logo
logo
Sign in

ISO 27001:2022 vs ISO 27001:2013 What Changed from 2013?

avatar
Ritvi Sharma
ISO 27001:2022 vs ISO 27001:2013 What Changed from 2013?

The ISO 27001:2022 certification standard is the most commonly used framework to provide assurance of an organization’s information security management system.

It has been updated by the ISO 27001:2022 standard, which took effect on April 1st, 2018.

In this article, we will discuss what changed since 2013 and why it was important for organizations to undergo this change.


ISO ISMS: Information Security Management System


ISO 27001:2022 is an updated version of the ISO 27001 standard.


It has been revised to reflect new challenges and changes in the global business environment that have come about since it was first published back in 2008.


The major change is that now you can use both versions interchangeably, which means you don’t need to worry about choosing between them when implementing your information security management system (ISMS).


A Recap:


ISO 27001:2013, the foundation for all Information Security Management Systems (ISMSs), has been published since 2013.


This version of ISO 27001 is based on best-practice models from around the world and includes a risk assessment framework to help organizations establish a baseline for their information security management processes.


The latest revision to this standard was published in March 2019 as ISO/IEC 27001:2019 — version 2.


ISO ISMS Framework Scope


The ISO 27001:2013 standard is a framework for managing an organization’s information security risk.

It specifies the requirements for establishing, implementing, operating, monitoring, and reviewing an Information Security Management System (ISMS).


Context of the Organization


The organization’s context is the external environment, which includes the industry and market that it operates. Internal context refers to how your company operates internally.


For example, if you are an auditor for a large corporation, then your internal context may include its financial systems along with information about its employees and customers.


The business context includes all aspects of an organization’s day-to-day operations such as sales figures and customer service metrics.


Leadership


Leadership is the process of influencing a group of people to achieve a common objective.


Leadership is required for the success of any organization, and it’s an important part of ISO 27001:2013.

In addition to being able to influence others, you also need to be able to influence yourself as well.

This can be done by following through on your commitments and taking ownership of your actions and decisions in order for them not only to benefit you but also to benefit others around you as well (for example: if something goes wrong during implementation).


Planning


Planning is the process of defining the purpose, goals, and objectives of an ISMS. It involves determining what needs to be accomplished, who will do what, and when.


It is a continuous process because it continues throughout implementation.


Planning helps to identify risks and vulnerabilities by understanding how your organization operates; then you can plan how best to mitigate them or eliminate them altogether from occurring again in future years.


Once you’ve identified these concerns, you can begin implementing controls that will help ensure they don’t happen again – this is called “risk identification.


Support


ISO 27001:2022 has introduced the concept of ‘Support’ as a part of its management system.


Support is defined as an activity carried out by the management to ensure that the ISMS is implemented properly and in accordance with established standards.


It includes activities such as auditing, training, and awareness raising.


The new standard also introduced an additional requirement to provide “a clear understanding” within your organization about what support will be provided (e.g., how many people will be involved, where they will come from etc).


After this, it has been revised and updated to include changes made by the ISO 27001:2022 committee which was formed in 2017.


Some of these changes include the removal of limits on the number of information security management systems an organization can have and instead giving them flexibility for their requirements based on their current situation.


So why not get certified today and show the world that you are up to date with the industry standards and are capable of aligning organizations with their goals.


Check out our official ISO 27001 2022 Lead Auditor for more!


Thank you for reading!




collect
0
avatar
Ritvi Sharma
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more