Quality Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Quality Magazine logo
  • NEWS
  • PRODUCTS
    • SUBMIT YOUR PRODUCT
  • CHANNELS
    • AUTOMATION
    • MANAGEMENT
    • MEASUREMENT
    • NDT
    • QUALITY 101
    • SOFTWARE
    • TEST & INSPECTION
    • VISION & SENSORS
  • MARKETS
    • AEROSPACE
    • AUTOMOTIVE
    • ENERGY
    • GREEN MANUFACTURING
    • MEDICAL
  • MEDIA
    • A WORD ON QUALITY PUZZLE
    • EBOOK
    • PODCASTS
    • VIDEOS
    • WEBINARS
  • EVENTS
    • EVENT CALENDAR
    • QUALITY SHOW
    • IMTS
  • DIRECTORIES
    • BUYERS GUIDE
    • NDT SOURCEBOOK
    • VISION & SENSORS
    • TAKE A TOUR
  • INFOCENTERS
    • NEXT GENERATION SPC & QUALITY ANALYTICS
  • AWARDS
    • ROOKIE OF THE YEAR
    • PLANT OF THE YEAR
    • PROFESSIONAL OF THE YEAR
  • MORE
    • eNEWSLETTER
    • INDUSTRY LINKS
    • THE LEADERSHIP SURVEY
    • CLASSIFIEDS
    • MARKET RESEARCH
    • PRODUCT SPOTLIGHTS
    • QUALITY STORE
    • WHITE PAPERS
  • EMAG
    • eMAGAZINE
    • ARCHIVES
    • CONTACT
    • ADVERTISE
  • SIGN UP!
Management

Column | John Vandenbemden

Do You Need to Implement ISO27001?

The question is how vulnerable are you to a cyberattack?

By John Vandenbemden
Hacker in a dark hoodie committing cyber crime with a laptop, green binary numbers on a black background.

Image Source: Tick-Tock / iStock / Getty Images Plus

February 17, 2025

Do you need to implement ISO27001 information security, cybersecurity and privacy protection – information security management systems requirements?

The question is how vulnerable are you to a cyberattack? Many organizations have ignored how secure their information technology system is. I know two organizations that have been attacked with one of those occurring during a renewal audit. This attack resulted in production being terminated for two days and on the third day it began operation using manual documentation until the system was up and running. There was no contact with the attacker, only the damage it left behind. The second was a ransom attack that the client did pay. Why did they pay? The attack went all the way back to their home computer which also contained personnel data on it. Unfortunately, even though they paid the ransom, they only received a portion of the files that were stolen. Needless to say, both organizations reacted by installing and implementing programs for general security such as fire walls, antivirus as well as cybersecurity. In fact, cloud security is now included in ISO 27001: 2022 which was not covered in the previous 2013 version.

READ MORE

  • Is Customer Satisfaction Dead?
  • The Standard Explained: What is ISO 17025: 2017?
  • Inspection vs. Auditing: A conversation with John Vandenbemden
  • Read more from John Vandenbemden

ISO27001:2022 is considered the world’s leading information security standard and is supported by ISO 27002: 2022. ISO 27001: 2022 was published on October 25th, 2022. ISO 27001 and ISO 27002 are exactly the same with the difference being that ISO 27002 provides detailed guidance on how the 93 controls could be implemented. The 2022 revision transformed the 114 security controls in the 2013 standard into the 93 controls to provide a better structure. There were 58 controls that remained in place, 24 that were merged and 11 new controls. The fourteen sections in the 2013 version were changed to four sections and two annexes.

  • Organizational Controls: Has 37 controls which address various organizational issues.
  • People Controls: There are 8 controls to focus on human resources security.
  • Physical Controls: These 14 controls address the physical environment.
  • Technological Controls: 34 controls are related to technological solutions.
  • Annex A: Attributes are used to provide a matrix of all the new controls and compares it to their attributes for providing guidance in their usage.
  • Annex B: Provides a correspondence with ISO/IEC 27002: 2013.

