ISO 27001 2002 Update Webinar.pdf

ControlCase
ControlCaseControlCase
WEBINAR:
ISO 27001:2022 UPDATE
Presented by:
Ricardo Pardo, Controlcase Partner SOC & ISO
Kishor Vaswani, ControlCase Chief Strategy Officer
Agenda
© ControlCase. All Rights Reserved. 2
A. Introduction to ControlCase
B. Overview of the ISO Family of Standards
C. What are the updates to 27001:2022?
1. Revision Update
2. Summary of Changes
3. Timelines
4. Impact of the changes
D. Q&A
A.
© 2020 ControlCase. All Rights Reserved. 3
ControlCase Introduction
ControlCase Snapshot
CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES
Go beyond the auditor’s checklist to:
Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance.
© 2020 ControlCase. All Rights Reserved. 4
• Demonstrate compliance more efficiently
and cost effectively (cost certainty)
• Improve efficiencies
⁃ Do more with less resources and gain
compliance peace of mind
• Free up your internal resources to focus
on their priorities
• Offload much of the compliance burden to
a trusted compliance partner
1,000+ 300+
10,000+
CLIENTS IT SECURITY
CERTIFICATIONS
SECURITY
EXPERTS
Solution
© ControlCase. All Rights Reserved. 5
Certification and Continuous Compliance Services
“
I’ve worked on both sides of auditing. I
have not seen any other firm deliver
the same product and service with the
same value. No other firm provides that
continuous improvement and the level of
detail and responsiveness.
— Security and Compliance Manager,
Data Center
Certification Services
One Audit™
Assess Once. Comply to Many.
© 2020 ControlCase. All Rights Reserved. 6
“You have 27 seconds to make a first
impression. And after our initial
meeting, it became clear that they
were more interested in helping
our business and building a
relationship, not just getting the
business.
— Sr. Director, Information Risk & Compliance,
Large Merchant
PCI DSS ISO 27001
& 27002
SOC 1,2,3 & SOC
for Cybersecurity
HITRUST CSF
HIPAA PCI P2PE GDPR NIST CSF Risk
Assessment
PCI PIN PCI PA-DSS FedRAMP PCI 3DS
OVERVIEW OF THE ISO FAMILY OF
STANDARDS
B.
© ControlCase. All Rights Reserved. 7
What is ISO 27001?
© ControlCase. All Rights Reserved. 8
INTERNATIONAL ORGANIZATION FOR STANDARDIZATION
ISO/IEC 27001 (WIDELY KNOWN AS ISO 27001) IS PART OF THE ISO/IEC 27000 FAMILY OF STANDARDS
Focused on information
security and enabling
organizations to manage
security assets.
ISO 27001 provides the
requirements for an
Information Security
Management System
(ISMS).
Takes a risk-based
approach to managing
information security.
ISO 27001 vs ISO 27002
© ControlCase. All Rights Reserved. 9
• ISO 27001 is the central framework of the ISO 27000
series relating to information security management.
• Lists each aspect required for the ISMS.
• ISO 27001 contains implementation requirements
for an ISMS.
• ISO 27001 is a certification.
27001 27002
• ISO 27002 is a supplementary standard that focuses on
the information security controls that organizations might
choose to implement.
• Addresses information security controls only
• ISO 27002 is not a certification
What is ISO 27701?
© ControlCase. All Rights Reserved. 10
INTERNATIONAL ORGANIZATION FOR STANDARDIZATION
ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002
and provides additional guidance for the protection of privacy, which is
potentially affected by the collection and processing of personal information.
What is ISO 27017 and 27018?
© ControlCase. All Rights Reserved. 11
Security techniques — Code of practice for information security
controls based on ISO/IEC 27002 for cloud services.
27017 27018
Security techniques - Code of practice for protection of personally
identifiable information (PII) in public clouds acting as PII processors.
• Both are add-on extensions of
the ISO 27001 standard.
• All of the clauses and
annexures apply the same as
the main 27001.
• You cannot perform either of
these without the 27001.
• An accrediting body cannot
performed these if they have
not performed the 27001
assessment
What is an ISMS?
An ISMS (Information Security Management Systems) is a framework of policies
and procedures that includes all legal, physical and technical controls involved in
an organization's information risk management processes.
© ControlCase. All Rights Reserved. 12
Compliance vs Certification
© ControlCase. All Rights Reserved. 13
ISO 27001 COMPLIANT
Means the organization
follows the ISO 27001 standard.
ISO 27001 CERTIFIED
Means the organization’s ISO 27001
Information Security Management System
has been certified in compliance with the
standard by auditors known as Certification
Bodies.
Who Needs ISO 27001 Certification?
Any organization that wishes or is required to formalise and improve business
processes around information security, privacy and securing its information assets.
The size/turnover of a business does not dictate the need for ISO 27001.
© ControlCase. All Rights Reserved. 14
Privacy Add-on Assessment (ISO 27701)
© ControlCase. All Rights Reserved. 15
INTERNATIONAL ORGANIZATION FOR STANDARDIZATION
• Additional assessment time
required.
• Depends on the entity being a
PII controller or PII processor
or both.
PII CONTROLLER
• Covers areas like contracts
and obligations to consumer.
• Covers retention and disposal
objectives.
PII PROCESSOR
• Covers areas such as marketing
and advertising use.
• Covers inter-organization and
inter-country rules of PII.
How Often Do You Need ISO 27001?
© ControlCase. All Rights Reserved. 16
INTERNATIONAL ORGANIZATION FOR STANDARDIZATION
ISO Certification is
valid for 3 years.
Surveillance audits are
required in year 2 and year 3.
Certification Methodology – YEAR 1
© ControlCase. All Rights Reserved. 17
ITERATIVE PRE-ASSESSMENT ISO STAGE 1 AUDIT ISO STAGE 2 AUDIT DELIVERABLES
• Consolidated Pre-Assessment
• Evaluation of policies and
procedures.
