Information Security Management
ISO 27001 Amendment 1:2024
What you need to know about the recent amendment to ISO 27001.
How to address “Climate Action Considerations” in your ISMS.
Published: 27 April 2025 · Last updated: 22 April 2026
At A Glance
ISO 27001 Amendment 1:2024 added an addition to the standard, and wants you to evaluate and record the risk of climate change on your ISMS. Not the carbon footprint, but the actual risk of an earthquake, flood or drought, etc. Most of these are covered by outsourced services like AWS or Google, so I advise my clients to add them to their external influences / interested party assessments in the Context of the Organisation, and then include a risk entry.
Occasionally, ISO feels that it needs to issue a small update to the standard to reflect something important, but not necessarily overhaul the whole standard. It happens infrequently, but it does happen. The ISO 27001 standard (the most recent 2022 version) has been amended in 2024 to include climate action considerations. So, if you want to know what you need to do, then read on…
Most businesses are facing mounting pressure to address environmental concerns, so ISO has taken a step toward integrating climate change into Information Security Management Systems (ISMS). These updates encourage organisations to adopt a holistic approach to risk management, considering environmental factors that may impact their security landscape.
Key Changes in ISO 27001 Amendment 1:2024
The amendment primarily affects Clause 4, sub clauses 4.1 and 4.2, which outline an organisation’s context and stakeholder expectations.
The update acknowledges that external environmental factors, including climate change, can profoundly impact business operations and security postures.
1. Clause 4.1 – Understanding the Organisation and Its Context
- Organisations must now determine whether climate change is a relevant issue for their ISMS and document the assessment.
- For example, this may include climate-related risks such as natural disasters, regulatory changes, and sustainability policies, which must be assessed in terms of their potential impact on information security.
- Businesses should consider disruptions such as severe weather affecting data centre operations, supply chain vulnerabilities due to environmental events, or new government compliance requirements related to sustainability.
2. Clause 4.2 – Understanding the Needs and Expectations of Interested Parties
- A new note clarifies that relevant stakeholders, such as customers, regulators, and industry bodies, may have specific climate-related requirements.
- For example, businesses in compliance-heavy industries or those operating in regions with strict environmental regulations may need to adjust their security policies accordingly.
- Companies should explore sustainability-driven security initiatives to align with the expectations of partners and clients who prioritise environmentally responsible practices.
ISO 27001:2022 — Amendment 1:2024 at a Glance
Areas to Consider
ISO 27001 has always prioritised risk management, and this update just expands its scope to include climate-related threats.
Things I suggest you consider;
- Physical Risks – e.g. extreme weather events that threaten data centres, impact supply chains, or disrupt operations.
- Regulatory Risks – e.g. stricter government policies on sustainability and carbon emissions could affect IT infrastructure, data processing, and energy consumption.
- Reputational Risks – e.g. Companies that fail to address climate-related security concerns may face stakeholder pressure, loss of investor confidence, or diminished customer trust.
By recognising these factors within the ISMS, organisations can improve resilience and future-proof their security strategies.
What Should You Do?
I recommend not overthinking it too much. I suggest to my clients that they add a recognition of the requirement into the internal/external factors under 4.1 and the stakeholders under 4.2, then add in a brief risk assessment.
Some suggested actions:
How To Address ISO 27001 Amendment 1:2024
Evaluate & Update Internal/External Issues Assessment
It’ll depend entirely on where and how you originally did this, but under Clauses 4.1 & 4.2, you need to document your evaluation of the influences on your ISMS, including factors and stakeholder needs.
Discuss any relevant aspects, and ensure they are documented. If you are using my Information Security Manual as part of my ISO 27001 toolkit, update sections 4.1 & 4.2.
Consider stakeholders to see if they have any specific climate-related security expectations. Don’t go mad, documenting a high-level consideration in the management meeting minutes, or contract reviews or something.
Update The Risk Assessments
Make sure you add something into your risk register to demonstrate consideration/scoring/prioritisation, and ownership of any climate-related risks.
Consider climate-related threats to information security. It’s okay to look at a shared responsibility model with your supplier and deem that’s their ownership (e.g., AWS handling data centre protections), but make it a clear conclusion.
Review business continuity and disaster recovery plans
Review business continuity and disaster recovery plans with climate risks in mind, especially if you have on-prem servers. Then ensure continuity plans account for potential disruptions, such as extreme weather affecting key infrastructure. If you do this, my advice is to make sure it’s reflected somewhere in the risk assessments.
Update Policies (if needed)
Consider incorporating sustainability considerations into security policies. It depends on how ‘green’ your business is, but you could explore green data centres, energy-efficient hardware, and digital waste-reduction initiatives to align security practices with environmental responsibility. Water usage by AI data centres is going to be a big one in future.
Stay Informed
Stay informed on evolving climate-related regulations to remain compliant with emerging industry standards. A proactive stance on regulatory changes will help organisations adapt smoothly. So you might want to make an adjustment to the log of regulatory obligations if anything climate-related touches security.
FAQs
Do I have to address Amendment 1?
Yes. Sorry. Maybe to a greater or lesser extent, but since ISO has now published it as an update to ISO 27001:2022, you are obligated to give it consideration.
How much work do I need to put into it?
Don’t go crazy. Give it some consideration, document that, take action if necessary. For most of my clients, it’s just not a relevant issue, so they capture it in the risk register, and the Information Security Manual, and say ‘we’ve considered it, but don’t feel…’ etc.
Are there any other ISO 27001 amendments?
Not at the time of writing this.
Do I need to get re-audited?
No. No need to get reaudited, they’ll review it at the next audit. It’s not a major change.
When do I need to do it by?
ISO have published this as an immediate amendment, so if you’re due a surveillance audit, your auditor may raise it.
Conclusion
For full details on this amendment, visit the official ISO website: ISO 27001 Amendment 1:2024. It’s free to anyone who has already purchased the standard.
Keep it simple, make sure you’ve highlighted the consideration of climate change in your context of the organisation (however you’ve addressed it), and risks.
Get Started
Free Templates
Free
The 14 mandatory documents. The starting point for any ISO 27001 project.
A great way to get started without the commitment.
Templates
Full Toolkit
£85
130+ documents; policies, risk register, audit pack, staff communications and everything else you need to build a working ISMS.
Buy now →Do-It-Yourself
DIY Course
£285
The Do-It-Yourself course introduces the standard, its requirements, and then shows you how to implement it, stage by stage.
Includes the full toolkit & email consultancy.
More support?
Coaching
~£3,500
I can guide you through the standard and help you tailor it to your business through a series of coaching workshops.
Includes the full toolkit, personal consultancy, and first-pass guarantee.