"How ISO 27001 Certification Boosts Customer Trust and Business Success - feature  image_ How ISO 27001 Certification Boosts Customer Trust and Business Success\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/ISO-Blog-1.png\" data-width=\"248\" data-height=\"140\" style=\"aspect-ratio: auto 1920 \/ 1080;\"><\/span><\/p>\n<p style=\"text-align: center;\">Discover how ISO 27001 certification helps build trust with your customers.<\/p>\n<h3 id=\"t-1742986096430\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Structural Changes<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:319,&quot;335559739&quot;:319}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">The structure of ISO 27001 comprises two main parts: the clauses (4 to 10), which form the core requirements of the ISMS, and Annex A, which lists specific security controls. While the main clauses remain broadly consistent between 2013 and 2022, subtle refinements enhance clarity and flexibility.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">In 2013, clauses 4 to 10 were detailed but somewhat rigid, requiring organisations to interpret and adapt them to their contexts. The 2022 version retains the same intent\u2014covering context, leadership, planning, support, operation, evaluation, and improvement\u2014but rewords sections for usability. For example, requirements are now more concise, reducing ambiguity for implementers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span><img decoding=\"async\" alt=\"\" data-id=\"15398\" width=\"602\" data-init-width=\"1440\" height=\"339\" data-init-height=\"810\" title=\"ISO27001 comparison chart\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/61.jpg\" data-width=\"602\" data-height=\"339\" style=\"aspect-ratio: auto 1440 \/ 810;\"><\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">The most substantial overhaul occurs in Annex A. In 2013, Annex A contained 114 controls organised into 14 domains, such as \u201cA.11 Physical and Environmental Security\u201d and \u201cA.13 Communications Security.\u201d These domains were comprehensive but often overlapped, creating complexity. In contrast, ISO 27001:2022 reduces this to 93 controls, grouped into four intuitive themes: Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). This thematic approach simplifies navigation and aligns controls with specific organisational functions.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 id=\"t-1742986096431\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Key Differences in Detail<\/span><span data-ccp-parastyle=\"heading 4\">: <\/span><span data-ccp-parastyle=\"heading 4\">ISO 27001:2013 vs ISO 27001:2022<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:319,&quot;335559739&quot;:319}\">&nbsp;<\/span><\/h3>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoNormalTable\" data-tablelook=\"1696\" aria-rowcount=\"16\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Aspect<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p style=\"text-align: center;\"><b><span data-contrast=\"auto\">ISO 27001:2013<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p style=\"text-align: center;\"><b><span data-contrast=\"auto\">ISO 27001:2022<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Publication Date<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">October 2013<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">October 2022<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Purpose<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Establishes an ISMS to manage information security risks systematically.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Updates the ISMS to address modern threats (e.g., cloud, remote work, cyberattacks).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Main Clauses (4-10)<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Detailed but less streamlined; focuses on context, leadership, planning, etc.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Refined for clarity and flexibility; intent unchanged but wording improved.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Annex A Controls<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">114 controls across 14 domains (A.5 to A.18).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">93 controls grouped into 4 themes: Organisational (37), People (8), Physical (14), Technological (34).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Control Organisation<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Broad domains (e.g., &#8220;A.12 Operations Security&#8221;) with some overlap.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Thematic grouping reduces redundancy and improves usability (e.g., merging access controls).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Example Control Change<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">&#8220;A.9.2.5 Review of user access rights&#8221; and &#8220;A.9.2.6 Removal or adjustment&#8221; separate.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Consolidated into &#8220;5.18 Access rights&#8221; for streamlined implementation.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">New Controls<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">None specific to emerging tech like cloud or threat intelligence.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">11 new controls (e.g., 5.7 Threat intelligence, 5.23 Cloud security, 8.28 Secure coding).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Control Attributes<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">No tagging system; controls lack metadata for alignment with other frameworks.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Attributes added: Control type, Security properties, Cybersecurity concepts, etc.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Clause 4.2 (Interested Parties)<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Less prescriptive; no explicit documentation requirement.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Requires documenting interested parties and their requirements.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Clause 6.1.3 (Risk Treatment)<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">General guidance; less focus on justifying control selections.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Clarifies link to Annex A; requires justification for control choices\/exclusions.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Clause 9.1 (Monitoring)<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Less specific on implementation details (e.g., &#8220;when&#8221; and &#8220;who&#8221;).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Mandates defining &#8220;when&#8221; and &#8220;who&#8221; for monitoring activities.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"13\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Planning Emphasis<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Focuses on controls rather than process integration.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Emphasises planning (Clause 6.3) and integrates &#8220;processes&#8221; with activities.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"14\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Transition Deadline<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Not applicable (original standard).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">31 October 2025 (IAF deadline for 2013-certified organisations).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"15\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Benefits<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Solid foundation for basic security management.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">More relevant to modern tech, easier alignment with frameworks like NIST\/GDPR.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<tr aria-rowindex=\"16\">\n<td data-celllook=\"4369\">\n<p><b><span data-contrast=\"auto\">Challenges<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Gaps in addressing cloud, IoT, or advanced threats.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<td data-celllook=\"4369\">\n<p><span data-contrast=\"auto\">Requires training, reassessment, and potentially new tools for updated controls.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4 id=\"t-1742986096432\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">1. Number and&nbsp;<\/span><span data-ccp-parastyle=\"heading 5\">Organisation<\/span><span data-ccp-parastyle=\"heading 5\"> of Annex A Controls<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">The reduction from 114 to 93 controls in 2022 does not signify a weakening of the standard. Instead, it results from merging redundant controls and eliminating outdated ones. For example, in 2013, \u201cA.9.2.5 Review of user access rights\u201d and \u201cA.9.2.6 Removal or adjustment of access rights\u201d were distinct controls. In 2022, these combine into \u201c5.18 Access rights,\u201d streamlining implementation without losing rigour.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">The shift to four themes also improves practicality. Organisational controls address governance and policies, People controls focus on human factors, Physical controls cover premises security, and Technological controls target IT systems. This structure helps organisations assign responsibilities more effectively. For instance, a facilities manager can focus on the 14 Physical controls, while IT teams tackle the 34 Technological ones.