• Multiple rounds of assessment
before Stage 1 and Stage 2
Audit.
Onsite/ Remote
Average of 4 days
Onsite/ Remote
Average of 6 days
• ISO 27001 Certificate
issued
• Extension Documents
Released
PHASE PHASE
3
1 2
PHASE
Minimum 10 days between Stage 1 – 2
2A 2B
AVERAGE TIMELINE FOR PHASE 1 – 3 IS 6 MONTHS
ISO Surveillance Audits – YEAR 2 and YEAR 3
© ControlCase. All Rights Reserved. 18
ISO 27001 REQUIRES THAT SURVEILLANCE AUDITS
BE COMPLETED FOR YEAR 2 AND YEAR 3.
Surveillance audits are mini audits
assessing the certified client's management
system’s is still compliant to ISO 27001.
Surveillance audits are not
full system audits.
General Compliance Challenges
© ControlCase. All Rights Reserved. 19
Takes people away from
their core responsibilities
Proving and maintaining compliance places
a significant burden on organizations.
Strains already
taxed resources
ORGANIZATIONS STRUGGLE WITH:
Dealing with multiple
regulations.
Keeping up with changing
regulations and
compliance requirements.
Understanding and
translating compliance
frameworks.
The lack of visibility into
their compliance posture.
The time spent
preparing for audits.
TRADITIONAL AUDITOR’S CHECKLIST APPROACH ISN’T ENOUGH.
Common Challenges to ISO 27001/27701
Business
Associate
Vulnerability
Management
Logging &
Monitoring
Encryption PII Policies
& Training
• Agreements to be
formalized
• Vendor
management
process
• Periodic
vulnerability
management
• Patching devices
• Application
code rewrite
• 24X7X365
monitoring
• Managing volume
of logs
• Encryption of PII • Annual training
• Documented PII
policies and
procedures
© ControlCase. All Rights Reserved. 20
WHAT ARE THE UPDATES TO
27001:2022?
C.
© ControlCase. All Rights Reserved. 21
What are the updates to 27001:2022
© ControlCase. All Rights Reserved. 22
No major changes to
ISO 27001: 2013
Mandatory Clauses 4 to 10.
The Security Controls
contained in Annex A
have decreased
from 114 to 93.
Controls (ISO 27002:2022) are
now grouped in 4 main
domains (instead of the
previous 14) and are tagged for
easier reference and use.
• Organizational Controls
• People Controls
• Physical Controls
• Technological Controls
New controls have
been introduced, while
none of the controls
were deleted, many
controls were merged,
thereby reducing the
overall number.
SUMMARY OF CHANGES
Four Domains for ISO 27002:2022
© ControlCase. All Rights Reserved. 23
ORGANIZATIONAL CONTROLS PEOPLE CONTROLS
PHYSICAL CONTROLS TECHNOLOGICAL CONTROLS
What are the Control Updates to 27002:2022
© ControlCase. All Rights Reserved. 24
Threat intelligence
Physical security
monitoring
Data masking Web filtering
Information security for
the use of cloud
services
Configuration
management
Data leakage prevention Secure coding
ICT readiness for
business continuity
Information deletion Monitoring activities
ISO 27002: Organizational Controls
Policies for information security Return of assets
Addressing information security within
supplier agreements
Information security during disruption
Segregation of duties Classification of information
Managing information security in the ICT
supply chain
ICT readiness for business continuity (new)
Management responsibilities Labelling of information
Monitoring, review and change
management of supplier services
Legal, statutory, regulatory, and contractual
requirements
Contact with authorities Information transfer
Information security for use of cloud
services (new)
Intellectual property rights
Contact with special interest groups Access control
Information security incident management
planning and preparation
Protection of records
Threat intelligence (new) Identity management
Assessment and decision on information
security events
Privacy and protection of PII
Information security in project management Authentication information Response to information security incidents Independent review of information security
Inventory of information and other
associated assets
Access rights Learning from information security incidents
Compliance with policies, rules and
standards for information security
Acceptable use of information and other
associated assets
Information security in supplier relationships Collection of evidence Documented operating procedures
© ControlCase. All Rights Reserved. 25
ISO 27002: Physical Controls
Physical security perimeters
Securing offices, rooms and facilities
Physical security monitoring (new)
Protecting against physical and environmental threats
Working in secure areas
Clear desk and clear screen
Equipment siting and protection
Security of assets off-premises
Storage media
Supporting utilities
Cabling security
Equipment maintenance
Secure disposal or re-use of equipment
© ControlCase. All Rights Reserved. 26
Control 7.14: Secure disposal or re-use of equipment (example)
© ControlCase. All Rights Reserved. 27
Adoption Timeline
© ControlCase. All Rights Reserved. 28
Any ISO 27001 audit that happens after Oct 2025
must be against the new version.
Companies can voluntarily choose to certify against
the ISO 27002:2022 revision with ControlCase in
mid 2023.
Next Steps
© ControlCase. All Rights Reserved. 29
Companies should review
their risk register and the
applied risk treatments to
ensure alignment with the
revised standard.
Update the Statement of
Applicability (SoA) to
align with the updated
Annex A.
Review and update your
documentation,
including policies and
procedures to meet the
new controls
Get audited against the
new ISO 27001:2022
standard using a certified
auditor such as
ControlCase
Step 1 Step 2 Step 3 Step 4
Q & A
D.
© ControlCase. All Rights Reserved. 30
THANK YOU FOR THE OPPORTUNITY
TO CONTRIBUTE TO YOUR IT
COMPLIANCE PROGRAM.
www.controlcase.com
contact@controlcase.com
Download ISO 27001 Compliance Checklist
ISO 27001 Compliance Blog
Schedule ISO 27001 Compliance Discussion
1 sur 31

