Filter posts by category

ISO 27001 – 2022 Changes

ISO 27001 Annex A 8.33 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.33

If you are navigating the transition from the old ISO 27001:2013 standard to the shiny new ISO 27001:2022 version, you’ve probably noticed that things have been moved around quite a bit. The Annex A controls have been consolidated, renamed, and in many cases, sharpened to deal with modern digital risks. One specific area that has

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.33 Read More »

ISO 27001 Annex A 8.32 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.32

If you have been keeping up with the world of information security, you’ve likely noticed that the ISO 27001 standard recently underwent its first major refresh in nearly a decade. For those managing compliance, the transition from the 2013 version to the ISO 27001:2022 update felt like a significant shift, particularly regarding how the Annex

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.32 Read More »

ISO 27001 Annex A 8.31 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.31

If you have been working with information security standards for a while, you will know that the transition from ISO 27001:2013 to the ISO 27001:2022 update brought about some significant “housekeeping.” While the core requirements of the management system stayed largely the same, the Annex A controls underwent a massive facelift. One of the most

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.31 Read More »

ISO 27001 Annex A 8.30 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.30

When it comes to building software, many organisations choose to look outside their own walls for talent. Whether it is a specialist agency, a freelance developer, or an offshore team, outsourcing can speed up delivery and lower costs. However, from a security perspective, it often feels like handing over the keys to your house and

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.30 Read More »

ISO 27001 Annex A 8.29 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.29

If you are navigating the transition from the old ISO 27001:2013 standard to the updated 2022 version, you have likely noticed that things look quite different. The Annex A controls have been streamlined, reordered, and in many cases, strengthened. One area that has seen a significant shift in focus is how we validate our security

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.29 Read More »

ISO 27001 Annex A 8.28 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.28

If you have been working within the framework of information security for a while, you’ve likely noticed that the ISO 27001 standard recently had a major makeover. One of the most significant shifts occurred in how we handle software development. Specifically, we are looking at the transition from the 2013 controls to the 2022 version’s

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.28 Read More »

ISO 27001 Annex A 8.27 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.27

If you have been working with information security standards for a while, you know that the transition from ISO 27001:2013 to the 2022 update brought about some significant structural changes. One of the most talked-about additions is Control 8.27, which focuses on Secure System Architecture and Engineering. But if you are looking for this specific

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.27 Read More »

ISO 27001 Annex A 8.25 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.25

Transitioning from ISO 27001:2013 to the 2022 update is a significant milestone for any security-conscious organisation. It isn’t just about moving numbers around; it’s about modernising how we protect data in a world of rapid DevOps and cloud-native building. One of the most impactful changes for development teams is found in Annex A 8.25: Secure

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.25 Read More »

ISO 27001 Annex A 8.22 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.22

If you have been following the evolution of cybersecurity standards, you know that the leap from ISO 27001:2013 to the 2022 version was more than a simple rebrand. It was a tactical shift designed to address the complexities of modern infrastructure, think cloud-native environments, hybrid work, and zero-trust architectures. One of the most vital technical

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.22 Read More »

ISO 27001 Annex A 8.19 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.19

If you have been working with information security standards for any length of time, you know that the transition from ISO 27001:2013 to the ISO 27001:2022 update brought about some significant “housekeeping.” While many of the core principles stayed the same, the way they are organised and prioritised shifted to meet the demands of a

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.19 Read More »

ISO 27001 Annex A 8.18 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.18

If you have been navigating the transition from the old ISO 27001:2013 standard to the new ISO 27001:2022 version, you’ve likely noticed that the Annex A controls have had a significant makeover. One of the most critical shifts involves how we handle the “keys to the kingdom”, specifically, privileged access rights. In the new 2022

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.18 Read More »

ISO 27001 Annex A 8.16 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.16

When comparing the ISO 27001:2013 standard to the 2022 update, you might be searching for the old control that corresponds to Annex A 8.16: Monitoring Activities. The truth is, while the spirit of monitoring was present in the 2013 version (often tucked into incident management or logging), the 2022 update elevates it to a dedicated,

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.16 Read More »

ISO 27001 Annex A 8.15 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.15

In the transition from ISO 27001:2013 to the 2022 update, the way we handle system audit trails has become much more streamlined. If you are reviewing your old Statement of Applicability (SoA) and looking for the specific requirements for logs, you will find they have been unified under Annex A 8.15: Logging. While the fundamental

