Navigating ISO/IEC 27001:2022 requirements with Thales’ cybersecurity expertise

Diverse cybersecurity threats are now more the norm than the exception. This is according to the Kroll Cyber Threat Intelligence team report for the first quarter of 2024. How can organisations fight back? By establishing a robust framework for managing information security risks effectively – and that’s where ISO/IEC 27001:2022 helps.

But let’s be precise: helps against what?

The Kroll report cites email compromise, ransomware, unauthorised access and web compromise as the most prominent threat incident types. Insider threat cases are also on the rise, especially in the technology and telecoms industries.

One of the most challenging cybersecurity aspects is the rapidly evolving threat landscape. New regulations and additional vulnerabilities lead to changing organisational priorities. In the last year and a half, we saw a seismic shift as AI capabilities became prominent.

In short, tech leaders need to understand how to mitigate against new threats while also exploring how new tools can help safeguard networks and systems. Despite its cumbersome name, ISO/IEC 27001 is here to help.

Deep Dive into ISO/IEC 27001:2022

Historical context and evolution

ISO/IEC 27001 has been a cornerstone in information security management since its inception. This standard provides a systematic approach to managing sensitive company information, ensuring it remains secure. Over the years, the framework has evolved to address emerging threats and incorporate new technologies, culminating in the 2022 update.

Main components of the October 2022 update

The ISO/IEC 27001:2022 update introduces three critical changes aimed at enhancing the framework’s effectiveness. These are confidentiality, integrity and availability.

  • Confidentiality: Ensuring that information is accessible only to those authorised to access it, protecting sensitive data from unauthorised disclosure.
  • Integrity: Maintaining the accuracy and completeness of information and processing methods, ensuring that data is not altered in an unauthorised manner.
  • Availability: Ensuring that authorised users have access to information and associated assets when required, preventing disruptions in business operations.
ISO/IEC 27001:2022

Image credit: KPMG

Additional Updates and Requirements

Risk Management Enhancements

The 2022 update also places a stronger emphasis on risk management, encouraging organisations to adopt more proactive and comprehensive approaches. This includes identifying potential threats, assessing their impact and implementing measures to mitigate them effectively. Organisations must continuously monitor and review risks so they can adapt their strategies as necessary to stay ahead of evolving threats.

Supply Chain Security

With cyberattacks increasingly targeting supply chains, the new requirements highlight the importance of securing all links in the supply chain. Organisations are urged to collaborate with their suppliers and partners to ensure robust security measures are in place throughout the network. This involves conducting thorough assessments of third-party security practices and integrating supply chain security into the overall information security management system.

New Security Controls

ISO/IEC 27001:2022 introduces new security controls designed to address contemporary threats. These controls cover a range of areas, including:

  • Cloud Security: Ensuring the protection of data stored and processed in cloud environments. Organisations must implement appropriate measures to secure cloud-based services and maintain compliance with the standard.
  • Remote Work Security: Addressing the unique challenges posed by remote work environments, such as securing remote access and managing mobile devices. Organisations are required to implement secure remote access protocols and provide employees with guidelines for maintaining security while working remotely.
  • AI in Threat Detection and Prevention: Leveraging artificial intelligence to enhance threat detection and prevention capabilities. This includes deploying AI-driven tools for real-time monitoring and analysis of security events.

These updates ensure that the ISO/IEC 27001 framework remains relevant and effective in the face of evolving cybersecurity threats, providing organisations with the tools they need to safeguard their information assets.

Why ISO/IEC 27001:2022 matters

For organisations looking to protect their information assets in a structured and efficient manner, ISO/IEC 27001:2022 is the way to do achieve it. The framework not only helps in managing risks but also enhances customer trust and meets regulatory requirements, making it an asset in today’s cybersecurity landscape. Below, we summarise the value of an ISO 27001:2022 certification:

