The Inner Circle

 View Only
Expand all | Collapse all

ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements

  • 1.  ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements

    Posted Nov 23, 2022 02:57:00 AM
    Hi All,

    ISO/IEC recently published ISO/IEC 27001:2022 Information security, cybersecurity, and privacy protection - Information security management systems - Requirements

    This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to apply to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.

    You can preview this standard here: https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en

    You can purchase this standard here: https://www.iso.org/standard/82875.html

    ------------------------------
    Michael Roza CPA, CISA, CIA, MBA, Exec MBA
    ------------------------------


  • 2.  RE: ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements

    Posted Nov 25, 2022 04:23:00 AM
    Thanks Mike for timely alert. We just had survelliance audit for a previous accreditation.

    To add:
    • The number of controls has decreased from 114 to 93.
    • The controls are placed into 4 sections, instead of the previous 14.
    • There are 11 new controls, while none of the controls were deleted, and many controls were merged.


    ------------------------------
    Srikanth Katuri
    CIOBP
    IQVIA
    ------------------------------



  • 3.  RE: ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements

    Posted Nov 25, 2022 07:19:00 AM
    Glad it was helpful!

    ------------------------------
    Michael Roza CPA, CISA, CIA, MBA, Exec MBA
    ------------------------------