Overview
ISO/TS 22375:2018 - Security and resilience - Guidelines for complexity assessment process provides a structured, generic framework for assessing the complexity of an organization’s systems to improve security and resilience. The technical specification defines principles and a step‑wise complexity assessment process that helps organizations identify hidden vulnerabilities and provide early indication of complexity‑related risk. It is applicable to all sizes and types of organizations and system boundaries, including critical assets, strategic networks, supply chains, industrial plants, community infrastructures, banks and commercial enterprises.
Key Topics and Requirements
- Principles: Recognizes complexity as a fundamental system attribute and defines that excessive complexity can create new forms of risk. The process should inform security and risk management.
- Preliminary assessment: Requires top management mandate and commitment, clear policy, allocation of resources, assigned roles and accountabilities, and training to embed competence and awareness.
- Planning: Defines scope, objectives and frequency of complexity assessment. Scope should consider organizational size, mission, legal obligations, products, services and operational objectives.
- Assessment content:
- Identification of structural complexity (elements, relationships) and functional complexity (processes, procedures).
- Detection of interdependencies between processes and units and the main parameters driving complexity.
- Use of documented methodologies, procedures and reliable data sources.
- Implementation: Conduct assessments using tailored methods and procedures; utilize Annex A (list of potential complexity parameters) and Annex B (examples of carrying out the process) for practical guidance.
- Monitoring & review: Establish ongoing review, measurement, and continuous improvement to ensure the complexity assessment remains relevant and effective.
Applications and Who Should Use It
ISO/TS 22375:2018 is intended for practitioners responsible for organizational security, resilience and risk management:
- Security/resilience managers and risk officers
- Business continuity and continuity planners
- Systems engineers and architecture teams assessing interdependencies
- Asset managers, supply‑chain and infrastructure operators
- Senior management seeking to understand complexity‑related vulnerabilities
Practical uses include:
- Early detection of hidden vulnerabilities arising from system complexity
- Prioritizing mitigation actions to reduce complexity‑related risk
- Informing design decisions, procurement, and change management to avoid unnecessary complexity
- Supporting compliance and governance by documenting complexity parameters, scope and objectives
Related Standards
- ISO 22300 - Security and resilience - Vocabulary (referenced for terms and definitions)
- Developed by ISO/TC 292 (Security and resilience) - consult national bodies for implementation guidance
Keywords: ISO/TS 22375:2018, complexity assessment, security and resilience, complexity-related risk, organizational complexity, complexity assessment process.