Download of Record of Default (RoD) is disabled for creditors - To request for RoD, please call RoD Hotline No 88673 92123 or Email at rod@nesl.co.in

Climate change considerations in Information Security Management Systems (ISMS)

Climate change has been a disturbing and critical challenge among all nations for a long period. Climate change refers to the ongoing transition or alteration of Earth’s climate patterns, driven by various natural and human activities. Natural shifts happen due to changes in behaviour of celestial bodies especially the Sun, volcanic eruptions, catastrophic wild fires etc. However, in the recent times the alarming state of extreme conditions arrived due to human activities such as the burning of fossil fuels,  which releases greenhouse gases into the atmosphere. trapping heat and causing a gradual increase in global temperatures. The consequences of climate change are far-reaching and include rising sea levels, extreme weather events like floods and hurricanes, extra ordinary heat waves etc. which endangers human well being and also leads to food scarcity.

The United Nations Framework Convention on Climate Change (UNFCCC), one of the principal international frameworks for addressing climate change, was formalized in 2015 as part of UN Climate Change Conference (COP 21) in Paris. A legally binding international treaty, popularly known as “The Paris agreement” was signed in 2016 as part of UNFCCC.

India, in which vast population depends on climate sensitive sectors like agriculture took a leap start in identifying the impacts and need for a strategic plan for mitigating the future adverse effects. In this perspective, Government of India launched a long-term plan in 2008, namely National Action Plan for Climate Change (NAPCC) to mitigate and adapt to the adverse impact of climate change. There are eight distinct missions created as part of NAPCC. These missions are:

  • National Solar Mission
  • National Mission for Enhanced Energy Efficiency
  • National Mission on Sustainable Habitat
  • National Water Mission
  • National Mission for Sustaining Himalayan Ecosystem
  • Green India Mission
  • National Mission for Sustainable Agriculture
  • National Mission on Strategic Knowledge for Climate Change

The concerned Ministry in the Government of India was renamed to the current title of “Ministry of Environment, Forest and Climate Change” to give emphasis on the topic and increase the priority and visibility.

We at National E-Governance Services Limited also makes it contribution to this cause with support of our Digital Document Execution or DDE platform which promotes sustainability by obviating the need for paper in agreements. As per our estimates, till date, NESL’ s DDE has saved more than 35000 trees. Also, we strive to include solar projects, EV projects etc which promotes sustainability as part of the Corporate Social Responsibility (CSR) initiative.

In response to the challenges posed by climate change, the International Organization for Standardization (ISO) has made an amendment to some of the Management System Standards, including Information Security Management Systems (ISMS) as defined in ISO/IEC 27001:2022. This Climate Change Amendment requires the certified organizations to integrate climate change considerations into their information security management systems (ISMS).

The  clause 4.1 and Clause 4.2 of the standard was amended as per the amendment ISO/IEC 27001:2022/Amd. 1:2024(en) released in February, 2024.

Clause 4.1 is about understanding the organization and its context. The climate change addition to this clause is, “The organization shall determine whether climate change is a relevant issue.”

Clause 4.2 is about understanding the needs and expectations of interested parties. The climate change addition to this clause is, “NOTE: Relevant interested parties can have requirements related to climate change.”

Even though Information Security and Climate changes are perceived to different corners of a table, the amendment has provided an opportunity for the practitioners to assess the risks and opportunities with respect to climate change.

Some of the direct impacts with respect to climate change include  Data centre disruptions in extreme weather events, Supply chain disruptions, increased cyber risks due to ad hoc changes due to extreme climate condition, increased business continuity .and disaster recovery requirements etc.

These conditions and assessment of impact with respect to climate change will necessitate organisations to have detailed risk assessment and risk management, amendments in policies and procedures, review of BCP and DR plan, Changes in monitoring,  Supply chain management and Service Level Agreements (SLA), Training and Awareness etc.

By proactively and efficiently addressing these climate change issues, ISO/IEC 27001:2022 certified organisations can strengthen their resilience, protect their information assets, and maintain the trust and confidence of their stakeholders in a volatile cyber landscape.

-by Jyothish Jolisa
VP (Information Security) & CISO

Leave a Reply

Your email address will not be published. Required fields are marked *