詳細検索

New Standard ISO27001 for ISMS Certification: 2022 Transition Success Stories and Key Takeaways

Avatar
by 菊池
3 min read

New Standard ISO27001 for ISMS Certification: 2022 Transition Success Stories and Key Takeaways
Translated from 日本語 • View original
菊池
菊池

Hello! This is Kikuchi, an analyst at Colorkrew Security. In the previous blog, we explained the overview of the ISMS standard revision. I will explain how I responded to the 11 new management measures added from this time with the new ISMS standard.

Compatible with the new ISMS standard

Hello! This is Kikuchi, an analyst at Colorkrew Security.

Many companies have obtained ISMS certification as an objective evaluation criterion for their own security.
This time, as the deadline for the application of the 2022 version of the revised ISO27001, which has been revised for the first time in nine years, approaches, I will explain how I responded and passed the examination after being assigned in a hurry.

Revisions

After attending an external seminar, I found out that the 2022 version of the standard has the following three changes.
(External seminars do not talk about how to respond specifically.)

  1. Revision of the text of the standard bullet points 4~10
  2. Annex A Chapter Structure Changes
  3. Addition of New Control Measures in Annex A 11

Specification text Bullet points 4~10 Revised text

Items 4~10 are all non-exclusionary requirements for ISMS, so your company's ISMS manual based on this will need to be revised.
For example, "6.3 Planning for Changes" has been added to the standard.
This is a request to implement changes in the ISMS in a planned manner, so the following sentence has been added to the manual.

'6.3 Formulate a plan for changes If there are changes to the ISMS, they shall be discussed and amended by the ISMS Steering Committee and approved by top management. `

Annex A Chapter Structure Changes

The A.5~A.18 categories have been changed to the following four categories.

"5 Organizational Management Strategies

", "6 Human Management Strategies"

, "7 Physical Management Strategies"

, "8 Technical Management Strategies"

In addition, the total number of control measures has been reduced from 114 to 93, such as several control measures being combined into one.
(Since there are no abolished items and it will be a composition change, it does not mean that the previous response will be reduced.)

We started by creating a comparison table of which of the previous management measures corresponded to the 2022 version.

Based on the comparison table, we changed the structure of the implementation regulations that defined specific operation methods.
(In addition to the new management measures, there are places where the body of the requirements has been added or changed, so please be careful.) )

Annex A Addition of New Management Measures

The following 11 new management measures have been added.

5.7 Threat Intelligence
5.23 Information Security for Cloud Service Usage
5.30 ICT Preparedness for Business Continuity
7.4 Physical Security Monitoring
8.9 Configuration Management
8.10 Deletion of Information
"8.11 Data Masking
8.12 Data Leakage Prevention
8.16 Surveillance Activities
8.23 Web Filtering
8.28 Security-Minded Coding

The main focus of this revision is how to operate and evaluate these management measures.
I will explain these in the next article.

Related Articles