#132 What changes need to be Implemented for ISO 27001:2022?
The ISO Show15 Helmi 2023

#132 What changes need to be Implemented for ISO 27001:2022?

The updated ISO 27001:2022 has had several changes, including the addition of 11 completely new controls and the merging of 56 other controls into 24 newly titled controls.

These changes mean that anyone with a current ISO 27001:2013 certificate will be required to update and add certain elements in their existing Information Security Management System to ensure compliance to ISO 27001:2022 ahead of the October 2025 deadline.

Join Mel this week as she explains the changes that need to be made, including what key documentation requires updating to align with ISO 27001:2022.

You'll learn

What changes need to be made to your existing Information Security Management System?

What key documents need to be updated?

How can you get a free copy of ISO 27001:2022?

Resources

Isologyhub

ISO 27001 Transition Programme

What you need to know to transition to ISO 27001:2022

In this episode, we talk about:

[00:44] In the last episode we covered the planning stages for your transition – catch up here

[01:02] We have a free 'Guide to the ISO 27001 Changes' available – simply fill out the form at the end of the Show Notes to download your copy

[01:29] You should have a copy of ISO 27001:2022 ahead of Implementing the changes (you can get a free copy if you sign up to our Transition Programme by April 1st 2023)

[01:35] Before you move onto Implementation, ensure that you have: planned back from your transition date, have an understanding of the new controls and had a Discovery session / Gap Analysis to see where the gaps in your current system are

[02:11] This is also a good opportunity to revamp your Management System! We have a few older episodes to help you with this: #102, #103, #104

[02:50] What needs updating? This will include:

  • Your Statement of Applicability
  • Risk Assessment
  • Objectives
  • Action Plans
  • Monitoring and measurement (reviewing what you are monitoring / measuring and how it's recorded
  • Internal Audit Schedule / Programme – To include the new controls

[03:45] At this stage you need to look at what controls you have in place – there may be some you can now merge together to reduce any paperwork involved.

[04:25] We have some tools available to tackle the new controls (i.e Threat Intelligence, data masking, physical security monitoring ect) if you need some extra help

[04:50] It's not just about updating documentation, you will need to fully implement and communication these new controls to the wider business. You may find that you already have some controls covered, but not yet formalised.

[05:30] The main aspect of the Implementation phase is to address the gaps found during the Gap Analysis. For example, new controls such as data masking, threat intelligence and web filtering, which you may not have considered seriously before, now need to put formal documented measures in place to address it.

[06:26] Communication and evidence should be at the forefront of your mind when updating your Info Sec Management System.

[06:39] Don't just implement controls for the sake of it – considering how they are going to reduce risk and how they're going to make a difference to improve your Risk Register and Statement of Applicability.

[07:00] The Implementation phase of our Transition Programme is 1-3 days depending on your level of required support

[07:54] You should also consider creating a Communication Plan to share knowledge of these changes to the wider business. Make sure you also compile any evidence of training on new elements of your Management System too. We will have Coffee Break Training available on the isologyhub which could help with this.

Grab a copy of our ISO 27001:2022 Guideline to the changes here

Keep an eye out for next weeks episode where we explain how to complete your ISO 27001:2022 transition.

We'd love to hear your views and comments about the ISO Show, here's how:

Share the ISO Show on Twitter or Linkedin

Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.

Subscribe to keep up-to-date with our latest episodes:

Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(200)

#258 What is BS 99001? Quality Management For The Built Environment

#258 What is BS 99001? Quality Management For The Built Environment

Many of you will be familiar with ISO 9001, the leading Quality Management Standard, which provides a solid foundation for managing any business. However, for certain industries, ISO 9001 alone is not...

16 Syys 44min

#257 How to meet legislative and ISO requirements in leasehold properties

#257 How to meet legislative and ISO requirements in leasehold properties

Many businesses do not own the property they operate in, this can lead to complex questions over who has ownership over certain property and facility related legal obligations. Managing areas such as...

19 Elo 33min

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation ...

5 Elo 45min

#255 AI Due Diligence - Information Security Checks Before You Integrate AI

#255 AI Due Diligence - Information Security Checks Before You Integrate AI

AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate...

22 Heinä 19min

#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're c...

1 Heinä 25min

#253 Building The Case For Health & Safety Regulations & Standards

#253 Building The Case For Health & Safety Regulations & Standards

Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn't necessarily formally recognised until the 1970's here in the UK.   Health & Safety often gets mo...

24 Kesä 27min

#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certi...

17 Kesä 33min

#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

Watch the video interview here Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The...

10 Kesä 34min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
vallattomat
psykopodiaa-podcast
mimmit-sijoittaa
rss-rahapodi
rss-oivalluksia-rahasta-elamasta
ostan-asuntoja-podcast
oppimisen-psykologia
lakicast
rss-paasipodi
rss-alanvaihtajat
rss-porssipodi
rss-karon-grilli
rss-startup-ministerio
rss-inderes
rss-siksi-viestinta
rahapuhetta
hyva-paha-johtaminen
rss-pinnan-alle
rss-sami-miettinen-neuvottelija