The new ISO 27002:2022
For the first time since 2013 a new revision of ISO 27002 has been published. In case you think thats too good to be true, I suggest you go and have a look at the official ISO publication.
ISO 27002 has always been a standard applicable to organizations of all types and sizes. It serves as a reference for implementing controls for information security risk treatment as part of an information security management system (ISMS) based on?ISO/IEC?27001. It is mostly used as a guideline for organizations determining and implementing commonly accepted information security controls.
What has changed?
The most obvious change was made to the controls included in this standard. The previous revision ISO 27002:2013 contained 114 controls, classified into 14 control objectives. The 2022 revision version contains 93 controls, divided over 4 chapters:
The following image provides an overview of the new structure. New controls are highlighted in yellow.
领英推荐
Another significant change was made to the profile of each control. ISO 27002:2022 adds the following attributes to each control.
In the following picture you can see the attributes for control 8.32 Change Management.
All in all ISO 27002 seems to have received a major upgrade in terms of structure and flexibility. As soon as an amendment for ISO 27001 will be released, organizations can get certified. However taking the necessary steps to prepare for this upgrade is something you can start with today.
Cybersecurity Advisor | MSc, CISSP, CISM, CDPSE, CCSP, CCSK, AZ 500, ITIL,ISO 27001
2 年sweet!!!
Head of Cybersecurity GRC @ Confidential Cybersecurity Expert | Cybersecurity Risk Management | Leadership | Cybersecurity Governance and Compliance
2 年Thank you for your sharing.
IT Audit || Regulatory Compliance || Security Governance|| IT SOX Compliance || Process Improvement || ITGC || Risk Management || IT Compliance Analyst|| IT Controls
2 年Thanks for sharing
Catalyseur de cohérence, d'excellence et d'amélioration continue, je guide, conseille et accompagne à tous les niveaux de l'organisation /CEA
2 年Thanks Aron for your sharing. Thierry, this information may be of interest to you.
Senior Cybersecurity GRC | Project Manager | ISO 27001 Lead Implementer
2 年Thanks for sharing, Aron.