Information security is becoming increasingly important in today's digital age, and the International Standards Organization (ISO) has published the latest update to the internationally recognized information security standard, ISO 27001:2022, on October 25, 2022. This article will provide an overview of the main changes in the mandatory clauses, Annex A, and how to transition to this new ISO 27001:2022 update.
Mandatory Clauses:
The changes to the mandatory clauses are not significant, but there are a few noteworthy changes:
Annex A:
The biggest change in ISO 27001:2022 is the restructuring and revision of Annex A. The number of controls has been reduced from 114 to 93, and they are now divided into four sections instead of the previous 14. This change aims to make the standard more concise and easier to implement. The new sections and controls are:
How Will The Update Affect Your Organization?
If you are implementing ISO 27001:
You don't need to panic, as certification entities will likely offer certification to ISO 27001:2022 just six months after its publication. Additionally, ISO 27001:2013 will still be valid for another three years, so all your work towards implementing ISO 27001:2013 will still be useful. However, you may want to use the new Annex A controls from ISO 27001:2022 as an alternative control set, depending on your progress with ISO 27001:2013 implementation.
If you are already certified to ISO 27001:2013:
You will have time to fully migrate to the new requirements, and the best time to do so is before your next internal audit. Allocating internal audit activities three months before the external assessment will allow you to identify and fix any potential nonconformities before the external assessor arrives.
תודה רבה, הטופס נשלח בהצלחה
אירעה שגיאה בהזנת הפרטים, אנא נסו שנית
רחוב - הכלנית 26, כפר סבא
טלפון - 054-2277887
פקס - 09-7770139
מייל - ronit@ronitsadeh.com
האתר נבנה ועוצב ע"י חברת קודנט בניית אתרים לעסקים | קידום אורגני