European 2017 Revision of ISO/IEC 27001: What has changed?

  • ISO 27001 Certification in Oman Released at the commencing regarding April 2017 via BSI (the British Standards Institution), the par BS EN ISO/IEC 27001:2017 is a corrigendum upon previous honor BS ISO/IEC 27001:2013. It has raised some concern among companies including Information Security Management Systems certified in opposition to ISO 27001, the leading ISO standard because of information safety hazard management. It used to be acknowledged by BSI up to expectation that incorporates preceding amendments (called a “corrigendum”), launched for ISO 27001.

    In this article, we’ll furnish your data in regard to such as modified in that instant version, then the affect concerning these modifications to ISO 27001 certified ISMSs. We’ll also pass you know as groups thought to reflect on consideration together with regards in conformity with this recent standard.

    What is a technical corrigendum?

    A technical corrigendum is a guide ancient via standardization bodies along the reason after mend an existing standard, after correct infant pragmatic flaws, enforce usability improvements, then encompass limited-applicability extensions.

    Such amendments to that amount are viewed relevant are released at some point of the present day life-cycle of a standard’s version. ISO 27001 Services in Oman they are additionally predicted in accordance with stay covered as like updates at the standard’s subsequent scheduled review.

    ISO 27001 associated corrigenda

    ISO 27001 has 3 related corrigenda (where “corrigenda” is the plural on corrigendum), dated out of September 2014, December 2015, and March 2017. The first two had been published via ISO (the International Organization for Standardization) or the ultimate one via BSI. These corrigenda cover the accordant issues:

    September 2014 corrigendum was once associated in imitation of power A.8.1.1 (Inventory of Assets), replacing the control’s goal text from:

    This alternate currently makes it manifest as information itself additionally ought to remain regarded an asset after keep blanketed of the inventory. Click right here in imitation of recommend that corrigendum. See also: How after take care of Asset exercise book (Asset inventory) in accordance in accordance with ISO 27001.


    ISO 27001 Registration in Oman the December 2015 corrigendum was associated in imitation of sub-clause 6.1.3 (Information Security Risk Treatment), particularly in conformity with item d), touching the Statement concerning Applicability (SoA). It was simply a cosmetic adjustment, setting apart the required content because a SoA beside the major item within separated bullets. In my choice it synthesis makes clearer to that amount an SoA have to incorporate at least IV elements:

    • The indispensable controls according to enforce the information safety chance treatment, thinking about no longer only those of Annex A however also controls designed through the company as required, as much well as like others identified from any source (e.g., controls out of NIST SP 800 collection on documents)
    • Justification for inclusion of this controls
    • The controls repute (e.g. implemented and not)
    • The justification because except for somebody about the Annex A controls


    How to get ISO 27001 Consulting Services in Oman?

    Certvalue is one about the administration ISO 27001 Consultant in Oman imparting the data safety management system after every organization. How in accordance with get ISO 27001 Consultant Services among Oman lowlife one on the well-recognized companies including professionals between each and every enterprise area in imitation of enforce the grade with a hundred percent music document regarding success. You be able write to us at you visit our respectable website at we are ISO Certification Consultant Companies among Oman, Australia, Saudi Arabia, Lebanon, Qatar, New Zealand, Afghanistan, Kuwait, Malaysia, Italy and India. Certvalue and provide you contact details so one on our certification expert shall contact thou at the earliest in imitation of apprehend thine requirements higher yet supply superior accessible situation at market. longevity