ANSI INCITS ISO IEC 27001-2013 Information technology - Security techniques - Information security management systems - Requirements.pdf
《ANSI INCITS ISO IEC 27001-2013 Information technology - Security techniques - Information security management systems - Requirements.pdf》由会员分享,可在线阅读,更多相关《ANSI INCITS ISO IEC 27001-2013 Information technology - Security techniques - Information security management systems - Requirements.pdf(30页珍藏版)》请在麦多课文档分享上搜索。
1、 INCITS/ISO/IEC 27001:2013 2014 (ISO/IEC 27001:2013, IDT) Information technology Security techniques Information security management systems Requirements INCITS/ISO/IEC 27001:2013 2014 PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file
2、may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat ac
3、cepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that
4、the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. Adopted by INCITS (InterNational Committee for Information Technology Standards) as an American National Standard. Date o
5、f ANSI Approval: 6/18/2014 Published by American National Standards Institute, 25 West 43rd Street, New York, New York 10036 Copyright 2014 by Information Technology Industry Council (ITI). All rights reserved. These materials are subject to copyright claims of International Standardization Organiza
6、tion (ISO), International Electrotechnical Commission (IEC), American National Standards Institute (ANSI), and Information Technology Industry Council (ITI). Not for resale. No part of this publication may be reproduced in any form, including an electronic retrieval system, without the prior written
7、 permission of ITI. All requests pertaining to this standard should be submitted to ITI, 1250 Eye Street NW, Washington, DC 20005. Printed in the United States of America ii ITIC 2014 All rights reserved ISO/IEC 27001:2013(E) ISO/IEC 2013 All rights reserved iiiContents PageForeword iv0 Introduction
8、 .v1 Scope . 12 Normative references 13 Terms and definitions . 14 Context of the organization . 14.1 Understanding the organization and its context . 14.2 Understanding the needs and expectations of interested parties 14.3 Determining the scope of the information security management system 14.4 Inf
9、ormation security management system . 25 Leadership 25.1 Leadership and commitment . 25.2 Policy . 25.3 Organizational roles, responsibilities and authorities 36 Planning . 36.1 Actions to address risks and opportunities . 36.2 Information security objectives and planning to achieve them . 57 Suppor
10、t . 57.1 Resources . 57.2 Competence . 57.3 Awareness . 57.4 Communication 67.5 Documented information . 68 Operation . 78.1 Operational planning and control 78.2 Information security risk assessment. 78.3 Information security risk treatment 79 Performance evaluation . 79.1 Monitoring, measurement,
11、analysis and evaluation . 79.2 Internal audit 89.3 Management review . 810 Improvement 910.1 Nonconformity and corrective action . 910.2 Continual improvement 9Annex A (normative) Reference control objectives and controls 10Bibliography .23ISO/IEC 27001:2013(E)ForewordISO (the International Organiza
12、tion for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respec
13、tive organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of informatio
14、n technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1.International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2.The main task of the joint technical committee is to prepare International Standards. Draft International Sta
15、ndards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote.Attention is drawn to the possibility that some of the elements of this document may be the
16、subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights.ISO/IEC 27001 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques.This second edition cancels and replaces the fir
17、st edition (ISO/IEC 27001:2005), which has been technically revised.iv ISO/IEC 2013 All rights reservedISO/IEC 27001:2013(E)0 Introduction0.1 GeneralThis International Standard has been prepared to provide requirements for establishing, implementing, maintaining and continually improving an informat
18、ion security management system. The adoption of an information security management system is a strategic decision for an organization. The establishment and implementation of an organizations information security management system is influenced by the organizations needs and objectives, security req
19、uirements, the organizational processes used and the size and structure of the organization. All of these influencing factors are expected to change over time.The information security management system preserves the confidentiality, integrity and availability of information by applying a risk manage
20、ment process and gives confidence to interested parties that risks are adequately managed.It is important that the information security management system is part of and integrated with the organizations processes and overall management structure and that information security is considered in the des
21、ign of processes, information systems, and controls. It is expected that an information security management system implementation will be scaled in accordance with the needs of the organization.This International Standard can be used by internal and external parties to assess the organizations abili
22、ty to meet the organizations own information security requirements.The order in which requirements are presented in this International Standard does not reflect their importance or imply the order in which they are to be implemented. The list items are enumerated for reference purpose only.ISO/IEC 2
23、7000 describes the overview and the vocabulary of information security management systems, referencing the information security management system family of standards (including ISO/IEC 270032, ISO/IEC 270043and ISO/IEC 270054), with related terms and definitions.0.2 Compatibility with other manageme
24、nt system standardsThis International Standard applies the high-level structure, identical sub-clause titles, identical text, common terms, and core definitions defined in Annex SL of ISO/IEC Directives, Part 1, Consolidated ISO Supplement, and therefore maintains compatibility with other management
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIINCITSISOIEC270012013INFORMATIONTECHNOLOGYSECURITYTECHNIQUESINFORMATIONSECURITYMANAGEMENTSYSTEMSREQUIREMENTSPDF

链接地址:http://www.mydoc123.com/p-436416.html