New Security Controls in ISO 27001:2022

The latest version of ISO 27001 was released on October 25, 2022, superseding the nine-year-old ISO 27001:2013. Designated as ISO 27001:2022, it has introduced 11 new security controls within its revised framework. However, the total number of controls has decreased from 114 to 93 due to the consolidation of some controls. Additionally, the former 14 control categories have been reorganized into four principal themes: Organizational, People, Physical, and Technological, offering greater alignment with the NIST CSF.

From a high-level understanding, below is the summary of the controls available under each theme of the new standard:

1. Organizational Controls
Number of controls:
37
Control numbers: ISO 27001 Annex A 5.1 to 5.37
Focus: These controls address the overall governance and management of information security within an organization, including policies, processes, and procedures that dictate the organization’s approach to regulations and data protection.

2. People Controls
Number of controls: 8
Control numbers: ISO 27001 Annex A 6.1 to 6.8
Focus: This theme encompasses controls related to human resources and personnel security, defining how employees interact with information and each other to maintain security.

3. Physical Controls
Number of controls: 14
Control numbers: ISO 27001 Annex A 7.1 to 7.13
Focus: Physical controls are designed to protect tangible assets and ensure the security of facilities, including access controls, environmental safeguards, and asset disposal processes. Such safeguards are essential for the preservation of confidential information.

4. Technological Controls
Number of controls: 34
Control numbers: ISO 27001 Annex A 8.1 to 8.34
Focus: This theme includes controls related to the technological aspects of information security, such as data protection measures, secure coding practices, and incident response protocols. Technological constraints help organizations establish a secure, compliant IT infrastructure, encompassing everything from authentication methods to configurations, backup and disaster recovery (BUDR) strategies, and information logging.

ISO27001 Standard

ISO/IEC 27001 is an internationally recognized standard for information security management systems (ISMS), created by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standard was first published in 2005 and has undergone several revisions, with the latest version being ISO/IEC 27001:2022.

Purpose and Importance

The primary purpose of ISO 27001 is to provide a framework for organizations to establish, implement, maintain, and continually improve their information security management systems. It aims to help organizations protect their information assets, manage risks effectively, and comply with legal and regulatory requirements. By adhering to this standard, organizations can demonstrate their commitment to information security and enhance their resilience against cyber threats.

Key Features

  • Risk Management: ISO 27001 emphasizes a risk-based approach, requiring organizations to identify, assess, and treat information security risks tailored to their specific context.
  • Comprehensive Framework: The standard outlines requirements for documentation, management responsibility, internal audits, and continual improvement, ensuring a systematic approach to information security.
  • Certification: Organizations can seek third-party certification to verify compliance with ISO 27001, which is recognized globally as a mark of effective information security management.

ISO 27001 was developed in response to the growing need for organizations to manage information security risks in a structured manner with management ownership an increasingly digital world, making it a critical tool for businesses of all sizes and sectors.

Understanding Security Standards: A Comprehensive Guide

In today’s ever evolving cyber world, security standards are more critical than ever. They provide a framework for protecting sensitive information and ensuring the integrity of enterprise systems. This article delves into the key security standards you should be aware of and how they can benefit organizations across the world.

What Are Security Standards?

Security standards are established guidelines and specifications designed to ensure the safety and security of information systems. They help organizations protect data, manage risks, and comply with legal and regulatory requirements.

Key Security Standards

1. ISO/IEC 27001: This international standard provides a framework for an Information Security Management System (ISMS). It helps organizations manage the security of assets such as financial information, intellectual property, employee details, and information entrusted by third parties.

2. NIST Cybersecurity Framework: Developed by the National Institute of Standards and Technology, this framework provides a policy framework of computer security guidance for how private sector organizations in the US can assess and improve their ability to prevent, detect, and respond to cyber-attacks.

3. Payment Card Industry Data Security Standard (PCI DSS): The Payment Card Industry Data Security Standard is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.

4. GDPR: The General Data Protection Regulation is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It also addresses the transfer of personal data outside the EU and EEA areas.

5. Committee of Sponsoring Organizations of the Treadway Commission (COSO): COSO Framework is a widely recognized framework for designing, implementing, and evaluating internal controls and guidelines for businesses to evaluate internal controls, risk management, and fraud deterrence. While the original aim was to contain the financial frauds, it has since evolved to cover broader aspects of organizational governance and risk management.

6. NERC CIP
North American Electric Reliability Corporation Critical Infrastructure Protection is a framework of 14 ratified and proposed standards that applies to utility companies within the bulk power system. The standards outline recommended controls and policies to monitor, regulate, manage and maintain the security of critical infrastructure systems.

CIP standards include the following:

CIP-004-6 Cyber Security — Personnel and Training.
CIP-008-6 Cyber Security — Incident Reporting and Response Planning.
CIP-013-1 Cyber Security — Supply Chain Risk Management.
CIP-014-1 Physical Security.
Bulk power system owners, operators and users must comply with the NERC CIP framework.

Benefits of Implementing Security Standards

  • Enhanced Security: Implementing security standards helps protect against data breaches and cyber attacks.
  • Compliance: Adhering to standards ensures compliance with legal and regulatory requirements.
  • Customer Trust: Demonstrating a commitment to security can enhance customer trust and confidence.
  • Risk Management: Standards provide a structured approach to identifying and managing risks.