NEW COMPLIANCE FOR INFORMATION SECURITY MANAGEMENT SYSTEM (ISMS) MS ISO/IEC 27001:2022 | INFOCOMM DEVELOPMENT CENTRE (iDEC) idec
» ARTICLE » NEW COMPLIANCE FOR INFORMATION SECURITY MANAGEMENT SYSTEM (ISMS) MS ISO/IEC 27001:2022

NEW COMPLIANCE FOR INFORMATION SECURITY MANAGEMENT SYSTEM (ISMS) MS ISO/IEC 27001:2022

ISO/IEC 27001 (ISMS) specifies the requirements for establishing, operating, monitoring, reviewing, maintaining and improving an organisation’s Information Security Management System (ISMS). Compliance to this standard indicates that the organisation’s management system should ensure the confidentiality, integrity and availability of its information (Reference: SIRIM).

In 2022, ISO/IEC 27001, the Information Security Management System (ISMS) standard, was updated to reflect current information security challenges and risks. Key changes in the ISO/IEC 27001:2022 standard include:

  1. Simplified Structure: The requirements of the standard have been reorganized from 14 to four main areas: Organization, People, Physical, and Technology.
  2. Updated Controls: The number of controls in the standard has been reduced from 114 to 93. Some controls have been merged, removed, or reintroduced to align with the current threat landscape.
  3. Introduction of Attributes: Five new attributes have been added to align with modern digital terminology: Control Type, Information Security Characteristics, Cybersecurity Concepts, Operational Capabilities, and Security Domains.

 

Prepared by:
Ts. Rosliza Ibrahim
Bahagian Sokongan Pengguna

Date of Input: 27/03/2025 | Updated: 27/03/2025 | zuraya

MEDIA SHARING

INFOCOMM DEVELOPMENT CENTRE (iDEC)
Universiti Putra Malaysia
43400 UPM Serdang
Selangor Darul Ehsan
03 97691990
03 97693003
W, (01:12:18pm-01:17:18pm, 11 Aug 2026)   [*LIVETIMESTAMP*]