Cyber security is an understandable concern for any organisation, but an effective ISMS can significantly reduce the risk of exposure to security breaches.
What’s included?
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
If you are implementing or thinking about implementing an ISMS, you need both of these standards as your principal points of reference. ISO 27001 is the only security standard that takes an integrated approach to information security, addressing the four essential facets of cyber security (people, processes, technology and physical controls) in a single, cohesive strategy.
What’s changed with the 2022 version?
- New requirements on planned changes and how your organisation should deal with them.
- More focus on how the organisation must deal with the needs and expectations of interested parties.
- Objectives must now be documented and monitored. (There is a double requirement for the documentation: the objectives must be available as documented information, and the organisation must retain documented information about the objectives.)
- More alignment with the common phrasing used across ISO management system standards.
For more guidance on ISO 27001, visit our information page.