News
Detailed explanation of the 11 new security controls in the new edition of the ISO 27002:2022 standard
A clear reading of the changes introduced by the ISO 27002:2022 standard and key points to consider for your ISO 27001 compliance.
If you are a security practitioner dealing with the ISO 27001 standard, you are probably wondering what the new features introduced in the changes to this standard in 2022 are.
This article focuses on 11 new controls that must be introduced into the ISO 27001 standard.
What you will notice is that some of these new controls are very similar to the old controls from the 2013 revision; however, these controls have been classified as new in the ISO 27002:2022 standard.
Finally, keep in mind that these controls are not mandatory: ISO 27001 allows you to exclude a control if:
- You have not identified any associated risk.
- There are no legal, regulatory, or contractual requirements to implement this particular control.
So, let’s review the 11 controls in more detail.
A.5.7 Threat intelligence
Description:
This control requires you to gather information about threats and analyze it in order to take appropriate mitigation measures. This information may concern specific attacks, methods and technologies used by attackers, and/or attack trends. You must collect this information internally, as well as from external sources such as vendor reports, announcements from government agencies, etc.
Technology :
Small businesses probably do not need new technologies related to this control; rather, they will need to find ways to extract information about these threats from their existing systems. If they do not already have one, large businesses will need to acquire a system that alerts them to new threats, as well as vulnerabilities and incidents. Businesses of all sizes will need to use threat information to strengthen their systems.
Organization/process :
You need to define the processes for collecting and using threat information to introduce preventive controls into your IT systems, improve your risk assessment, and introduce new security testing methods.
The people :
Raise employee awareness about the importance of sending threat notifications and train them on how to communicate and to whom these threats should be communicated.
Documents :
No documentation is required by the ISO 27001 standard; however, you may include rules regarding threat information in the following documents :
- Supplier security policy – Define how threat information is communicated between the company and its suppliers and partners.
- Incident management procedure – Define how threat information is communicated internally within the company.
- Security operational procedures – Define how to collect and process threat information.
A.5.23 Information security for the use of cloud services
Description:
This control requires you to define security requirements for cloud services to better protect your information in the cloud. This includes the purchase, operation, management, and termination of the use of cloud services.
Technology :
In most cases, new technology will not be necessary, as the majority of cloud services already have security features. In some cases, you may need to upgrade your service to a more secure service, while in rare cases, you may need to change cloud providers if they do not have security features. In most cases, the only change required will be to utilize the existing cloud security features more thoroughly.
Organization/process :
You need to establish a process to determine security requirements for cloud services and to determine the selection criteria for a cloud provider; furthermore, you must define a process to determine acceptable cloud usage, as well as security requirements when canceling the use of a cloud service.
The people :
Raise employee awareness of security risks related to the use of cloud services and train them on how to use the security features of cloud services.
Documents :
No documentation is required by the ISO 27001 standard; however, if you are a small business, you may include rules regarding cloud services in the vendor security policy. Large companies may develop a separate policy that specifically focuses on the security of cloud services.
A.5.30 ICT Preparation for Business Continuity
Description:
This control requires that your information system be prepared to face potential disruptions so that the required information and assets are available when needed. This includes planning for preparedness, implementation, maintenance, and testing.
Technology :
If you have not invested in solutions that enable the resilience and redundancy of your systems, you may need to introduce such technology – this can range from data backup to establishing redundant communication links. These solutions should be planned based on your risk assessment and the speed of recovery of your data and systems.
Organization/process :
In addition to the planning process, which must take into account the risks and the business needs for recovery, you must also establish the maintenance process for your information system and the testing process for your disaster recovery and/or business continuity plans.
The people :
Raise employee awareness of potential disruptions that may occur and train them on how to maintain information systems so that they are ready for a possible disruption.
Documents :
No documentation is required by the ISO 27001 standard; however, if you are a small business, you may include ICT preparedness in the following documents:
- Disaster recovery plan – preparation planning, implementation, and maintenance
- Internal audit report – preparedness testing
If you are a large organization or have implemented the ISO 22301 standard, you must document preparedness through business impact analysis (BIA), business continuity strategy, business continuity plan, and business continuity test plan and report.
