{"id":4106,"date":"2013-09-05T13:16:29","date_gmt":"2013-09-05T12:16:29","guid":{"rendered":"http:\/\/www.solucominsight.fr\/?p=4106"},"modified":"2019-12-31T11:33:17","modified_gmt":"2019-12-31T10:33:17","slug":"mise-a-jour-de-liso-27001-quels-impacts-operationnels","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/","title":{"rendered":"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?"},"content":{"rendered":"<p>Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme\u00a0?<\/p>\n<h2>Une nouvelle publication qui gagne en lisibilit\u00e9<\/h2>\n<p>La premi\u00e8re \u00e9volution de cette nouvelle version est une r\u00e9organisation globale des th\u00e9matiques. Elles manquaient effectivement de clart\u00e9 par le pass\u00e9.<\/p>\n<p>Cela se mat\u00e9rialise par l\u2019adoption d\u2019une structure globale PDCA bien plus affirm\u00e9e qu\u2019auparavant. Elle reprend la structure dite \u00ab\u00a0haut-niveau\u00a0\u00bb par ISO\/IEC qui d\u00e9finit une organisation, une terminologie et des d\u00e9finitions communes afin de garantir une unit\u00e9 entre les diff\u00e9rentes normes de syst\u00e8me de management.\u00a0Ceci facilitera la construction de syst\u00e8mes de management int\u00e9gr\u00e9s.<\/p>\n<p>Contrairement \u00e0 la pr\u00e9c\u00e9dente publication, une progression lin\u00e9aire apparait plus clairement et permet un d\u00e9coupage en 4 phases.<\/p>\n<ul>\n<li>La premi\u00e8re correspondant au \u00ab\u00a0PLAN\u00a0\u00bb est nomm\u00e9e \u00ab\u00a0<em>Context<\/em>\u00a0\u00bb, \u00ab\u00a0<em>Leadership<\/em>\u00a0\u00bb, et \u00ab\u00a0<em>Planning<\/em>\u00a0\u00bb (chapitre 4 \u00e0 6). Elle d\u00e9crit l\u2019identification du contexte de l\u2019organisation, la d\u00e9finition de la gouvernance du SMSI, l\u2019identification des risques et la d\u00e9termination des objectifs de s\u00e9curit\u00e9 ainsi que la planification de leur mise en \u0153uvre. Il est \u00e0 noter l\u2019utilisation d\u2019un vocabulaire plus pr\u00e9cis que dans l\u2019ISO 27001:2005 concernant l\u2019\u00e9nonciation des clauses.<\/li>\n<\/ul>\n<ul>\n<li>La seconde phase, \u00ab\u00a0<em>DO<\/em>\u00a0\u00bb (chapitres 7 \u00ab\u00a0Support\u00a0\u00bb et 8 \u00ab\u00a0Operation\u00a0\u00bb), explique l\u2019identification et l\u2019allocation des moyens supports du SMSI, l\u2019\u00e9laboration de la documentation et le d\u00e9ploiement des mesures de traitement du risque.<\/li>\n<\/ul>\n<ul>\n<li>Une phase \u00ab\u00a0<em>CHECK<\/em>\u00a0\u00bb (chapitre 9 \u00ab\u00a0<em>Performance Evaluation<\/em>\u00a0\u00bb) se dessine et comprend la mise en \u0153uvre des processus de contr\u00f4le, d\u2019audit interne et de revue par la direction du SMSI.<\/li>\n<\/ul>\n<ul>\n<li>Enfin, une phase \u00ab\u00a0<em>ACT<\/em>\u00a0\u00bb (chapitre 10 \u00ab\u00a0<em>Improvement<\/em>\u00a0\u00bb) explique les processus de traitement des non-conformit\u00e9s et d\u2019am\u00e9lioration du SMSI. Ceux-ci sont simplifi\u00e9s en r\u00e9duisant en particulier le contr\u00f4le sur les enregistrements.<\/li>\n<\/ul>\n<h2>Des \u00e9volutions de forme plus que de fond<\/h2>\n<p>Plusieurs concepts sont abord\u00e9s plus en d\u00e9tail dans la nouvelle version de l\u2019ISO 27001.<\/p>\n<h4>L\u2019apparition du terme \u00a0\u00ab\u00a0<em>top management\u00a0<\/em>\u00bb<\/h4>\n<p>Un chapitre entier (5.3. <em>Organizational roles, responsabilities and authorities<\/em>) dans la nouvelle ISO 27001 remplace une simple clause et souligne l\u2019importance de l\u2019assignation des responsabilit\u00e9s par le \u00ab\u00a0<em>top management\u00a0<\/em>\u00bb. Cette d\u00e9nomination est \u00e9galement reprise dans les phases de construction du SMSI, de contr\u00f4les et de revue de direction.<\/p>\n<h4>Les interfaces enfin reconnues en tant que telles<\/h4>\n<p>La norme pr\u00e9cise enfin le concept d\u2019interface (4.3.c). Tr\u00e8s utilis\u00e9 actuellement, il permet de d\u00e9finir les r\u00f4les et responsabilit\u00e9s des diff\u00e9rents \u00ab\u00a0fournisseurs\u00a0\u00bb du SMSI, qu\u2019ils soient internes ou externes. Cette pr\u00e9cision ent\u00e9rine un concept d\u00e9j\u00e0 bien en place. D\u2019autre part, les parties prenantes deviennent un \u00e9l\u00e9ment d\u00e9terminant pour identifier les exigences de s\u00e9curit\u00e9\u00a0 (4.2.a).