ISO/IEC 27001:2022
Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 19
- Дата публикации:
- 25 октября 2022 г.
- Издание:
- ISO/IEC IS 27001 edition 3 version 1
- ICS:
- 03.100.70
This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.
Abstract
Overview
ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements - defines the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). The standard is generic and applicable to all organizations, regardless of type, size or nature, and requires organizations to assess and treat information security risks in a way that is tailored to their needs. The 2022 edition aligns the ISMS structure with the harmonized Annex SL high-level structure and with ISO/IEC 27002:2022 guidance.
Key topics and technical requirements
- Scope and context (Clause 4): Understand the organization, its internal and external context, interested parties, and determine the ISMS scope.
- Leadership and governance (Clause 5): Senior management commitment, information security policy, and defined roles, responsibilities and authorities.
- Planning (Clause 6): Requirements for addressing risks and opportunities, conducting information security risk assessments, and developing risk treatment plans and security objectives.
- Support (Clause 7): Resource allocation, competence, awareness, communication, and documented information controls.
- Operation (Clause 8): Operational planning and control, implementation of risk treatment measures, and execution of security controls.
- Performance evaluation (Clause 9): Monitoring, measurement, internal audit and management review to verify ISMS effectiveness.
- Improvement (Clause 10): Nonconformity handling, corrective actions and continual improvement of the ISMS.
- Annex A (normative): Reference control objectives and information security controls to guide risk treatment (see ISO/IEC 27002 for implementation guidance).
Important: Clauses 4–10 are mandatory for claims of conformity; organizations may not exclude these requirements.
Practical applications and who uses this standard
ISO/IEC 27001:2022 is used to:
- Build a risk-based ISMS that protects confidentiality, integrity and availability of information.
- Support cybersecurity and privacy protection programs by formalizing governance, controls and monitoring.
- Prepare for third-party certification or to demonstrate compliance to customers, regulators and partners.
- Integrate information security with other management systems (e.g., quality, continuity) using the Annex SL structure.
Typical users:
- CIOs, CISOs and IT/security teams
- Compliance and privacy officers
- Risk managers and internal auditors
- Managed security service providers and consultants
- Small-to-large organizations seeking formalized security controls or certification
Related standards (select)
- ISO/IEC 27000 - Overview and vocabulary for ISMS
- ISO/IEC 27002:2022 - Code of practice for information security controls (implementation guidance)
- Other ISO management system standards that use Annex SL (for integrated management systems)
Keywords: ISO/IEC 27001:2022, ISMS, information security, cybersecurity, privacy protection, risk assessment, Annex A controls, ISO/IEC 27002, certification.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27001:2022
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
ISO/IEC 27000:2014
ОтменёнInformation technology — Security techniques — Information security management systems — Overview and vocabul…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…