Standard

BS EN ISO/IEC 27001:2023+A1:2024 - TC

Information security, cybersecurity and privacy protection. Information security management systems. Requirements

Current

Published:

 

 

Client note: In support of the ISO London Declaration on Climate Change, ISO passed a resolution last year that has resulted in two new statements of text being added to a number of existing management systems standards (MSS), and will be included in all new standards under development/revision, to address the need to consider the effect of Climate Change on the ability to achieve the intended results of the management system.

If you previously bought one of the below quality management standards, you will be entitled to receive an updated amendment with the 2024 London Declaration version of the standard:

  • BS EN ISO 29001:2020   
  • BS EN ISO 41001:2018   
  • BS EN ISO 22301:2019   
  • BS EN ISO 19443:2022   
  • BS EN ISO 37101:2022   
  • BS EN ISO 22000:2018   
  • BS EN ISO 34101-1:2020   
  • BS EN ISO 15378:2017   
  • BS EN ISO 9001:2015   
  • BS EN ISO 14001:2015   
  • BS EN ISO 45001:2023 
  • BS EN ISO/IEC 27001:2023
  • BS EN ISO 50001:2018

If you’re eligible for the revised 2024 London Declaration version, we will be in touch as soon as possible. For further information and any questions you may have, please contact cservices@bsigroup.com.

What is BS EN ISO/IEC 27001 - Information security management systems about?

Widely used and globally recognized, BS EN ISO/IEC 27001:2023 provides requirements for the development and operation of an information security management system (ISMS) to mitigate the risks of breaches and cybercrime. It is the flagship document of the international ISO/IEC 27000 series of standards on information security management.

BS EN ISO/IEC 27001 enables organizations of all sectors and sizes to manage the security of assets such as financial information, intellectual property, employee data and information entrusted by third parties. It helps you to continually review and refine the way you do this, not only for today, but also for the future.

Learn more about why businesses choose to invest in information security standards here.

What are the benefits of BS EN ISO/IEC 27001 - Information security management systems?

BS EN ISO/IEC 27001 helps organizations secure their information assets, operate efficiently and build their resilience. By adopting its guidance and changing your process to conform to its requirements, businesses can benefit from:

- Reduced cybersecurity risks

- Protected personal records and sensitive information

- Stronger business continuity management and compliance

- Reduced information security costs

- Effective staff training and awareness of information security issues

- Increased tendering opportunities

- Improved reputation and levels of trust from customers and employees

BS EN ISO/IEC 27001:2023 contributes to UN Sustainable Development Goal 9 on industry, innovation and infrastructure.

To learn more about what BS EN ISO/IEC 27001:2023 covers and its benefits, listen to The Standards Show podcast episode here.

Discover how Risk Evolves – a UK-based consultancy firm – uses BS EN ISO/IEC 27001 to keep their clients’ data secure. Read their story here.

Who is BS EN ISO/IEC 27001 - Information security management systems for?

BS EN ISO/IEC 27001 was developed specifically so that it guidance could be used by businesses of every size and sector – from multi-nationals to SMEs. As long as they create, collect, process, store, transmit and dispose of information in various forms including electronic, physical and verbal (e.g. conversations and presentations), then this information security standard can be a valuable tool for an organization.

Typical users and implementers of the BS EN ISO/IEC 27001 standard will be:

- Chief Information Security Officers (CISOs)

- Cyber security risk analysts/advisors

- Information security consultants

- Risk managers in compliance and information security

        What does BS EN ISO/IEC 27001 - Information security management systems cover?

        BS EN ISO/IEC 27001:2023 specifies requirements for:

        - Establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented ISMS within the context of the organization’s overall business risks

        - The implementation of security controls customized to the needs of individual organizations or parts thereof

        The requirements set out in BS EN ISO/IEC 27001 are generic and intended to be applicable to all organizations, regardless of type, size and nature. Learn about how to implement its guidance in your business here.

        Some other important information security standards include:

        BS EN ISO/IEC 27002 Information security, cybersecurity and privacy protection. Information security controls

        BS ISO/IEC 27003 Information technology. Security techniques. Information security management systems. Guidance

        BS ISO/IEC 27004 Information technology. Security techniques. Information security management. Monitoring, measurement, analysis and evaluation

        BS ISO/IEC 27005 Information security, cybersecurity and privacy protection. Guidance on managing information security risks

        Browse the full BS ISO/IEC 27000 standard series here.

        What’s new about BS EN ISO/IEC 27001?

        BS EN ISO/IEC 27001:2023 is a revision of ISO/IEC 27001:2013. The significance of the new (third) edition BS EN ISO/IEC 27001:2023 is to realign it with BS EN ISO/IEC 27002:2022 Information Security Controls.

        Therefore, it incorporates the revisions of:

        - ISO/IEC 27001:2013

        - ISO/IEC 27001:2013/Cor 1:2014 (correction to Annex A)

        - ISO/IEC 27001:2013/Cor 1:2015 (correction of the ambiguity in one of the requirements)

        And the merge of:

        - ISO/IEC 27001:2013/DAmd 1 (which has replaced Annex A in its entirety)

        Learn more about what has changed in the latest BS EN ISO/IEC 27001:2023 version of the standard, and the benefits of those changes to your business by reading our article here.

        Enhance your skills with BSI Academy training courses and qualifications

        Embed best practice and help secure your organizations data and infrastructure with BSI Academy’s range of ISO 27001 training courses.

        Completing effective training equips you with the skills to continually review and refine the way you protect your information, not only for today, but also for the future.

        View our training courses - only available via BSI Academy

        Product Details
        Descriptors
        Anti-burglar measures
        Technical documents
        Records (documents)
        Data processing
        Management
        Information systems
        Computer networks
        Data storage protection
        Computer technology
        Information exchange
        Computers
        Data security
        Maintenance
        Documents
        Classification systems
        ICS Codes
        03.100.70 Management systems
        35.030 IT Security
        Committee
        IST/33/1
        International relationships
        Identical to:

        ISO/IEC 27001:2022/Amd 1:2024

        EN ISO/IEC 27001:2022/Amd 1

        ISBN
        978 0 539 33553 8
        Publisher
        BSI