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h4 id=\"t-1742986096433\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">2. New Controls Introduced in 2022<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">To address emerging risks, ISO 27001:2022 introduces 11 new controls:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">5.7 Threat intelligence<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Organisations must now gather and analyse data on potential threats, such as monitoring dark web forums for leaked credentials. This proactive approach contrasts with the reactive stance of 2013.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">5.23 Information security for use of cloud services<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: With cloud adoption soaring, this control ensures secure configuration and vendor management. For example, a company using Microsoft Azure must assess its provider\u2019s security practices.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">5.30 ICT readiness for business continuity<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: This ensures IT systems support operations during disruptions, such as maintaining backups for ransomware recovery.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">7.4 Physical security monitoring<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Organisations must monitor premises, perhaps with CCTV, to detect unauthorised access.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.1 Data masking<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Sensitive data, like customer details, must be obscured to prevent exposure during testing or breaches.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.9 Configuration management<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Systems must be securely configured to reduce vulnerabilities, such as disabling unused ports.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.10 Information deletion<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Secure disposal of data, like shredding old drives, prevents recovery by attackers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.11 Data leakage prevention<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Tools like firewalls or encryption stop unauthorised data leaks, vital in remote work settings.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.12 Web filtering<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Blocking access to malicious sites protects against phishing or malware.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.16 Monitoring activities<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Enhanced system monitoring detects anomalies, such as unusual login attempts.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><span data-contrast=\"auto\" lang=\"EN-GB\">8.28 Secure coding<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Developers must follow practices to minimise software vulnerabilities, critical for in-house applications.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<\/ul>\n<h4 id=\"t-1742986096434\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">3. Updated Control Attributes in 2022<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">A novel feature in 2022 is the tagging of controls with attributes, including:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<ul>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Control type<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>Preventive (stopping incidents), Detective (identifying them), or Corrective (fixing them).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Security properties<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Confidentiality, Integrity, Availability.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Cybersecurity concepts<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Aligned with NIST CSF categories (Identify, Protect, Detect, Respond, Recover).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Operational capabilities<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>Areas like Governance or Asset Management.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Security domains<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Such as Application Security or Physical Security.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">This metadata enables organisations to map controls to other frameworks, like GDPR or NIST, and tailor them to specific risks. In 2013, controls lacked this flexibility, limiting interoperability.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h4 id=\"t-1742986096435\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">4. Clause Updates (Main Body)<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">Several clauses see refinements:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<ul>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 4.2 (Understanding the needs and expectations of interested parties)<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>The 2022 version mandates documenting interested parties (e.g., customers, regulators) and their requirements, unlike the less prescriptive 2013 approach.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 6.1.3 (Information security risk treatment)<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>This now requires justifying control selections and exclusions, linking them explicitly to Annex A, whereas 2013 was vaguer.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 9.1 (Monitoring, measurement, analysis, and evaluation)<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Organisations must specify \u201cwhen\u201d and \u201cwho\u201d for monitoring, adding precision absent in 2013.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">These changes promote accountability and ensure the ISMS is actionable and measurable.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h4 id=\"t-1742986096436\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">5. Emphasis on Planning and Processes<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 6.3 in 2022 emphasises planning changes to the ISMS, while \u201cprocesses\u201d are explicitly mentioned alongside activities. This shift integrates security into organisational workflows, moving beyond the 2013 focus on standalone controls. For example, a company might embed threat intelligence into its IT operations rather than treating it as an isolated task.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<h3 id=\"t-1742986096437\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 3\">Overt Software Solutions and Our ISO 27001:2022 Journey<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">Here at Overt Software Solutions, we are a UK-based team passionate about supporting education and business with top-notch IT services. For years, we have been a reliable partner, helping with everything from managed IT support to software development and cybersecurity. We have always taken information security seriously\u2014it is at the heart of what we do. That is why we were so proud to hold ISO 27001:2013 certification, a clear sign of how much we care about keeping our clients\u2019 data safe. Now, we are thrilled to share some exciting news: we have upgraded to ISO 27001:2022, a big step forward that brings us right up to date with the latest global standards.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span><img decoding=\"async\" alt=\"\" data-id=\"15402\" width=\"601\" data-init-width=\"1440\" height=\"338\" data-init-height=\"810\" title=\"Overt Software journey in ISO27001\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/63.jpg\" data-width=\"601\" data-height=\"338\" style=\"aspect-ratio: auto 1440 \/ 810;\"><\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">This upgrade is not just a tick in a box for us\u2014it shows how we are always looking ahead, ready to tackle today\u2019s cybersecurity challenges. By moving to the 2022 standard, we have beefed up our Information Security Management System (ISMS) with some brilliant new controls, like \u201c5.23 Information security for use of cloud services\u201d and \u201c8.11 Data leakage prevention.\u201d What does that mean for our customers? Well, if you are an educational institution using our federated identity management tools\u2014like Shibboleth or SAML\u2014you can rest easy knowing sensitive student and staff data in the cloud is even better protected. And for businesses relying on our custom IT support or software solutions, it means stronger defences against nasty threats like ransomware, keeping your operations safe and your reputation intact.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">For us, this upgrade is all about giving our customers peace of mind. We are not just meeting industry standards\u2014we are going beyond them. It is about making sure you feel confident in our services, knowing we have got your back with secure, dependable solutions. That way, you can focus on what matters most to you, whether that is shaping young minds or growing your business. We are proud to be part of your journey, and this step forward with ISO 27001:2022 only deepens our commitment to you.