ISO/IEC 27001:2022 has 93 Annex A controls across four themes, including 11 new controls covering cloud security, threat intelligence, data leakage, and secure coding.
All controls must be considered in the Statement of Applicability.

ISO/IEC 27001:2022 has 93 Annex A controls across four themes, including 11 new controls covering cloud security, threat intelligence, data leakage, and secure coding.
All controls must be considered in the Statement of Applicability.
A risk register is only useful if someone reads it.
Keep it active, assign real owners, and review it when risks change.
Risk management should be used, not just filed.
[[email protected]](mailto:[email protected])
Introducing our Virtual Chief AI Officer (vCAIO) service.
AI governance, risk, ISO 42001, EU AI Act and NIST AI RMF, managed at executive level on a fractional basis.
Learn more: riskprofs.com/virtual-chief-ai-officer
Cybersecurity, AI, and business resilience shouldn’t operate in silos.
Our Virtual Chief Governance Officer (vCGO) provides integrated governance, risk management, and board-level oversight across all three.
Learn more: riskprofs.com/virtual-chief-governance-officer
Build resilience before disruption happens.
Our Virtual Business Resilience Manager (vBRM) provides expert business continuity, disaster recovery and crisis management support aligned with ISO 22301.
Learn more: riskprofs.com/virtual-business-resilience-manager