ISO 22342:2023
Security and resilience — Protective security — Guidelines for the development of a security plan for an organization
Security and resilience — Protective security — Guidelines for the development of a security plan for an organization
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 11
- Дата публикации:
- 28 апреля 2023 г.
- Издание:
- ISO IS 22342 edition 1 version 1
- ICS:
- 03.100.01
This document gives guidance on developing and maintaining security plans. The security plan describes how an organization establishes effective security planning and how it can integrate security within organizational risk management practices. This document is applicable to all organizations regardless of type, size and nature, whether in the private, public or not-for-profit sectors, that wish to develop effective security plans in a consistent manner. This document is applicable to any organization intending to implement measures designed to protect their assets against malicious acts and mitigate their associated risks. This document does not provide specific criteria for identifying the need to implement or enhance prevention and protection measures against malicious acts. It does not apply to services and operations delivered by private security companies.
Abstract
Overview - ISO 22342:2023 (Security plan development)
ISO 22342:2023 provides guidance for developing and maintaining a security plan for organizations of any type, size or sector. The standard describes how to integrate protective security into organizational risk management, allocate responsibilities, and apply controls to protect assets against malicious acts. It supports an adaptive, agile approach that can be integrated into existing management systems and aligned with an organization’s mission and objectives.
Key topics and technical requirements
ISO 22342:2023 focuses on practical components needed to create an effective security plan. Major topics include:
-
Governance
- Define security objectives, scope and boundaries of the security plan.
- Establish leadership, roles, accountabilities and responsibilities.
- Identify legal, regulatory and contractual obligations.
- Set up communication, documented information, reporting, evaluation and continuous improvement.
-
Management of risk
- Align security planning with risk management processes (referenced to ISO 31000).
- Define risk scope, context and criteria; conduct risk assessment, treatment and acceptance of residual risk.
- Ensure communication, consultation, monitoring, review and recordkeeping for security risks.
-
Security controls
- Select appropriate levels of protection and operational controls (technical and human-related).
- Prepare procedures, contingency planning for low-likelihood/unforeseen events, and timelines for security activities.
-
Security controls process
- Process for selecting, implementing, testing, evaluating and monitoring controls.
- Methods to determine effectiveness and to adjust measures through iterative review.
Note: ISO 22342:2023 gives guidance but does not prescribe specific criteria for when to implement particular prevention/protection measures and does not apply to services delivered by private security companies.
Practical applications - who should use it
ISO 22342 is intended for any organization that wants to standardize the development and maintenance of a security plan. Typical users include:
- Security managers and risk managers
- C-suite and board members responsible for governance and resilience
- Compliance and continuity professionals
- Facilities and operations managers
- Consultants and advisors developing organizational security frameworks
Practical uses: designing enterprise security plans, integrating protective security into management systems, developing contingency planning, and establishing governance and reporting frameworks to manage security risk.
Related standards
- ISO 31000 - Risk management - Guidelines (alignment of risk processes)
- ISO 22300 - Security and resilience - Vocabulary (definitions)
- ISO 28000:2022 - Supply chain/security plan content referenced
Keywords: ISO 22342:2023, security plan, protective security, security planning, risk management, security controls, governance, organizational security, contingency planning.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 22342:2023
Похожие стандарты
Стандарты, упомянутые в описании
ISO 28000:2022
ДействующийSecurity and resilience — Security management systems — Requirements
Overview ISO 28000:2022 - Security and resilience - Security management systems - Requirements specifies requirements for a security management system (SMS) with a strong emphasis on supply chain sec…
ISO 31000:2018
ДействующийRisk management — Guidelines
Overview ISO 31000:2018 - Risk management - Guidelines provides a unified, organization‑wide approach to managing risk. It offers adaptable guidance that can be customized to any organization, sector…
BS EN ISO 2234:2002
ДействующийPackaging. Complete, filled transport packages and unit loads. Stacking tests using a static load.
ISO 22300:2021
ОтменёнSecurity and resilience — Vocabulary
Overview ISO 22300:2021 - Security and resilience - Vocabulary is the third edition (2021) of ISO’s core vocabulary for security and resilience standards. It defines generic and subject‑specific term…