#129 What clauses have been updated in ISO 27001:2022?
The ISO Show25 Jan 2023

#129 What clauses have been updated in ISO 27001:2022?

As many of you are aware, an updated version of ISO 27001 was published in October 2022. While there is a 2-year grace period for transition, we would urge everyone to make a start on implementing the changes to ensure you are compliant with latest best practice standards. But where do you start?

In the last episode, Mel and Steve gave an overview of the updated ISO 27001:2022, including a high-level look at some of the key changes.

In addition to the control changes, there have been several changes made to specific clauses within the Standard.

Mel is once again joined by Steve Mason, Managing Consultant here at Blackmores, to discuss the ISO 27001:2022 clause updates and their purpose.

You'll learn

  • What clauses have been updated from the 2013 version of ISO 27001?
  • Why have these clauses been updated?

Resources

In this episode, we talk about:

[01:06] The changes to these clauses appear to align your Management System with the business more so than in the previous iteration of ISO 27001 – a key focus is integration.

[01:20] First change: Clause 4.2 Understanding the needs and expectations of Interested parties – 'c) which of these requirements will be addressed through the information security management system.' - This seeks to align the Management System with interested parties and identify where it may or may not be able to meet their needs and expectations.

[03:30] Clause 4.4 Information Security Management System – 'The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.' – There will be more focus on process flows and not Policies and Procedures. This can be further used to align the Management System with your business, by clearly identifying where it fits in with your business activities.

[06:14] Clause 5.1. Leadership – 'Reference to "business" in this document can be interpreted broadly to mean those activities that are core to the purposes of the organization's existence.' – This acts more as a reminder to top management to ensure they include the Management System as part of the business and not just a bolt-on. It should be a part of the strategy and part of the business (part of the ship, part of the crew)

[07:42] Clause 6.1.3 Information Security Risk Treatment –' Note 2 in sub-clause 'c' now states 'Annex A contains a list of possible information security controls.' (it had previously read Annex A contains a comprehensive list of control objectives and controls.) – This simply means that you can add references to other controls outside of the list provided within Annex A i.e. NIST or Cyber Essentials. Though, do be careful to avoid doing this at minutia level, as that just increases Management System maintenance.

[09:15] Clause 6.2 Information security objectives and planning to achieve them –' A couple of extra points have been added to this clause: d) be monitored g) be available as documented information' - The monitoring was previously a given, but not really specified. So now, you'll have to demonstrate how you're monitoring objective planning and achievements.

[10:24] Clause 6.3 Planning of Changes – 'When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.' – This has now been aligned more with ISO 9001's approach to changes. All changes should be planned before implementation, and this now includes information security consideration. Fun fact – they forgot to include this clause in the Standard table of contents! (as of January 2023, this will probably be added later!)

[11:55] Clause 9.3.2 Management Review Inputs –' c) changes in needs and expectations of interested parties that are relevant to the information security management system' – This just ensures that the needs and expectations of your Interested Parties are reviewed and not just left stagnant.

[13:20] To help you revamp your Management Review, check out episodes #99 and #100

As a reminder, we'll be running a mini-series through January and February on the updated ISO 27001:2022 in addition to how you can transition to the new version.

Keep an eye out for next weeks episode where we dive into the clause clarifications and control changes of ISO 27001:2022…

We'd love to hear your views and comments about the ISO Show, here's how:

Subscribe to keep up-to-date with our latest episodes:

Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(200)

#258 What is BS 99001? Quality Management For The Built Environment

#258 What is BS 99001? Quality Management For The Built Environment

Many of you will be familiar with ISO 9001, the leading Quality Management Standard, which provides a solid foundation for managing any business. However, for certain industries, ISO 9001 alone is not...

16 Sep 44min

#257 How to meet legislative and ISO requirements in leasehold properties

#257 How to meet legislative and ISO requirements in leasehold properties

Many businesses do not own the property they operate in, this can lead to complex questions over who has ownership over certain property and facility related legal obligations. Managing areas such as...

19 Aug 33min

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It's estimated to generate around £50 billion in economic benefit, along with the creation ...

5 Aug 45min

#255 AI Due Diligence - Information Security Checks Before You Integrate AI

#255 AI Due Diligence - Information Security Checks Before You Integrate AI

AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate...

22 Jul 19min

#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

The path towards becoming an ISO consultant is often a meandering one. It's not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We're c...

1 Jul 25min

#253 Building The Case For Health & Safety Regulations & Standards

#253 Building The Case For Health & Safety Regulations & Standards

Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn't necessarily formally recognised until the 1970's here in the UK.   Health & Safety often gets mo...

24 Jun 27min

#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

#252 Wavenet's On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certi...

17 Jun 33min

#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

Watch the video interview here Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The...

10 Jun 34min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
rss-penger-polser-og-politikk
e24-podden
rss-borsmorgen-okonominyhetene
rss-pa-konto
rss-skravla-gar
pengepodden-2
utbytte
finansredaksjonen
tid-er-penger-en-podcast-med-peter-warren
stormkast-med-valebrokk-stordalen
rss-orjasater
lederpodden
livet-pa-veien-med-jan-erik-larssen
pengesnakk
morgenkaffen-med-finansavisen
lydartikler-fra-aftenposten
liberal-halvtime
rss-markedspuls-2