Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
IT Security NachrichtenAnthropic-Chef warnt vor KI-Botnetz-Übernahme(21.09.2026 um 08:06 Uhr)
IT Security NachrichtenVor Gipfeltreffen: China und USA tauschen sich zu KI aus(21.09.2026 um 08:18 Uhr)
IT Security NachrichtenHacker stiehlt Daten von Studierenden der Münchner LMU(21.09.2026 um 08:34 Uhr)
IT Security NachrichtenNeue Schutzfunktionen in Microsoft Teams(21.09.2026 um 09:41 Uhr)
IT Security DownloadsSublime Text Download - Beliebter Texteditor(21.09.2026 um 09:12 Uhr)
IT Security DownloadsMaxthon Portable - Kostenloser Web-Browser mit Cloud-Anbindung(21.09.2026 um 09:18 Uhr)
IT Security DownloadsArtMoney Download - Cheat-Programm für Spiele(21.09.2026 um 09:19 Uhr)
IT Security DownloadsNTLite Free Download - Windows-ISO anpassen(21.09.2026 um 09:22 Uhr)
IT Security NachrichtenAnthropic-Chef warnt vor KI-Botnetz-Übernahme(21.09.2026 um 08:06 Uhr)
IT Security NachrichtenVor Gipfeltreffen: China und USA tauschen sich zu KI aus(21.09.2026 um 08:18 Uhr)
IT Security NachrichtenHacker stiehlt Daten von Studierenden der Münchner LMU(21.09.2026 um 08:34 Uhr)
IT Security NachrichtenNeue Schutzfunktionen in Microsoft Teams(21.09.2026 um 09:41 Uhr)
IT Security DownloadsSublime Text Download - Beliebter Texteditor(21.09.2026 um 09:12 Uhr)
IT Security DownloadsMaxthon Portable - Kostenloser Web-Browser mit Cloud-Anbindung(21.09.2026 um 09:18 Uhr)
IT Security DownloadsArtMoney Download - Cheat-Programm für Spiele(21.09.2026 um 09:19 Uhr)
IT Security DownloadsNTLite Free Download - Windows-ISO anpassen(21.09.2026 um 09:22 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Third edition of ISO/IEC 27001 coming

An ISO/IEC JTC 1/SC 27 meeting last night was informed that the planned amendment to ISO/IEC 27001:2013 is to be absorbed into a new third edition of the standard to become ISO/IEC 27001:2022.Apparently, the new 2022 version of '27001 will…

0
↗ Quelle (blog.noticebored.com)
Reagiere als Erste:r — dein Feedback zählt!

An ISO/IEC JTC 1/SC 27 meeting last night was informed that the planned amendment to ISO/IEC 27001:2013 is to be absorbed into a new third edition of the standard to become ISO/IEC 27001:2022.

Apparently, the new 2022 version of '27001 will have minor editorial corrections in the main body text (including one of the two corrigenda published previously), a small but valuable clarification to the notes on subclause 6.1.3, and a complete replacement for Annex A reflecting ISO/IEC 27002:2022.

The transition arrangements are still uncertain but this is my understanding:

  • Nobody will be able to use ISO/IEC 27001:2022 formally until it is published, hopefully on October 1st;
  • The International Accreditation Forum will publish a mandate for the national accreditation bodies (such as IANZ here in New Zealand) at the same time, with details of the 3 year transition period:
    • Accreditation and certification bodies will be required to update their processes, and train and prepare auditors for accreditation and certification against the new standard within a year of its release;
    • Organisations may wish to be certified against the new standard as soon as the certification bodies are ready to do so, or may (continue to) use the old standard for up to three years beyond its release, meaning a full certification cycle;
  • Already (right now), organisations are free to declare any or all of the controls in ISO/IEC 27001:2013 Annex A inapplicable in their Statement of Applicability, instead opting to use an appropriate selection of controls e.g. from ISO/IEC 27002:2022, NIST SP800-50, NIST CSF, ISF, COBIT, CSA, GDPR, PCI-DSS and whatever other sources they like (including entirely custom control sets) in accordance with the current ISO/IEC 27001:2013 clause 6.1.3 note 2, which says in part "The control objectives andcontrols listed in Annex A are not exhaustive and additional control objectives and controls may be needed." Regardless of where the controls come from, organisations must:
    • Use '27001 Annex A as a checklist to confirm that they have not neglected controls that are in fact applicable and necessary to mitigate their information risks;
    • Justify the exclusion of controls from Annex A;
    • Justify the inclusion of controls in the ISMS SoA on the basis that they are required to treat inacceptable information risks; and
    • Indicate their implementation status.

It is worth knowing that ISO/IEC 27001:2013 Annex A can be entirely excluded since it is at least partially out of date and an incomplete reference set of information security controls. ISO/IEC 27002:2022 is considerably improved, but even so it is also weak in some areas, hence may need to be supplemented by other controls that are relevant to each organisation's information risks.

Furthermore, the certification bodies should already be capable of certifying organisations that declare the current Annex A controls inapplicable, opting for other control sets instead. I'm not clear why they and the accreditation bodies would need up to a year to prepare for ISO/IEC 27001:2022 Maybe they will be ready sooner, especially given that their primary job is to confirm the mandatory management system elements against the '27001 main body clauses (which are to remain substantially the same as now), rather than conducting an in-depth audit of the information security controls.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Third edition of ISO/IEC 27001 coming

Thematisch verwandte Begriffe: Third, edition, ISOIEC, 27001 · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94030 | A security vulnerability has been detected in SerenityOS up to 3d83e4509…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick