Publication of the new ISO 27002 standard
June 2023 Dutch version
ISO 27002 specifies information security controls related to risks and threats that must be incorporated into an Information Security Management System. ISO 27002 is part of ISO 27001 and must therefore be implemented by every ISO 27001-certified company. As with every revision of an ISO standard, a three-year transition period applies.
Remco Glashouwer
Author
Fewer control measures
The number of control measures has been reduced from 114 in the previous standard to 93 in ISO 27002:2022. The reduction in the number of control measures is primarily due to consolidations. With the new standard and fewer measures, companies are expected to think more independently and add their own measures where necessary.
New layout
The new standard does, however, introduce a new structure for the control measures. Whereas the old standard was divided into 14 substantive chapters, this has been reduced to 4 main topics, namely:
- Organizational control measures (Chapter 5).
- Human-centered management measures (Chapter 6).
- Physical control measures (Chapter 7).
- Technological control measures (Chapter 8).
New management measures
The new ISO 27002 standard includes 11 new control measures. These measures address new developments in information security and cloud services. The new control measures are:
- 5.7 Information and analyses on threats
- 5.23 Information Security for the Use of Cloud Services
- 5.30 IT Readiness for Business Continuity
- 7.4 Monitoring Physical Security
- 8.9 Configuration Management
- 8.10 Deletion of Information
- 8.11 Data Masking
- 8.12 Preventing Data Breaches
- 8.16 Monitoring Activities
- 8.23 Applying Web Filters
- 8.28 Secure Encryption