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span><img decoding=\"async\" alt=\"\" data-id=\"15407\" width=\"400\" data-init-width=\"1276\" height=\"182\" data-init-height=\"580\" title=\"ISO27001_2022_overt\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/ISO27001_2022_overt.png\" data-width=\"400\" data-height=\"182\" style=\"aspect-ratio: auto 1276 \/ 580;\"><\/span><\/p>\n<h3 id=\"t-1742986096438\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Key Takeaways&nbsp;<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:319,&quot;335559739&quot;:319,&quot;335559740&quot;:279}\">&nbsp;<\/span><\/h3>\n<p><span data-contrast=\"auto\" lang=\"EN-GB\">ISO 27001:2022 refines its 2013 predecessor with clearer clauses, a restructured Annex A, and new controls addressing today\u2019s threats. From threat intelligence to secure coding, these updates ensure organisations remain resilient. At Overt Software Solutions, our successful upgrade to ISO 27001:2022 underscores our dedication to providing top-tier security and IT services. This milestone strengthens our ability to protect our customers\u2019 data in an increasingly perilous digital world. Whether you are an educational institution or a business seeking robust cybersecurity, Overt Software Solutions can assist you better than ever. <\/span><a href=\"https:\/\/www.overtsoftware.id\/index.php\/contact\/\" target=\"_blank\" style=\"outline: none;\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-charstyle=\"Hyperlink\">Contact us<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-GB\"> today for more information on how we can enhance your security and support your success.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With cyber threats advancing at a rapid pace, organisations must adopt robust frameworks to safeguard their information assets. ISO\/IEC 27001 is a globally recognised standard for managing information security risks systematically. Its origins trace back to the British Standard BS 7799-2, first published in 1999, which laid the groundwork for formal information security management systems [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2902,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"<div class=\"thrv_wrapper tve-toc tve-elem-scroll tve-toc-expandable tcb-local-vars-root\" data-columns=\"1\" data-ct=\"toc-60733\" data-transition=\"slide\" data-headers=\"h2,h3,h4\" data-numbering=\"none\" data-highlight=\"heading\" data-ct-name=\"Table of Contents 13\" data-heading-style=\"{&quot;0&quot;:&quot;tve-u-195d21239ed&quot;,&quot;1&quot;:&quot;tve-u-1968078288a&quot;,&quot;2&quot;:&quot;tve-u-1968078288f&quot;}\" style=\"\" data-css=\"tve-u-1968078287d\" data-state-default=\"expanded\" data-state-default-d=\"expanded\" data-animation=\"slide\" data-bullet-style=\"{&quot;0&quot;:&quot;tve-u-17399ff41d4&quot;,&quot;1&quot;:&quot;tve-u-17399ffc502&quot;,&quot;2&quot;:&quot;tve-u-17399ffedb7&quot;}\" data-number-style=\"{&quot;0&quot;:&quot;tve-u-17399fecc2c&quot;,&quot;1&quot;:&quot;tve-u-173dc8687ce&quot;,&quot;2&quot;:&quot;tve-u-173dc86929b&quot;}\" data-distribute=\"false\" data-state-default-m=\"collapsed\" data-element-name=\"Table of Contents\" data-form-settings=\"__TCB_FORM__{&quot;form_identifier&quot;:&quot;-form-g0d8xf&quot;}__TCB_FORM__\" data-id=\"ma277fkl\"><div class=\"thrive-colors-palette-config\" style=\"display: none !important\">__CONFIG_colors_palette__{\"active_palette\":0,\"config\":{\"colors\":{\"4204a\":{\"name\":\"Main Accent\",\"parent\":-1},\"ea1e7\":{\"name\":\"Main Accent Light\",\"parent\":\"4204a\",\"lock\":{\"lightness\":1}}},\"gradients\":[]},\"palettes\":[{\"name\":\"Default\",\"value\":{\"colors\":{\"4204a\":{\"val\":\"var(--tcb-skin-color-0)\"},\"ea1e7\":{\"val\":\"rgba(214, 93, 0, 0.08)\",\"hsl_parent_dependency\":{\"h\":26,\"l\":0.42,\"s\":1.28}}},\"gradients\":[]},\"original\":{\"colors\":{\"4204a\":{\"val\":\"rgb(30, 136, 69)\",\"hsl\":{\"h\":142,\"s\":0.63,\"l\":0.32,\"a\":1}},\"ea1e7\":{\"val\":\"rgba(4, 215, 85, 0.08)\",\"hsl_parent_dependency\":{\"h\":143,\"s\":0.96,\"l\":0.42,\"a\":0.08}}},\"gradients\":[]}}]}__CONFIG_colors_palette__<\/div><div class=\"tve-toc-divider\" style=\"position: absolute; width: 0; height: 0; overflow: hidden;\"><div class=\"thrv_wrapper thrv-divider tve-vert-divider\" data-style=\"tve_sep-1\" data-color-d=\"rgb(217, 217, 217)\"><hr class=\"tve_sep tve_sep-1\" style=\"\"><\/div><\/div><svg class=\"toc-icons\" style=\"position: absolute; width: 0; height: 0; overflow: hidden;\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><symbol viewBox=\"0 0 24 24\" id=\"toc-bullet-0-ma277fkl\" data-id=\"icon-chevron_right-duotone\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"><\/path><path d=\"M10 6L8.59 7.41 13.17 12l-4.58 4.59L10 18l6-6-6-6z\"><\/path><\/symbol><symbol viewBox=\"0 0 24 24\" id=\"toc-bullet-1-ma277fkl\" data-id=\"icon-chevron_right-duotone\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"><\/path><path d=\"M10 6L8.59 7.41 13.17 12l-4.58 4.59L10 18l6-6-6-6z\"><\/path><\/symbol><symbol viewBox=\"0 0 24 24\" id=\"toc-bullet-2-ma277fkl\" data-id=\"icon-chevron_right-duotone\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"><\/path><path d=\"M10 6L8.59 7.41 13.17 12l-4.58 4.59L10 18l6-6-6-6z\"><\/path><\/symbol><\/svg>\n\t<div class=\"tve-content-box-background\" data-css=\"tve-u-1968078287f\" style=\"\"><\/div>\n\t<div class=\"thrv_wrapper tve-toc-title tcb-icon-display reverse tve-no-dropzone tve-prevent-content-edit\" data-css=\"tve-u-19680782881\" style=\"\">\n\t<div class=\"tve-content-box-background\" style=\"\"><\/div>\n\t<div class=\"tve-cb\" style=\"\">\n\t\t<div class=\"tve-toc-title-icon\" data-icon-code=\"icon-chevron-down-solid\" style=\"\"><svg class=\"tcb-icon\" viewBox=\"0 0 24 24\" data-id=\"icon-chevron-down-solid\" data-name=\"\"><path d=\"M7.41,8.58L12,13.17L16.59,8.58L18,10L12,16L6,10L7.41,8.58Z\"><\/path><\/svg><\/div>\n\t\t<div class=\"thrv_wrapper thrv_text_element tve_no_icons\">\t\t\t<div class=\"tcb-plain-text\" data-css=\"tve-u-19680782882\" style=\"\">table of contents<\/div> \t\t<\/div>\n\t<\/div>\n<\/div><div class=\"tve-cb tve-toc-content tve-prevent-content-edit\">\n\t\t\n\n\t\t<div class=\"thrv_wrapper thrv_contentbox_shortcode thrv-content-box tve-elem-default-pad\" data-css=\"tve-u-19680782884\" style=\"\">\n\t<div class=\"tve-content-box-background\" style=\"\" data-css=\"tve-u-19680782885\"><\/div>\n\t<div class=\"tve-cb\"><\/div>\n<\/div><div class=\"thrv_wrapper tve-toc-list tcb-no-delete tcb-no-save tcb-no-clone tve-no-dropzone\" data-css=\"tve-u-19680782887\" style=\"\">\n\t\t\t<div class=\"tve-content-box-background\" data-css=\"tve-u-19680782888\" style=\"\"><\/div>\n\t\t\t<div class=\"tve-cb\">\n\t\t\t\t<div class=\"tve_ct_content tve_clearfix\"><div class=\"ct_column\"><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-1968078288a\" data-element-name=\"Heading Level 2\"><a href=\"#t-1742986096429\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Background of ISO 27001:2013 vs 2022 Versions&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-1968078288a\" data-element-name=\"Heading Level 2\"><a href=\"#t-1742986096430\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Structural Changes&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-1968078288a\" data-element-name=\"Heading Level 2\"><a href=\"#t-1742986096431\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Key Differences in Detail: ISO 27001:2013 vs ISO 27001:2022&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-1968078288f\" data-element-name=\"Heading Level 3\"><a href=\"#t-1742986096432\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">1. Number and&nbsp;Organisation of Annex A Controls&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-1968078288f\" data-element-name=\"Heading Level 3\"><a href=\"#t-1742986096433\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">2. New Controls Introduced in 2022&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-1968078288f\" data-element-name=\"Heading Level 3\"><a href=\"#t-1742986096434\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">3. Updated Control Attributes in 2022&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-1968078288f\" data-element-name=\"Heading Level 3\"><a href=\"#t-1742986096435\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">4. Clause Updates (Main Body)&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level2 tve_no_icons\" data-tag=\"H4\" data-css=\"tve-u-1968078288f\" data-element-name=\"Heading Level 3\"><a href=\"#t-1742986096436\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">5. Emphasis on Planning and Processes&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-1968078288a\" data-element-name=\"Heading Level 2\"><a href=\"#t-1742986096437\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Overt Software Solutions and Our ISO 27001:2022 Journey&nbsp;<\/a><\/div><div class=\"thrv_wrapper tve-toc-heading tve-toc-heading-level1 tve_no_icons\" data-tag=\"H3\" data-css=\"tve-u-1968078288a\" data-element-name=\"Heading Level 2\"><a href=\"#t-1742986096438\" class=\"tve-toc-anchor tve-jump-scroll\" jump-animation=\"smooth\">Key Takeaways&nbsp;&nbsp;<\/a><\/div><\/div><div class=\"thrv_wrapper thrv-divider tve-vert-divider\" data-style=\"tve_sep-1\" data-color-d=\"rgb(217, 217, 217)\"><hr class=\"tve_sep tve_sep-1\" style=\"\"><\/div><\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/div>\n<\/div><div class=\"thrv_wrapper thrv_text_element\">\t<p lang=\"EN-GB\"><span data-contrast=\"auto\" lang=\"EN-GB\">With cyber threats advancing at a rapid pace, organisations must adopt robust frameworks to safeguard their information assets. ISO\/IEC 27001 is a globally recognised standard for managing information security risks systematically. Its origins trace back to the British Standard BS 7799-2, first published in 1999, which laid the groundwork for formal information security management systems (ISMS). The first international version, ISO\/IEC 27001:2005, was published in 2005, replacing BS 7799-2. A major revision came with ISO\/IEC 27001:2013, followed by the latest update in 2022, which addresses modern challenges such as cloud computing, remote working, and sophisticated cyberattacks, aligning its structure and Annex A controls with ISO\/IEC 27002:2022.