Menu

Call us on 03450 21 21 51

ISO27001:2022 is on its way. Here’s what you can expect
The SRM Blog

ISO27001:2022 is on its way. Here’s what you can expect

Claire Greathead

Written by Claire Greathead

7th June 2022

Share this article

ISO27001:2022

The globally recognised security standard is updating, and bringing a few key changes with it

Since its last update in 2013, ISO27001 has become recognised around the world as the leading standard for information security management systems. Now, in 2022, the standard is set to update once again, and businesses are keen to know exactly what to expect from the incoming changes.

Fear not, because we’ve got all the information you need. Here’s what you can expect from ISO27001:2022.

What is ISO27001:2022?

ISO27001:2022 is the latest draft of the ISO27001 standard for information security. It allows businesses to equip themselves with risk-based approaches to cybersecurity, using a framework which is recognised internationally as best practice.

ISO:27001 introduces an Information Security Management System (ISMS) to assist businesses in identifying, assessing, mitigating and managing cybersecurity risks to business data and assets. It provides a set of guidelines designed to help organisations implement the best practices of ISMS.

How does it differ from ISO27001:2013?

The main difference between the 2013 and 2022 updates of the standard is that you cannot earn ISO27001:2022 certification. ISO27001:2013 remains the main standard, while ISO27001:2022 consists of a set of supporting controls which exist to provide guidance, and help businesses implement the best security practices for ISO27001:2013 certification.

In short, they are part of the same standard.

Clauses 4 to 10 of ISO27001:2013 will remain largely the same with the update in place. These include key sections such as: scope, interested parties, information security policies, context, resources, risk management, communication, document control, training & awareness, monitoring and measurement, management review, internal audit and corrective actions.

However, elsewhere the standard has changed. Annex A of ISO27001:2013 has been updated to increase the convenience of implementation. The number of controls has decreased from 114 to 93, and are placed in 4 sections instead of 14 (People, Organisational, Technological and Physical). Many controls have been merged, and 11 new controls have been added. These are:

  • Configuration management
  • Data leakage prevention
  • Data masking
  • ICT readiness for business continuity
  • Information deletion
  • Information security for use of cloud services
  • Monitoring activities
  • Physical security monitoring
  • Secure coding
  • Threat intelligence
  • Web filtering

When will the changes be implemented?

The changes to the ISO27001 standard are already in motion. ISO27001:2022 was officially published on February 15th 2022, but the updates themselves are scheduled to be published in October of this year. However, a definitive date has not yet been stated. In order to ensure that your business stays in line with accreditation standards, it’s important to get familiar with the new requirements now and begin taking the necessary steps.

Should you wait for the update before seeking compliance?

Many businesses will be wondering whether to wait for the updates to be fully implemented before seeking ISO27001 certification. This will depend entirely on the urgency in which you need to achieve accreditation. For example, if you have a client waiting for you to be certified before moving forward, it’s best to act now as you will still have to align to ISO27001:2013 clauses either way.

If certification is less urgent to your business, it’s best to start implementing the controls that cover gaps in your current business structure, and commence the complete certification requirements when ISO27001:2022 is published.

If you’re starting your implementation now, you should commence meeting the existing clauses as described in the 2013 standard. As the changes coming later in the year are moderate, the effort needed to transition to ISO27001:2022 will be minimal.

Find out more about improving your organisation’s cybersecurity and achieving the necessary accreditations by getting in touch with the experts at SRM today. Click here to contact a member of our team.