Transitioning with Confidence: Embracing ISO/IEC 27001:2022
ISO 27001, an international standard for information security management systems (ISMS), provides a framework to establish, implement, and continually improve security practices. Recently, ISO/IEC 27001:2022 was released, superseding the previous 2013 edition. So what's new?
Karolína Kubínová works at axelum as a Security Analyst specializing in preparing companies for security certifications, conducting internal audits and improving security processes (mainly based on ISO 27K, KB Act and best practices). She also works on social engineering, especially phishing and vishing campaigns, and security awareness.
The Latest in ISO/IEC 27001:2022
The ISO/IEC 27001:2022 updates bring noteworthy changes, mainly showcased in Annex A. But it's not just about Annex A – the new version also brings subtle enhancements. Terminology has been clarified, sentences have been revamped for better understanding, and paragraphs restructured for clarity.
So, what's different? ISO/IEC 27001:2022 now places a greater spotlight on documenting information security objectives and evaluating performance (think monitoring and measurement). There's also a call for methodical, controlled adjustments to the information security management system.
In the realm of Operational Planning and Control, organisations are now tasked with planning, executing, and managing processes to hit their information security objectives. This involves setting up process criteria and implementing controls that align with those criteria. It's all part of the evolving landscape of ISO/IEC 27001:2022.
Revamping Annex A
Annex A's controls have transformed. The total number of controls has been slimmed down from 114 to 93 with a blend of merging and adding. And while the control family has become leaner, it's also become smarter. This streamlined approach means a more effective and succinct set of controls. And speaking of controls, ISO 27002, the security control guru, has also had a 2022 update.
Out of those 93 controls, 35 remain unchanged, 23 have been given a fresh name, 56 have cosied up into 24 pairs, and one has turned into a dynamic duo. Not stopping there, 11 newcomers have joined the control party.
- Information security policies
- Organisation of information security
- Human resources security
- Asset management
- Access control
- Cryptography
- Physical and environmental security
- Operational security
- Communications security
- System acquisition, development and maintenance
- Supplier relationships
- Information security incident management
- Information security aspects of business continuity management
- Compliance
- People controls
- Organizational controls
- Technological controls
- Physical controls
and 11 new controls
- Threat intelligence
- Information security for the use of cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
Attributes for Control Clarity
Now each control has several attributes assigned to it. Including control attributes in the standard provides a standardised method for organising and categorising controls that allow efficient sorting and filtering. This facilitates the identification of specific requirements for different departments or groups within an organisation.
The standard provides a clear representation of control attributes:
- Control type: preventive, detective, corrective.
- Information security properties: confidentiality, integrity, availability.
- Cyber security concepts: identify, detect, protect, respond, recover.
- Operational capabilities: application security, asset management, continuity, governance, human resource security, identity and access management, information protection, information security assurance, information security event management, legal and compliance, physical security, secure configuration, system and network security, supplier relationships security, threat and vulnerability management.
- Security domains: defence, governance and ecosystem, protection and resilience.
Smooth Transition to ISO/IEC 27001:2022
Please note that the new update does not affect your current certification. ISO 27001:2013 certification is still valid until October 31, 2025. However, it is advisable for companies to start updating their controls and processes to comply with the requirements of the new revision as soon as possible.
Here's the timeline breakdown:
What Needs to Be Done?
Don’t Be Afraid to Ask for Assistance!
Whether you’re adapting existing ISMS or implementing the standard from scratch, we’re here to help you every step of the way! At axelum, we understand the importance of a seamless transition to ISO/IEC 27001:2022, and we are dedicated to providing you with the necessary support and expertise.
With our team of experts and extensive experience with information security management, we offer comprehensive support tailored to meet your specific needs. Our services include conducting thorough gap analyses, developing customised transition plans, and providing expert guidance on updating policies, procedures, and documentation to align with the new ISO/IEC 27001:2022 requirements.
Read More
Right in Your Inbox
Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.