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/p><p lang=\"EN-GB\"><span data-contrast=\"auto\" lang=\"EN-GB\">&nbsp;<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">At Overt Software Solutions, we are proud to announce our successful upgrade from ISO 27001:2013 to ISO 27001:2022, reinforcing our commitment to delivering secure, cutting-edge IT services to our customers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-1968078289c\" style=\"\"><span class=\"tve_image_frame\"><img class=\"tve_image wp-image-15394\" alt=\"\" data-id=\"15394\" width=\"602\" data-init-width=\"1440\" height=\"339\" data-init-height=\"810\" title=\"evolution of ISO27001\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/59.jpg\" data-width=\"602\" data-height=\"339\" style=\"aspect-ratio: auto 1440 \/ 810;\"><\/span><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1742986096429\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Background of ISO 27001:2013 vs 2022 Versions<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:319,&quot;335559739&quot;:319}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-GB\">ISO 27001:2013 provided a solid foundation for establishing, implementing, maintaining, and improving an Information Security Management System (ISMS). Its purpose was to help organisations identify risks, implement controls, and ensure continual improvement in security practices. However, by the late 2010s, the cybersecurity landscape had shifted dramatically. The rise of cloud services, Internet of Things (IoT) devices, remote workforces, and advanced threats like ransomware exposed limitations in the 2013 version. These gaps necessitated an update to keep the standard relevant.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-GB\">Published in October 2022, ISO 27001:2022 builds on its predecessor while introducing refinements and new controls. The update reflects the evolution of technology and organisational needs, ensuring that the standard remains a practical tool for managing modern risks. For instance, the 2013 version offered little guidance on cloud security or threat intelligence, areas now critical to most businesses. The 2022 revision addresses these shortcomings, making it a forward-looking framework suited to today\u2019s digital environment.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_contentbox_shortcode thrv-content-box tve-elem-default-pad cb_style_4\" data-style=\"cb_style_4\" data-css=\"tve-u-1968078289d\" style=\"\">\n\t<div class=\"tve-content-box-background cb_style_4-bg\" data-css=\"tve-u-1968078289f\" style=\"\"><\/div>\n\t<div class=\"tve-cb cb_style_4-cb\" data-css=\"tve-u-196807828a1\" style=\"\"><div class=\"thrv_wrapper thrv_text_element\"><p style=\"text-align: center;\" data-css=\"tve-u-196807828a3\"><strong>Want to learn more about ISO 27001? We have the content you need. Click below to read.<\/strong><\/p><\/div><div class=\"thrv_wrapper thrv-columns\" style=\"--tcb-col-el-width: 910;\"><div class=\"tcb-flex-row v-2 tcb--cols--2\" data-css=\"tve-u-196807828a4\" style=\"\"><div class=\"tcb-flex-col\"><div class=\"tcb-col\"><div class=\"thrv_wrapper thrv_contentbox_shortcode thrv-content-box tve-elem-default-pad cb_style_4\" data-style=\"cb_style_4\" data-css=\"tve-u-196807828a6\" style=\"\">\n\t<div class=\"tve-content-box-background cb_style_4-bg\" data-css=\"tve-u-196807828a8\" style=\"\"><\/div>\n\t<div class=\"tve-cb cb_style_4-cb\" data-css=\"tve-u-196807828aa\" style=\"\"><div class=\"thrv_wrapper thrv-columns\" style=\"--tcb-col-el-width: 417.5;\" data-css=\"tve-u-196807828ac\"><div class=\"tcb-flex-row v-2 tcb--cols--1\" data-css=\"tve-u-196807828ad\" style=\"\"><div class=\"tcb-flex-col\"><div class=\"tcb-col\"><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-196807828af\" style=\"\"><span class=\"tve_image_frame\"><img decoding=\"async\" class=\"tve_image wp-image-4749\" alt=\"Iso27001 Certification_ The best way to protect your data blogpost Feature image by Overt Software Solution\" data-id=\"4749\" width=\"248\" data-init-width=\"1920\" height=\"140\" data-init-height=\"1080\" title=\"Iso27001 Certification_ The best way to protect your data blogpost Feature image by Overt Software Solution\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/Iso27001-Certification_-The-best-way-to-protect-your-data-blogpost-Feature-image-by-Overt-Software-Solution.jpg\" data-width=\"248\" data-height=\"140\" style=\"aspect-ratio: auto 1920 \/ 1080;\"><\/span><\/div><div class=\"thrv_wrapper thrv_text_element\"><p style=\"text-align: center;\" data-css=\"tve-u-196807828b1\">Learn what ISO 27001 certification means and how it strengthens your security.<\/p><\/div><\/div><\/div><\/div><\/div><div class=\"thrv_wrapper thrv-button thrv-button-v2 tcb-local-vars-root\" data-css=\"tve-u-196807828b3\" style=\"\">\n\t<div class=\"thrive-colors-palette-config\" style=\"display: none !important\">__CONFIG_colors_palette__{\"active_palette\":0,\"config\":{\"colors\":{\"62516\":{\"name\":\"Main Accent\",\"parent\":-1}},\"gradients\":[]},\"palettes\":[{\"name\":\"Default Palette\",\"value\":{\"colors\":{\"62516\":{\"val\":\"var(--tcb-skin-color-0)\"}},\"gradients\":[]}}]}__CONFIG_colors_palette__<\/div>\n\t<a href=\"https:\/\/www.overtsoftware.com\/iso27001-certification\/\" class=\"tcb-button-link tcb-plain-text\" target=\"_blank\" style=\"\">\n\t\t<span class=\"tcb-button-texts\"><span class=\"tcb-button-text thrv-inline-text\">Read the full article<\/span><\/span>\n\t<\/a>\n<\/div><\/div>\n<\/div><\/div><\/div><div class=\"tcb-flex-col\"><div class=\"tcb-col\"><div class=\"thrv_wrapper thrv_contentbox_shortcode thrv-content-box tve-elem-default-pad cb_style_4\" data-style=\"cb_style_4\" data-css=\"tve-u-196807828b5\" style=\"\">\n\t<div class=\"tve-content-box-background cb_style_4-bg\" data-css=\"tve-u-196807828b7\" style=\"\"><\/div>\n\t<div class=\"tve-cb cb_style_4-cb\" data-css=\"tve-u-196807828b9\" style=\"\"><div class=\"thrv_wrapper thrv-columns\" style=\"--tcb-col-el-width: 417.5;\" data-css=\"tve-u-196807828bb\"><div class=\"tcb-flex-row v-2 tcb--cols--1\" data-css=\"tve-u-196807828bd\" style=\"\"><div class=\"tcb-flex-col\"><div class=\"tcb-col\"><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-196807828bf\" style=\"\"><span class=\"tve_image_frame\"><img decoding=\"async\" class=\"tve_image wp-image-10986\" alt=\"How ISO 27001 Certification Boosts Customer Trust and Business Success - feature image_ How ISO 27001 Certification Boosts Customer Trust and Business Success\" data-id=\"10986\" width=\"248\" data-init-width=\"1920\" height=\"140\" data-init-height=\"1080\" title=\"How ISO 27001 Certification Boosts Customer Trust and Business Success - feature  image_ How ISO 27001 Certification Boosts Customer Trust and Business Success\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/ISO-Blog-1.png\" data-width=\"248\" data-height=\"140\" style=\"aspect-ratio: auto 1920 \/ 1080;\"><\/span><\/div><\/div><\/div><\/div><\/div><div class=\"thrv_wrapper thrv_text_element\"><p style=\"text-align: center;\" data-css=\"tve-u-196807828c1\">Discover how ISO 27001 certification helps build trust with your customers.<\/p><\/div><div class=\"thrv_wrapper thrv-button thrv-button-v2 tcb-local-vars-root\" data-css=\"tve-u-196807828c2\" style=\"\">\n\t<div class=\"thrive-colors-palette-config\" style=\"display: none !important\">__CONFIG_colors_palette__{\"active_palette\":0,\"config\":{\"colors\":{\"62516\":{\"name\":\"Main Accent\",\"parent\":-1}},\"gradients\":[]},\"palettes\":[{\"name\":\"Default Palette\",\"value\":{\"colors\":{\"62516\":{\"val\":\"var(--tcb-skin-color-0)\"}},\"gradients\":[]}}]}__CONFIG_colors_palette__<\/div>\n\t<a href=\"https:\/\/www.overtsoftware.com\/iso-27001-certification-customer-trust\/\" class=\"tcb-button-link tcb-plain-text\" target=\"_blank\">\n\t\t<span class=\"tcb-button-texts\"><span class=\"tcb-button-text thrv-inline-text\">Read the full article<\/span><\/span>\n\t<\/a>\n<\/div><\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div>\n<\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1742986096430\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Structural Changes<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:319,&quot;335559739&quot;:319}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-GB\">The structure of ISO 27001 comprises two main parts: the clauses (4 to 10), which form the core requirements of the ISMS, and Annex A, which lists specific security controls. While the main clauses remain broadly consistent between 2013 and 2022, subtle refinements enhance clarity and flexibility.