ISO Compliance Governance Knowledge Hub

ISO 27001:2013 to 2022 Control Mapping: Where Did A.14 Go?

Maciej
ISO 27001:2013 to 2022 Control Mapping: Where Did A.14 Go?
TL;DR

ISO 27001:2022 restructured Annex A from 114 controls in 14 domains (A.5–A.18) into 93 controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). No control's substance was deleted — overlapping controls were merged into 24 consolidated ones, 58 were updated, and 11 are genuinely new (threat intelligence, cloud services security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding). The domain people search for most, A.14 (system acquisition, development and maintenance), landed almost entirely in the technological theme: secure development policy became 8.25, application security requirements 8.26, secure engineering principles 8.27, the change-control cluster merged into 8.32, environment separation into 8.31, outsourced development 8.30, security testing 8.29, and test data 8.33 — with requirements analysis folded into 5.8. The official correspondence tables are in ISO/IEC 27002:2022 Annex B. The transition period ended on 31 October 2025, so certificates against the 2013 edition are no longer valid — but the old numbering survives in questionnaires and contracts, and the practical work is updating your SoA, policies, and answer library to the 2022 numbering while keeping this translation table handy for everyone else's paperwork.

Type "A.14 ISO 27001" into a search engine and you'll find a small crowd looking for a domain that no longer exists. The 2013 numbering is embedded in security questionnaires, customer contracts, old audit reports, and policies written before 2022 — so even though the 2013 edition itself is dead, its numbering keeps turning up in paperwork you're expected to answer.

The formal status first: the transition period for ISO/IEC 27001:2022 ended on 31 October 2025. Certificates issued against 27001:2013 are no longer valid, and every audit now runs against the 2022 edition. What follows is the translation table between the two worlds — with a full walk-through of the domain people miss most.

The restructure in one view

ISO 27001:2013 had 114 controls in 14 domains (A.5 through A.18). The 2022 revision reorganized them into 93 controls in four themes:

  • A.5 Organizational — 37 controls
  • A.6 People — 8 controls
  • A.7 Physical — 14 controls
  • A.8 Technological — 34 controls

Nothing was simply deleted. Overlapping controls were merged into 24 consolidated ones, 58 were updated, and 11 are genuinely new — the full 2022 control set is covered in our complete Annex A guide. The official correspondence tables, in both directions, are published in ISO/IEC 27002:2022, Annex B — that's the authoritative source when a mapping question gets contentious.

Where each 2013 domain went

2013 domainWhere it lives in 2022
A.5 Information security policies5.1
A.6 Organization of information security5.2–5.4 and 5.8; mobile devices → 8.1, teleworking → 6.7
A.7 Human resource securityThe People theme: 6.1–6.6
A.8 Asset management5.9–5.13 (inventory, acceptable use, return, classification, labelling); storage media → 7.10
A.9 Access controlPolicy and identity side → 5.15–5.18; technical side → 8.2–8.5 and 8.18
A.10 Cryptography8.24
A.11 Physical and environmental securityThe Physical theme: 7.1–7.14
A.12 Operations securityMostly Technological: 8.6–8.8, 8.13, 8.15–8.17, 8.19, 8.31, 8.32, 8.34; operating procedures → 5.37
A.13 Communications securityNetworks → 8.20–8.22; information transfer → 5.14; confidentiality agreements → 6.6
A.14 System acquisition, development and maintenance8.25–8.33, plus 5.8 — full table below
A.15 Supplier relationships5.19–5.23
A.16 Incident management5.24–5.28; event reporting by staff → 6.8
A.17 Business continuity5.29–5.30; redundancy → 8.14
A.18 Compliance5.31–5.36; technical compliance review folded into 8.8

Where did A.14 go?

A.14 — system acquisition, development and maintenance — is the domain software companies knew best, which is why its disappearance generates so many searches. It didn't disappear; it moved almost entirely into the technological theme:

2013 control2022 control
14.1.1 Security requirements analysis and specification5.8 Information security in project management (merged with 6.1.5)
14.1.2 Securing application services on public networks8.26 Application security requirements
14.1.3 Protecting application services transactions
14.2.1 Secure development policy8.25 Secure development life cycle
14.2.2 System change control procedures8.32 Change management (merged with 12.1.2)
14.2.3 Technical review after operating platform changes
14.2.4 Restrictions on changes to software packages
14.2.5 Secure system engineering principles8.27 Secure system architecture and engineering principles
14.2.6 Secure development environment8.31 Separation of development, test and production environments (merged with 12.1.4)
14.2.7 Outsourced development8.30 Outsourced development
14.2.8 System security testing8.29 Security testing in development and acceptance
14.2.9 System acceptance testing
14.3.1 Protection of test data8.33 Test information

If you build software, the heart of old A.14 is now the 8.25–8.28 cluster — covered control-by-control in our secure development controls guide.

