BS ISO IEC 27010-2015 Information technology Security techniques Information security management for inter-sector and inter-organizational communications《信息技术 安全技术 部门间和组织间通信用信息安全管理.pdf
《BS ISO IEC 27010-2015 Information technology Security techniques Information security management for inter-sector and inter-organizational communications《信息技术 安全技术 部门间和组织间通信用信息安全管理.pdf》由会员分享,可在线阅读,更多相关《BS ISO IEC 27010-2015 Information technology Security techniques Information security management for inter-sector and inter-organizational communications《信息技术 安全技术 部门间和组织间通信用信息安全管理.pdf(46页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards PublicationBS ISO/IEC 27010:2015Information technology Security techniques Information securitymanagement for inter-sectorand inter-organizationalcommunicationsBS ISO/IEC 27010:2015 BRITISH STANDARDNational forewordThis British Standard is the UK implementation of ISO/IEC 27010:2015. I
2、t supersedes BS ISO/IEC 27010:2012 which is withdrawn.The UK participation in its preparation was entrusted to TechnicalCommittee IST/33/1, Information Security Management Systems.A list of organizations represented on this committee can beobtained on request to its secretary.This publication does n
3、ot purport to include all the necessaryprovisions of a contract. Users are responsible for its correctapplication. The British Standards Institution 2015.Published by BSI Standards Limited 2015ISBN 978 0 580 89580 7ICS 35.040Compliance with a British Standard cannot confer immunity fromlegal obligat
4、ions.This British Standard was published under the authority of theStandards Policy and Strategy Committee on 30 November 2015.Amendments/corrigenda issued since publicationDate T e x t a f f e c t e dBS ISO/IEC 27010:2015Information technology Security techniques Information security management for
5、 inter-sector and inter-organizational communicationsTechnologies de linformation Techniques de scurit Gestion de la scurit de linformation des communications intersectorielles et interorganisationnellesINTERNATIONAL STANDARDISO/IEC27010Reference numberISO/IEC 27010:2015(E)Second edition2015-11-15 I
6、SO/IEC 2015BS ISO/IEC 27010:2015ii ISO/IEC 2015 All rights reservedCOPYRIGHT PROTECTED DOCUMENT ISO/IEC 2015, Published in SwitzerlandAll rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechan
7、ical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or ISOs member body in the country of the requester.ISO copyright officeCh. de Blandonnet 8 CP 401CH-1214 Vernier, Geneva, Switz
8、erlandTel. +41 22 749 01 11Fax +41 22 749 09 47copyrightiso.orgwww.iso.orgISO/IEC 27010:2015(E)BS ISO/IEC 27010:2015ISO/IEC 27010:2015(E)Foreword viIntroduction vii1 Scope . 12 Normative references 13 Terms and definitions . 14 Concepts and justification 14.1 Introduction 14.2 Information sharing co
9、mmunities . 24.3 Community management 24.4 Supporting entities 24.5 Inter-sector communication . 24.6 Conformity 34.7 Communications model 45 Information security policies 45.1 Management direction for information security . 45.1.1 Policies for information security 45.1.2 Review of the policies for
10、information security 56 Organization of information security . 57 Human resource security 57.1 Prior to employment 57.1.1 Screening 57.1.2 Terms and conditions of employment . 57.2 During employment 57.3 Termination and change of employment . 58 Asset management . 58.1 Responsibility for assets . 58
11、.1.1 Inventory of assets . 58.1.2 Ownership of assets 58.1.3 Acceptable use of assets 68.1.4 Return of assets 68.2 Information classification 68.2.1 Classification of information . 68.2.2 Labelling of information 68.2.3 Handling of assets . 68.3 Media handling . 68.4 Information exchanges protection
12、 . 78.4.1 Information dissemination . 78.4.2 Information disclaimers 78.4.3 Information credibility . 78.4.4 Information sensitivity reduction . 88.4.5 Anonymous source protection . 88.4.6 Anonymous recipient protection . 88.4.7 Onwards release authority 99 Access control 910 Cryptography 910.1 Cryp
13、tographic controls 910.1.1 Policy on the use of cryptographic controls . 910.1.2 Key management . 911 Physical and environmental security 9 ISO/IEC 2015 All rights reserved iiiContents PageBS ISO/IEC 27010:2015ISO/IEC 27010:2015(E)12 Operations security . 912.1 Operational procedures and responsibil
14、ities . 912.2 Protection from malware 1012.2.1 Controls against malware 1012.3 Backup . 1012.4 Logging and monitoring . 1012.4.1 Event logging 1012.4.2 Protection of log information . 1012.4.3 Administrator and operator logs 1012.4.4 Clock synchronization 1012.5 Control of operational software 1012.
15、6 Technical vulnerability management . 1012.7 Information systems audit considerations 1012.7.1 Information systems audit controls . 1012.7.2 Community audit rights 1013 Communications security 1113.1 Network security management . 1113.2 Information transfer . 1113.2.1 Information transfer policies
16、and procedures 1113.2.2 Agreements on information transfer 1113.2.3 Electronic messaging 1113.2.4 Confidentiality or non-disclosure agreements .1114 System acquisition, development and maintenance 1115 Supplier relationships .1215.1 Information security in supplier relationships 1215.1.1 Information
17、 security policy for supplier relationships .1215.1.2 Addressing security within supplier agreements 1215.1.3 Information and communication technology supply chain .1215.2 Supplier service delivery management 1216 Information security incident management 1216.1 Management of information security inc
18、idents and improvements .1216.1.1 Responsibilities and procedures . 1216.1.2 Reporting information security events .1216.1.3 Reporting information security weaknesses 1316.1.4 Assessment of, and decision on, information security events .1316.1.5 Response to information security incidents .1316.1.6 L
19、earning from information security incidents 1316.1.7 Collection of evidence .1316.1.8 Early warning system .1317 Information security aspects of business continuity management .1317.1 Information security continuity 1317.1.1 Planning information security continuity .1317.1.2 Implementing information
20、 security continuity .1417.1.3 Verify, review and evaluate information security continuity .1417.2 Redundancies 1418 Compliance 1418.1 Compliance with legal and contractual requirements .1418.1.1 Identification of applicable legislation and contractual requirements 1418.1.2 Intellectual property rig
21、hts . 1418.1.3 Protection of records .1418.1.4 Privacy and protection of personally identifiable information 1418.1.5 Regulation of cryptographic controls .1418.1.6 Liability to the information sharing community .1418.2 Information security reviews 15Annex A (informative) Sharing sensitive informati
22、on 16iv ISO/IEC 2015 All rights reservedBS ISO/IEC 27010:2015ISO/IEC 27010:2015(E)Annex B (informative) Establishing trust in information exchanges 21Annex C (informative) The Traffic Light Protocol 25Annex D (informative) Models for organizing an information sharing community 26Bibliography .32 ISO
23、/IEC 2015 All rights reserved vBS ISO/IEC 27010:2015ISO/IEC 27010:2015(E)ForewordISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC
24、participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, govern
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSISOIEC270102015INFORMATIONTECHNOLOGYSECURITYTECHNIQUESINFORMATIONSECURITYMANAGEMENTFORINTERSECTORANDINTERORGANIZATIONALCOMMUNICATIONS

链接地址:http://www.mydoc123.com/p-588444.html