Publication of the new ISO 27002 standard

June 2023 Dutch version

ISO 27002 specifies information security controls related to risks and threats that must be incorporated into an Information Security Management System. ISO 27002 is part of ISO 27001 and must therefore be implemented by every ISO 27001-certified company. As with every revision of an ISO standard, a three-year transition period applies.

Photo by Remco Glashouwer

Remco Glashouwer

Author

Fewer control measures

The number of control measures has been reduced from 114 in the previous standard to 93 in ISO 27002:2022. The reduction in the number of control measures is primarily due to consolidations. With the new standard and fewer measures, companies are expected to think more independently and add their own measures where necessary.

New layout

The new standard does, however, introduce a new structure for the control measures. Whereas the old standard was divided into 14 substantive chapters, this has been reduced to 4 main topics, namely:

  • Organizational control measures (Chapter 5).
  • Human-centered management measures (Chapter 6).
  • Physical control measures (Chapter 7).
  • Technological control measures (Chapter 8).

New management measures

The new ISO 27002 standard includes 11 new control measures. These measures address new developments in information security and cloud services. The new control measures are:

  • 5.7 Information and analyses on threats
  • 5.23 Information Security for the Use of Cloud Services
  • 5.30 IT Readiness for Business Continuity
  • 7.4 Monitoring Physical Security
  • 8.9 Configuration Management
  • 8.10 Deletion of Information
  • 8.11 Data Masking
  • 8.12 Preventing Data Breaches
  • 8.16 Monitoring Activities
  • 8.23 Applying Web Filters
  • 8.28 Secure Encryption

Want to know more?

Call me for more information

Fill out your information and we will call you as soon as possible!