ISO 27001, the international standard for Information Security Management Systems (ISMS), underwent a significant revision in 2022. One of the key changes was the introduction of new requirements. This article will explore these new requirements in detail, comparing them with those of ISO 27001:2013 (New Requirements in ISO 27001:2022).
New Requirements in ISO 27001:2013
The 2013 version of ISO 27001 introduced a set of requirements that organizations needed to fulfill to establish, implement, maintain, and continually improve an ISMS1. These requirements were spread across various clauses, including understanding the organization and its context, leadership and commitment, policy, organizational roles, responsibilities and authorities, planning, support, operation, performance evaluation, and improvement2.
New Requirements in ISO 27001:2022
The 2022 revision of ISO 27001 introduced several new requirements34. Here are some of the key additions:
- Clause 3: Added links for ISO and IEC databases.
- Clause 4.2 ©: Added a new bullet requiring an analysis of which of the interested party requirements must be addressed through the ISMS.
- Clause 4.4: Added a requirement to establish, implement, maintain, and continually improve processes and their interactions.
- Clause 5.1: Added a Note to clarify the term “business”.
- Clause 6.3: Added a new section for “Planning of Changes”.
These new requirements reflect the evolving cybersecurity landscape and the need for organizations to have a comprehensive understanding of their information security risks4.
Conclusion – New Requirements in ISO 27001:2022
The introduction of new requirements in ISO 27001:2022 represents a significant evolution of the standard. By adding these new requirements, the standard helps organizations to develop a more comprehensive and effective ISMS. However, it’s important for organizations to understand these changes and adapt their ISMS accordingly to ensure continued compliance with the standard.
ISO 27001 Services
ITSec Security Consulting Limited provides ISO 27001 Consulting and Certification. Our experts can guide you through the process of achieving ISO 27001 certification, ensuring that your business meets the highest standards of information security.
ISO 27001 Related Documents:
https://www.isaca.de/sites/default/files/isaca_2017_implementation_guideline_isoiec27001_screen.pdf
Find Us immediately for the Security Assessment in Hong Kong, United Kingdom, Europe, Estonia, Singapore…
Facebook:
https://www.facebook.com/ITSec-Security-Consulting-237738580247975
Google:
https://itsecsecurityconsulting.business.site/?m=true
Website:
Case Reference:
https://sraa-com-hk.preview-domain.com/security-assessment-and-audit-case-reference
找電腦老師 Information for game, football, mobile, anime and iphone