28.05.2024
Blog
Regulatory
Cyber Security

The Evolution of ISO 27001: A New Chapter in Information Security Management

ISO 27001 was revised two years ago. Since 1 May, initial certification and recertification have only been possible in accordance with the new standard. The new version contains significant changes aimed at strengthening organisations’ resilience and adaptability with regard to information security. This article highlights the key changes and offers insights into how organisations can adapt

Heike Abels
Referentin für Unternehmenskommunikation

The ISO/IEC 27001 standard is the globally recognised standard for information security management systems (ISMS). Its revisions are of crucial importance to organisations that wish to keep their information security up to date and proactively address potential security threats. The latest changes to ISO 27001 aim to adapt the standard to the fast-changing digital landscape and the associated security risks. The revision of ISO 27001, now titled ‘Information Security, Cybersecurity and Privacy Protection’, places an even greater emphasis on security and data protection. Key changes include:

Enhanced risk management processes

Risk management lies at the heart of ISO 27001. The revision places greater emphasis on the identification, assessment and treatment of risks in a constantly changing threat environment. In light of the growing threats in cyberspace, the International Organisation for Standardisation (ISO) has emphasised the need to introduce advanced risk management strategies that help organisations effectively update their risk management processes in order to develop resilient and robust ISMSs.

Strengthening senior management

One of the most significant changes is the greater involvement of senior management in information security. Senior managers are required to foster a culture of security and to improve the effectiveness of the ISMS through direct engagement and support.

Adapting to new technologies

In a world where new technologies are emerging at a rapid pace, adapting the ISMS to these developments is crucial. Organisations must keep pace with the security requirements of new technologies whilst ensuring compliance. The standard now explicitly takes into account the security aspects of new technologies such as cloud computing, artificial intelligence and the Internet of Things (IoT). Consequently, further measures have been introduced, for example in the areas of threat intelligence, secure coding and monitoring. For instance, organisations are required to collect and analyse data on potential threats to information security. They must also implement best practices in secure coding to prevent vulnerabilities that could be caused by inadequate coding methods. In the area of monitoring, guidelines are provided to improve network monitoring activities, with a view to detecting anomalous behaviour and responding to security events and incidents.

Flexibility and scalability

The changes reflect a deeper understanding that ISMSs must be flexible and scalable to meet the varying needs and sizes of organisations.

Increasing resilience through Business Continuity Management (BCM)

Well-thought-out business continuity management is an essential component of establishing an ISMS and achieving ISO 27001 certification. Through effective business continuity planning, organisations can ensure that full operational capability is restored as quickly as possible in the event of unavoidable or unexpected business interruptions, thereby minimising the impact. This planning requires a thorough risk assessment and analysis, as well as the implementation of measures that safeguard the integrity, availability and confidentiality of data in accordance with all relevant regulations, laws and guidelines.

Implementing the new requirements poses a challenge for many organisations. First and foremost, it is important to gain and maintain an overview of the data requiring protection and to identify the gaps between the outdated version and the new ISO 27001. Once the specific requirements are clear, a project plan setting out the measures to be implemented must be drawn up, and the existing management system must be updated in stages. To ensure a successful transition to the current standard, everyone involved in the process must be included during the implementation phase, so that nothing stands in the way at the end of the audit. Materna provides consultancy services, amongst other things, on the introduction or updating of an ISMS in accordance with ISO 27001, carries out maturity assessments, including the preparation of an action plan, supports you in drawing up ISMS security documentation or implementing technical security measures, conducts internal audits and guides you through your external certification audit.

Further information: Information Security and ISMS or Cyber Security Check

Heike Abels
Referentin für Unternehmenskommunikation

Heike Abels arbeitet bei Materna als Referentin für Unternehmenskommunikation. Sie betreut redaktionell verschiedene Formate für die externe Kommunikation. Thematischer Schwerpunkt ist der Bereich Cross Market Services. Dazu zählen Enterprise Service Management, Customer Service und Cyber Security.