Recommandé

ISO 27001 Awareness/TRansition.pptx par
ISO 27001 Awareness/TRansition.pptxISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptxDr Madhu Aman Sharma
1.4K vues44 diapositives
NQA ISO 27001 Implementation Guide par
NQA ISO 27001 Implementation GuideNQA ISO 27001 Implementation Guide
NQA ISO 27001 Implementation GuideNQA
464 vues32 diapositives
Why ISO27001 For My Organisation par
Why ISO27001 For My OrganisationWhy ISO27001 For My Organisation
Why ISO27001 For My OrganisationVigilant Software
1.9K vues20 diapositives
ISO/IEC 27001:2022 – What are the changes? par
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?PECB
5.4K vues66 diapositives
ISO 27001_2022 Standard_Presentation.pdf par
ISO 27001_2022 Standard_Presentation.pdfISO 27001_2022 Standard_Presentation.pdf
ISO 27001_2022 Standard_Presentation.pdfSerkanRafetHalil1
169 vues67 diapositives
2022 Webinar - ISO 27001 Certification.pdf par
2022 Webinar - ISO 27001 Certification.pdf2022 Webinar - ISO 27001 Certification.pdf
2022 Webinar - ISO 27001 Certification.pdfControlCase
1.2K vues38 diapositives

Contenu connexe

Tendances

ISO 27005:2022 Overview 221028.pdf par
ISO 27005:2022 Overview 221028.pdfISO 27005:2022 Overview 221028.pdf
ISO 27005:2022 Overview 221028.pdfAndrey Prozorov, CISM, CIPP/E, CDPSE. LA 27001
8.6K vues33 diapositives
ISO 27001 Certification - The Benefits and Challenges par
ISO 27001 Certification - The Benefits and ChallengesISO 27001 Certification - The Benefits and Challenges
ISO 27001 Certification - The Benefits and ChallengesCertification Europe
5.7K vues11 diapositives
Overview of ISO 27001 ISMS par
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMSAkhil Garg
1.5K vues33 diapositives
ISO 27001 2013 isms final overview par
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overviewNaresh Rao
2K vues34 diapositives
What is iso 27001 isms par
What is iso 27001 ismsWhat is iso 27001 isms
What is iso 27001 ismsCraig Willetts ISO Expert
1.5K vues33 diapositives
ISO 27001 par
ISO 27001ISO 27001
ISO 27001n|u - The Open Security Community
30.2K vues17 diapositives

Tendances(20)

