Quality Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Quality Magazine logo
  • NEWS
  • PRODUCTS
    • FEATURED PRODUCTS
    • SUBMIT YOUR PRODUCT
  • CHANNELS
    • AUTOMATION
    • MANAGEMENT
    • MEASUREMENT
    • NDT
    • QUALITY 101
    • SOFTWARE
    • TEST & INSPECTION
    • VISION & SENSORS
  • MARKETS
    • AEROSPACE
    • AUTOMOTIVE
    • ENERGY
    • GREEN MANUFACTURING
    • MEDICAL
  • MEDIA
    • A WORD ON QUALITY PUZZLE
    • EBOOKS
    • PODCASTS
    • VIDEOS
    • WEBINARS
  • EVENTS
    • EVENT CALENDAR
    • IMTS
  • DIRECTORIES
    • BUYERS GUIDE >
      • Supplier Insights
    • NDT SOURCEBOOK
    • VISION & SENSORS
    • TAKE A TOUR
  • INFOCENTERS
    • Digital Quality Management Systems
    • NEXT GENERATION SPC & QUALITY ANALYTICS
  • AWARDS
    • ROOKIE OF THE YEAR
    • PLANT OF THE YEAR
    • PROFESSIONAL OF THE YEAR
  • MORE
    • Expert Columns
    • NEWSLETTERS
    • QUALITY STORE
    • INDUSTRY LINKS
    • SPONSOR INSIGHTS
  • EMAG
    • eMAGAZINE
    • ARCHIVES
    • CONTACT
    • ADVERTISE
  • SIGN UP!
The Quality Industry Voices ManagementThe Quality Edge

The Quality Edge

Do You Need to Implement ISO27001?

The question is how vulnerable are you to a cyberattack?

By John Vandenbemden
Hacker in a dark hoodie committing cyber crime with a laptop, green binary numbers on a black background.

Image Source: Tick-Tock / iStock / Getty Images Plus

February 17, 2025

Do you need to implement ISO27001 information security, cybersecurity and privacy protection – information security management systems requirements?

The question is how vulnerable are you to a cyberattack? Many organizations have ignored how secure their information technology system is. I know two organizations that have been attacked with one of those occurring during a renewal audit. This attack resulted in production being terminated for two days and on the third day it began operation using manual documentation until the system was up and running. There was no contact with the attacker, only the damage it left behind. The second was a ransom attack that the client did pay. Why did they pay? The attack went all the way back to their home computer which also contained personnel data on it. Unfortunately, even though they paid the ransom, they only received a portion of the files that were stolen. Needless to say, both organizations reacted by installing and implementing programs for general security such as fire walls, antivirus as well as cybersecurity. In fact, cloud security is now included in ISO 27001: 2022 which was not covered in the previous 2013 version.

READ MORE

  • Is Customer Satisfaction Dead?
  • The Standard Explained: What is ISO 17025: 2017?
  • Inspection vs. Auditing: A conversation with John Vandenbemden
  • Read more from John Vandenbemden

ISO27001:2022 is considered the world’s leading information security standard and is supported by ISO 27002: 2022. ISO 27001: 2022 was published on October 25th, 2022. ISO 27001 and ISO 27002 are exactly the same with the difference being that ISO 27002 provides detailed guidance on how the 93 controls could be implemented. The 2022 revision transformed the 114 security controls in the 2013 standard into the 93 controls to provide a better structure. There were 58 controls that remained in place, 24 that were merged and 11 new controls. The fourteen sections in the 2013 version were changed to four sections and two annexes.

  • Organizational Controls: Has 37 controls which address various organizational issues.
  • People Controls: There are 8 controls to focus on human resources security.
  • Physical Controls: These 14 controls address the physical environment.
  • Technological Controls: 34 controls are related to technological solutions.
  • Annex A: Attributes are used to provide a matrix of all the new controls and compares it to their attributes for providing guidance in their usage.
  • Annex B: Provides a correspondence with ISO/IEC 27002: 2013.

ISO 27001: 2022 supported by ISO 27002: 2022 provides a transparent structure of controls that are able to be applied throughout an organization. There are additional controls and focus on technical aspects of cybersecurity and the human elements of protecting privacy. There are additional standards that support ISO 27001. ISO 20000-1 Information technology - Service management – Part 1: Service management system requirements and ISO 27006 Information technology – Security techniques – Requirements for bodes providing audit and certification of information security management systems. Both of these standards provide me with additional guidance in auditing and implementation of information security management.