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-GB\">In 2013, clauses 4 to 10 were detailed but somewhat rigid, requiring organisations to interpret and adapt them to their contexts. The 2022 version retains the same intent\u2014covering context, leadership, planning, support, operation, evaluation, and improvement\u2014but rewords sections for usability. For example, requirements are now more concise, reducing ambiguity for implementers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-196807828c4\" style=\"\"><span class=\"tve_image_frame\"><img class=\"tve_image wp-image-15398\" alt=\"\" data-id=\"15398\" width=\"602\" data-init-width=\"1440\" height=\"339\" data-init-height=\"810\" title=\"ISO27001 comparison chart\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/61.jpg\" data-width=\"602\" data-height=\"339\" style=\"aspect-ratio: auto 1440 \/ 810;\"><\/span><\/div><div class=\"thrv_wrapper thrv_text_element\"><p><span data-contrast=\"auto\" lang=\"EN-GB\">The most substantial overhaul occurs in Annex A. In 2013, Annex A contained 114 controls organised into 14 domains, such as \u201cA.11 Physical and Environmental Security\u201d and \u201cA.13 Communications Security.\u201d These domains were comprehensive but often overlapped, creating complexity. In contrast, ISO 27001:2022 reduces this to 93 controls, grouped into four intuitive themes: Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). This thematic approach simplifies navigation and aligns controls with specific organisational functions.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1742986096431\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Key Differences in Detail<\/span><span data-ccp-parastyle=\"heading 4\">: <\/span><span data-ccp-parastyle=\"heading 4\">ISO 27001:2013 vs ISO 27001:2022<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:319,&quot;335559739&quot;:319}\">&nbsp;<\/span><\/h3><\/div><div class=\"thrv_wrapper tve_wp_shortcode\" data-css=\"tve-u-196807828c6\"><div class=\"tve_shortcode_raw\" style=\"display: none\">___TVE_SHORTCODE_RAW__&lt;table style=\"font-weight: 400;\" data-tablestyle=\"MsoNormalTable\" data-tablelook=\"1696\" aria-rowcount=\"16\"&gt;&lt;tbody&gt;&lt;tr aria-rowindex=\"1\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Aspect&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p style=\"text-align: center;\"&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;ISO 27001:2013&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p style=\"text-align: center;\"&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;ISO 27001:2022&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"2\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Publication Date&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;October 2013&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;October 2022&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"3\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Purpose&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Establishes an ISMS to manage information security risks systematically.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Updates the ISMS to address modern threats (e.g., cloud, remote work, cyberattacks).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"4\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Main Clauses (4-10)&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Detailed but less streamlined; focuses on context, leadership, planning, etc.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Refined for clarity and flexibility; intent unchanged but wording improved.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"5\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Annex A Controls&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;114 controls across 14 domains (A.5 to A.18).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;93 controls grouped into 4 themes: Organisational (37), People (8), Physical (14), Technological (34).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"6\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Control Organisation&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Broad domains (e.g., \"A.12 Operations Security\") with some overlap.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Thematic grouping reduces redundancy and improves usability (e.g., merging access controls).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"7\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Example Control Change&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;\"A.9.2.5 Review of user access rights\" and \"A.9.2.6 Removal or adjustment\" separate.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Consolidated into \"5.18 Access rights\" for streamlined implementation.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"8\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;New Controls&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;None specific to emerging tech like cloud or threat intelligence.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;11 new controls (e.g., 5.7 Threat intelligence, 5.23 Cloud security, 8.28 Secure coding).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"9\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Control Attributes&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;No tagging system; controls lack metadata for alignment with other frameworks.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Attributes added: Control type, Security properties, Cybersecurity concepts, etc.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"10\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Clause 4.2 (Interested Parties)&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Less prescriptive; no explicit documentation requirement.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Requires documenting interested parties and their requirements.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"11\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Clause 6.1.3 (Risk Treatment)&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;General guidance; less focus on justifying control selections.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Clarifies link to Annex A; requires justification for control choices\/exclusions.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"12\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Clause 9.1 (Monitoring)&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Less specific on implementation details (e.g., \"when\" and \"who\").&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Mandates defining \"when\" and \"who\" for monitoring activities.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"13\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Planning Emphasis&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Focuses on controls rather than process integration.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Emphasises planning (Clause 6.3) and integrates \"processes\" with activities.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"14\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Transition Deadline&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Not applicable (original standard).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;31 October 2025 (IAF deadline for 2013-certified organisations).&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"15\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Benefits&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Solid foundation for basic security management.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;More relevant to modern tech, easier alignment with frameworks like NIST\/GDPR.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;tr aria-rowindex=\"16\"&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;b&gt;&lt;span data-contrast=\"auto\"&gt;Challenges&lt;\/span&gt;&lt;\/b&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Gaps in addressing cloud, IoT, or advanced threats.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;td data-celllook=\"4369\"&gt;&lt;p&gt;&lt;span data-contrast=\"auto\"&gt;Requires training, reassessment, and potentially new tools for updated controls.&lt;\/span&gt;&lt;span data-ccp-props=\"{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0}\"&gt;&nbsp;&lt;\/span&gt;&lt;\/p&gt;&lt;\/td&gt;&lt;\/tr&gt;&lt;\/tbody&gt;&lt;\/table&gt;__TVE_SHORTCODE_RAW___<\/div><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1742986096432\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">1. Number and&nbsp;<\/span><span data-ccp-parastyle=\"heading 5\">Organisation<\/span><span data-ccp-parastyle=\"heading 5\"> of Annex A Controls<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-GB\">The reduction from 114 to 93 controls in 2022 does not signify a weakening of the standard. Instead, it results from merging redundant controls and eliminating outdated ones. For example, in 2013, \u201cA.9.2.5 Review of user access rights\u201d and \u201cA.9.2.6 Removal or adjustment of access rights\u201d were distinct controls. In 2022, these combine into \u201c5.18 Access rights,\u201d streamlining implementation without losing rigour.