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.15 Read More »

ISO 27001 Annex A 8.14 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.14

In the transition from ISO 27001:2013 to the 2022 update, the way we talk about keeping the lights on has become much more sophisticated. If you are looking at your old Statement of Applicability (SoA) and trying to find where your redundancy requirements moved, they are now under Annex A 8.14: Redundancy of Information Processing

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.14 Read More »

ISO 27001 Annex A 8.9 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.9

One of the most significant shifts in the transition from ISO 27001:2013 to the 2022 update is the introduction of dedicated controls for modern technical challenges. While many older controls were simply merged or renamed, Annex A 8.9: Configuration Management is a standout addition. It marks a transition from “informal” setup practices to a mandatory,

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.9 Read More »

ISO 27001 Annex A 8.8 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.8

If you’ve been managing your information security using the 2013 version of ISO 27001, you’ll know that staying on top of software bugs and system weaknesses has always been a core requirement. However, in the 2022 update, the landscape of “Management of Technical Vulnerabilities” has shifted significantly. What used to be Control 12.6.1 is now

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.8 Read More »

ISO 27001 Annex A 8.7 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.7

Malware has evolved rapidly since the 2013 version of ISO 27001 was released. Back then, “antivirus” was often seen as a set-it-and-forget-it tool. Today, we face ransomware, fileless malware, and sophisticated phishing campaigns that can bypass traditional signatures. To address this, the 2022 update transformed the old Control 12.2.1 into Annex A 8.7: Protection Against

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.7 Read More »

ISO 27001 Annex A 8.5 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.5

If you have been managing an Information Security Management System (ISMS) based on the 2013 standard, you likely remember Control 9.4.2, which focused heavily on “Secure log-on procedures.” As we transition into the ISO 27001:2022 era, this has been refined and renamed to Annex A 8.5: Secure Authentication. The update reflects a major shift in

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 8.5 Read More »

ISO 27001 Annex A 7.14 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.14

When an organisation upgrades its IT hardware, the old equipment doesn’t just disappear. Whether you are donating old laptops to charity, returning leased servers, or sending decommissioned hard drives to a recycler, you are handling a potential “data goldmine” for attackers. This is where ISO 27001 comes in to ensure that your “trash” doesn’t become

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.14 Read More »

ISO 27001 Annex A 7.13 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.13

If you are navigating the transition from the old ISO 27001:2013 standard to the updated 2022 version, you have likely noticed that the Annex A controls have undergone a significant facelift. One of the specific areas that has moved is the control regarding equipment maintenance. In the 2013 version, this sat under the somewhat clunky

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.13 Read More »

ISO 27001 Annex A 7.10 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.10

When the ISO 27001 standard was updated in 2022, one of the primary goals was to simplify the complex web of 114 controls and make them more intuitive for modern businesses. One area that benefited significantly from this “clean-up” is the management of physical storage media. In the 2022 version, several older controls were consolidated

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.10 Read More »

ISO 27001 Annex A 7.9 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.9

Transitioning from ISO 27001:2013 to the 2022 update involves more than just renumbering controls. It represents a fundamental shift in how we view the “perimeter” of our businesses. In the 2013 era, assets usually stayed within the four walls of an office. Today, your assets are in coffee shops, home offices, and transit hubs. This

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.9 Read More »

ISO 27001 Annex A 7.6 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.6

When you are upgrading your Information Security Management System (ISMS) from the 2013 version to the 2022 update, you will notice that the “Physical” theme has been streamlined to reflect modern working environments. One of the most critical controls for any organization handling sensitive hardware or physical records is the management of secure areas. In

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.6 Read More »

ISO 27001 Annex A 7.5 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.5

When transitioning from the 2013 version of ISO 27001 to the 2022 update, many organisations focus heavily on the new digital controls. However, the physical environment remains a massive risk factor. In the 2022 version, the protection against external and environmental threats has been refined and moved to Annex A 7.5: Protecting against physical and

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.5 Read More »

ISO 27001 Annex A 7.4 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.4

If you are in the middle of transitioning your Information Security Management System (ISMS) from the 2013 version to the 2022 update, you have probably noticed that the physical security section has been given a significant upgrade. While the older version focused heavily on perimeters and entry points, the new standard introduces a more proactive