The 11 genuinely new controls

These had no 2013 predecessor — if your ISMS was built on the old standard and never re-baselined, these are the rows most likely missing from your Statement of Applicability:

  • 5.7 Threat intelligence — collect and analyze information about threats
  • 5.23 Information security for use of cloud services — acquiring, using, and exiting cloud services
  • 5.30 ICT readiness for business continuity — recovery capability planned and tested
  • 7.4 Physical security monitoring — premises monitored for unauthorized access
  • 8.9 Configuration management — configurations established, documented, monitored
  • 8.10 Information deletion — data deleted when no longer required
  • 8.11 Data masking — masking per policy and business requirements
  • 8.12 Data leakage prevention — applied to systems handling sensitive information
  • 8.16 Monitoring activities — networks and systems monitored for anomalous behaviour
  • 8.23 Web filtering — access to external websites managed
  • 8.28 Secure coding — secure coding principles applied to development

Ready to Streamline Your Compliance?

Discover how AuditBadger can simplify your compliance management process.

What you actually need to update

  • Your Statement of Applicability. Re-issued on 2022 numbering, all 93 controls considered — the new controls explicitly decided on, not silently absent. (Structure and worked example in our SoA guide.)
  • Policies that cite control numbers. A policy referencing "per A.12.4.1" now points at nothing; sweep documents for old references.
  • Your questionnaire answer library. Customers' security questionnaires still ask about 2013 controls, and will for years. Keep the mapping handy and answer in their numbering with yours in parentheses — it reads as competence, not pedantry.
  • Contracts that name 2013 controls. No need to panic or renegotiate; the substance survived the renumbering. Respond with the mapped 2022 control when compliance is queried.

One companion change worth knowing while you're modernizing references: in February 2024, Amendment 1 added climate change considerations to the clause side of the standard — two sentences most teams still haven't heard about, covered in our amendment guide.

The renumbering was cosmetic in substance and disruptive in paperwork — which is precisely the kind of change worth handling with a lookup table instead of an afternoon of searching. For what the 2022 controls actually require, start with the Annex A guide; for the mandatory clauses behind them, the clauses 4–10 series.

FAQ

Frequently asked questions

How many controls does ISO 27001:2022 have compared to 2013? +

The 2013 edition had 114 controls organized into 14 domains (A.5 through A.18). The 2022 edition has 93 controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). The reduction came from consolidation, not deletion — overlapping controls were merged into 24 consolidated ones, 58 were updated, and 11 controls are genuinely new.

What happened to Annex A.14 in ISO 27001:2022? +

A.14 (system acquisition, development and maintenance) was redistributed, mostly into the technological theme: secure development policy became 8.25, application security requirements 8.26 (merging 14.1.2 and 14.1.3), secure engineering principles 8.27, security testing 8.29 (merging 14.2.8 and 14.2.9), outsourced development 8.30, environment separation 8.31, the change-control cluster 8.32, and test data 8.33. Security requirements analysis (14.1.1) moved to 5.8, information security in project management. The substance survived — only the numbering changed.

What are the 11 new controls in ISO 27001:2022? +

The controls with no 2013 predecessor are: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering, and 8.28 secure coding. If your ISMS was built on the 2013 standard and never re-baselined, these are the rows most likely missing from your Statement of Applicability.

Is ISO 27001:2013 still valid? +

No. The transition period ended on 31 October 2025 — certificates issued against ISO/IEC 27001:2013 are no longer valid, and all certification and surveillance audits now run against the 2022 edition. The old numbering still appears in security questionnaires, contracts, and older content, which is why a 2013-to-2022 mapping remains useful even though the 2013 edition itself is retired.

Where is the official mapping between ISO 27001:2013 and 2022 controls published? +

In ISO/IEC 27002:2022, Annex B, which contains the correspondence tables in both directions — 2022 controls to their 2013 predecessors and vice versa. When a mapping question gets contentious, for example in a customer security review, Annex B is the authoritative reference to cite.

Keep reading

More implementation notes and operator context from the same topic area.

Next step

Ready to replace scattered compliance work?

See how AuditBadger turns policies, evidence, risks, and audit prep into one operating system for lean teams.

Start Subscription