top of page

Why the updated ISO 27001 standard matters to every business’ security

  • Nov 1, 2023
  • 3 min read

On August 4, 2022, a major cyberattack targeted Advanced, a supplier for the National Health Service (NHS), resulting in the disruption of critical services like NHS 111 and urgent treatment centres. This incident underscored the significance of having standardised security controls in place. To protect themselves, organisations should consider the adoption of ISO 27001.


ISO 27001 is an internationally recognised standard for Information Security Management Systems. Originally introduced in 2005, it is designed to assist businesses in establishing and maintaining a robust information security framework to mitigate risks such as cyberattacks, data breaches, and theft.


As of October 25, 2022, this standard has undergone updates to align with the evolving cybersecurity and information security landscape.


ISO 27001 comprises a set of clauses (from 4 to 10) outlining the management system and Annex A, which defines various controls. These clauses cover areas like risk management, scope, and information security policy, while Annex A's controls encompass activities like patch management, antivirus, and access control.


It's important to note that not all of these controls are mandatory, allowing businesses to select the ones that best suit their needs.


The update of ISO 27001 became necessary due to significant changes in the technology industry over the past nine years. Emerging technologies have reshaped the cybersecurity landscape, prompting a review and revision of the standard to align with current security requirements.


ISO 27002, the guidance on applying Annex A controls, has already been updated, with the number of controls reduced from 114 to 93 and the introduction of 11 new controls. These changes are aimed at aligning the standard with modern technology, including a new control for cloud technology, which was not as prominent when the controls were first introduced in 2013.


In October, ISO 27001 was updated and aligned with the new version of ISO 27002, enabling businesses to achieve compliance with the updated 2022 controls and certify themselves as meeting this updated standard.


ISO 27001 certification can benefit your business in several ways. It demonstrates to customers that your organisation takes information security seriously, which is essential in addressing customer concerns about data security.


Additionally, as many companies now require rigorous due diligence, ISO 27001 compliance is becoming mandatory, providing a competitive advantage. It also serves as a form of cyber-insurance by taking preemptive steps to prevent costly cyberattacks and disruptions. Furthermore, ISO 27001 helps educate users about potential security risks, reducing the likelihood of their credentials being compromised.


To make the most of ISO 27001, it's essential to integrate its processes and procedures into everyday activities within your organisation.


Overcoming the challenges of ISO 27001 certification can be a complex task. Addressing resource constraints and a lack of in-house knowledge is crucial. You can allocate the necessary budget and trust industry experts within your organisation to manage the implementation.


For organisations lacking experience in implementing the standard, bringing in external specialists can be a cost-effective strategy, as they have the expertise to streamline the certification process.


While implementing ISO 27001 may seem daunting, businesses have some time to transition to the new version of the standard, and it offers numerous benefits for establishing a reputation as a trusted and secure partner in today's interconnected world.


We’re offering a completely free, no obligation, tailored Gap Analysis to see how close you would be to implementing ISO 27001:2022. Simply go to the following link to sign up: daten-consult.co.uk/free-iso-27001-gap-analysis



 
 
 

Recent Posts

See All

Comments


bottom of page