Overview of ISO 27001 ISMS par Akhil Garg
Overview of ISO 27001 ISMSOverview of ISO 27001 ISMS
Overview of ISO 27001 ISMS
Akhil Garg1.5K vues
ISO 27001 2013 isms final overview par Naresh Rao
ISO 27001 2013 isms final overviewISO 27001 2013 isms final overview
ISO 27001 2013 isms final overview
Naresh Rao2K vues
ISO 27001:2013 Implementation procedure par Uppala Anand
ISO 27001:2013 Implementation procedureISO 27001:2013 Implementation procedure
ISO 27001:2013 Implementation procedure
Uppala Anand20.1K vues
Iso 27001 isms presentation par Midhun Nirmal
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
Midhun Nirmal17.2K vues
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard par PECB
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information StandardQuick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
Quick Guide to ISO/IEC 27701 - The Newest Privacy Information Standard
PECB 7.3K vues
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a... par PECB
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
PECB 235 vues
Basic introduction to iso27001 par Imran Ahmed
Basic introduction to iso27001Basic introduction to iso27001
Basic introduction to iso27001
Imran Ahmed10.7K vues
ISO 27001 - Information security user awareness training presentation - part 3 par Tanmay Shinde
ISO 27001 - Information security user awareness training presentation - part 3ISO 27001 - Information security user awareness training presentation - part 3
ISO 27001 - Information security user awareness training presentation - part 3
Tanmay Shinde24.9K vues
How can the ISO 27701 help to design, implement, operate and improve a privac... par Hernan Huwyler, MBA CPA
How can the ISO 27701 help to design, implement, operate and improve a privac...How can the ISO 27701 help to design, implement, operate and improve a privac...
How can the ISO 27701 help to design, implement, operate and improve a privac...
ISO/IEC 27701 vs GDPR: What you need to know par PECB
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to know
PECB 2.3K vues
ISO27001: Implementation & Certification Process Overview par Shankar Subramaniyan
ISO27001: Implementation & Certification Process OverviewISO27001: Implementation & Certification Process Overview
ISO27001: Implementation & Certification Process Overview

Similaire à ISO 27001 2002 Update Webinar.pdf

ISO 27001 In The Age Of Privacy par
ISO 27001 In The Age Of PrivacyISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of PrivacyControlCase
415 vues26 diapositives
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_... par
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...acinfotec
392 vues38 diapositives
Continuous Compliance Monitoring par
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance MonitoringControlCase
815 vues35 diapositives
Control Standards for Information Security par
Control Standards for Information SecurityControl Standards for Information Security
Control Standards for Information SecurityJohnHPazEMCPMPITIL5G
129 vues9 diapositives
Whitepaper iso 27001_isms | All about ISO 27001 par
Whitepaper iso 27001_isms | All about ISO 27001Whitepaper iso 27001_isms | All about ISO 27001
Whitepaper iso 27001_isms | All about ISO 27001Chandan Singh Ghodela
101 vues16 diapositives
ISO/IEC 27001:2013 An Overview par
ISO/IEC 27001:2013  An Overview ISO/IEC 27001:2013  An Overview
ISO/IEC 27001:2013 An Overview Ahmed Riad .
40K vues7 diapositives

Similaire à ISO 27001 2002 Update Webinar.pdf(20)

ISO 27001 In The Age Of Privacy par ControlCase
ISO 27001 In The Age Of PrivacyISO 27001 In The Age Of Privacy
ISO 27001 In The Age Of Privacy
ControlCase415 vues
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_... par acinfotec
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
C-SEC|2016 Session 1 Addressing Cyber Threats with Modern Security Framework_...
acinfotec392 vues
Continuous Compliance Monitoring par ControlCase
Continuous Compliance MonitoringContinuous Compliance Monitoring
Continuous Compliance Monitoring
ControlCase815 vues
ISO/IEC 27001:2013 An Overview par Ahmed Riad .
ISO/IEC 27001:2013  An Overview ISO/IEC 27001:2013  An Overview
ISO/IEC 27001:2013 An Overview
Ahmed Riad .40K vues
Soc 2 attestation or ISO 27001 certification - Which is better for organization par VISTA InfoSec
Soc 2 attestation or ISO 27001 certification - Which is better for organizationSoc 2 attestation or ISO 27001 certification - Which is better for organization
Soc 2 attestation or ISO 27001 certification - Which is better for organization
VISTA InfoSec211 vues
SOC 2 Compliance and Certification par ControlCase
SOC 2 Compliance and CertificationSOC 2 Compliance and Certification
SOC 2 Compliance and Certification
ControlCase3.4K vues
Soc 2 vs iso 27001 certification withh links converted-converted par VISTA InfoSec
Soc 2 vs iso 27001 certification withh links converted-convertedSoc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-converted
VISTA InfoSec180 vues
The best way to use ISO 27001 par powertech
The best way to use ISO 27001The best way to use ISO 27001
The best way to use ISO 27001
powertech958 vues
G12: Implementation to Business Value par HyTrust
G12: Implementation to Business ValueG12: Implementation to Business Value
G12: Implementation to Business Value
HyTrust430 vues
NQA Your Complete Guide to ISO 27001 par NQA
NQA Your Complete Guide to ISO 27001NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001
NQA 129 vues
NQA Your Complete Guide to ISO 27001 par NA Putra
NQA Your Complete Guide to ISO 27001NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001
NA Putra96 vues
Iso27001 Isaca Seminar (23 May 08) par samsontamwaiho
Iso27001  Isaca Seminar (23 May 08)Iso27001  Isaca Seminar (23 May 08)
Iso27001 Isaca Seminar (23 May 08)
samsontamwaiho1.3K vues
Iso27001 Isaca Seminar (23 May 08) par samsontamwaiho
Iso27001  Isaca Seminar (23 May 08)Iso27001  Isaca Seminar (23 May 08)
Iso27001 Isaca Seminar (23 May 08)
samsontamwaiho620 vues
CQI-IRCA 27001:2013 Lead Auditor Course par Desmond Muchetu
CQI-IRCA 27001:2013  Lead Auditor Course CQI-IRCA 27001:2013  Lead Auditor Course
CQI-IRCA 27001:2013 Lead Auditor Course
Desmond Muchetu72 vues
NQA ISO 9001 to ISO 27001 Gap Guide par NQA
NQA ISO 9001 to ISO 27001 Gap GuideNQA ISO 9001 to ISO 27001 Gap Guide
NQA ISO 9001 to ISO 27001 Gap Guide
NQA 358 vues

