Revised information: security standard ISO/IEC 27002:2022

Revised information: security standard ISO/IEC 27002:2022

Nov 01, 2022

The ISO (International Organization for Standardization) published a new version of the ISO/IEC 27002:2022 on 15 February 2022. The ISO 27002 is an information security standard stipulating best practices for information security measures in the implementation and maintenance of an Information Security Management System (ISMS). You can read about the most important changes in this article.

ISO 27002

ISO 27002 is an elaboration of ISO 27001. ISO 27001 certification details the requirements for information security management systems. It lets you implement a solid information security strategy to meet the expectations of your customers, regulators and industry systematically. ISO 27002 details the measures for preventing or reducing identified risks.

What changes?

There are three major changes to ISO 27002 from the previous version:
  • 1. The standard is organized differently. The measures are divided into four sections: organizational measures, personnel measures, physical measures and technological measures;
  • 2. A number of measures have been merged;
  • 3. 11 new measures have been added.

What does this mean for your organization?

Als organisatie kunt u nu al werken volgens de maatregelen uit de nieuwe 27002. Bij de verlengingsaudit toetst DEKRA of u hiermee voldoet aan de ISO/IEC 27001:2022.

Want to learn more?

Would you like to stay updated on the latest developments regarding ISO 27001 and ISO 27002? Sign up for our newsletter so you don’t miss a thing! For any questions please contact a DEKRA expert.