ISO/IEC 27001 - Information security
Today, information security is (super)vital for organisations of all kinds. Confidentiality, integrity and availability of information are becoming strategic success factors when it comes to gaining the trust of customers, business partners and the public.
ISO/IEC 27001 - Information security
Today, information security is (super)vital for organisations of all kinds. Confidentiality, integrity and availability of information are becoming strategic success factors when it comes to gaining the trust of customers, business partners and the public.
Summary
ISO/IEC 27001 is the globally applied standard for the certification of an information security management system. This aims to protect information based on an analysis of business risks with regard to confidentiality, integrity and availability.
Version ISO/IEC 27001:2022 was published at the end of October 2022 and no major changes were made. As no more than two amendments ( AMD - Amendment) should be made to a standard, a version 2022 is now being published.
The changes can primarily be found in Annex A - Objectives and measures, which result from the newly published ISO/IEC 27002:2022.
ISO/IEC 27001 is structured in the same way as ISO 9001:2015, but does not include the business processes, but rather the measures to ensure information security. Although an ISO 9001:2015-compliant management system is not a prerequisite, it is the ideal basis. If this is missing, the processes in which the measures are embedded still need to be described.