On the occasion of the SEC4YOU user meeting in June 2021, we presented the current draft the new ISO/IEC 27002:2021.
The new ISO 27002:2021 is an extension of the aging ISO 27002:2013 (+corrections from 2014 and 2015) and adds the following control objectives:
- Threat intelligence
- Information security for use of cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
The structure and the content
The structure has been significantly changed and now includes the following areas:
5. organizational controls
6. personnel controls
7. physical controls
8. technological controls
The 114 control objectives in 27002:2013 have become approximately 93 control objectives in ISO 27002:2021.
Although the term “cybersecurity” is in the title of the standard, there is not a single control objective that specifically addresses cybersecurity threats. But of course, InfoSec measures support resilience against cyberattacks.
The topic of data protection is dealt with on ¾ page, so the standard does not offer any comprehensive recommendations for data protection.
In the back of the standard, there is an easy-to-use mapping table that can be used to efficiently transfer all controls from 27002:2013 to the new numbering of ISO/IEC 27002:2021. This helps to restructure existing guidelines and quickly identify their completeness.
Things to know about the standard
- ISO 27001:2013 is currently being adapted to the structure of ISO 27002:2021, which should be completed by the end of 2021 or the beginning of 2022. From the validity of the revision, there is a transition period of one year in which the old structure can still be used for certification.
- Companies wishing to be certified from 2022 onwards are recommended to already create their ISMS according to the new structure and to work with the 27002:2013 to 27002:2021 mapping in Annex B of the standard.
- Companies with existing 27001 certification will probably only have to switch to the new structure after 3 years. In any case, however, all companies should align with and implement the new control objectives.
- When will the standard be available for purchase? Presumably from the end of 2021.
Questions?
We will be happy to answer them via our contact form or by call.