<\/p>\n<h4>Une d\u00e9finition des indicateurs simplifi\u00e9e<\/h4>\n<p>Un chapitre (6.2. <em>Information security objectives and plans to achieve them<\/em>) \u00e9nonce la n\u00e9cessit\u00e9 de documenter des objectifs de s\u00e9curit\u00e9 de l\u2019information \u00e0 des niveaux pertinents. Mais surtout il met en avant le fait que les mesures de s\u00e9curit\u00e9 doivent \u00eatre suivies par des indicateurs seulement si cela est \u00ab\u00a0<em>practicable<\/em>\u00a0\u00bb. Nous verrons ce que donnera la traduction en fran\u00e7ais mais il en est termin\u00e9 de l\u2019obligation de mettre des indicateurs sur l\u2019ensemble des mesures de s\u00e9curit\u00e9.<\/p>\n<h4>La d\u00e9claration d\u2019applicabilit\u00e9 voit son \u00ab\u00a0ouverture\u00a0\u00bb renforc\u00e9e<\/h4>\n<p>La\u00a0 nouvelle ISO 27001 renforce la capacit\u00e9 \u00e0 r\u00e9aliser une d\u00e9claration d\u2019applicabilit\u00e9 qui ne se restreint pas aux mesures de l\u2019ISO 27002\u00a0: \u00ab\u00a0l\u2019organisation peut ajouter des objectifs de contr\u00f4les et cr\u00e9er les contr\u00f4les lorsque cela est n\u00e9cessaire ou encore les identifier \u00e0 partir de n\u2019importe quelle source\u00a0\u00bb, cependant elle doit v\u00e9rifier qu\u2019aucune mesure majeure de s\u00e9curit\u00e9 de l\u2019ISO 27002 n\u2019a \u00e9t\u00e9 omise. Ce point cl\u00e9 a fait l\u2019objet de nombreux d\u00e9bats, mais il est essentiel pour conserver une \u00ab\u00a0comparabilit\u00e9\u00a0\u00bb entre plusieurs certifications, au-del\u00e0 du simple p\u00e9rim\u00e8tre.<\/p>\n<h4>La communication autour du SMSI, \u00e0 r\u00e9fl\u00e9chir en interne comme en externe<\/h4>\n<p>Un nouveau chapitre (7.4 <em>Communication<\/em>) \u00e9nonce la n\u00e9cessit\u00e9 pour chaque organisation, de d\u00e9terminer dans son cas particulier, le besoin en termes de communication interne ou externe \u00e0 r\u00e9aliser concernant le SMSI (sujet, communiquant, cible, proc\u00e9d\u00e9).<\/p>\n<h2>Une nouvelle publication, mais quels changements pour la mise en place d\u2019un SMSI ou le maintien d\u2019une certification ISO 27001 ?<\/h2>\n<p>Par une meilleure coh\u00e9rence dans l\u2019encha\u00eenement des chapitres et dans la lecture de la logique globale PDCA ainsi qu\u2019une plus grande pr\u00e9cision dans la d\u00e9finition de plusieurs concepts, \u00a0la nouvelle version de l\u2019ISO 27001 clarifie la mise en \u0153uvre de la norme.<\/p>\n<p>Il ne s\u2019agit donc pas d\u2019une r\u00e9volution, les concepts restent les m\u00eames. Cependant, la norme gagne en clart\u00e9 et en efficacit\u00e9. La migration des SMSI existants ne posera pas de probl\u00e8mes fondamentaux et pourra m\u00eame \u00eatre l\u2019occasion de simplifier certains processus comme ceux des indicateurs ou encore le suivi des non-conformit\u00e9s. De plus, la structure unifi\u00e9e avec les autres normes de syst\u00e8mes de management (ISO 9001\u2026) facilitera la mise en \u0153uvre de syst\u00e8mes de management int\u00e9gr\u00e9s.<\/p>\n<p>Les annexes de l\u2019ISO 27001, bas\u00e9es sur la norme ISO 27002, ont \u00e9galement \u00e9t\u00e9 revues en profondeur.<\/p>\n<p>Une nouvelle mouture qui facilitera le quotidien de nombreux RSSI\u00a0!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version&#8230;<\/p>\n","protected":false},"author":193,"featured_media":6222,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3222,36],"tags":[70,62,1261,1156,3304,181,63],"coauthors":[1280,1281],"class_list":["post-4106","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyberrisk-management-strategy","category-cybersecurity-digital-trust","tag-gestion-des-risques","tag-iso-27001","tag-iso-27002","tag-normes","tag-risk-management-strategy-governance","tag-rssi","tag-smsi"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?<\/title>\n<meta name=\"description\" content=\"Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme ?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?\" \/>\n<meta property=\"og:description\" content=\"Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme ?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2013-09-05T12:16:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-12-31T10:33:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"843\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Florence Le Goff, Thibault Lapedagne\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Florence Le Goff, Thibault Lapedagne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\"},\"author\":{\"name\":\"Florence Le Goff\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/3dbf603d68922dd355bf464e2d050098\"},\"headline\":\"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?