A.7.4 Physical security monitoring
Description:
This control requires you to monitor sensitive areas to allow access only to authorized individuals. This may include your offices, production facilities, warehouses, and other premises.
Technology :
Depending on your risks, you may need to implement alarm or video surveillance systems; you may also decide to implement a non-technical solution such as a person observing the area (for example, a guard).
Organization/process :
You must define who is in charge of monitoring sensitive areas and what communication channels to use to report an incident.
The people :
Raise employee awareness of the risks of unauthorized physical access in sensitive areas and train them on the use of surveillance technology.
Documents :
No documentation is required by the ISO 27001 standard; however, you may include physical security monitoring in the following documents:
- Procedures that regulate physical security – what is monitored and who is responsible for monitoring
- Incident management procedure – how to report and manage a physical security incident
A.8.9 Configuration management
Description:
This control requires you to manage the entire security configuration lifecycle of your information system to ensure an adequate level of security and to prevent any unauthorized changes. This includes defining the configuration, implementing it, monitoring it, and reviewing it.
Technology :
The information system whose configuration needs to be managed may include software, hardware, services, or networks. Small businesses will likely be able to handle configuration management without any additional tools, while large enterprises probably need software that enforces defined configurations.
Organization/process :
You must establish a process for proposing, reviewing, and approving security configurations, as well as the processes for managing and monitoring configurations.
The people :
Make employees understand why strict control of security configuration is necessary and train them on defining and implementing security configurations.
Documents :
The ISO 27001 standard requires this control to be documented. If you are a small business, you can document the configuration rules in your security operational procedures. Large enterprises will generally have a separate procedure that defines the configuration process.
You will generally have distinct specifications that define the security configurations for each of your systems, in order to avoid frequent updates of the documents mentioned in the previous paragraph. Additionally, all changes made to the configurations must be recorded to allow for an audit trail.
A.8.10 Information Deletion
Description:
This control requires you to delete data when it is no longer needed, in order to prevent the leakage of sensitive information and to ensure compliance with confidentiality and other requirements. This may include deletion in your IT systems, removable media, or cloud services.
Technology :
You must use secure deletion tools, in accordance with regulatory or contractual requirements, or in accordance with your risk assessment.
Organization/process :
You must establish a process that defines which data should be deleted and when, and outlines the responsibilities and methods for deletion.
The people :
Make employees understand why it is important to delete sensitive information and train them on how to do it correctly.
Documents :
No documentation is required by the ISO 27001 standard; however, you may include rules on information deletion in the following documents:
- Deletion and Destruction Policy – how information on removable media is deleted
- Acceptable Use Policy – how regular users should delete sensitive information on their computers and mobile devices
- Security Operating Procedures – how system administrators should delete sensitive information
A.8.11 Data Masking
Description:
This control requires you to use data masking with access control to limit the exposure of sensitive information. This primarily means personal data, as it is heavily regulated by privacy regulations, but it could also include other categories of sensitive data.
Technology :
Companies can use "pseudonymization" or "anonymization" tools to mask data if required by privacy or other regulations. Other methods such as encryption or obfuscation can also be used.
Organization/process :
You must establish processes that will determine which data should be masked, who can access what type of data, and what methods will be used to mask the data.
The people :
Make employees understand why data masking is important and train them on what data needs to be masked and how.
Documents :
No documentation is required by the ISO 27001 standard; however, you may include rules on data masking in the following documents:
- Information classification policy – determine which data is sensitive and which categories of data need to be masked
- Access control policy – defines who can access what type of masked or unmasked data
- Secure development policy – defines the data masking technology
- Large companies, or companies that must comply with the General Data Protection Regulation (GDPR) of the European Union and similar privacy regulations, must also have the following documents:
- Privacy Policy / Personal Data Protection Policy – general responsibilities for data masking
- Anonymization and "pseudonymization" Policy – details on how data masking is implemented in the context of privacy regulation
A.8.12 Data Leak Prevention
Description:
This control requires you to implement various data leak measures to prevent unauthorized disclosure of sensitive information and, if such incidents occur, to detect them in a timely manner. This includes information contained in computer systems, networks, or any other device.
