When you submit an enquiry via our website, we use the personal data you supply to respond to your query, including providing you with any requested information about our products and services. We may also email you several times after your enquiry in order to follow up on your interest and ensure that we have answered your it to your satisfaction. We will do this based on our legitimate interest in providing accurate information prior to a sale. Your enquiry is stored and processed as an email which is hosted by Microsoft within the European Economic Area (EEA). We keep enquiry emails for two years, after which they are securely archived and kept for seven years, when we delete them.
Obviously the big news story at the moment concerning the ISO27001 standard is the new set of controls published by ISO in February in the form of ISO27002:2022. After a false start and much deliberation, ISO will be updating the ISO27001 standard to match ISO27002 during the year, but in the meantime, we have a slightly awkward period of time where the two standards don’t match. The CertiKit ISO27001 Toolkit Version 11A is an interim release which provides many of the documents needed to bring your ISMS into line with the new control set when you’re ready.
If you haven’t heard, the new set of controls specified in ISO27002:2022 consists of 93 individual controls organised into four themes, namely:
Many of the controls from the previous version have been merged and there are eleven new ones to contend with, which are:
What this means is that organizations that are either already certified to the ISO27001 standard, or are working towards certification, have a choice to make of when to adopt the new control set. Many will undoubtedly simply wait until the new version of ISO27001 appears and then use the transition period (usually around 2 years) to make the switch.
However, there is an opportunity for some to get ahead of the change and to start the adoption of the new controls sooner. And that is what this update to the ISO27001 Toolkit is all about.
In Version 11A we have added a new folder called ISO27002 2022 – New controls which provides a total of 25 additional documents covering the 11 new controls. These are a combination of policies, processes, reports and spreadsheet tools that allow an organization to start to address the new control requirements, whilst maintaining their current ISO27001:2013 ISMS (information security management system).
The list of new documents is as follows:
Of course, you’ll need to consider whether all of these controls are applicable to your organization in the usual “ISO27001 Statement of Applicability” way.
When ISO publishes the new version of the ISO27001 standard (understood to be in 2022) we will be updating the CertiKit ISO27001 Toolkit accordingly (to Version 12) and this will also be available free of charge for those who qualify for our lifetime updates scheme. (This depends on the date you purchased your ISO27001 toolkit, speak to our team if you have any queries).
We expect there to be a transition period for the new standard, and it may well take some time for registered certification bodies to train their auditors up to certify against it, so the first certificates for ISO/IEC 27001:2022 may not be seen until 2023.
In summary, it’s an exciting but possibly confusing time for ISO27001 so don’t forget we’re here to help via our toolkits and related services, so feel free to get in touch.
CertiKit is a provider of ISO toolkits, consultancy and internal auditing services, and has helped more than 4000 organizations worldwide with their compliance.
For more guidance on implementing the ISO27001:2022 standard, we’ve put together a list of our best free resources including video guides, blogs and downloadable documents.