\",\"datePublished\":\"2013-09-05T12:16:29+00:00\",\"dateModified\":\"2019-12-31T10:33:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\"},\"wordCount\":936,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg\",\"keywords\":[\"Gestion des risques\",\"ISO 27001\",\"iso 27002\",\"normes\",\"Risk management\",\"RSSI\",\"SMSI\"],\"articleSection\":[\"Cyberrisk Management &amp; Strategy\",\"Cybersecurity &amp; Digital Trust\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\",\"name\":\"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg\",\"datePublished\":\"2013-09-05T12:16:29+00:00\",\"dateModified\":\"2019-12-31T10:33:17+00:00\",\"description\":\"Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme ?\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg\",\"width\":1500,\"height\":843},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/3dbf603d68922dd355bf464e2d050098\",\"name\":\"Florence Le Goff\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/florence-le-goff\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?","description":"Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme ?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/","og_locale":"en_US","og_type":"article","og_title":"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?","og_description":"Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme ?","og_url":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/","og_site_name":"RiskInsight","article_published_time":"2013-09-05T12:16:29+00:00","article_modified_time":"2019-12-31T10:33:17+00:00","og_image":[{"width":1500,"height":843,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg","type":"image\/jpeg"}],"author":"Florence Le Goff, Thibault Lapedagne","twitter_misc":{"Written by":"Florence Le Goff, Thibault Lapedagne","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/"},"author":{"name":"Florence Le Goff","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/3dbf603d68922dd355bf464e2d050098"},"headline":"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?","datePublished":"2013-09-05T12:16:29+00:00","dateModified":"2019-12-31T10:33:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/"},"wordCount":936,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg","keywords":["Gestion des risques","ISO 27001","iso 27002","normes","Risk management","RSSI","SMSI"],"articleSection":["Cyberrisk Management &amp; Strategy","Cybersecurity &amp; Digital Trust"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/","url":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/","name":"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg","datePublished":"2013-09-05T12:16:29+00:00","dateModified":"2019-12-31T10:33:17+00:00","description":"Pilier de tr\u00e8s nombreuses d\u00e9marches s\u00e9curit\u00e9, la norme ISO 27001 est en cours de mise \u00e0 jour. Sa publication, attendue pour la fin de l\u2019ann\u00e9e, apporte de nombreux changements bienvenus. Quels sont-ils et comment utiliser au mieux cette nouvelle version de la norme ?","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2014\/11\/robert-kotsch-fotolia.com_.jpg","width":1500,"height":843},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/2013\/09\/mise-a-jour-de-liso-27001-quels-impacts-operationnels\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"Mise \u00e0 jour de l\u2019ISO 27001 : quels impacts op\u00e9rationnels ?"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/3dbf603d68922dd355bf464e2d050098","name":"Florence Le Goff","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/florence-le-goff\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/4106","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/193"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=4106"}],"version-history":[{"count":9,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/4106\/revisions"}],"predecessor-version":[{"id":6235,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/4106\/revisions\/6235"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/6222"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=4106"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=4106"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=4106"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=4106"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}