Is there any updated documentation on the ISO/IEC 27001:2022 Azure regulatory compliance initiative?

Lucas Kuiper 5 Reputation points
2025-08-05T12:00:19.28+00:00

The ISO/IEC 27001:2022 initiative is now (finally) included in Azure but it contains some weird required parameters at assigning the initiative that really need some explanation.

Furthermore, what I noticed was that the 2013 version contains 452 policies, whereas the newer 2022 version only has 63 policies. Or should we see this as an add-on to the set of policies in the 2013 version? When searching for an explanation in the documentation at ISO/IEC 27001 - Azure Compliance | Microsoft Learn the 2022 version is mentioned but everything else is still based on the 2013 version and only links to an overview of the policies in the 2013 initiative.

It would be helpful if someone could elaborate on this!

Also check:
https://learn.microsoft.com/en-us/answers/questions/1414185/azure-initiative-for-iso-27001-2022

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.