Plus de ControlCase

PCI DSS v4 - ControlCase Update Webinar Final.pdf par
PCI DSS v4 - ControlCase Update Webinar Final.pdfPCI DSS v4 - ControlCase Update Webinar Final.pdf
PCI DSS v4 - ControlCase Update Webinar Final.pdfControlCase
657 vues31 diapositives
Integrated Compliance Webinar.pptx par
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptxControlCase
621 vues30 diapositives
2022-Q2-Webinar-ISO_Spanish_Final.pdf par
2022-Q2-Webinar-ISO_Spanish_Final.pdf2022-Q2-Webinar-ISO_Spanish_Final.pdf
2022-Q2-Webinar-ISO_Spanish_Final.pdfControlCase
388 vues40 diapositives
French PCI DSS v4.0 Webinaire.pdf par
French PCI DSS v4.0 Webinaire.pdfFrench PCI DSS v4.0 Webinaire.pdf
French PCI DSS v4.0 Webinaire.pdfControlCase
341 vues35 diapositives
DFARS CMMC SPRS NIST 800-171 Explainer.pdf par
DFARS CMMC SPRS NIST 800-171 Explainer.pdfDFARS CMMC SPRS NIST 800-171 Explainer.pdf
DFARS CMMC SPRS NIST 800-171 Explainer.pdfControlCase
72 vues29 diapositives
Webinar-MSP+ Cyber Insurance Fina.pptx par
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptxControlCase
70 vues26 diapositives

Plus de ControlCase(20)

PCI DSS v4 - ControlCase Update Webinar Final.pdf par ControlCase
PCI DSS v4 - ControlCase Update Webinar Final.pdfPCI DSS v4 - ControlCase Update Webinar Final.pdf
PCI DSS v4 - ControlCase Update Webinar Final.pdf
ControlCase657 vues
Integrated Compliance Webinar.pptx par ControlCase
Integrated Compliance Webinar.pptxIntegrated Compliance Webinar.pptx
Integrated Compliance Webinar.pptx
ControlCase621 vues
2022-Q2-Webinar-ISO_Spanish_Final.pdf par ControlCase
2022-Q2-Webinar-ISO_Spanish_Final.pdf2022-Q2-Webinar-ISO_Spanish_Final.pdf
2022-Q2-Webinar-ISO_Spanish_Final.pdf
ControlCase388 vues
French PCI DSS v4.0 Webinaire.pdf par ControlCase
French PCI DSS v4.0 Webinaire.pdfFrench PCI DSS v4.0 Webinaire.pdf
French PCI DSS v4.0 Webinaire.pdf
ControlCase341 vues
DFARS CMMC SPRS NIST 800-171 Explainer.pdf par ControlCase
DFARS CMMC SPRS NIST 800-171 Explainer.pdfDFARS CMMC SPRS NIST 800-171 Explainer.pdf
DFARS CMMC SPRS NIST 800-171 Explainer.pdf
ControlCase72 vues
Webinar-MSP+ Cyber Insurance Fina.pptx par ControlCase
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptx
ControlCase70 vues
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf par ControlCase
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
2022-Q3-Webinar-PPT-DataProtectionByDesign.pdf
ControlCase811 vues
Webinar-Spanish-PCI DSS-4.0.pdf par ControlCase
Webinar-Spanish-PCI DSS-4.0.pdfWebinar-Spanish-PCI DSS-4.0.pdf
Webinar-Spanish-PCI DSS-4.0.pdf
ControlCase597 vues
Webinar - CMMC Certification.pptx par ControlCase
Webinar - CMMC Certification.pptxWebinar - CMMC Certification.pptx
Webinar - CMMC Certification.pptx
ControlCase632 vues
HITRUST Certification par ControlCase
HITRUST CertificationHITRUST Certification
HITRUST Certification
ControlCase906 vues
FedRAMP Certification & FedRAMP Marketplace par ControlCase
FedRAMP Certification & FedRAMP MarketplaceFedRAMP Certification & FedRAMP Marketplace
FedRAMP Certification & FedRAMP Marketplace
ControlCase1.1K vues
PCI DSS Compliance Checklist par ControlCase
PCI DSS Compliance ChecklistPCI DSS Compliance Checklist
PCI DSS Compliance Checklist
ControlCase1.2K vues
OneAudit™ - Assess Once, Certify to Many par ControlCase
OneAudit™ - Assess Once, Certify to ManyOneAudit™ - Assess Once, Certify to Many
OneAudit™ - Assess Once, Certify to Many
ControlCase704 vues
Managing Multiple Assessments Using Zero Trust Principles par ControlCase
Managing Multiple Assessments Using Zero Trust PrinciplesManaging Multiple Assessments Using Zero Trust Principles
Managing Multiple Assessments Using Zero Trust Principles
ControlCase260 vues
PCI DSS Compliance in the Cloud par ControlCase
PCI DSS Compliance in the CloudPCI DSS Compliance in the Cloud
PCI DSS Compliance in the Cloud
ControlCase565 vues
Performing One Audit Using Zero Trust Principles par ControlCase
Performing One Audit Using Zero Trust PrinciplesPerforming One Audit Using Zero Trust Principles
Performing One Audit Using Zero Trust Principles
ControlCase375 vues
Vendor Management for PCI DSS, HIPAA, and FFIEC par ControlCase
Vendor Management for PCI DSS, HIPAA, and FFIECVendor Management for PCI DSS, HIPAA, and FFIEC
Vendor Management for PCI DSS, HIPAA, and FFIEC
ControlCase361 vues
Performing PCI DSS Assessments Using Zero Trust Principles par ControlCase
Performing PCI DSS Assessments Using Zero Trust PrinciplesPerforming PCI DSS Assessments Using Zero Trust Principles
Performing PCI DSS Assessments Using Zero Trust Principles
ControlCase348 vues
PCI DSS Business as Usual par ControlCase
PCI DSS Business as UsualPCI DSS Business as Usual
PCI DSS Business as Usual
ControlCase366 vues

