Organizations that have an implemented and certified information security management system no later than 31 October, 2025 must align their systems with the new edition of the ISO/IEC 27001:2022 standard. With the desire to help domestic business entities and facilitate their transition, ISS also published editions in the Serbian language of the following standards:
The first standard, which is intended for certification, contains requirements for the establishment, implementation, maintenance and continuous improvement of information security management systems, as well as requirements for risk assessment and handling of information security risks. The second one contains information security controls with implementation instructions.
These standards, as well as all other standards in the field of information security, cyber security and privacy protection, are under the jurisdiction of the ISS NTC I224, Identification, cards, financial activities and IT security techniques.
In addition to other members of this NTC, the representatives of the Ministry for Information and Telecommunications actively participated in the work of the NTC I224 on the preparation of translations, which significantly contributed to the harmonization of the terminology of the standards and the draft of the new Law on Information Security, where possible. During the period of the public enquiry on the translation of the mentioned standards, NTC members, primarily the ISS NTC CASCO, submitted their constructive proposals.
Andreas Wolf, one of the leading experts of ISO/IEC JTC1/SC 27, Information security, cyber security and privacy protection, highlighted the importance of bolstering organizational cyber resistance is underscored by both industry standards and experts by saying:
“The organizations that will lead us into the digital future are those that are not only vulnerable enough to admit they can’t do it alone, but are also confident and savvy enough to realize that it’s better for businesses to not even attempt it. Organizations that adopt cyber resilience quickly emerge as leaders in their industry.”