The new ISO 27002:2022

The new ISO 27002:2022

For the first time since 2013 a new revision of ISO 27002 has been published. In case you think thats too good to be true, I suggest you go and have a look at the official ISO publication.

ISO 27002 has always been a standard applicable to organizations of all types and sizes. It serves as a reference for implementing controls for information security risk treatment as part of an information security management system (ISMS) based on?ISO/IEC?27001. It is mostly used as a guideline for organizations determining and implementing commonly accepted information security controls.

What has changed?

The most obvious change was made to the controls included in this standard. The previous revision ISO 27002:2013 contained 114 controls, classified into 14 control objectives. The 2022 revision version contains 93 controls, divided over 4 chapters:

  • 5. Organizational Controls (37 controls)
  • 6. People Controls (8 controls)
  • 7. Physical Conrols (14 controls)
  • 8. Technological Controls (34 controls)

The following image provides an overview of the new structure. New controls are highlighted in yellow.

No alt text provided for this image

Another significant change was made to the profile of each control. ISO 27002:2022 adds the following attributes to each control.

  • Control type [Preventive, Detective, Corrective]
  • Information security property?[Confidentiality, Integrity, Availability]
  • Cybersecurity concepts [Identify, Protect, Detect, Respond, Recover]
  • Operational capabilities?[Application security, Asset management, Continuity, Data protection, Governance, Human resource security, Identity and access management, Information security event management, Legal and compliance, Physical security, Secure configuration, Security assurance, Supplier relationships security, System and network security, Threat and vulnerability management]
  • Security Domains?[Governance_and_Ecosystem, Protection, Defence, Resilience]

In the following picture you can see the attributes for control 8.32 Change Management.

No alt text provided for this image

All in all ISO 27002 seems to have received a major upgrade in terms of structure and flexibility. As soon as an amendment for ISO 27001 will be released, organizations can get certified. However taking the necessary steps to prepare for this upgrade is something you can start with today.


Paul U.

Cybersecurity Advisor | MSc, CISSP, CISM, CDPSE, CCSP, CCSK, AZ 500, ITIL,ISO 27001

2 年

sweet!!!

回复
Abdullah Albaqami

Head of Cybersecurity GRC @ Confidential Cybersecurity Expert | Cybersecurity Risk Management | Leadership | Cybersecurity Governance and Compliance

2 年

Thank you for your sharing.

回复
Similolu O.

IT Audit || Regulatory Compliance || Security Governance|| IT SOX Compliance || Process Improvement || ITGC || Risk Management || IT Compliance Analyst|| IT Controls

2 年

Thanks for sharing

回复
Frédéric Biron

Catalyseur de cohérence, d'excellence et d'amélioration continue, je guide, conseille et accompagne à tous les niveaux de l'organisation /CEA

2 年

Thanks Aron for your sharing. Thierry, this information may be of interest to you.

回复
Jonathas Abranches

Senior Cybersecurity GRC | Project Manager | ISO 27001 Lead Implementer

2 年

Thanks for sharing, Aron.

回复

要查看或添加评论,请登录

Aron Lange的更多文章

  • 4 New and Free Resources by NIST

    4 New and Free Resources by NIST

    I haven't used my LinkedIn Newsletter in a while. But, due to popular request, I'm giving it another shot.

    1 条评论
  • The Top 5 Newsletters of 2023

    The Top 5 Newsletters of 2023

    In 2023, I sent out 25 newsletters about Governance, Risk and Compliance topics. Here are the most popular editions of…

  • Introducing LearnGRC

    Introducing LearnGRC

    Dear Readers, when I started this newsletter, I wanted to focus on demystifying the world of information security…

    16 条评论
  • My Journey to Becoming a Certified Information Security Manager (CISM)

    My Journey to Becoming a Certified Information Security Manager (CISM)

    Dear Community, I have some thrilling news to share with you! I have decided to embark on a journey towards becoming a…

    4 条评论
  • The All-New Resource Center

    The All-New Resource Center

    Dear Readers, I am thrilled to announce the release of Resource Center! As security professionals, we are always on the…

    15 条评论
  • Cybersecurity Made Easy: Free and Low-Cost Courses

    Cybersecurity Made Easy: Free and Low-Cost Courses

    In today's world, cybersecurity is becoming more and more critical. With the rise of cyberattacks, the need for…

    8 条评论
  • Free Resources for Security and GRC

    Free Resources for Security and GRC

    Here is my list of free resources that will help you to break into GRC and information security. By the way, this is…

    10 条评论
  • Running an audit programme

    Running an audit programme

    Running an internal audit programme is a mandatory requirement within all management systems that seek to be certified…

    1 条评论
  • Security Controls

    Security Controls

    In this edition of InfoSec Insights we are going to talk about controls. You will learn what controls are used for and…

    2 条评论
  • ISO 27005 - Risk Management

    ISO 27005 - Risk Management

    ISO/IEC 27005 provides guidance on implementing a process-oriented risk management approach to assist in implementing…

    35 条评论

社区洞察

其他会员也浏览了