Download of Record of Default (RoD) is disabled for creditors - To request for RoD, please call RoD Hotline No 88673 92123 or Email at rod@nesl.co.in

Timely upgrade of Information Security Management System (ISMS) – Testimony of Organisation’s commitment on Information Security

As an Information Utility, NeSL is one of the key pillars of insolvency and bankruptcy ecosystem of India. Through innovative interventions within the framework such as Digital Document Execution (DDE), Electronic Bank Guarantee etc., NeSL has also facilitated dematerialization of financial contracts. Since we hold critical information assets, predefined policies, processes and procedures plays a key role in this digital ecosystem. In view of the same, NeSL implemented Information Security Management System (ISMS). The ISMS implementation of NeSL is certified as per ISO/IEC 27001:2013 standards.

The International Organization Standardisation (ISO) conducts periodic review of the standards and releases updates as per the needs across the globe. Such release of update on ISO/IEC 27001 standards were released in October 2022. This was necessitated due to the drastic changes in the cyber security arena. Increased usage of mobile devices, wide acceptance of remote working, implementation BYOD (Bring Your Own Device) in organisations, momentum to the concept of Zero-trust Architecture (ZTA) during this period has also catalysed the release.

Even though ISO has provided three years period (till Oct 2025) for the transition, NeSL decided to adapt the clauses and controls as per the revised standard in it’s ISMS and to apply for re-certification as per ISO/IEC 27001:2022 standard. The implementation is completed and is awaiting for the certification audits by accredited agency. ISO through it’s standards, associated controls and guidelines for implementation provided a clear direction and requirements for the transition to the latest standard requirements.

The difference as per 2022 standards starts from the title, which is modified to “ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems” from the present title of “ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems ” . This demonstrates that ISO 27001:2022 has moved its focus towards cyber security, threat intelligence and the adoption of data & privacy  protection.

ISMS as per 27001 standards requirements defines clauses and controls. In the present version of ISO/IEC 27001:2022, the Clauses 4–10 have been retained as such with few changes in the requirements, mainly for aligning ISO 27001 to other recent ISO management systems. However, these requirement changes are also required to be implemented. On the other hand, the controls as defined in Annex A has been overhauled. This is more important as we define the Statement of Applicability (SoA) of ISMS implementation  around this Annex A controls.

While ISO 27001:2013 standards defines 114 controls spread across 14 control objectives, the revised Annex A as per present standard defines 93 controls in 4 thematic areas. The implementation guidelines for these information Security controls are defined in ISO 27002:2022. The details of 93 Annex A controls are given below.

Organisational (37 controls)

Organisational controls emphasise on the policies, procedures and other organisational measures required for the information security.

People (8 controls)

Human resources are critical part of the information Security and the controls around the same is defined here.

Physical (14 controls)

Physical security and facilitating conducive environment is important in protecting the information assets of the organisation.

Technological (34 controls)

The security in the digital domain is incomplete without Technological controls with proper identification, implementation and continuous monitoring. The controls necessary for the IT infrastructure, SW development activities, constant monitoring etc are well defined in the controls under this theme.

In spite of addition of 11 new controls (2 in Organisational, 1 in Physical and 8 in Technological), the total number of controls has been reduced to 93 from 114 in previous version by reviewing and merging the controls for ease of implementation and monitoring.

Annex A and ISO 27002:2022 contain the following new controls:

  1. ICT readiness for business continuity
  2. Information security for use of Cloud services
  3. Physical security monitoring
  4. Web filtering
  5. Data masking
  6. Secure coding
  7. Threat intelligence
  8. Information deletion
  9. Monitoring activities
  10. Data leakage prevention
  11. Configuration management

The transition to the upgraded standard at the earliest possible time frame stands as a testimony of Organisation’s commitment on Information Security and provides added assurance on the CIA (Confidentiality, Integrity and Availability) of information assets to the users. The implementation and certification as per ISO/IEC 27001:2022 standard with due importance on data privacy and protection can also be leveraged for the upcoming Digital Personal Data Protection (DPDP) act, on issuance of notification in the official gazette by Government of India and based on the applicability in NeSL operations.

-by Jyothish Jolisa
VP (Information Security) & CISO

Leave a Reply

Your email address will not be published. Required fields are marked *