Changes to ISO 27001

ISO 27001 is an international standard that outlines the requirements for an information security management system (ISMS). It provides a framework for organisations to follow in order to securely manage their information and protect it from unauthorised access, use, disclosure, disruption, modification, or destruction.

The previous version of ISO 27001 was ISO/IEC 27001:2013. However, a new version, ISO/IEC 27001:2022, was released in October 2022. Some of the key changes in the updated standard include:

  1. A stronger emphasis on risk management The updated standard places a greater emphasis on risk assessment and the treatment of risk. It also requires organisations to establish a formal risk management process – we’d recommend organisations follow the ISO 31000 risk management process.
  2. New requirements for supply chain security – The updated standard includes new requirements for managing and protecting information throughout the supply chain. Globally, we’ve seen regulators focussing on this. Many regulators have introduced guidelines/regulation around the outsourcing of critical business activities.
  3. A focus on data privacy – The updated standard includes additional requirements related to the protection of personal data and the handling of data breaches. This ties in with the introduction of many pieces of data protection regulations, including GDPR.
  4. Changes to the structure and organization of the standard – The updated standard has a new structure, with a more logical flow and clearer language.

It is important for organizations that are currently certified to ISO 27001:2013 to be aware of these changes and to prepare for the transition to the updated standard. This may involve updating their ISMS to meet the new requirements and undergoing a recertification process.

To learn more about how the CalQRisk solution can assist with cybersecurity risk management, ISO 27001 compliance and more, request a free tailored demo.

 

Recent News

Carbon Accounting – I’ve calculated my emissions – How do I report?

Congratulations you've calculated your emissions! Now for next steps. Reporting your emissions is a crucial step for transparency, ...
Read More

CNaught and GreenFeet Team Up to Simplify Climate Action 

We are so excited to announce our partnership with CNaught, a leading provider of high-integrity carbon credit portfolios. ...
Read More

Carbon Accounting – Where Do I Start ? 

Are you a business looking to measure your carbon emissions? Do you find yourself lost amongst the numerous ...
Read More
NIS2 EU Cybersecurity Directive EU-wide legislation

How Incidents Link to Controls

Effective risk management is essential for organisations to protect their assets, reputation, and operational continuity. One of the ...
Read More

CalQRisk Nominated for Four RegTech Insight Awards – Vote Now!

We’re excited to share some fantastic news—CalQRisk has been nominated for four prestigious awards in the RegTech Insight ...
Read More

CalQRisk: A Finalist for the 2025 ECSO Cybersecurity Awards

We are thrilled to announce that we’ve been named a finalist in the ECSO Awards 2025, competing for ...
Read More

CalQRisk Acquire GreenFeet and Launch Sustainability Solution 

CalQRisk have acquired GreenFeet, a tried and tested solution that allows organisations to -   Calculate their emissions using ...
Read More

Digital Operational Resilience Act (DORA): A New Era Begins

Today, January 17th, 2025, marks a significant milestone in the European Union's regulatory landscape with the official launch ...
Read More

CalQRisk Shortlisted as Best Technology Partner in Housing Digital Innovation Awards

CalQRisk has been named a finalist in the Housing Digital Digital Innovation awards. CalQRisk is nominated as best ...
Read More

CalQRisk Achieves G-Cloud 14 Approved Supplier Status

Delighted to confirm that following on from our GCloud 13 supplier status, that CalQRisk has been listed as ...
Read More