ISO/IEC 27001:2022

Scope: International active Effective: Oct 25, 2022 Official source

Requirements Covered

Access Control Information Integrity

Timeline

MilestoneDateNotes
PublishedOct 25, 2022ISO/IEC 27001:2022 released

Provisions (2)

Confidentiality and Access

Implements: Access Control active Effective: Oct 25, 2022
"ISO/IEC 27001 frames confidentiality as ensuring that only the right people can access organizational information."

Requirements

RequirementDetails
Confidential accessEnsure only the right people can access information
Risk managementManage risks to information handled by the organization

Information Integrity

Implements: Information Integrity active Effective: Oct 25, 2022
"ISO/IEC 27001 treats information integrity as one of the three core information-security principles, alongside confidentiality and availability."

Requirements

RequirementDetails
Information integrityKeep information reliably stored and protected from erasure or damage
Risk managementUse an ISMS to manage risks to information security