ISO 27001 has been updated – here’s everything you need to know

We recently ran a webinar about the update that’s been made to ISO 27001. During the session, Darren explained what has been updated, when the changes come into effect, what the transition period is, and what the changes mean for you. Here is a summary of the session: 

Why is ISO 27001 being updated? 

ISO 27001 has undergone its first major update since 2013 and the new version is live now. Although there have been incremental changes and updates over the years, this update is a major overhaul that takes into account new working practices, threats, and controls. The changes in the 2022 version of the standard are centred around the Annex A controls.  

What’s the transition period? 

The transition period for the new standard began on November 1st, 2022, and there is a three-year certification period during which companies can still be assessed to the old standard of 2013. However, all new and existing certificates will have to be assessed to the new standard by May 1st, 2024. Any existing 2013 certifications will be withdrawn in 2025 if they have not been updated to the new standard. Therefore, companies have a three-year transition period to update their systems and processes to align with the new standard. 

What are the changes? 

Despite the major overhaul, the changes to the main body of text and clauses 1 to 10 are minimal. This means that companies can continue to use their existing systems and processes and slowly introduce the new updates over time. The terminology has changed slightly, and there have been minor english and numbering updates to improve consistency and translation into other languages. 

The one major change in the main body of text and clauses is the mapping of operational processes. This involves criteria in the planning stages to ensure the Information Security Management System (ISMS) is effective. This includes identifying the interdependencies, running effective internal audits, conducting management reviews, and having a process flow for external providers.  

Mapping out process flows and data mapping flows is a familiar concept for those who have implemented the ISO 9001 standard. This change in ISO 27001 allows companies to identify risks and opportunities for improvement in their processes and plan for continuous improvement.  

The communication requirements for the ISMS have also been expanded. While it has always been necessary to communicate who is assigned to a particular role and what their responsibilities are, it is now also necessary to define how and when communication will occur. This may involve a specific platform or method of transmission, and it must be defined during the planning stages of the ISMS. 

The changes to the ISMS should sound familiar to organisations that have already been implementing the Plan-Do-Check-Act (PDCA) cycle. However, the Annex A of the ISO 27001 standard has undergone a major update, with 11 new controls, 24 merged controls, and 58 updated controls. These updates reflect modern working practices and the growing importance of remote working, as well as considerations around Personally Identifiable Information (PII) and General Data Protection Regulation (GDPR). The new controls also emphasise the importance of monitoring and secure coding. 

Despite the updates to Annex A, the older controls are still required, as they remain relevant to current technologies and threats. The older teleworking controls have been updated to reflect the newer term of remote working, and additional controls have been added for threat intelligence, cloud working, monitoring, business continuity, and technical controls of data. Implementing these new controls may require organisations to obtain a new version of the ISO 27002 standard to ensure they have the latest implementation guidance. 

Three new organisational controls were added, including the requirement for threat intelligence. This control means organisations need to be aware of their threat environment and consider the origins of those threats. This requires a multi-layered approach that is both strategic and tactical, with actionable steps taken during the planning stages to identify, collect, analyse, and communicate threats to those who need to know them. This includes external threats as well as internal threats. 

What do these changes mean for companies and their teams? 

Firstly, companies should start thinking about the new version and consider implementing it going forward. They should also review their existing systems and processes and identify areas that need updating to align with the new standard. This will help ensure a smooth transition and avoid any issues with certification down the line. Companies should also consider training their teams on the changes to the standard, including the new attributes and mapping of operational processes. This will help ensure that everyone is aware of the changes and can work together to implement them effectively. It is also a good opportunity to review and update training programs to ensure they align with the new standard. 

Q&A session: 

Are there any additional cost requirements to meet the new standard?

According to the information provided by BSI in their transition course, if you want to upgrade your certificate to the new standard within your three-year certificate, it will require an additional day for upgrading your certificate in continuity audit. However, if you were to go straight out for recertification, then it wouldn’t be any change. 

Do the new controls need to be fully implemented? Or is it enough to have a plan in place?

To obtain the 2022 version certification, everything has to be fully implemented and working and monitored. Unlike continuation audits, where it is possible to have a plan in place with an owner, a deadline, and a treatment plan, achieving certification to the new standard requires everything to be fully implemented. 

Regarding the increased requirements for logging and monitoring, do you need an off-the-shelf solution? Or would manual monitoring be enough?

ISO has to fit the environment that is being certified, and while it is possible to get away with manual monitoring, it will be very difficult with the new controls of logging and monitoring data leakage, internal and external threats. Therefore, it would be challenging not to have some sort of solution that can report, monitor, and alert with an action plan in place to be on top of everything in the new standard.