ISO 27001:2013 to 2022 Control Mapping: Where Did A.14 Go?
ISO 27001:2022 restructured Annex A from 114 controls in 14 domains (A.5–A.18) into 93 controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). No control's substance was deleted — overlapping controls were merged into 24 consolidated ones, 58 were updated, and 11 are genuinely new (threat intelligence, cloud services security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding). The domain people search for most, A.14 (system acquisition, development and maintenance), landed almost entirely in the technological theme: secure development policy became 8.25, application security requirements 8.26, secure engineering principles 8.27, the change-control cluster merged into 8.32, environment separation into 8.31, outsourced development 8.30, security testing 8.29, and test data 8.33 — with requirements analysis folded into 5.8. The official correspondence tables are in ISO/IEC 27002:2022 Annex B. The transition period ended on 31 October 2025, so certificates against the 2013 edition are no longer valid — but the old numbering survives in questionnaires and contracts, and the practical work is updating your SoA, policies, and answer library to the 2022 numbering while keeping this translation table handy for everyone else's paperwork.
Type "A.14 ISO 27001" into a search engine and you'll find a small crowd looking for a domain that no longer exists. The 2013 numbering is embedded in security questionnaires, customer contracts, old audit reports, and policies written before 2022 — so even though the 2013 edition itself is dead, its numbering keeps turning up in paperwork you're expected to answer.
The formal status first: the transition period for ISO/IEC 27001:2022 ended on 31 October 2025. Certificates issued against 27001:2013 are no longer valid, and every audit now runs against the 2022 edition. What follows is the translation table between the two worlds — with a full walk-through of the domain people miss most.
The restructure in one view
ISO 27001:2013 had 114 controls in 14 domains (A.5 through A.18). The 2022 revision reorganized them into 93 controls in four themes:
- A.5 Organizational — 37 controls
- A.6 People — 8 controls
- A.7 Physical — 14 controls
- A.8 Technological — 34 controls
Nothing was simply deleted. Overlapping controls were merged into 24 consolidated ones, 58 were updated, and 11 are genuinely new — the full 2022 control set is covered in our complete Annex A guide. The official correspondence tables, in both directions, are published in ISO/IEC 27002:2022, Annex B — that's the authoritative source when a mapping question gets contentious.
Where each 2013 domain went
| 2013 domain | Where it lives in 2022 |
|---|---|
| A.5 Information security policies | 5.1 |
| A.6 Organization of information security | 5.2–5.4 and 5.8; mobile devices → 8.1, teleworking → 6.7 |
| A.7 Human resource security | The People theme: 6.1–6.6 |
| A.8 Asset management | 5.9–5.13 (inventory, acceptable use, return, classification, labelling); storage media → 7.10 |
| A.9 Access control | Policy and identity side → 5.15–5.18; technical side → 8.2–8.5 and 8.18 |
| A.10 Cryptography | 8.24 |
| A.11 Physical and environmental security | The Physical theme: 7.1–7.14 |
| A.12 Operations security | Mostly Technological: 8.6–8.8, 8.13, 8.15–8.17, 8.19, 8.31, 8.32, 8.34; operating procedures → 5.37 |
| A.13 Communications security | Networks → 8.20–8.22; information transfer → 5.14; confidentiality agreements → 6.6 |
| A.14 System acquisition, development and maintenance | 8.25–8.33, plus 5.8 — full table below |
| A.15 Supplier relationships | 5.19–5.23 |
| A.16 Incident management | 5.24–5.28; event reporting by staff → 6.8 |
| A.17 Business continuity | 5.29–5.30; redundancy → 8.14 |
| A.18 Compliance | 5.31–5.36; technical compliance review folded into 8.8 |
Where did A.14 go?
A.14 — system acquisition, development and maintenance — is the domain software companies knew best, which is why its disappearance generates so many searches. It didn't disappear; it moved almost entirely into the technological theme:
| 2013 control | 2022 control |
|---|---|
| 14.1.1 Security requirements analysis and specification | 5.8 Information security in project management (merged with 6.1.5) |
| 14.1.2 Securing application services on public networks | 8.26 Application security requirements |
| 14.1.3 Protecting application services transactions | |
| 14.2.1 Secure development policy | 8.25 Secure development life cycle |
| 14.2.2 System change control procedures | 8.32 Change management (merged with 12.1.2) |
| 14.2.3 Technical review after operating platform changes | |
| 14.2.4 Restrictions on changes to software packages | |
| 14.2.5 Secure system engineering principles | 8.27 Secure system architecture and engineering principles |
| 14.2.6 Secure development environment | 8.31 Separation of development, test and production environments (merged with 12.1.4) |
| 14.2.7 Outsourced development | 8.30 Outsourced development |
| 14.2.8 System security testing | 8.29 Security testing in development and acceptance |
| 14.2.9 System acceptance testing | |
| 14.3.1 Protection of test data | 8.33 Test information |
If you build software, the heart of old A.14 is now the 8.25–8.28 cluster — covered control-by-control in our secure development controls guide.
