11. Jun 2024

New features and what happens next

Aspects of climate change included in the standards for management systems

The International Organization for Standardization (ISO) and the International Accreditation Forum (IAF) recognized a while ago that the climate crisis and its effects present many major challenges. As a result, ISO and IAF published a joint communiqué on February 22, 2024.

This communiqué lists changes that are intended to ensure that companies and organizations address these issues. These changes are embedded in Chapters 4.1 - Understanding the organization and its context and 4.2 - Understanding the needs and expectations of stakeholders and are as follows

Chapter 4.1: "The organization shall determine whether climate change is a relevant issue."

Chapter 4.2: "NOTE: Relevant interested parties can have requirements related to climate change."

 

This affects, among others, the standards

ISO 27001:2022, ISO 22301:2019, ISO 20000-1:2018.

Effects on organizations

For certified companies, nothing will change except that the certificates will remain valid unchanged. The new requirements will be reviewed by auditors in the respective audits. However, certified companies must ensure that they address the topic of climate change and the resulting challenges by addressing the issues (as defined above) in context and taking into consideration the requirements of interested parties accordingly.

What is the next step?

These requirements will be included in all type A management system standards (certifiable standards) - this includes the standards ISO 27001:2022, ISO 22301:2019 and ISO 20000-1:2018 and will subsequently be included in the harmonized structure of Appendix 2 of Annex SL.

In addition, the Auditing Practices Group, an informal ISO group consisting of experts, auditors and users, has issued guidance on how these topics can be queried as examples in an ISO 9001 audit. This guidance can serve as a basis for organizations to query and anchor the above-mentioned topics for themselves.

How does CIS support you?

Our auditors are prepared to deal with this topic in the audits and to consider and query the relevant issues in an integrated manner. If you have any further questions, please do not hesitate to contact us or your responsible auditor.

Contact us here

News & Events

The basis for long-term success!

19. Aug 2024

Global Threat Report 2024: Current situation

Newest trends in cybercrime

Learn more
06. Aug 2024

Lateral entry as an IT security auditor – a field report

06. Aug 2024

TISAX®: Information security in the automotive industry

06. Aug 2024

TISAX® deep dive: the three assessment levels

06. Aug 2024

TISAX® deep dive: the 12 test objectives (labels)

10. Oct 2024

Event: CIS Compliance Summit 2024

Austrian platform for experts, professionals and desicion makers in the security industry. Be part of it - save the date: October 10th, 2024

Learn more
17. Apr 2024

CIS joins the Austrian Data Centre Association (ADCA)

New cooperation

Learn more
17. Apr 2024

Smart compliance for data centres

NISG and EN 50600

Learn more
28. Mar 2024

ISO 42001 – the new standard for artificial intelligence

World's first standard for AI

Learn more
07. Mar 2024

The future of AI and data ownership

A balancing act between AI, information security and data ownership

Learn more
07. Mar 2024

Are we losing control of our data through artificial intelligence (AI)?

A balancing act between AI, information security and data ownership

Learn more
31. Jan 2024

CIS is the first inspection body for EN 50600

Product and service certification for data centers

Learn more
+43 1 532 98 90