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.4 Read More »

ISO 27001 Annex A 7.3 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.3

When you are navigating the transition from ISO 27001:2013 to the 2022 update, it is easy to get caught up in the digital jargon of cloud security and threat intelligence. However, the physical environment remains a critical pillar of any robust Information Security Management System (ISMS). One of the most important shifts in the physical

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.3 Read More »

ISO 27001 Annex A 7.1 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.1

When most people think of ISO 27001, they immediately think of digital threats, hackers, firewalls, and encryption. But a significant portion of the standard has always been dedicated to the “real world.” In the transition from the 2013 version to the 2022 update, the rules for protecting your physical space were given a modern makeover.

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 7.1 Read More »

ISO 27001 Annex A 6.6 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 6.6

In the transition from ISO 27001:2013 to the 2022 update, the standard underwent a significant structural “clean up.” While many people focus on the brand-new technical controls, some of the most practical changes happened to the way we manage legal and people-centric risks. Annex A 6.6: Confidentiality or Non-Disclosure Agreements (NDAs) is a prime example.

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 6.6 Read More »

ISO 27001 Annex A 6.4 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 6.4

When an organisation undergoes the transition from ISO 27001:2013 to the 2022 update, much of the attention naturally goes to technical upgrades like cloud security or threat intelligence. However, some of the most critical changes involve how we manage our people. One such area is the disciplinary process, now found under Annex A 6.4. While

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 6.4 Read More »

ISO 27001 Annex A 5.37 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.37

If you have spent any time with the ISO 27001 standard, you know that documentation is the backbone of a successful Information Security Management System (ISMS). When the standard moved from the 2013 version to the 2022 update, many controls were shifted, merged, or expanded. One of the most essential “day-to-day” controls, Documented Operating Procedures,

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.37 Read More »

ISO 27001 Annex A 5.36 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.36

When ISO 27001 transitioned from the 2013 version to the 2022 update, many organisations felt a bit like they were learning a new language. While the “grammar” of the management system stayed the same, the “vocabulary” of the Annex A controls was completely rewritten. One of the most important consolidations in this new dictionary is

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.36 Read More »

ISO 27001 Annex A 5.35 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.35

When ISO 27001 was updated from the 2013 version to the 2022 iteration, many people focused on the shiny new controls like threat intelligence or cloud security. However, some of the most critical changes happened to the “governance” controls, the ones that ensure your security actually works. Annex A 5.35, which covers the Independent Review

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.35 Read More »

ISO 27001 Annex A 5.34 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.34

If you have been navigating the world of data protection recently, you know that privacy is no longer just a “bonus” feature of information security, it is a central requirement. When ISO 27001 transitioned from the 2013 version to the 2022 update, one of the most significant shifts occurred in how we handle Personally Identifiable

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.34 Read More »

ISO 27001 Annex A 5.33 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.33

If you have been managing an Information Security Management System (ISMS) for a few years, you are likely aware that the ISO 27001 standard recently had a major refresh. While the management system itself stayed mostly the same, the Annex A controls, the specific actions we take to secure data, were rearranged and modernised. One

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.33 Read More »

ISO 27001 Annex A 5.32 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.32

If you have been working with information security standards for a while, you’ll know that the transition from ISO 27001:2013 to the 2022 update brought about some significant housekeeping. One of the areas that saw a shift in placement, though its core mission remains vital is the protection of Intellectual Property Rights (IPR). In the

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.32 Read More »

ISO 27001 Annex A 5.31 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.31

If you have been working within the world of information security for a while, you probably know that ISO 27001 underwent a significant facelift recently. We moved from the familiar 2013 version to the more modern 2022 iteration. While the core management system requirements stayed relatively stable, the Annex A controls, the “bread and butter”

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.31 Read More »

ISO 27001 Annex A 5.27 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.27

In the world of information security, experience is the best teacher but only if you actually take the time to listen. The transition from ISO 27001:2013 to the 2022 update brought a significant refinement to how organizations should process their failures. This is found in Annex A 5.27: Learning from information security incidents. If you

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.27 Read More »

