ANSI INCITS ISO IEC 27006-2007 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems.pdf
《ANSI INCITS ISO IEC 27006-2007 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems.pdf》由会员分享,可在线阅读,更多相关《ANSI INCITS ISO IEC 27006-2007 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems.pdf(44页珍藏版)》请在麦多课文档分享上搜索。
1、INCITS/ISO/IEC 27006:20072008 (ISO/IEC 27006:2007, IDTInformation technology Security techniques Requirements forbodies providing auditand certification of informationsecurity management systems INCITS/ISO/IEC 27006:20072008(ISO/IEC 27006:2007, IDT)INCITS/ISO/IEC 27006:20072008 ii ITIC 2008 All righ
2、ts reserved PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading
3、 this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the Genera
4、l Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given b
5、elow. Adopted by INCITS (InterNational Committee for Information Technology Standards) as an American National Standard. Date of ANSI Approval: 7/1/2008 Published by American National Standards Institute, 25 West 43rd Street, New York, New York 10036 Copyright 2008 by Information Technology Industry
6、 Council (ITI). All rights reserved. These materials are subject to copyright claims of International Standardization Organization (ISO), International Electrotechnical Commission (IEC), American National Standards Institute (ANSI), and Information Technology Industry Council (ITI). Not for resale.
7、No part of this publication may be reproduced in any form, including an electronic retrieval system, without the prior written permission of ITI. All requests pertaining to this standard should be submitted to ITI, 1250 Eye Street NW, Washington, DC 20005. Printed in the United States of America INC
8、ITS/ISO/IEC 27006:20072008 ITIC 2008 All rights reserved iii Contents Foreword .5 Introduction .6 Information technology Security techniques Requirements for bodies providing audit and certification of information security management systems .1 1 Scope 1 2 Normative references .1 3 Terms and definit
9、ions 1 4 Principles 2 5 General requirements.2 5.1 Legal and contractual matter .2 5.2 Management of impartiality2 5.3 Liability and financing 3 6 Structural requirements .3 6.1 Organizational structure and top management 3 6.2 Committee for safeguarding impartiality .3 7 Resource requirements 3 7.1
10、 Competence of management and personnel 3 7.2 Personnel involved in the certification activities 4 7.3 Use of individual external auditors and external technical experts .6 7.4 Personnel records 6 7.5 Outsourcing 6 8 Information requirements 6 8.1 Publicly accessible information.6 8.2 Certification
11、documents .6 8.3 Directory of certified clients.7 8.4 Reference to certification and use of marks .7 8.5 Confidentiality 7 8.6 Information exchange between a certification body and its clients .7 9 Process requirements 7 9.1 General requirements.7 9.2 Initial audit and certification 11 9.3 Surveilla
12、nce activities 15 9.4 Recertification 16 9.5 Special audits . 16 9.6 Suspending, withdrawing or reducing scope of certification 16 9.7 Appeals . 17 9.8 Complaints 17 9.9 Records of applicants and clients . 17 10 Management system requirements for certification bodies . 17 10.1 Options . 17 10.2 Opti
13、on 1 Management system requirements in accordance with ISO 9001 17 10.3 Option 2 General management system requirements . 17 Annex A (informative) Analysis of a client organizations complexity and sector-specific aspects 18 A.1 Organizations risk potential 18 A.2 Sector-specific categories of inform
14、ation security risk 20 Annex B (informative) Example areas of auditor competence 21 B.1 General competence considerations . 21 INCITS/ISO/IEC 27006:20072008 iv ITIC 2008 All rights reserved B.2 Specific competence considerations 21 Annex C (informative) Audit time 23 Annex D (informative) Guidance f
15、or review of implemented ISO/IEC 27001:2005, Annex A controls. 29 INCITS/ISO/IEC 27006:20072008 ITIC 2008 All rights reserved v Foreword ISO (the International Organization for Standardization) and IEC (International Electrotechnical Commission) form the specialized system for worldwide standardizat
16、ion. National bodies that are members of ISO and IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutua
17、l interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. International Standards are drafted in accordanc
18、e with the rules given in the ISO/IEC Directives, Part 2. The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the technical committees are circulated to the member bodies for voting. Publication as an International Standard r
19、equires approval by at least 75 % of the member bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO shall not be held responsible for identifying any or all such patent rights. ISO/IEC 27006 was prepared by
20、Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques. INCITS/ISO/IEC 27006:20072008 vi ITIC 2008 All rights reserved Introduction ISO/IEC 17021 is an International Standard which sets out criteria for bodies operating audit and certification of
21、organizations management systems. If such bodies are to be accredited as complying with ISO/IEC 17021 with the objective of auditing and certifying Information Security Management Systems (ISMS) in accordance with ISO/IEC 27001:2005, some additional requirements and guidance to ISO/IEC 17021 are nec
22、essary. These are provided by this International Standard. The text in this International Standard follows the structure of ISO/IEC 17021, and the additional ISMS-specific requirements and guidance on the application of ISO/IEC 17021 for ISMS certification are identified by the letters “IS”. The ter
23、m “shall” is used throughout this International Standard to indicate those provisions which, reflecting the requirements of ISO/IEC 17021 and ISO/IEC 27001, are mandatory. The term “should” is used to indicate those provisions which, although they constitute guidance for the application of the requi
24、rements, are expected to be adopted by a certification body. One aim of this International Standard is to enable accreditation bodies to more effectively harmonise their application of the standards against which they are bound to assess certification bodies. In this context, any variation from the
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIINCITSISOIEC270062007INFORMATIONTECHNOLOGYSECURITYTECHNIQUESREQUIREMENTSFORBODIESPROVIDINGAUDITANDCERTIFICATIONOFINFORMATIONSECURITYMANAGEMENTSYSTEMSPDF

链接地址:http://www.mydoc123.com/p-436418.html