BS PD ISO IEC TS 33072-2016 Information technology Process assessment Process capability assessment model for information security management《信息技术 过程评定 信息安全管理的过程能力评估模型》.pdf
《BS PD ISO IEC TS 33072-2016 Information technology Process assessment Process capability assessment model for information security management《信息技术 过程评定 信息安全管理的过程能力评估模型》.pdf》由会员分享,可在线阅读,更多相关《BS PD ISO IEC TS 33072-2016 Information technology Process assessment Process capability assessment model for information security management《信息技术 过程评定 信息安全管理的过程能力评估模型》.pdf(196页珍藏版)》请在麦多课文档分享上搜索。
1、PD ISO/IEC TS 33072:2016 Information technology Process assessment Process capability assessment model for information security management BSI Standards Publication WB11885_BSI_StandardCovs_2013_AW.indd 1 15/05/2013 15:06PD ISO/IEC TS 33072:2016 PUBLISHED DOCUMENT National foreword This Published Do
2、cument is the UK implementation of ISO/IEC TS 33072:2016. The UK participation in its preparation was entrusted to Technical Committee IST/15, Software and systems engineering. A list of organizations represented on this committee can be obtained on request to its secretary. This publication does no
3、t purport to include all the necessary provisions of a contract. Users are responsible for its correct application. The British Standards Institution 2016. Published by BSI Standards Limited 2016 ISBN 978 0 580 93543 5 ICS 35.080 Compliance with a British Standard cannot confer immunity from legal o
4、bligations. This Published Document was published under the authority of the Standards Policy and Strategy Committee on 30 September 2016. Amendments/corrigenda issued since publication Date Text affected Information technology Process assessment Process capability assessment model for information s
5、ecurity management Technologies de linformation valuation des procds Modle dvaluation de la capacit des procds pour le management de la scurit de linformation ISO/IEC TS 33072 First edition 2016-07-15 Reference number ISO/IEC TS 33072:2016(E) TECHNICAL SPECIFICATION ISO/IEC 2016 Corrected version 20
6、16-09-01PD ISO/IEC TS 33072:2016 PUBLISHED DOCUMENT National foreword This Published Document is the UK implementation of ISO/IEC TS 33072:2016. The UK participation in its preparation was entrusted to Technical Committee IST/15, Software and systems engineering. A list of organizations represented
7、on this committee can be obtained on request to its secretary. This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application. The British Standards Institution 2016. Published by BSI Standards Limited 2016 ISBN 978 0 580 93
8、543 5 ICS 35.080 Compliance with a British Standard cannot confer immunity from legal obligations. This Published Document was published under the authority of the Standards Policy and Strategy Committee on 30 September 2016. Amendments/corrigenda issued since publication Date Text affected Informat
9、ion technology Process assessment Process capability assessment model for information security management Technologies de linformation valuation des procds Modle dvaluation de la capacit des procds pour le management de la scurit de linformation ISO/IEC TS 33072 First edition 2016-07-15 Reference nu
10、mber ISO/IEC TS 33072:2016(E) TECHNICAL SPECIFICATION ISO/IEC 2016 Corrected version 2016-09-01ISO/IEC TS 33072:2016(E) ISO/IEC 2016 All rights reserved iii Contents Page Foreword . v Introduction vi 1 Scope 1 2 Normative references 1 3 Terms and definitions . 1 4 Overview of the Process Assessment
11、Model . 2 4.1 Introduction to Overview 2 4.2 Structure of the Process Assessment Model . 3 4.2.1 Processes . 3 4.2.2 Process dimension 4 4.2.3 Capability dimension 4 4.3 Assessment Indicators . 6 4.3.1 Process Capability Indicators 7 4.3.2 Process Performance Indicators . 8 4.4 Measuring process cap
12、ability 9 5 The process dimension and process performance indicators (Level 1) . 10 5.1 General . 10 5.2 ORG.1 Asset management . 11 5.3 TEC.01 Capacity management . 12 5.4 TEC.02 Change management . 13 5.5 COM.01 Communication management 13 5.6 TEC.03 Configuration management 14 5.7 COM.02 Document
13、ation management . 15 5.8 ORG.2 Equipment management 17 5.9 ORG.3 Human resource employment management 18 5.10 COM.03 Human resource management 19 5.11 COM.04 Improvement 20 5.12 TEC.04 Incident management 21 5.13 ORG.4 Infrastructure and work environment . 21 5.14 COM.05 Internal audit 22 5.15 TOP.
14、1 Leadership 23 5.16 COM.06 Management review 24 5.17 COM.07 Non-conformity management 25 5.18 COM.09 Operational implementation and control 26 5.19 COM.08 Operational planning 27 5.20 COM.10 Performance evaluation . 29 5.21 TEC.05 Product/service release . 30 5.22 TEC.08 Product/Service/System requ
15、irements 31 5.23 COM.11 Risk and opportunity management . 32 5.24 TEC.06 Service availability management 33 5.25 TEC.07 Service continuity management . 34 5.26 ORG.5 Supplier management . 34 5.27 TEC.09 Technical data preservation and recovery 35 6 Process capability indicators . 36 6.1 Introduction
16、 36 6.2 Process capability levels and process attributes 36 6.2.1 Process capability Level 0: Incomplete process . 36 6.2.2 Process capability Level 1: Performed process 36 6.2.3 Process capability Level 2: Managed process . 37 PD ISO/IEC TS 33072:2016 ISO/IEC TS 33072:2016(E) ii ISO/IEC 2016 All ri
17、ghts reserved iv vISO/IEC TS 33072:2016(E) iv ISO/IEC 2016 All rights reserved 6.2.4 Process capability Level 3: Established process 42 6.2.5 Process capability Level 4: Predictable process 46 6.2.6 Process capability Level 5: Innovating process 51 6.3 Related processes for process attributes 55 Ann
18、ex A (informative) Conformity of the process assessment model . 57 A.1 Introduction . 57 A.2 Requirements for process assessment models 57 A.2.1 Introduction . 57 A.2.2 Process assessment model scope . 57 A.2.3 Requirements for process assessment models 58 A.2.4 Assessment indicators 58 A.2.5 Mappin
19、g process assessment models to process reference models. 59 A.2.6 Expression of assessment results 61 Annex B (informative) Input and output characteristics 62 B.1 General . 62 B.2 Generic input and outputs . 63 B.3 Specific inputs and outputs . 67 Annex C (informative) Association between base prac
20、tices and ISO/IEC 27001 requirements 97 C.1 Associations of base practices with requirements . 98 C.2 Associations of requirements with base practices . 136 C.3 Base practices that have no associated requirements. 180 Bibliography . 183 PD ISO/IEC TS 33072:2016 ISO/IEC TS 33072:2016(E) iii ISO/IEC 2
21、016 All rights reserved 96 97 135 179 182ISO/IEC TS 33072:2016(E) ISO/IEC 2016 All rights reserved v Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies th
22、at are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other intern
23、ational organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. The procedures used to develop this document and those intended for its
24、further maintenance are described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for the different types of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directive
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSPDISOIECTS330722016INFORMATIONTECHNOLOGYPROCESSASSESSMENTPROCESSCAPABILITYASSESSMENTMODELFORINFORMATIONSECURITYMANAGEMENT

链接地址:http://www.mydoc123.com/p-398724.html