  • Helps Address Potential Regulatory Expectations: ISO 27001 can help organisations comply with a host of laws, including the high-profile General Data Protection Regulation (GDPR) and the Network and Information Systems (NIS) regulations.
  • Provides Trust to Customers During Contracting: By obtaining ISO 27001 certification, an organisation demonstrates to its customers, partners and stakeholders that information security is a top priority and that rigorous measures are in place to protect sensitive data.
  • Reduces Complexity of Other ISO Certifications: ISO 27001 certification reduces complexities associated with other certifications from within the ISO family of standards and other related international standards. This makes it easier for organisations to achieve and maintain multiple certifications.
  • Provides Greater Visibility of High-Risk Cyber Areas: The certification process involves a systematic risk assessment of the organization’s information assets and associated threats. This identification and assessment of risk areas help prioritise security controls and focus resources on protecting the most vulnerable areas.
  • Regular Assessment and Improvement: Achieving ISO 27001 certification provides companies with compliance with the requirements of the standard itself. This not only instills customer confidence but also meets the compliance frameworks that various industries require. The ISO standard results in regular assessment and improvement of the risk management strategy.
  • Informed Decision-Making for Security Investments: The ongoing review of risks, as required by the standard, helps to ensure that an organisation’s security strategy aligns with its business objectives. As a result, an organisation can make informed decisions on which security controls to invest in and which risks to accept.

These benefits make ISO/IEC 27001:2022 an essential framework for organisations seeking to enhance their information security posture and gain a competitive edge in the market.

Download Key Pillars for Protecting Sensitive Data from Thales

This whitepaper outlines the challenges of data security and provides strategies to discover and classify your critical data and apply data-centric security to it. Thales Group can help you set up data-centric security solutions in your organization.

Thales’ Role in Cybersecurity Certification

Thales is renowned for its expertise in cybersecurity, offering cutting-edge solutions that help organisations protect their critical information assets. With a deep understanding of the ISO/IEC 27001 framework, Thales provides invaluable support to organisations aiming for certification.

Thales’ Certification Support Services

Thales offers a comprehensive suite of services to assist organisations in achieving ISO/IEC 27001:2022 certification. It does so by addressing essential requirements listed in Annex A for Information Security Controls.

From initial gap analysis to full implementation support, Thales ensures that every aspect of the certification process is handled with precision and efficiency. Clients receive a raft of resources and support to help them with certification. This includes a comprehensive Data security compliance with the ISO/IEC 27001:2022 eBook that’s available for download.

How to achieve ISO/IEC 27001:2022 certification

Step-by-Step Certification Process

The journey to ISO/IEC 27001:2022 certification involves several key steps:

  • Gap analysis
  • Risk assessment
  • Implementation of security controls
  • Auditing

Thales guides organisations through each phase, ensuring a smooth and successful certification process.

How Thales simplifies certification

Thales simplifies the certification journey by providing expert guidance and support at every stage. Its tailored solutions and deep industry knowledge help organisations navigate the complexities of the ISO/IEC 27001:2022 requirements with ease. Below is a table that illustrates various ISO/IEC 27001:2022 Requirements and the corresponding Thales solution.

ISO/IEC 27001:2022 REQUIREMENTSTHALES SOLUTIONS
Classification of Information
5.12: Classification of InformationCipherTrust Data Discovery and Classification
Data Security
5.3: Segregation of DutiesCipherTrust Data Security Platform
5.33: Protection of RecordsCipherTrust Data Security Platform
5.34: Privacy and Protection of PIICipherTrust Data Security Platform
8.7: Protection against MalwareCipherTrust Transparent Encryption Ransomware Protection (CTE-RWP)
8.10: Information DeletionCipherTrust Data Security Platform
8.11: Data MaskingCipherTrust Tokenization
8.12: Data Leakage PreventionCipherTrust Data Security Platform
8.24: Use of CryptographyCipherTrust Enterprise Key Management, Thales Luna HSMs
Access Control & Authentication
5.15: Access ControlSafeNet Trusted Access
5.17: Authentication InformationSafeNet Trusted Access
5.18: Access RightsThales OneWelcome identity and access management solutions
6.7: Remote WorkingThales OneWelcome identity and access management solutions
8.3: Information Access RestrictionThales OneWelcome identity and access management solutions
8.4: Access to Source CodeCipherTrust Transparent Encryption
8.5: Secure AuthenticationSafeNet Trusted Access
Cloud Security
5.23: Information security for use of cloud servicesCipherTrust Cloud Key Manager, CipherTrust Transparent Encryption
5.30: ICT readiness for business continuityThales Data Protection on Demand (DPoD)
Application Security
8.25: Secure development lifecycleCipherTrust Platform Community Edition
8.26: Application security requirementsCipherTrust Secrets Management, CipherTrust Application Data Protection, Thales Data Protection on Demand (DPoD)

ISO/IEC 27001:2022 provides a robust framework for managing information security risks in an increasingly complex cyber threat landscape. Thales, with its expertise and comprehensive solutions, is the recommended partner for organisations seeking to achieve and maintain certification. Embrace the benefits of ISO/IEC 27001:2022 and safeguard your organisation’s information assets.

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.