Published On
November 12, 2024
ISO 27001:2022 introduces 11 new controls to address today’s evolving security landscape, strengthening information protection and risk management. Here’s a look at each new control:
Gathering, analyzing, and using threat intelligence to stay proactive and anticipate potential security threats.
Implementing specific security measures for cloud environments to ensure secure usage.
Preparing information and communication technologies to support business continuity in the event of disruptions.
Using surveillance and monitoring to protect physical environments and detect unauthorized access.
Establishing and maintaining secure configurations for systems and devices to minimize vulnerabilities.
Securely deleting information to prevent unauthorized recovery and ensure data privacy.
Obscuring parts of sensitive data to protect privacy, especially during testing or development.
Implementing safeguards to prevent unauthorized access, sharing, or loss of sensitive information.
Regularly observing systems and networks to detect and respond to suspicious activities.
Controlling access to harmful or inappropriate web content to protect users and systems.
Ensuring software is developed with secure coding practices to minimize vulnerabilities and enhance application security.
These new controls keep ISO 27001 relevant in the face of modern security challenges, from cloud service protection to threat intelligence and data leakage prevention. By implementing these controls, organizations stay resilient, responsive, and well-prepared for emerging risks.
#ISO27001 #ISMS #InformationSecurity #CyberSecurity