BS PD ISO IEC TS 33052-2016 Information technology Process reference model (PRM) for information security management《信息技术 信息安全管理的流程参考模型 (PRM)》.pdf
《BS PD ISO IEC TS 33052-2016 Information technology Process reference model (PRM) for information security management《信息技术 信息安全管理的流程参考模型 (PRM)》.pdf》由会员分享,可在线阅读,更多相关《BS PD ISO IEC TS 33052-2016 Information technology Process reference model (PRM) for information security management《信息技术 信息安全管理的流程参考模型 (PRM)》.pdf(70页珍藏版)》请在麦多课文档分享上搜索。
1、Information technology Process reference model (PRM) for information security management PD ISO/IEC TS 33052:2016 BSI Standards Publication WB11885_BSI_StandardCovs_2013_AW.indd 1 15/05/2013 15:06National foreword This Published Document is the UK implementation of ISO/IEC TS 33052:2016. The UK part
2、icipation in its preparation was entrusted to Technical Committee IST/15, Software and systems engineering. A list of organizations represented on this committee can be obtained on request to its secretary. This publication does not purport to include all the necessary provisions of a contract. User
3、s are responsible for its correct application. The British Standards Institution 2016. Published by BSI Standards Limited 2016 ISBN 978 0 580 92221 3 ICS 35.080 Compliance with a British Standard cannot confer immunity from legal obligations. This Published Document was published under the authority
4、 of the Standards Policy and Strategy Committee on 30 June 2016. Amendments/corrigenda issued since publication Date Text affected PUBLISHED DOCUMENT PD ISO/IEC TS 33052:2016Information technology Process reference model (PRM) for information security management Technologies de linformation Modle de
5、 rfrence des procds pour le management de la scurit de linformation ISO/IEC TS 33052 First edition 2016-06-15 Reference number ISO/IEC TS 33052:2016(E) TECHNICAL SPECIFICATION ISO/IEC 2016 PD ISO/IEC TS 33052:2016 ii ISO/IEC 2016 All rights reserved COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2016, Publish
6、ed in Switzerland All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permissio
7、n can be requested from either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Ch. de Blandonnet 8 CP 401 CH-1214 Vernier, Geneva, Switzerland Tel. +41 22 749 01 11 Fax +41 22 749 09 47 copyrightiso.org www.iso.org ISO/IEC TS 33052:2016(E) PD ISO/IE
8、C TS 33052:2016 ISO/IEC TS 33052:2016(E)Foreword iv Introduction v 1 Scope . 1 2 Normative references 1 3 T erms and definitions . 1 4 Overview of the PRM 1 5 Process descriptions 2 5.1 Introduction 2 5.2 ORG.1 Asset management 3 5.3 TEC.01 Capacity management . 3 5.4 TEC.02 Change management 4 5.5
9、COM.01 Communication management . 4 5.6 TEC.03 Configuration management 5 5.7 COM.02 Documentation management 5 5.8 ORG.2 Equipment management . 6 5.9 ORG.3 Human resource employment management 7 5.10 COM.03 Human resource management . 8 5.11 COM.04 Improvement . 9 5.12 TEC.04 Incident management 9
10、5.13 ORG.4 Infrastructure and work environment 9 5.14 COM.05 Internal audit11 5.15 TOP .1 Leadership .11 5.16 COM.06 Management review .12 5.17 COM.07 Non-conformity management .13 5.18 COM.09 Operational implementation and control 13 5.19 COM.08 Operational planning .15 5.20 COM.10 Performance eval
11、uation 17 5.21 TEC.05 Product/service release18 5.22 TEC.08 Product/Service/System requirements 18 5.23 COM.11 Risk and opportunity management 19 5.24 TEC.06 Service availability management 19 5.25 TEC.07 Service continuity management 20 5.26 ORG.5 Supplier management .20 5.27 TEC.09 Technical data
12、preservation and recovery 21 Annex A (informative) The relationship between management system requirements and a process reference model .22 Annex B (informative) Statement of conformity to ISO/IEC 33004 .58 Bibliography .60 ISO/IEC 2016 All rights reserved iii Contents Page PD ISO/IEC TS 33052:2016
13、 ISO/IEC TS 33052:2016(E) Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of Internationa
14、l Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with I
15、SO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. The procedures used to develop this document and those intended for its further maintenance are described in the ISO/IEC Directives, Part 1. In par
16、ticular the different approval criteria needed for the different types of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives). Attention is drawn to the possibility that some of the elements of this
17、 document may be the subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights. Details of any patent rights identified during the development of the document will be in the Introduction and/or on the ISO list of patent declarations received (s
18、ee www.iso.org/patents). Any trade name used in this document is information given for the convenience of users and does not constitute an endorsement. For an explanation on the meaning of ISO specific terms and expressions related to conformity assessment, as well as information about ISOs adherenc
19、e to the WTO principles in the Technical Barriers to Trade (TBT) see the following URL: Foreword - Supplementary information The committee responsible for this document is ISO/IEC JTC 1, Information technology, Subcommittee SC 7, Software and systems engineering.iv ISO/IEC 2016 All rights reserved P
20、D ISO/IEC TS 33052:2016 ISO/IEC TS 33052:2016(E) Introduction The purpose of this Technical Specification is to facilitate the development of a process assessment model (PAM) described in ISO/IEC TS 33072. ISO/IEC 33002 describes the requirements for the conduct of an assessment. ISO/IEC 33020 descr
21、ibes the measurement scale for assessing the process quality characteristic of process capability. ISO/IEC 33001 describes the concepts and terminology used for process assessment. A process reference model (PRM) is a model comprising definitions of processes described in terms of process purpose an
22、d outcomes, together with an architecture describing the relationships between the processes. Using the PRM in a practical application may require additional elements suited to the environment and circumstances. The PRM specified in this Technical Specification describes the processes including the
23、information security management system (ISMS) processes implied by ISO/IEC 27001. Each process of this PRM is described in terms of a purpose and outcomes and provides traceability to requirements. The PRM does not attempt to place the processes in any specific environment nor does it pre-determine
24、any level of process capability required to fulfil the ISO/IEC 27001 requirements. The PRM is not intended to be used for a conformity assessment audit or as a process implementation reference guide. The relationships between ISO/IEC TR 24774, ISO/IEC 27001, ISO/IEC 33002, ISO/IEC 33004, ISO/IEC 330
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSPDISOIECTS330522016INFORMATIONTECHNOLOGYPROCESSREFERENCEMODELPRMFORINFORMATIONSECURITYMANAGEMENT 信息技术

链接地址:http://www.mydoc123.com/p-398723.html