ISO 27001:2022 Technical Controls and Certification Guide
A practical guide to ISO 27001:2022 technical controls, ISO 27001 vulnerability management (8.8), configuration management (8.9), certification and evidence.
By NetGuardUpdated: 7 min readنسخه فارسی

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It defines how an organization identifies, assesses and treats information security risks with appropriate controls, and keeps improving that process. The ISO 27001:2022 technical controls in Annex A, such as vulnerability management and configuration management, are where the standard meets day-to-day infrastructure work. It is the only standard in the 27000 family you can be certified against.
For many organizations, ISO 27001 certification is a prerequisite for enterprise customers, international partners and public-sector contracts. Its real value, though, is the structure it gives security. This guide covers ISMS basics, the 2022 revision, the technological controls relevant to hardening and vulnerabilities, the certification process and the evidence auditors ask for.
What is ISO 27001 and how does an ISMS work?
An ISMS is the set of policies, processes, roles and controls that turns information security into a repeatable management process. Clauses 4 to 10 of the standard set out its requirements:
- Clause 4 – Context: internal and external issues, interested parties and the ISMS scope.
- Clause 5 – Leadership: top management commitment, the security policy, roles and responsibilities.
- Clause 6 – Planning: risk assessment and treatment, security objectives and the Statement of Applicability (SoA).
- Clause 7 – Support: resources, competence, awareness, communication and documented information.
- Clause 8 – Operation: carrying out risk assessment and treatment in practice.
- Clause 9 – Performance evaluation: monitoring and measurement, internal audit and management review.
- Clause 10 – Improvement: nonconformities, corrective action and continual improvement.
Annex A provides a reference list of controls. Based on its risk assessment, the organization selects the controls it needs and records in the SoA why each control is included or excluded. The companion standard ISO/IEC 27002 explains how to implement each control, but certification is always against ISO 27001.
What changed in ISO 27001:2022: four control themes
The 2022 edition was the largest revision since 2013. The previous 114 controls in 14 domains were reorganized into 93 controls in four themes; some were merged and 11 new controls were added. The transition period from the 2013 version ended on 31 October 2025, so valid certificates must now be against the 2022 edition.
| Theme | Numbering | Controls | Examples |
|---|---|---|---|
| Organizational | 5.1–5.37 | 37 | Policies, asset inventory, threat intelligence, incidents |
| People | 6.1–6.8 | 8 | Screening, awareness and training, remote working |
| Physical | 7.1–7.14 | 14 | Perimeters, physical security monitoring, equipment |
| Technological | 8.1–8.34 | 34 | Vulnerabilities, configuration, logging, networks, crypto |
The new controls are threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28). ISO 27002:2022 also tags each control with attributes, such as control type and cybersecurity concepts, which makes mapping to frameworks like NIST CSF easier.
ISO 27001:2022 technical controls for hardening and vulnerabilities
Most infrastructure and security engineering work lives in the technological theme. These controls relate directly to system hardening and vulnerability management:
| Control | Title | In practice |
|---|---|---|
| 8.7 | Protection against malware | Active, updated anti-malware/EDR on all systems |
| 8.8 | Management of technical vulnerabilities | Regular scans, risk assessment, patching on deadline |
| 8.9 | Configuration management | Documented secure baselines, audits, drift detection |
| 8.15 | Logging | Security logs enabled, retained and protected |
| 8.16 | Monitoring activities | Networks and systems monitored for anomalies |
| 8.20 | Networks security | Hardened network devices, controlled traffic |
| 8.22 | Segregation of networks | Segmentation between groups of systems and services |
| 8.23 | Web filtering | Restricted access to malicious websites |
| 8.32 | Change management | Changes recorded and approved before deployment |
Control 8.8: ISO 27001 vulnerability management
Control 8.8 requires the organization to obtain information about technical vulnerabilities of the systems in use, evaluate its exposure and take appropriate measures. In practice that means a complete asset inventory, regular (ideally authenticated) vulnerability scanning, prioritization by severity, exploit likelihood and asset criticality, defined remediation deadlines, and rescans to confirm fixes. Our vulnerability management lifecycle guide walks through the full process.