Dernier

Affiliate Marketing par
Affiliate MarketingAffiliate Marketing
Affiliate MarketingNavin Dhanuka
17 vues30 diapositives
Marketing and Community Building in Web3 par
Marketing and Community Building in Web3Marketing and Community Building in Web3
Marketing and Community Building in Web3Federico Ast
14 vues64 diapositives
ATPMOUSE_융합2조.pptx par
ATPMOUSE_융합2조.pptxATPMOUSE_융합2조.pptx
ATPMOUSE_융합2조.pptxkts120898
35 vues70 diapositives
information par
informationinformation
informationkhelgishekhar
10 vues4 diapositives
The Dark Web : Hidden Services par
The Dark Web : Hidden ServicesThe Dark Web : Hidden Services
The Dark Web : Hidden ServicesAnshu Singh
14 vues24 diapositives
IETF 118: Starlink Protocol Performance par
IETF 118: Starlink Protocol PerformanceIETF 118: Starlink Protocol Performance
IETF 118: Starlink Protocol PerformanceAPNIC
414 vues22 diapositives

Dernier(9)

Marketing and Community Building in Web3 par Federico Ast
Marketing and Community Building in Web3Marketing and Community Building in Web3
Marketing and Community Building in Web3
Federico Ast14 vues
ATPMOUSE_융합2조.pptx par kts120898
ATPMOUSE_융합2조.pptxATPMOUSE_융합2조.pptx
ATPMOUSE_융합2조.pptx
kts12089835 vues
The Dark Web : Hidden Services par Anshu Singh
The Dark Web : Hidden ServicesThe Dark Web : Hidden Services
The Dark Web : Hidden Services
Anshu Singh14 vues
IETF 118: Starlink Protocol Performance par APNIC
IETF 118: Starlink Protocol PerformanceIETF 118: Starlink Protocol Performance
IETF 118: Starlink Protocol Performance
APNIC414 vues
How to think like a threat actor for Kubernetes.pptx par LibbySchulze1
How to think like a threat actor for Kubernetes.pptxHow to think like a threat actor for Kubernetes.pptx
How to think like a threat actor for Kubernetes.pptx
LibbySchulze15 vues
Building trust in our information ecosystem: who do we trust in an emergency par Tina Purnat
Building trust in our information ecosystem: who do we trust in an emergencyBuilding trust in our information ecosystem: who do we trust in an emergency
Building trust in our information ecosystem: who do we trust in an emergency
Tina Purnat110 vues