Technology :
For this purpose, you can use systems to monitor potential leak channels, including emails, removable storage devices, mobile devices, etc., and systems that prevent information leaks – for example, by disabling downloads to removable storage, quarantining emails, limiting data copy-pasting, restricting data uploads to external systems, encryption, etc.
Organization/process :
You must establish processes that determine the sensitivity of data, assess the risks of various technologies (for example, the risks of taking photos of sensitive information with a smartphone), monitor channels with potential data leak risks, and define the technology to be used to block the exposure of sensitive data.
The people :
Raise employee awareness about the types of sensitive data that are processed in the company and why it is important to prevent leaks, and train them on what is allowed and what is not allowed when handling sensitive data.
Documents :
No documentation is required by the ISO 27001 standard; however, you can include rules on leak prevention in your internal policies and procedures.
A.8.16 Monitoring Activities
Description:
This control requires you to monitor your systems in order to recognize unusual activities and, if necessary, activate the appropriate incident response. This includes monitoring your IT systems, networks, and applications.
Technology :
For your networks, systems, and applications, you can monitor the following items: security tool logs, event logs, who accesses what, the activities of your key administrators, incoming and outgoing traffic, the proper execution of code, and how system resources are used and their performance.
Organization/process :
You must establish a process that defines the systems that will be monitored; how monitoring responsibilities are determined; and the monitoring methods, establishing a baseline for unusual activities and reporting events and incidents.
The people :
Inform employees that their activities will be monitored and explain what is and what is not considered normal behavior. Train IT administrators on the use of monitoring tools.
Documents :
No documentation is required by the ISO 27001 standard; however, if you are a small business, you may include rules on monitoring in the security operational procedures. Large companies might develop a separate procedure that describes how to monitor their systems.
Additionally, it would be helpful to keep records of monitoring activities.
A.8.23 Web Filtering
Description:
This control requires you to manage the websites that your users access, in order to protect your IT systems. In this way, you can prevent your systems from being compromised by malicious code and also prevent users from accessing illegal content from the Internet.
Technology :
You can use tools that block access to specific IP addresses, which may include the use of anti-malware software. You can also use non-technical methods, such as developing a list of prohibited websites and asking users not to visit them.
Organization/process :
You need to establish processes that determine which types of websites are not allowed and how the web filtering tools are maintained.
The people :
Raise employee awareness about the dangers of using the Internet and indicate where to find safe usage guidelines, and train your system administrators on how to perform web filtering.
Documents :
No documentation is required by the ISO 27001 standard; however, if you are a small business, you may include rules on web filtering in the following documents:
- Security operational procedures – Define rules for system administrators on how to implement web filtering.
- Acceptable Use Policy – Define rules for all users on what constitutes acceptable use of the Internet.
Large companies may develop a separate procedure that describes how web filtering is performed.
A.8.28 Secure Coding
Description:
This control requires you to establish secure coding principles and apply them to your software development to reduce security vulnerabilities in the software. This could include activities before, during, and after coding.
Technology :
You may use tools to maintain an inventory of libraries, to protect the source code from tampering, to log errors and attacks, and for testing. You may also use security components such as authentication, encryption, etc.
Organization/process :
You must establish a process to define the minimum secure coding baseline – for both internal software development and third-party software components, a process for monitoring emerging threats and guidance on secure coding, a process to decide which external tools and libraries may be used, and a process that defines the activities performed before coding, during coding, after coding (review and maintenance), and for modifying the software.
The people :
Raise your software developers' awareness of the importance of using secure coding principles and train them on secure coding methods and tools.
Documents :
No documentation is required by the ISO 27001 standard; however, if you are a small business, you may include rules on secure coding in the secure development policy. Large companies can develop separate secure coding procedures for each of their software development projects.
Summary
This article presents the 11 new controls introduced in the ISO/IEC 27002:2022 standard, explaining their role and implementation across technological, organizational, human, and documentary aspects.