ISO 27001 Annex A 5.26 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.26

When a security incident hits, the difference between a minor hiccup and a business-ending catastrophe often comes down to one thing: the quality of your response. ISO 27001 has always mandated that organizations react to incidents, but the transition from the 2013 version to the 2022 update has refined how we handle the “heat of

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.26 Read More »

ISO 27001 Annex A 5.25 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.25

In the world of information security, not every digital “ping” or system anomaly is a catastrophe. However, the ability to quickly distinguish a routine event from a full-blown crisis is what separates resilient organisations from those that end up in the headlines. This is exactly what Annex A 5.25: Assessment and Decision on Information Security

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.25 Read More »

ISO 27001 Annex A 5.23 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.23

For nearly a decade, the ISO 27001:2013 standard served as the gold standard for information security. However, back in 2013, the “cloud” was often treated as just another type of outsourcing. Fast forward to the 2022 update, and the reality has shifted. Most businesses now live in the cloud. Recognising this, the updated standard introduced

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.23 Read More »

ISO 27001 Annex A 5.21 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.21

In the world of information security, your protection is only as strong as the weakest link in your chain. Increasingly, that link isn’t inside your office—it is somewhere deep within your Information and Communications Technology (ICT) supply chain. With the release of ISO 27001:2022, the standard has taken a much more aggressive stance on how

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.21 Read More »

ISO 27001 Annex A 5.20 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.20

In the transition from the 2013 version of ISO 27001 to the 2022 update, many organisations have found that the “Supplier Management” domain has received a significant level of attention. While the previous article in this series touched on the overarching relationship management (Annex A 5.19), Annex A 5.20 specifically zooms in on the legal

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.20 Read More »

ISO 27001 Annex A 5.19 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.19

In the modern business landscape, very few companies operate in a vacuum. We rely on cloud providers, software vendors, and specialized consultants to keep the wheels turning. This interconnectedness is a superpower, but from a security perspective, it is also a significant vulnerability. ISO 27001 has always recognized this, but the 2022 update brings a

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.19 Read More »

ISO 27001 Annex A 5.17 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.17

When you think about information security, “Authentication Information” is often the first line of defence that comes to mind. It is the secret handshake, the passwords, tokens, and biometrics, that proves you are who you say you are. In the transition from ISO 27001:2013 to the 2022 version, this area saw a significant structural facelift.

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.17 Read More »

ISO 27001 Annex A 5.15 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.15

If you have been navigating the world of information security for a while, you know that keeping up with ISO standards can feel like chasing a moving target. With the release of ISO 27001:2022, many professionals are scratching their heads wondering exactly how their existing controls have shifted. One of the most significant areas of

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.15 Read More »

ISO 27001 Annex A 5.11 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.11

Offboarding an employee used to be relatively simple: you’d collect their building pass, take back their laptop, and wish them well. But in today’s world of remote work, cloud accounts, and personal devices, “getting your stuff back” has become significantly more complex. This is where ISO 27001:2022 Annex A 5.11, “Return of Assets,” comes into

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.11 Read More »

ISO 27001 Annex A 5.9 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.9

Asset management has always been the bedrock of a solid Information Security Management System (ISMS). After all, you cannot protect what you don’t know you have. However, as our work environments have shifted from physical filing cabinets to complex cloud infrastructures and virtual machines, the standard had to evolve. This evolution is most evident in

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.9 Read More »

ISO 27001 Annex A 5.6 - what changed in the 2022 update

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.6

If you have been working with information security standards for a while, you know that ISO 27001 isn’t a static document. It evolves to keep pace with an increasingly complex digital landscape. One of the specific areas that often sparks questions during a transition is Annex A 5.6, which deals with “Contact with special interest

What Changed Between the 2013 and 2022 Versions? ISO 27001:2022 Annex A 5.6 Read More »

ISO 27001 Annex A 5.5 - what changed in the 2022 update

How to Audit What Changed Between the 2013 and 2022 Versions: ISO 27001 Annex A 5.5

If you are preparing for an internal audit or transitioning your Information Security Management System (ISMS) to the latest standards, you have likely noticed that the landscape has shifted. One specific area that requires a closer look is how your organisation interacts with the outside world—specifically, government bodies and regulators. This brings us to the

How to Audit What Changed Between the 2013 and 2022 Versions: ISO 27001 Annex A 5.5 Read More »