ISO 27001 2002 Update Webinar.pdf

  • 1. WEBINAR: ISO 27001:2022 UPDATE Presented by: Ricardo Pardo, Controlcase Partner SOC & ISO Kishor Vaswani, ControlCase Chief Strategy Officer
  • 2. Agenda © ControlCase. All Rights Reserved. 2 A. Introduction to ControlCase B. Overview of the ISO Family of Standards C. What are the updates to 27001:2022? 1. Revision Update 2. Summary of Changes 3. Timelines 4. Impact of the changes D. Q&A
  • 3. A. © 2020 ControlCase. All Rights Reserved. 3 ControlCase Introduction
  • 4. ControlCase Snapshot CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES Go beyond the auditor’s checklist to: Dramatically cut the time, cost and burden from becoming certified and maintaining IT compliance. © 2020 ControlCase. All Rights Reserved. 4 • Demonstrate compliance more efficiently and cost effectively (cost certainty) • Improve efficiencies ⁃ Do more with less resources and gain compliance peace of mind • Free up your internal resources to focus on their priorities • Offload much of the compliance burden to a trusted compliance partner 1,000+ 300+ 10,000+ CLIENTS IT SECURITY CERTIFICATIONS SECURITY EXPERTS
  • 5. Solution © ControlCase. All Rights Reserved. 5 Certification and Continuous Compliance Services “ I’ve worked on both sides of auditing. I have not seen any other firm deliver the same product and service with the same value. No other firm provides that continuous improvement and the level of detail and responsiveness. — Security and Compliance Manager, Data Center
  • 6. Certification Services One Audit™ Assess Once. Comply to Many. © 2020 ControlCase. All Rights Reserved. 6 “You have 27 seconds to make a first impression. And after our initial meeting, it became clear that they were more interested in helping our business and building a relationship, not just getting the business. — Sr. Director, Information Risk & Compliance, Large Merchant PCI DSS ISO 27001 & 27002 SOC 1,2,3 & SOC for Cybersecurity HITRUST CSF HIPAA PCI P2PE GDPR NIST CSF Risk Assessment PCI PIN PCI PA-DSS FedRAMP PCI 3DS
  • 7. OVERVIEW OF THE ISO FAMILY OF STANDARDS B. © ControlCase. All Rights Reserved. 7
  • 8. What is ISO 27001? © ControlCase. All Rights Reserved. 8 INTERNATIONAL ORGANIZATION FOR STANDARDIZATION ISO/IEC 27001 (WIDELY KNOWN AS ISO 27001) IS PART OF THE ISO/IEC 27000 FAMILY OF STANDARDS Focused on information security and enabling organizations to manage security assets. ISO 27001 provides the requirements for an Information Security Management System (ISMS). Takes a risk-based approach to managing information security.
  • 9. ISO 27001 vs ISO 27002 © ControlCase. All Rights Reserved. 9 • ISO 27001 is the central framework of the ISO 27000 series relating to information security management. • Lists each aspect required for the ISMS. • ISO 27001 contains implementation requirements for an ISMS. • ISO 27001 is a certification. 27001 27002 • ISO 27002 is a supplementary standard that focuses on the information security controls that organizations might choose to implement. • Addresses information security controls only • ISO 27002 is not a certification
  • 10. What is ISO 27701? © ControlCase. All Rights Reserved. 10 INTERNATIONAL ORGANIZATION FOR STANDARDIZATION ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002 and provides additional guidance for the protection of privacy, which is potentially affected by the collection and processing of personal information.
  • 11. What is ISO 27017 and 27018? © ControlCase. All Rights Reserved. 11 Security techniques — Code of practice for information security controls based on ISO/IEC 27002 for cloud services. 27017 27018 Security techniques - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors. • Both are add-on extensions of the ISO 27001 standard. • All of the clauses and annexures apply the same as the main 27001. • You cannot perform either of these without the 27001. • An accrediting body cannot performed these if they have not performed the 27001 assessment
  • 12. What is an ISMS? An ISMS (Information Security Management Systems) is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organization's information risk management processes. © ControlCase. All Rights Reserved. 12
  • 13. Compliance vs Certification © ControlCase. All Rights Reserved. 13 ISO 27001 COMPLIANT Means the organization follows the ISO 27001 standard. ISO 27001 CERTIFIED Means the organization’s ISO 27001 Information Security Management System has been certified in compliance with the standard by auditors known as Certification Bodies.
  • 14. Who Needs ISO 27001 Certification? Any organization that wishes or is required to formalise and improve business processes around information security, privacy and securing its information assets. The size/turnover of a business does not dictate the need for ISO 27001. © ControlCase. All Rights Reserved. 14
  • 15. Privacy Add-on Assessment (ISO 27701) © ControlCase. All Rights Reserved. 15 INTERNATIONAL ORGANIZATION FOR STANDARDIZATION • Additional assessment time required. • Depends on the entity being a PII controller or PII processor or both. PII CONTROLLER • Covers areas like contracts and obligations to consumer. • Covers retention and disposal objectives. PII PROCESSOR • Covers areas such as marketing and advertising use. • Covers inter-organization and inter-country rules of PII.
  • 16. How Often Do You Need ISO 27001? © ControlCase. All Rights Reserved. 16 INTERNATIONAL ORGANIZATION FOR STANDARDIZATION ISO Certification is valid for 3 years. Surveillance audits are required in year 2 and year 3.
  • 17. Certification Methodology – YEAR 1 © ControlCase. All Rights Reserved. 17 ITERATIVE PRE-ASSESSMENT ISO STAGE 1 AUDIT ISO STAGE 2 AUDIT DELIVERABLES • Consolidated Pre-Assessment • Evaluation of policies and procedures. • Multiple rounds of assessment before Stage 1 and Stage 2 Audit. Onsite/ Remote Average of 4 days Onsite/ Remote Average of 6 days • ISO 27001 Certificate issued • Extension Documents Released PHASE PHASE 3 1 2 PHASE Minimum 10 days between Stage 1 – 2 2A 2B AVERAGE TIMELINE FOR PHASE 1 – 3 IS 6 MONTHS