The 11 genuinely new controls
These had no 2013 predecessor — if your ISMS was built on the old standard and never re-baselined, these are the rows most likely missing from your Statement of Applicability:
- 5.7 Threat intelligence — collect and analyze information about threats
- 5.23 Information security for use of cloud services — acquiring, using, and exiting cloud services
- 5.30 ICT readiness for business continuity — recovery capability planned and tested
- 7.4 Physical security monitoring — premises monitored for unauthorized access
- 8.9 Configuration management — configurations established, documented, monitored
- 8.10 Information deletion — data deleted when no longer required
- 8.11 Data masking — masking per policy and business requirements
- 8.12 Data leakage prevention — applied to systems handling sensitive information
- 8.16 Monitoring activities — networks and systems monitored for anomalous behaviour
- 8.23 Web filtering — access to external websites managed
- 8.28 Secure coding — secure coding principles applied to development
Ready to Streamline Your Compliance?
Discover how AuditBadger can simplify your compliance management process.
What you actually need to update
- Your Statement of Applicability. Re-issued on 2022 numbering, all 93 controls considered — the new controls explicitly decided on, not silently absent. (Structure and worked example in our SoA guide.)
- Policies that cite control numbers. A policy referencing "per A.12.4.1" now points at nothing; sweep documents for old references.
- Your questionnaire answer library. Customers' security questionnaires still ask about 2013 controls, and will for years. Keep the mapping handy and answer in their numbering with yours in parentheses — it reads as competence, not pedantry.
- Contracts that name 2013 controls. No need to panic or renegotiate; the substance survived the renumbering. Respond with the mapped 2022 control when compliance is queried.
One companion change worth knowing while you're modernizing references: in February 2024, Amendment 1 added climate change considerations to the clause side of the standard — two sentences most teams still haven't heard about, covered in our amendment guide.
The renumbering was cosmetic in substance and disruptive in paperwork — which is precisely the kind of change worth handling with a lookup table instead of an afternoon of searching. For what the 2022 controls actually require, start with the Annex A guide; for the mandatory clauses behind them, the clauses 4–10 series.
Frequently asked questions
How many controls does ISO 27001:2022 have compared to 2013? +
The 2013 edition had 114 controls organized into 14 domains (A.5 through A.18). The 2022 edition has 93 controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). The reduction came from consolidation, not deletion — overlapping controls were merged into 24 consolidated ones, 58 were updated, and 11 controls are genuinely new.
What happened to Annex A.14 in ISO 27001:2022? +
A.14 (system acquisition, development and maintenance) was redistributed, mostly into the technological theme: secure development policy became 8.25, application security requirements 8.26 (merging 14.1.2 and 14.1.3), secure engineering principles 8.27, security testing 8.29 (merging 14.2.8 and 14.2.9), outsourced development 8.30, environment separation 8.31, the change-control cluster 8.32, and test data 8.33. Security requirements analysis (14.1.1) moved to 5.8, information security in project management. The substance survived — only the numbering changed.
What are the 11 new controls in ISO 27001:2022? +
The controls with no 2013 predecessor are: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering, and 8.28 secure coding. If your ISMS was built on the 2013 standard and never re-baselined, these are the rows most likely missing from your Statement of Applicability.
Is ISO 27001:2013 still valid? +
No. The transition period ended on 31 October 2025 — certificates issued against ISO/IEC 27001:2013 are no longer valid, and all certification and surveillance audits now run against the 2022 edition. The old numbering still appears in security questionnaires, contracts, and older content, which is why a 2013-to-2022 mapping remains useful even though the 2013 edition itself is retired.
Where is the official mapping between ISO 27001:2013 and 2022 controls published? +
In ISO/IEC 27002:2022, Annex B, which contains the correspondence tables in both directions — 2022 controls to their 2013 predecessors and vice versa. When a mapping question gets contentious, for example in a customer security review, Annex B is the authoritative reference to cite.