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-GB\">The shift to four themes also improves practicality. Organisational controls address governance and policies, People controls focus on human factors, Physical controls cover premises security, and Technological controls target IT systems. This structure helps organisations assign responsibilities more effectively. For instance, a facilities manager can focus on the 14 Physical controls, while IT teams tackle the 34 Technological ones.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1742986096433\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">2. New Controls Introduced in 2022<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-GB\">To address emerging risks, ISO 27001:2022 introduces 11 new controls:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><ul class=\"\"><li><span data-contrast=\"auto\" lang=\"EN-GB\">5.7 Threat intelligence<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Organisations must now gather and analyse data on potential threats, such as monitoring dark web forums for leaked credentials. This proactive approach contrasts with the reactive stance of 2013.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">5.23 Information security for use of cloud services<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: With cloud adoption soaring, this control ensures secure configuration and vendor management. For example, a company using Microsoft Azure must assess its provider\u2019s security practices.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">5.30 ICT readiness for business continuity<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: This ensures IT systems support operations during disruptions, such as maintaining backups for ransomware recovery.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">7.4 Physical security monitoring<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Organisations must monitor premises, perhaps with CCTV, to detect unauthorised access.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.1 Data masking<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Sensitive data, like customer details, must be obscured to prevent exposure during testing or breaches.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.9 Configuration management<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Systems must be securely configured to reduce vulnerabilities, such as disabling unused ports.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.10 Information deletion<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Secure disposal of data, like shredding old drives, prevents recovery by attackers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.11 Data leakage prevention<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Tools like firewalls or encryption stop unauthorised data leaks, vital in remote work settings.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.12 Web filtering<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Blocking access to malicious sites protects against phishing or malware.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.16 Monitoring activities<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Enhanced system monitoring detects anomalies, such as unusual login attempts.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><span data-contrast=\"auto\" lang=\"EN-GB\">8.28 Secure coding<\/span><span data-contrast=\"auto\" lang=\"EN-GB\">: Developers must follow practices to minimise software vulnerabilities, critical for in-house applications.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><\/ul><p><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1742986096434\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">3. Updated Control Attributes in 2022<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-GB\">A novel feature in 2022 is the tagging of controls with attributes, including:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><ul class=\"\"><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Control type<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>Preventive (stopping incidents), Detective (identifying them), or Corrective (fixing them).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Security properties<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Confidentiality, Integrity, Availability.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Cybersecurity concepts<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Aligned with NIST CSF categories (Identify, Protect, Detect, Respond, Recover).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Operational capabilities<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>Areas like Governance or Asset Management.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Security domains<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Such as Application Security or Physical Security.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><\/ul><p><span data-contrast=\"auto\" lang=\"EN-GB\">This metadata enables organisations to map controls to other frameworks, like GDPR or NIST, and tailor them to specific risks. In 2013, controls lacked this flexibility, limiting interoperability.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1742986096435\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">4. Clause Updates (Main Body)<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-GB\">Several clauses see refinements:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><ul class=\"\"><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 4.2 (Understanding the needs and expectations of interested parties)<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>The 2022 version mandates documenting interested parties (e.g., customers, regulators) and their requirements, unlike the less prescriptive 2013 approach.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 6.1.3 (Information security risk treatment)<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>: <\/strong>This now requires justifying control selections and exclusions, linking them explicitly to Annex A, whereas 2013 was vaguer.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><li><strong><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 9.1 (Monitoring, measurement, analysis, and evaluation)<\/span><\/strong><span data-contrast=\"auto\" lang=\"EN-GB\"><strong>:<\/strong> Organisations must specify \u201cwhen\u201d and \u201cwho\u201d for monitoring, adding precision absent in 2013.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">&nbsp;<\/span><\/li><\/ul><p><span data-contrast=\"auto\" lang=\"EN-GB\">These changes promote accountability and ensure the ISMS is actionable and measurable.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h4 class=\"\" id=\"t-1742986096436\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 5\">5. Emphasis on Planning and Processes<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:333,&quot;335559739&quot;:333}\">&nbsp;<\/span><\/h4><p><span data-contrast=\"auto\" lang=\"EN-GB\">Clause 6.3 in 2022 emphasises planning changes to the ISMS, while \u201cprocesses\u201d are explicitly mentioned alongside activities. This shift integrates security into organisational workflows, moving beyond the 2013 focus on standalone controls. For example, a company might embed threat intelligence into its IT operations rather than treating it as an isolated task.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1742986096437\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 3\">Overt Software Solutions and Our ISO 27001:2022 Journey<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-GB\">Here at Overt Software Solutions, we are a UK-based team passionate about supporting education and business with top-notch IT services. For years, we have been a reliable partner, helping with everything from managed IT support to software development and cybersecurity. We have always taken information security seriously\u2014it is at the heart of what we do. That is why we were so proud to hold ISO 27001:2013 certification, a clear sign of how much we care about keeping our clients\u2019 data safe. Now, we are thrilled to share some exciting news: we have upgraded to ISO 27001:2022, a big step forward that brings us right up to date with the latest global standards.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-196807828c8\" style=\"\"><span class=\"tve_image_frame\"><img class=\"tve_image wp-image-15402\" alt=\"\" data-id=\"15402\" width=\"601\" data-init-width=\"1440\" height=\"338\" data-init-height=\"810\" title=\"Overt Software journey in ISO27001\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/63.jpg\" data-width=\"601\" data-height=\"338\" style=\"aspect-ratio: auto 1440 \/ 810;\"><\/span><\/div><div class=\"thrv_wrapper thrv_text_element\"><p><span data-contrast=\"auto\" lang=\"EN-GB\">This upgrade is not just a tick in a box for us\u2014it shows how we are always looking ahead, ready to tackle today\u2019s cybersecurity challenges. By moving to the 2022 standard, we have beefed up our Information Security Management System (ISMS) with some brilliant new controls, like \u201c5.23 Information security for use of cloud services\u201d and \u201c8.11 Data leakage prevention.