ISO/IEC 27001:2022
The international standard that specifies requirements for an Information Security Management System (ISMS). The 2022 revision categorizes 93 controls into 4 main themes (Organizational, People, Physical, Technological).
Framework Requirements & Categories
Detailed breakdown of the highly precise, accurate control domains defined by ISO/IEC 27001:2022.
Policies for information security
Management direction and support for information security in accordance with business requirements and relevant laws.
Information security roles and responsibilities
Definition and allocation of responsibilities for information security.
Segregation of duties
Separation of conflicting duties and areas of responsibility to reduce opportunities for unauthorized or unintentional modification or misuse of the organization's assets.
Management responsibilities
Management commitment to establishing the ISMS.
Contact with authorities
Appropriate contacts with relevant authorities.
Contact with special interest groups
Appropriate contacts with special interest groups or other specialist security forums and professional associations.
Threat intelligence
Collection and analysis of information relating to information security threats.
Information security in project management
Information security must be integrated into project management.
Inventory of information and other associated assets
Identification of assets and defining appropriate protection responsibilities.