  • 18. ISO Surveillance Audits – YEAR 2 and YEAR 3 © ControlCase. All Rights Reserved. 18 ISO 27001 REQUIRES THAT SURVEILLANCE AUDITS BE COMPLETED FOR YEAR 2 AND YEAR 3. Surveillance audits are mini audits assessing the certified client's management system’s is still compliant to ISO 27001. Surveillance audits are not full system audits.
  • 19. General Compliance Challenges © ControlCase. All Rights Reserved. 19 Takes people away from their core responsibilities Proving and maintaining compliance places a significant burden on organizations. Strains already taxed resources ORGANIZATIONS STRUGGLE WITH: Dealing with multiple regulations. Keeping up with changing regulations and compliance requirements. Understanding and translating compliance frameworks. The lack of visibility into their compliance posture. The time spent preparing for audits. TRADITIONAL AUDITOR’S CHECKLIST APPROACH ISN’T ENOUGH.
  • 20. Common Challenges to ISO 27001/27701 Business Associate Vulnerability Management Logging & Monitoring Encryption PII Policies & Training • Agreements to be formalized • Vendor management process • Periodic vulnerability management • Patching devices • Application code rewrite • 24X7X365 monitoring • Managing volume of logs • Encryption of PII • Annual training • Documented PII policies and procedures © ControlCase. All Rights Reserved. 20
  • 21. WHAT ARE THE UPDATES TO 27001:2022? C. © ControlCase. All Rights Reserved. 21
  • 22. What are the updates to 27001:2022 © ControlCase. All Rights Reserved. 22 No major changes to ISO 27001: 2013 Mandatory Clauses 4 to 10. The Security Controls contained in Annex A have decreased from 114 to 93. Controls (ISO 27002:2022) are now grouped in 4 main domains (instead of the previous 14) and are tagged for easier reference and use. • Organizational Controls • People Controls • Physical Controls • Technological Controls New controls have been introduced, while none of the controls were deleted, many controls were merged, thereby reducing the overall number. SUMMARY OF CHANGES
  • 23. Four Domains for ISO 27002:2022 © ControlCase. All Rights Reserved. 23 ORGANIZATIONAL CONTROLS PEOPLE CONTROLS PHYSICAL CONTROLS TECHNOLOGICAL CONTROLS
  • 24. What are the Control Updates to 27002:2022 © ControlCase. All Rights Reserved. 24 Threat intelligence Physical security monitoring Data masking Web filtering Information security for the use of cloud services Configuration management Data leakage prevention Secure coding ICT readiness for business continuity Information deletion Monitoring activities
  • 25. ISO 27002: Organizational Controls Policies for information security Return of assets Addressing information security within supplier agreements Information security during disruption Segregation of duties Classification of information Managing information security in the ICT supply chain ICT readiness for business continuity (new) Management responsibilities Labelling of information Monitoring, review and change management of supplier services Legal, statutory, regulatory, and contractual requirements Contact with authorities Information transfer Information security for use of cloud services (new) Intellectual property rights Contact with special interest groups Access control Information security incident management planning and preparation Protection of records Threat intelligence (new) Identity management Assessment and decision on information security events Privacy and protection of PII Information security in project management Authentication information Response to information security incidents Independent review of information security Inventory of information and other associated assets Access rights Learning from information security incidents Compliance with policies, rules and standards for information security Acceptable use of information and other associated assets Information security in supplier relationships Collection of evidence Documented operating procedures © ControlCase. All Rights Reserved. 25
  • 26. ISO 27002: Physical Controls Physical security perimeters Securing offices, rooms and facilities Physical security monitoring (new) Protecting against physical and environmental threats Working in secure areas Clear desk and clear screen Equipment siting and protection Security of assets off-premises Storage media Supporting utilities Cabling security Equipment maintenance Secure disposal or re-use of equipment © ControlCase. All Rights Reserved. 26
  • 27. Control 7.14: Secure disposal or re-use of equipment (example) © ControlCase. All Rights Reserved. 27
  • 28. Adoption Timeline © ControlCase. All Rights Reserved. 28 Any ISO 27001 audit that happens after Oct 2025 must be against the new version. Companies can voluntarily choose to certify against the ISO 27002:2022 revision with ControlCase in mid 2023.
  • 29. Next Steps © ControlCase. All Rights Reserved. 29 Companies should review their risk register and the applied risk treatments to ensure alignment with the revised standard. Update the Statement of Applicability (SoA) to align with the updated Annex A. Review and update your documentation, including policies and procedures to meet the new controls Get audited against the new ISO 27001:2022 standard using a certified auditor such as ControlCase Step 1 Step 2 Step 3 Step 4
  • 30. Q & A D. © ControlCase. All Rights Reserved. 30
  • 31. THANK YOU FOR THE OPPORTUNITY TO CONTRIBUTE TO YOUR IT COMPLIANCE PROGRAM. www.controlcase.com contact@controlcase.com Download ISO 27001 Compliance Checklist ISO 27001 Compliance Blog Schedule ISO 27001 Compliance Discussion