Here are some of the main differences between ISO 27001:2022 and ISO 27001:2013. Each difference also has the related article for more details:
1st Difference – Number of Controls:
ISO 27001:2022 now has 93 controls compared to 114 controls in ISO 27001:2013. There are 11 new controls in the 2022 version of the standard1. 56 controls in ISO/IEC 27001:2013 have been merged into 24 controls in ISO/IEC 27001:2022.
2nd Difference – Structure of Controls:
The controls in ISO 27001:2022 are organized into 4 themes: Organizational, People, Physical, and Technical1. This is a change from the 14 sections in ISO 27001:2013.
3st Difference – Holistic Approach:
While ISO 27001:2013 primarily focused on the CIA triad (confidentiality, integrity, availability) in risk assessment, ISO 27001:2022 adopts a more holistic approach2. It encourages organizations to consider a wide range of threats and vulnerabilities, including physical security, personnel security, and business continuity, among others.
4th Difference – New Requirements:
Several clauses were reworded or reordered in ISO/IEC 27001:20221. There are minimal new requirements in clauses 4-101. However, the change in clause 4.4 will significantly impact how an organization manages their ISMS.
5th Difference -Transition Period:
Organizations will have 36 months from the last day of the publication month (i.e., 31 October 2025) to transition to the new version of the standard.
ISO 27001 Related Documents:
https://www.isaca.de/sites/default/files/isaca_2017_implementation_guideline_isoiec27001_screen.pdf
Find Us immediately for the Security Assessment in Hong Kong, United Kingdom, Europe, Estonia, Singapore…
Facebook:
https://www.facebook.com/ITSec-Security-Consulting-237738580247975
Google:
https://itsecsecurityconsulting.business.site/?m=true
Website:
Case Reference:
https://sraa-com-hk.preview-domain.com/security-assessment-and-audit-case-reference
找電腦老師 Information for game, football, mobile, anime and iphone