Control 8.9: configuration management
New in 2022, control 8.9 requires that configurations, including security configurations, of hardware, software, services and networks are established, documented, implemented, monitored and reviewed. The simplest path is to adopt recognized guides such as CIS Benchmarks as your baseline, tailor them, and audit automatically to detect drift.
The ISO 27001 certification process
Certification is granted by an accredited certification body. The typical path:
- Define the scope: which business units, locations and systems are inside the ISMS.
- Assess risk and write the SoA: identify risks, select controls and document the Statement of Applicability.
- Implement and build records: run the controls long enough to produce operating history.
- Internal audit and management review: test the ISMS yourself and fix nonconformities before the external audit.
- Stage 1 audit: the auditor reviews documentation, scope and readiness.
- Stage 2 audit: through interviews and sampling, the auditor tests whether controls operate effectively.
- Surveillance audits: the certificate is valid for three years, with surveillance audits at least annually and a recertification audit at the end of the cycle.

Findings are usually classed as major or minor nonconformities. A major nonconformity, such as no working vulnerability management process, can block certification until corrective action is taken and verified.
What evidence do ISO 27001 auditors ask for?
Auditors want records, not assurances. For technical controls, expect requests for:
- The SoA, risk assessment report and risk treatment plan
- An up-to-date asset inventory with owners
- Vulnerability scan reports over several consecutive periods, remediation tickets and rescan results
- Secure configuration baselines and compliance reports against them
- Change management records and approvals
- Sample logs and evidence that they are reviewed
- Internal audit reports, management review minutes and corrective action records
- Documented exceptions and risk acceptance for systems that cannot be patched
Auditors look for trends, not snapshots. Several monthly scan reports showing critical vulnerabilities going down are far more convincing than one clean report produced the week before the audit. For a broader view of evidence and framework mapping, see our security compliance guide.
How NetGuard helps with ISO 27001
NetGuard covers the technical side of controls 8.8 and 8.9: authenticated and agentless vulnerability scanning of servers, network devices, endpoints and databases; hardening audits against CIS Benchmarks and your own baselines; configuration drift detection; and risk-based prioritization using known-exploited vulnerabilities and asset criticality. Findings are mapped to ISO 27001 controls, rescans verify remediation, and dated reports in English and Persian give auditors the trend evidence they look for. Learn more on our compliance page.
Frequently asked questions
What is ISO 27001?
ISO 27001 is the international standard for an information security management system (ISMS). It defines requirements for establishing, implementing, maintaining and continually improving information security, with controls selected from Annex A based on a risk assessment. It is certifiable, and the current edition, ISO/IEC 27001:2022, contains 93 controls in four themes: organizational, people, physical and technological.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 sets the requirements for the management system and lists the Annex A controls; certification is issued against it. ISO 27002 is implementation guidance that explains the purpose of each control and how to apply it in more detail. Organizations use 27002 to build their controls, but audits and certificates are always based on 27001.
How many controls are in ISO 27001:2022?
ISO 27001:2022 Annex A contains 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Compared with the 2013 edition, which had 114 controls across 14 domains, several controls were merged and 11 new ones were added, including threat intelligence, configuration management, data leakage prevention and web filtering.
What does ISO 27001 control 8.8 require?
Control 8.8, management of technical vulnerabilities, requires obtaining information about vulnerabilities in the systems you use, evaluating your exposure and taking appropriate action such as patching or compensating controls. Typical evidence includes periodic scan reports, risk-based prioritization, remediation tickets with deadlines and rescans that confirm vulnerabilities were actually fixed.
How long does ISO 27001 certification take?
There is no fixed timeline; it depends on scope size, current security maturity and available resources. Organizations with basic security processes already in place move faster. In most cases controls need to run for a while before the Stage 2 audit so there are operating records, such as several vulnerability scan cycles and an internal audit, to show the auditor.
- #ISO 27001:2022 technical controls
- #ISO 27001 vulnerability management
- #ISO 27001 Annex A
- #ISO 27001 control 8.8
- #ISO 27001 certification
- #ISMS