KEYWORDS: ISO 27001 ISO certification ISO standards manufacturing metrology standards standards accreditation

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Qm 0322 professional of the year john vandenbemden

John Vandenbemden currently sits on the ASQ Standards Committee as the Inspection Division representative. He is a voting member of TC 176 and chair of the SC5, USTAG 69 and and audits for SRI and Quality Auditing. Vandenbemden is past-chair of the ASQ Inspection Division. For more information, email [email protected].

Vandenbemden is also the 2022 Quality Professional of the Year.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • 2024 Quality Rookie of the Year Justin Wise 1440x750px banner with "Quality Rookie of the Year" logo inset

    Meet the 2024 Quality Rookie of the Year: Justin Wise

    Justin Wise is an exceptional individual who has been...
    Aerospace
    By: Michelle Bangert
  • Man with umbrella and coat stands outside while it rains at night looking at a building.

    Nondestructive Testing: Is there an ethics problem?

    I was a whistleblower who exposed fraudulent activities...
    NDT
    By: Dale Norwood
  • Unraveling Deflategate: Football stadium with closeup of football on field

    Unraveling the Tom Brady Deflategate

    The Deflategate scandal erupted following the 2014 AFC...
    Measurement
    By: Greg Cenker and Henry Zumbrun
Manage My Account
  • eMagazine Subscriptions
  • Newsletters
  • Online Registration
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Quality audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Quality or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Key Takeaways for Quality Leaders
    Sponsored byComplianceQuest

    Key Takeaways for Quality Leaders from the 2026 Gartner Magic Quadrant™ for QMS

  • This image shows a person seated next to a Bobcat T66 compact track loader.
    Sponsored byPolyWorks by InnovMetric

    Supercharging Digital Gauging at Bobcat North America

  • Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios
    Sponsored byDorsey Metrology International

    Ensuring Product Quality in a Competitive Manufacturing Landscape

Popular Stories

iStock-1352825159-jpg.jpg

U.S. Should Substantially Boost Support for Manufacturing USA Program, Issue National Industrial Manufacturing Strategy, Says New Report

a factory floor during what appears to be a training session or a daily briefing

The Root Cause of Defects We Rarely Name or Address

Dorsey Calibration Lab photo by Tom LaBarbera Picture this Studios

Ensuring Product Quality in a Competitive Manufacturing Landscape

2026 Quality Professional of the Year!

Events

June 22, 2026

Automate 2026

Automate is North America's largest robotics and automation event — and the best place to take your ideas from insight to impact.
 
Our show floor features the world’s leading automation solutions, from AI and robotics to motion control, vision systems, and more. Plus, our educational conference is second to none, led by the brightest minds in automation today.
 
Ready to transform the way you work? Take the next step at Automate.
July 14, 2026

Quality Leaders Forum: Better Communication, Better Quality Data

The Quality Leaders Forum is a quarterly, editor-moderated fireside chat series hosted by Quality Magazine, featuring candid conversations with senior manufacturing and operations executives shaping enterprise-level quality.

View All Submit An Event

Products

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

Lean Manufacturing and Service Fundamentals, Applications, and Case Studies

See More Products
Rookie of the Year Custom Content

Related Articles

  • What Kind of Gage Do You Need?

    See More
  • Typical CCMM shaft gage

    Do You Need a Dedicated Shaft Gage?

    See More
  • Car factory engineer in work uniform and white safety hat using a laptop.

    You Don’t Need More Data. You Need to See It Better

    See More

Related Products

See More Products
  • temp_6351_1_5705_1_8318_1_17674.jpg

    How To Implement Lean Manufacturing, 2E

  • 9781260121827_22.jpg

    The Six Sigma Handbook, 5th Edition

See More Products

Related Directories

  • isoTracker Solutions Ltd.

    Popular cloud-based QMS software with a global customer base. Ideal for small to medium-sized businesses, with no set-up cost and proactive support. Designed for easy compliance with ISO 9001, ISO 14001, ISO 17025, ISO 13485, ISO 45001, ISO 22000 and other QM standards. Pay only for the features you need and add to them as your business grows.
×

Stay in the know with Quality’s comprehensive coverage of
the manufacturing and metrology industries.

Newsletters | Website | eMagazine

JOIN TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Manufacturing Division
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletters
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Market Research
    • Reprints
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing