
ISO 27001 defines the framework for an Information Security Management System for businesses of any size, structure, or orientation. The title of the ISO/IEC 27001:2022 Standard has been changed from “Information Technology – Security Techniques” to “Information Security, Cybersecurity, and Privacy Protection” in order to cover a broader range of security controls.
By implementing ISO/IEC 27001:2022, organizations can demonstrate their commitment to protecting their information assets and ensuring the confidentiality, integrity, and availability of their information.
1- Increased focus on risk management:
The new version of the standard places a greater emphasis on risk management, with a specific focus on identifying, assessing, and treating information security risks.
2- Enhanced guidance on security controls:
The updated standard provides more detailed guidance on implementing security controls, including a new annex with a list of suggested security controls.
3- Revised structure and terminology:
The structure and terminology of the standard have been revised to align with other ISO management system standards, making it easier for organizations to integrate their information security management system with other management systems.
4- Greater emphasis on context and stakeholders:
The new version of the standard emphasizes the importance of understanding the context of the organization and its stakeholders when developing and implementing an ISMS.
5- Updated requirements for documentation:
The standard has updated requirements for documenting information security management processes and procedures, with a focus on ensuring that documentation is relevant and useful for the organization.
The standard refined 06 clauses, added 1 clause, rewrote 1 clause, and split 2 clauses. The description of the clauses are given below:-
Fig 1: – Changes in ISO/IEC 27001:2022
The number of controls in Annex A has been reduced from 114 to 93. The reduction in the number of controls is primarily due to the consolidation of many of them. 35 controls have remained the same, 23 have been renamed, 57 have been merged into 24 controls, and one has been divided into two.
The 93 controls have been divided into four groups or sections.
The 11 new controls are:-
Each control’s layout includes the control’s title, attribute table, purpose, guidance, and other information.
By implementing ISO/IEC 27001:2022, organizations can benefit in a number of ways, including:
Overall, ISO/IEC 27001:2022 provides a comprehensive framework for managing information security risks and protecting sensitive information and assets. By implementing this standard, organizations can demonstrate their commitment to information security and gain a competitive advantage in the marketplace.
Servosys Solutions is a unit of EML Consultancy Services Private Limited, a company headquartered in New Delhi, India. We are one of the fastest-growing providers of software products and technology services for business process automation solutions that address challenges like process turn-around time, organizational productivity, regulatory compliance, business scalability, operational visibility and excellence.
Adding {{itemName}} to cart
Added {{itemName}} to cart