SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Will ISO22301 become more important with the transistion to ISO27001:2013 ?

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Will ISO22301 become more important with the transistion to ISO27001:2013 ?

I would be interested in peoples view on this as it seems that 27001:2013 has watered down the controls for BC and DR and therefore may not meet some organisations requirements in these areas?
0 0

Assign topic to the user

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

Guest
DejanK Jan 12, 2016

Biffa,

Yes, ISO 22301 has greater importance now because the scope of business continuity in ISO 27001 is narrower in new 2013 revision. ISO 27001 focuses only on continuity of information security operations, not on the whole company.

Although, new control A.17.2.1 called "Availability of information processing facilities" basically requires disaster recovery to be established, and this is something that didn't exist in ISO 27001:2005. Therefore, 2013 revision is actually closer to disaster recovery than to business continuity.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics