Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Transitioning To ISO/IEC 27001:2013
News & Analysis

Transitioning To ISO/IEC 27001:2013

ISBuzz TeamBy ISBuzz TeamMarch 20, 2014Updated:July 3, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
ISO 27001
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In September 2013 the ISO/IEC 27001:2005 standard was replaced by the new version, ISO/IEC 27001:2013.

A customer poll recently conducted by IT Governance found that the majority of nearly 200 respondents planned to transition to ISO27001:2013 in early 2014. If you are already certified to ISO27001:2005, what does this mean for your organisation?

First, it’s important to know that achieving accredited certification through a Certification Body will be dependent on that Certification Body itself having achieved accreditation against the requirements of the new standard. Until your Certification Body has transitioned to the 2013 standard, your surveillance visits will continue to be against the 2005 version. .

Organisations certified to ISO27001:2005 will be required to transition to ISO27001:2013 over an estimated period of 12 months once their Certification Body has successfully transitioned. As the ISO27001:2013 standard has now been published you are, however, able to start preparations for obtaining ISO27001:2013 certification.

With significant structural changes including flexible risk assessment methodologies and the restructuring of security controls, you may find the transition process challenging.

ISO27001:2013 Transitioning and Implementation Resources

Whether you are transitioning to ISO27001:2013 or implementing it from scratch, documentation is one of the biggest and probably most daunting challenges you will face. ISO27001:2013 requires you to produce a comprehensive set of ISMS documents and records which you will use to conduct your information security processes. Fortunately, there are tools available that are designed to reduce the time and cost (e.g. man hours) associated with producing or updating existing documents. Here are some of them:

Documentation Toolkit

ISO 27001:2013 requires you to produce a comprehensive set of ISMS documents and records. Importantly, you need to conduct your information security practices according to these documents. Pre-written documents such as those included in the ISO27001:2013 ISMS Standalone Documentation Toolkit can help address the challenge of producing extensive documentation from scratch. The toolkit contains fully customisable and editable templates including seven Policies, 55 Procedures, 23 Work Instructions, 25 Records, guidance documents as well as Blank Templates that will enable you to bring in your existing documentation in-line with a consistent management system. (Full contents are available here.)

Conversion Tool

The ISO27001:2005 to ISO27001:2013 Conversion Tool maps the controls of ISO 27001:2005 to ISO27001:2013, identifying where controls have been deleted, relocated, adjusted and added to the new standard. It provides commentary on the controls and how they have changed, why they’ve changed, and how organisations will benefit from the new ISO27001:2013. It helps certified organisations make the transition from their existing ISO 27001:2005 ISMS to an ISO27001:2013 ISMS.

Gap Analysis Tool

ISO27001:2005 to 2013 Gap Analysis Tool has been created to help organisations who have implemented ISO27001:2005, to assess the current status of their compliance to ISO27001:2013. This tool will enable such organisations to identify where they need to make changes, implement new procedures, or phase out previous controls. It helps organisations to tackle the upgrade of their ISMS to ISO27001:2013 by identifying to project managers where to start. The outcome of this tool and the analysis that it provides is the base for organisations to then conduct a detailed, granular approach to assessing their current information security control structure.

By Neil Ford, Copywriter at IT Governance

ISO/IEC 27001IT Governance is the one-stop-shop for information, advice, guidance, books, tools, training and consultancy in the field of information security, IT governance, risk management and compliance. IT Governance has been involved in designing, and successfully implementing, cost-effective ISO 27001 information security management systems since the standard was first introduced in 1995.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Mastering Information Security Governance Frameworks

March 28, 202412 Mins Read

Navigate Cloud Computing Risk Management Successfully

March 17, 202412 Mins Read

Simplifying Cloud Computing Compliance: Key Strategies

March 17, 202412 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}