\u201d What does that mean for our customers? Well, if you are an educational institution using our federated identity management tools\u2014like Shibboleth or SAML\u2014you can rest easy knowing sensitive student and staff data in the cloud is even better protected. And for businesses relying on our custom IT support or software solutions, it means stronger defences against nasty threats like ransomware, keeping your operations safe and your reputation intact.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><p><span data-contrast=\"auto\" lang=\"EN-GB\">For us, this upgrade is all about giving our customers peace of mind. We are not just meeting industry standards\u2014we are going beyond them. It is about making sure you feel confident in our services, knowing we have got your back with secure, dependable solutions. That way, you can focus on what matters most to you, whether that is shaping young minds or growing your business. We are proud to be part of your journey, and this step forward with ISO 27001:2022 only deepens our commitment to you.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div><div class=\"thrv_wrapper tve_image_caption\" data-css=\"tve-u-196807828ca\" style=\"\"><span class=\"tve_image_frame\"><img class=\"tve_image wp-image-15407\" alt=\"\" data-id=\"15407\" width=\"400\" data-init-width=\"1276\" height=\"182\" data-init-height=\"580\" title=\"ISO27001_2022_overt\" loading=\"lazy\" src=\"https:\/\/www.overtsoftware.id\/wp-content\/uploads\/2025\/04\/ISO27001_2022_overt.png\" data-width=\"400\" data-height=\"182\" data-css=\"tve-u-196807828cc\" style=\"aspect-ratio: auto 1276 \/ 580;\"><\/span><\/div><div class=\"thrv_wrapper thrv_text_element\"><h3 class=\"\" id=\"t-1742986096438\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-parastyle=\"heading 4\">Key Takeaways&nbsp;<\/span><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:319,&quot;335559739&quot;:319,&quot;335559740&quot;:279}\">&nbsp;<\/span><\/h3><p><span data-contrast=\"auto\" lang=\"EN-GB\">ISO 27001:2022 refines its 2013 predecessor with clearer clauses, a restructured Annex A, and new controls addressing today\u2019s threats. From threat intelligence to secure coding, these updates ensure organisations remain resilient. At Overt Software Solutions, our successful upgrade to ISO 27001:2022 underscores our dedication to providing top-tier security and IT services. This milestone strengthens our ability to protect our customers\u2019 data in an increasingly perilous digital world. Whether you are an educational institution or a business seeking robust cybersecurity, Overt Software Solutions can assist you better than ever. <\/span><a href=\"https:\/\/www.overtsoftware.id\/index.php\/contact\/\" target=\"_blank\" class=\"\" style=\"outline: none;\" data-css=\"tve-u-196807dde91\"><span data-contrast=\"none\" lang=\"EN-GB\"><span data-ccp-charstyle=\"Hyperlink\">Contact us<\/span><\/span><\/a><span data-contrast=\"auto\" lang=\"EN-GB\"> today for more information on how we can enhance your security and support your success.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">&nbsp;<\/span><\/p><\/div>","tve_custom_css":"@media (min-width: 300px){.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper { width: calc(50% - 10px); }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:nth-child(n+3) { margin-top: 20px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:not(:nth-child(n+3)) { margin-top: 0px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:not(:nth-child(2n)) { margin-right: 20px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:nth-child(2n) { margin-right: 0px !important; }[data-css=\"tve-u-195d21239ed\"] { font-size: var(--tve-font-size,16px); --tve-font-size: 16px; color: var(--tve-color,rgb(85,85,85)); --tve-color: rgb(85,85,85); --tcb-applied-color: rgb(85,85,85); line-height: var(--tve-line-height,1.6em); --tve-line-height: 1.6em; padding: 8px !important; }[data-css=\"tve-u-195d21239ed\"].tve-state-expanded { color: var(--tve-color,rgb(255,255,255)); --tve-color: rgb(255,255,255); --tcb-applied-color: rgb(255,255,255); background-image: linear-gradient(var(--tcb-local-color-4204a),var(--tcb-local-color-4204a)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-195d21239ed\"]:hover { background-image: linear-gradient(var(--tcb-local-color-ea1e7),var(--tcb-local-color-ea1e7)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; color: var(--tve-color,var(--tcb-local-color-4204a)) !important; --tve-color: var(--tcb-local-color-4204a) !important; --tcb-applied-color: var$(--tcb-local-color-4204a) !important; }[data-css=\"tve-u-17399fecc2c\"] { padding: 0px !important; }[data-css=\"tve-u-173dc8687ce\"] { padding: 0px !important; }[data-css=\"tve-u-173dc86929b\"] { padding: 0px !important; }[data-css=\"tve-u-1968078287d\"] { --tve-toc-indent: 20px; max-width: 1000px; float: none; padding: 15px !important; margin-left: auto !important; margin-right: auto !important; --tcb-local-color-4204a: var(--tcb-skin-color-0) !important; --tcb-local-color-ea1e7: rgba(214,93,0,0.08) !important; --tve-applied-max-width: 1000px !important; }[data-css=\"tve-u-1968078287f\"] { box-shadow: rgba(0, 0, 0, 0.08) 0px 5px 12px 1px; overflow: hidden; border-radius: 0px !important; background-image: linear-gradient(rgb(255, 255, 255), rgb(255, 255, 255)) !important; border-top: none !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }[data-css=\"tve-u-19680782881\"] { padding: 12px 5px !important; margin-bottom: -1px !important; margin-top: 0px !important; }:not(#tve) [data-css=\"tve-u-19680782881\"] > .tve-content-box-background { background-color: rgb(244, 244, 244) !important; --tve-applied-background-color: rgb(244,244,244) !important; }[data-css=\"tve-u-19680782881\"] .tve-toc-title-icon { font-size: 16px !important; width: 16px !important; height: 16px !important; }:not(#tve) [data-css=\"tve-u-19680782882\"] { letter-spacing: 2px; text-transform: uppercase !important; font-size: 13px !important; color: rgb(0, 0, 0) !important; --tcb-applied-color: rgb(0,0,0) !important; --tve-applied-color: rgb(0,0,0) !important; }[data-css=\"tve-u-19680782884\"] { float: none; width: 40px; z-index: 3; position: relative; margin: 0px auto 5px !important; padding: 0px !important; }[data-css=\"tve-u-19680782885\"] { border-top: 2px solid var(--tcb-local-color-4204a) !important; border-bottom: none !important; }[data-css=\"tve-u-19680782887\"] { padding: 0px !important; margin-top: 0px !important; margin-bottom: 10px !important; }[data-css=\"tve-u-19680782888\"] { overflow: hidden; border-radius: 15px !important; }:not(#tve) [data-css=\"tve-u-19680782888\"] { background-image: none !important; }[data-css=\"tve-u-1968078288a\"] { font-size: var(--tve-font-size,16px); --tve-font-size: 16px; color: var(--tve-color,rgb(85,85,85)); --tve-color: rgb(85,85,85); --tcb-applied-color: rgb(85,85,85); line-height: var(--tve-line-height,1.6em); --tve-line-height: 1.6em; padding: 8px !important; }[data-css=\"tve-u-1968078288a\"].tve-state-expanded { color: var(--tve-color,rgb(255,255,255)); --tve-color: rgb(255,255,255); --tcb-applied-color: rgb(255,255,255); background-image: linear-gradient(var(--tcb-local-color-4204a),var(--tcb-local-color-4204a)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-1968078288a\"]:hover { color: var(--tve-color,var(--tcb-local-color-4204a)) !important; --tve-color: var(--tcb-local-color-4204a) !important; --tcb-applied-color: var$(--tcb-local-color-4204a) !important; background-image: linear-gradient(var(--tcb-local-color-ea1e7),var(--tcb-local-color-ea1e7)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }[data-css=\"tve-u-1968078288f\"] { font-size: var(--tve-font-size,16px); --tve-font-size: 16px; color: var(--tve-color,rgb(85,85,85)); --tve-color: rgb(85,85,85); --tcb-applied-color: rgb(85,85,85); line-height: var(--tve-line-height,1.6em); --tve-line-height: 1.6em; padding: 8px !important; }[data-css=\"tve-u-1968078288f\"].tve-state-expanded { color: var(--tve-color,rgb(255,255,255)); --tve-color: rgb(255,255,255); --tcb-applied-color: rgb(255,255,255); background-image: linear-gradient(var(--tcb-local-color-4204a),var(--tcb-local-color-4204a)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }:not(#tve) [data-css=\"tve-u-1968078288f\"]:hover { color: var(--tve-color,var(--tcb-local-color-4204a)) !important; --tve-color: var(--tcb-local-color-4204a) !important; --tcb-applied-color: var$(--tcb-local-color-4204a) !important; background-image: linear-gradient(var(--tcb-local-color-ea1e7),var(--tcb-local-color-ea1e7)) !important; background-size: auto !important; background-position: 50% 50% !important; background-attachment: scroll !important; background-repeat: no-repeat !important; }[data-css=\"tve-u-1968078289c\"] { width: 1440px; --tve-border-width: 1px; border: 1px solid rgb(106, 107, 108); --tve-applied-border: 1px solid rgb(106,107,108); }[data-css=\"tve-u-1968078289d\"] { padding: 15px !important; }[data-css=\"tve-u-1968078289f\"] { border-radius: 20px; box-shadow: rgba(21, 69, 94, 0.22) 0px 0px 27px 0px; background-color: rgba(0, 169, 230, 0) !important; border-right: none !important; border-left: none !important; border-image: initial !important; }:not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] p, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] li, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] blockquote, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] address, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] .tcb-plain-text, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] label, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] h1, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] h2, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] h3, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] h4, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] h5, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828a1\"] h6 { color: var(--tve-color,rgb(0,0,0)); --tve-applied-color: var$(--tve-color,rgb(0,0,0)); --tcb-applied-color: rgb(0,0,0); }[data-css=\"tve-u-196807828a1\"] { --tve-color: rgb(0,0,0); --tve-applied---tve-color: rgb(0,0,0); }:not(#tve) [data-css=\"tve-u-196807828a3\"] { padding-bottom: 0px !important; margin-bottom: 0px !important; }[data-css=\"tve-u-196807828a4\"] { padding-top: 5px !important; padding-bottom: 5px !important; }[data-css=\"tve-u-196807828a6\"] { padding: 15px !important; }[data-css=\"tve-u-196807828a8\"] { border-radius: 20px; box-shadow: rgba(21, 69, 94, 0.22) 0px 0px 27px 0px; background-color: rgba(0, 169, 230, 0) !important; border-right: none !important; border-left: none !important; border-image: initial !important; }:not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] p, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] li, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] blockquote, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] address, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] .tcb-plain-text, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] label, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] h1, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] h2, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] h3, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] h4, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] h5, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828aa\"] h6 { color: var(--tve-color,rgb(0,0,0)); --tve-applied-color: var$(--tve-color,rgb(0,0,0)); --tcb-applied-color: rgb(0,0,0); }[data-css=\"tve-u-196807828aa\"] { --tve-color: rgb(0,0,0); --tve-applied---tve-color: rgb(0,0,0); }[data-css=\"tve-u-196807828ac\"] { margin-bottom: 0px !important; }[data-css=\"tve-u-196807828ad\"] { padding-bottom: 10px !important; }[data-css=\"tve-u-196807828af\"] { width: 100%; border: 1px solid rgb(106, 107, 108); --tve-applied-border: 1px solid rgb(106,107,108); margin-top: 10px !important; }:not(#tve) [data-css=\"tve-u-196807828b1\"] { padding-bottom: 10px !important; margin-bottom: 0px !important; }[data-css=\"tve-u-196807828b3\"] .tcb-button-link { letter-spacing: 2px; background-image: linear-gradient(var(--tcb-local-color-62516,rgb(19,114,211)),var(--tcb-local-color-62516,rgb(19,114,211))); --tve-applied-background-image: linear-gradient(var$(--tcb-local-color-62516,rgb(19,114,211)),var$(--tcb-local-color-62516,rgb(19,114,211))); background-size: auto; background-attachment: scroll; border-radius: 5px; padding-right: 18px; padding-bottom: 18px; padding-left: 18px; background-position: 50% 50%; background-repeat: no-repeat; padding-top: 18px !important; background-color: transparent !important; }[data-css=\"tve-u-196807828b3\"] .tcb-button-link span { color: rgb(255, 255, 255); --tcb-applied-color: #fff; }[data-css=\"tve-u-196807828b3\"] { --tcb-local-color-62516: var(--tcb-skin-color-0) !important; min-width: 100% !important; margin-top: 0px !important; margin-bottom: 0px !important; }[data-css=\"tve-u-196807828b5\"] { padding: 15px !important; }[data-css=\"tve-u-196807828b7\"] { border-radius: 20px; box-shadow: rgba(21, 69, 94, 0.22) 0px 0px 27px 0px; background-color: rgba(0, 169, 230, 0) !important; border-right: none !important; border-left: none !important; border-image: initial !important; }:not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] p, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] li, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] blockquote, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] address, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] .tcb-plain-text, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] label, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] h1, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] h2, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] h3, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] h4, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] h5, :not(#tve) .thrv-content-box [data-css=\"tve-u-196807828b9\"] h6 { color: var(--tve-color,rgb(0,0,0)); --tve-applied-color: var$(--tve-color,rgb(0,0,0)); --tcb-applied-color: rgb(0,0,0); }[data-css=\"tve-u-196807828b9\"] { --tve-color: rgb(0,0,0); --tve-applied---tve-color: rgb(0,0,0); }[data-css=\"tve-u-196807828bb\"] { margin-bottom: 0px !important; margin-top: 10px !important; }[data-css=\"tve-u-196807828bd\"] { padding-bottom: 10px !important; }[data-css=\"tve-u-196807828bf\"] { width: 100%; border: 1px solid rgb(106, 107, 108); --tve-applied-border: 1px solid rgb(106,107,108); margin-top: 10px !important; }:not(#tve) [data-css=\"tve-u-196807828c1\"] { padding-bottom: 10px !important; margin-bottom: 0px !important; }[data-css=\"tve-u-196807828c2\"] .tcb-button-link { letter-spacing: 2px; background-image: linear-gradient(var(--tcb-local-color-62516,rgb(19,114,211)),var(--tcb-local-color-62516,rgb(19,114,211))); --tve-applied-background-image: linear-gradient(var$(--tcb-local-color-62516,rgb(19,114,211)),var$(--tcb-local-color-62516,rgb(19,114,211))); background-size: auto; background-attachment: scroll; border-radius: 5px; padding: 18px; background-position: 50% 50%; background-repeat: no-repeat; background-color: transparent !important; }[data-css=\"tve-u-196807828c2\"] .tcb-button-link span { color: rgb(255, 255, 255); --tcb-applied-color: #fff; }[data-css=\"tve-u-196807828c2\"] { --tcb-local-color-62516: var(--tcb-skin-color-0) !important; min-width: 100% !important; margin-top: 0px !important; margin-bottom: 0px !important; }[data-css=\"tve-u-196807828c4\"] { width: 1440px; --tve-border-width: 1px; border: 1px solid rgb(106, 107, 108); --tve-applied-border: 1px solid rgb(106,107,108); }[data-css=\"tve-u-196807828c6\"] { --tve-alignment: center; float: none; margin-left: auto !important; margin-right: auto !important; }[data-css=\"tve-u-196807828c8\"] { width: 1440px; border: 1px solid rgb(106, 107, 108); --tve-applied-border: 1px solid rgb(106,107,108); }[data-css=\"tve-u-196807828ca\"] { width: 400px; --tve-alignment: center; float: none; margin-left: auto !important; margin-right: auto !important; }:not(#tve) [data-css=\"tve-u-196807dde91\"] { color: var(--tcb-skin-color-0) !important; --tve-applied-color: var$(--tcb-skin-color-0) !important; }}@media (max-width: 767px){[data-css=\"tve-u-195d21239ed\"] { font-size: var(--tve-font-size,15px); --tve-font-size: 15px; padding: 7px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper { width: calc(100% + 0px); }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:nth-child(n+2) { margin-top: 20px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:not(:nth-child(n+2)) { margin-top: 0px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:not(:nth-child(n)) { margin-right: 20px !important; }.tcb-post-list[data-css=\"tve-u-16ecb5f152b\"] .post-wrapper.thrv_wrapper:nth-child(n) { margin-right: 0px !important; }[data-css=\"tve-u-1968078287d\"] { padding: 10px 10px 20px !important; }[data-css=\"tve-u-1968078288a\"] { font-size: var(--tve-font-size,15px); --tve-font-size: 15px; padding: 7px !important; }[data-css=\"tve-u-1968078288f\"] { font-size: var(--tve-font-size,15px); --tve-font-size: 15px; padding: 7px !important; }[data-css=\"tve-u-1968078289f\"] { border-radius: 10px; border-width: initial !important; border-style: none !important; border-color: initial !important; }[data-css=\"tve-u-196807828a8\"] { border-radius: 10px; border-width: initial !important; border-style: none !important; border-color: initial !important; }[data-css=\"tve-u-196807828b7\"] { border-radius: 10px; border-width: initial !important; border-style: none !important; border-color: initial !important; }}","tve_user_custom_css":"","tve_globals":{"e":"1","font_cls":[]},"tcb2_ready":1,"tcb_editor_enabled":1,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[32,33],"tags":[],"class_list":["post-2887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sso-solutions","category-lms-solutions","post-wrapper","thrv_wrapper"],"_links":{"self":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts\/2887","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/comments?post=2887"}],"version-history":[{"count":5,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts\/2887\/revisions"}],"predecessor-version":[{"id":2901,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/posts\/2887\/revisions\/2901"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/media\/2902"}],"wp:attachment":[{"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/media?parent=2887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/categories?post=2887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.overtsoftware.id\/index.php\/wp-json\/wp\/v2\/tags?post=2887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}