19 Apr 2024
ISO 27001 published by the International Organization for Standardization (ISO) is used as an international standard for Information Security, commonly known as ISMS (Information Security Management System). ISO 27001 was updated nine years after the 2013 edition was published. On October 25, 2022, this standard was superseded by ISO 27001 version 2022.
ISO 27001 covers elements that manage and control information security risks: confidentiality, integrity and availability of information. This article discusses the intricacies of this revision, providing insight into how businesses can align their information security management systems (ISMS) with the latest standard.
The following are the main changes in the ISO 27001:2022 version:
Changes to ISO 27001 clauses.
Changes in Annex A security controls.
Reduction in the number of controls.
Control categories consolidated.
Emergence of new controls.
ISO 27001: 2013 |
Difference |
ISO 27001: 2022 |
Information Technology, Security Techniques, Information Security Management System, Requirements |
Regulation |
Information security, cybersecurity and Privacy Protection, Information Security Management System, Requirements |
10 |
Total Clauses |
11 |
14 |
Number of Control Categories in Annex A |
4 |
114 |
Number of Security Controls in Annex A |
93 |
The answer depends on the situation and needs of each organization. But in general, we will summarize the advantages and disadvantages of each version of ISO 27001: 2013 and ISO 27001:2022, as follows:
ISO-27001 2013: This version includes more detailed and specific controls that can provide more detailed information security guidance and assurance. However, the drawback is that this version is more complex and rigid, making it difficult to adapt to the changing business and technology environment. Another drawback is that this version is less aligned with other ISO management standards, which can cause integration and consistency issues.
ISO-27001 2022: This version is more modern and flexible, making it easier to adapt and apply to various organizations by reducing the burden and cost of information security due to fewer and simpler controls. However, this version is less mature and tested and can lead to organizational uncertainty and confusion regarding information security. ISO 27001: 2022 is also closely aligned with other ISO management standards, which can promote integration and consistency.
Adopting ISO 27001:2022 is a strategic step towards information security and enhancing corporate credibility. Ideally, organizations wishing to transition to ISO 27001:2022 should do so three years from the publication date of ISO 27001:2022. Any company currently certified to ISO 27001:2013 has until October 31, 2025, to transition to the new revision.
Perkom can ensure that your journey to ISO 27001:2022 certification is thorough, seamless and rooted in the latest cybersecurity practices. Contact Us
Author: Ghea Devita
Marketing Communication PT Perkom Indah Murni