ISO 27001 and ISO 27002 2022 updates
ISO/IEC 27001:2022 – the newest version of ISO 27001 – was published in October 2022.
Organisations that are certified to ISO/IEC 27001:2013 have a three-year transition period to make the necessary changes to their ISMS (information security management system).
For more information about ISO 27001:2022 and its companion standard, ISO 27002:2022, and what they mean for your organisation, please visit ISO 27001 and ISO 27002: 2022 updates
Download your copy of ISO 27001:2022 here
Download your copy of ISO 27002:2022 here
The assessment and management of information security risks is at the core of ISO 27001
Section 6.1.2 of the ISO/IEC 27001 standard states the ISO 27001 risk assessment procedure must:
- Establish and maintain specific information security risk criteria.
- Ensure that repeated risk assessments “produce consistent, valid and comparable results”.
- Identify risks associated with the loss of confidentiality, integrity and availability of information within the information security management system’s scope.
- Identify the owners of those risks.
- Analyse and evaluate information security risks according to specific criteria.