The two-year transition period for moving from ISO/IEC 27001:2005 to ISO/IEC 27001:2013 has now ended. Certificates issued against the 2005 edition are no longer valid.
If your organisation has transitioned, congratulations. The move typically involved:
- Reviewing the context of the organisation and the needs of interested parties
- Updating the risk assessment method and risk treatment plan
- Re-mapping controls to the restructured Annex A (114 controls in 14 domains) and updating the Statement of Applicability
- Defining measurable information security objectives and monitoring ISMS performance
If you missed the deadline, or are considering certification for the first time, the 2013 edition is now the only route to certification.
Source: ISO/IEC 27001:2013 (ISO)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.