ISO 27001: 2022 supported by ISO 27002: 2022 provides a transparent structure of controls that are able to be applied throughout an organization. There are additional controls and focus on technical aspects of cybersecurity and the human elements of protecting privacy. There are additional standards that support ISO 27001. ISO 20000-1 Information technology - Service management – Part 1: Service management system requirements and ISO 27006 Information technology – Security techniques – Requirements for bodes providing audit and certification of information security management systems. Both of these standards provide me with additional guidance in auditing and implementation of information security management.

KEYWORDS: ISO 27001 ISO certification ISO standards manufacturing metrology standards standards accreditation

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Qm 0322 professional of the year john vandenbemden

John Vandenbemden currently sits on the ASQ Standards Committee as the Inspection Division representative. He is a voting member of TC 176 and chair of the SC5, USTAG 69 and and audits for SRI and Quality Auditing. Vandenbemden is past-chair of the ASQ Inspection Division. For more information, email [email protected].

Vandenbemden is also the 2022 Quality Professional of the Year.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • 2024 Quality Rookie of the Year Justin Wise 1440x750px banner with "Quality Rookie of the Year" logo inset

    Meet the 2024 Quality Rookie of the Year: Justin Wise

    Justin Wise is an exceptional individual who has been...
    Aerospace
    By: Michelle Bangert
  • Man with umbrella and coat stands outside while it rains at night looking at a building.

    Nondestructive Testing: Is there an ethics problem?

    I was a whistleblower who exposed fraudulent activities...
    NDT
    By: Dale Norwood
  • Unraveling Deflategate: Football stadium with closeup of football on field

    Unraveling the Tom Brady Deflategate

    The Deflategate scandal erupted following the 2014 AFC...
    Measurement
    By: Greg Cenker and Henry Zumbrun
Subscribe For Free!
  • eMagazine Subscriptions
  • eNewsletters
  • Online Registration
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Popular Stories

Technician working with the Vision Engineering LVC200.

Difference Between Calibration and Verification

Woman working in quality control, measuring a workpiece.

AI’s Double-Edged Sword: Security and Compliance in Manufacturing

QM0525-FEAT-A3-Automation-p1FT-Quality-Inspection.jpg

The Next Frontier of Automation: Quality Assurance in an AI-Driven Era

May 21 Quality Hexagon Live Webinar

Events

May 21, 2025

The Evolution of Laser Radar: Measuring Large Scale From Distance With High Accuracy

This webinar, featuring a live demonstration, will showcase the evolution of Hexagon’s direct scanning laser trackers: cutting-edge technology that now delivers traditional reflector-tracking accuracy to non-contact, large-part scanning.

View All Submit An Event

Products

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

See More Products
Play Quality's captivating word-guessing game! There's a new word every Friday.

Related Articles

  • People's hands joining different metal cog wheel together.

    Organizational Knowledge: So, where do we begin?

    See More
  • QM 0522 Test Inspection Standards

    The Journey to Creating an Inspection Standard

    See More
  • woman giving a presentation

    ISO 10012 Update

    See More

Events

View AllSubmit An Event
  • September 4, 2024

    Innovate to Dominate: IMTS 2024 Preview With Hexagon

    On Demand Discover how advancements like Digital Twins and automation are reshaping the industry, enabling manufacturers to push boundaries and achieve new levels of efficiency and quality.
  • April 16, 2025

    Connecting Metrology Data to Enable Global Quality Processes

    On Demand This event is part of our Live Streaming program where we give attendees who cannot make it to The Quality Show the opportunity to view presentations and download valuable content. In this session, you will learn how integrating metrology data into a "single source of truth" improves quality management, collaboration, and agility in manufacturing amid unpredictable supply chains.
View AllSubmit An Event
×

Stay in the know with Quality’s comprehensive coverage of
the manufacturing and metrology industries.

eNewsletter | Website | eMagazine

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Market Research
    • Reprints
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing