ISO 27001 & ISO 27002 Series
ISO 27001:2022 ISMS implementation guidance
ISO 27001:2022 gives direction to organisations on the elements there Information Security Management System needs to comply with. It helps your organisation in keeping control over the risks.
When we look at ISO 27001:2022 we mainly look at the chapters 4 to 10 for the requirements. Namely:
- 4. Context of the organisation
- 5. Leadership
- 6. Planning
- 7. Support
- 8. Operation
- 9. Performance evaluation
- 10. Improvement
Also see: ISO Series assessment
ISO 27002:2022 Security Controls Required to support ISO 27001:2022
ISO 27001:2022 defines the controls an organisation should implement to support ISO 27001:2022. They are also referred to as the Annex A Controls.
With ISO 27002:2022 the focus is on:
- Technological controls
- Physical controls
- People controls
- Organisational controls