DIN ISO IEC 27000-2011 Information technology - Security techniques - Information security management systems - Overview and vocabulary (ISO IEC 27000 2009)《信息技术 安全技术 信息安全管理系统 总论和词.pdf
《DIN ISO IEC 27000-2011 Information technology - Security techniques - Information security management systems - Overview and vocabulary (ISO IEC 27000 2009)《信息技术 安全技术 信息安全管理系统 总论和词.pdf》由会员分享,可在线阅读,更多相关《DIN ISO IEC 27000-2011 Information technology - Security techniques - Information security management systems - Overview and vocabulary (ISO IEC 27000 2009)《信息技术 安全技术 信息安全管理系统 总论和词.pdf(24页珍藏版)》请在麦多课文档分享上搜索。
1、July 2011 Translation by DIN-Sprachendienst.English price group 13No part of this translation may be reproduced without prior permission ofDIN Deutsches Institut fr Normung e. V., Berlin. Beuth Verlag GmbH, 10772 Berlin, Germany,has the exclusive right of sale for German Standards (DIN-Normen).ICS 0
2、1.040.35; 35.040!$sA|“1803089www.din.deDDIN ISO/IEC 27000Information technology Security techniques Information security management systems Overview and vocabulary (ISO/IEC 27000:2009)English translation of DIN ISO/IEC 27000:2011-07Informationstechnik IT-Sicherheitsverfahren Informationssicherheits-
3、Managementsysteme berblick und Terminologie(ISO/IEC 27000:2009)Englische bersetzung von DIN ISO/IEC 27000:2011-07Technologies de linformation Techniques de scurit Systmes de gestion de la scurit des informations Vue densemble et vocabulaire (ISO/CEI 27000:2009)Traduction anglaise de DIN ISO/IEC 2700
4、0:2011-07www.beuth.deDocument comprises pagesIn case of doubt, the German-language original shall be considered authoritative.2406.11 Contents Page National foreword .3 National Annex NA (informative) Bibliography.3 0 Introduction4 0.1 Overview.4 0.2 ISMS family of standards 4 0.3 Purpose of this In
5、ternational Standard .5 1 Scope 6 2 Terms and definitions6 3 Information security management systems11 3.1 Introduction11 3.2 What is an ISMS?.12 3.3 Process approach13 3.4 Why an ISMS is important.14 3.5 Establishing, monitoring, maintaining and improving an ISMS .15 3.6 ISMS critical success facto
6、rs .16 3.7 Benefits of the ISMS family of standards 16 4 ISMS family of standards 17 4.1 General information.17 4.2 Standards describing an overview and terminology .18 4.3 Standards specifying requirements.18 4.4 Standards describing general guidelines19 4.5 Standards describing sector-specific gui
7、delines.20 Annex A (informative) Verbal forms for the expression of provisions.21 Annex B (informative) Categorized terms.22 Bibliography 24 2 DIN ISO/IEC 27000:2011-07 National foreword This standard has been prepared by Joint Technical Committee ISO/IEC JTC 1 “Information technology”, Subcommittee
8、 SC 27 “IT Security techniques”. The responsible German body involved in its preparation was the Normenausschuss Informationstechnik und Anwendungen (Information Technology and selected IT Applications Standards Committee), Working Committee NA 043-01-27 AA IT-Sicherheitsverfahren. Attention is draw
9、n to the possibility that some of the elements of this document may be the subject of patent rights. DIN shall not be held responsible for identifying any or all such patent rights. ISO 9000 DIN EN ISO 9000 ISO/IEC 17021 DIN ISO/IEC 17021 ISO 19011 DIN EN ISO 19011 ISO/IEC 27001 DIN ISO/IEC 27001 IS
10、O/IEC 27002 DIN ISO/IEC 27002 ISO 27799 DIN EN ISO 27799 National Annex NA (informative) Bibliography DIN EN ISO 9000, Quality management systems Fundamentals and vocabulary DIN EN ISO/IEC 17021, Conformity assessment Requirements for bodies providing audit and certification of management systems DI
11、N EN ISO 19011 Guidelines for quality and/or environmental management systems auditing DIN ISO/IEC 27001, Information technology Security techniques Information security management systems Requirements DIN ISO/IEC 27002, Information technology Security techniques Code of practice for information sec
12、urity management DIN EN ISO 27799, Health informatics Information security management in health using ISO/IEC 27002 3 DIN ISO/IEC 27000:2011-07 The DIN Standards corresponding to the International Standards referred to in this document are as follows: 0 Introduction 0.1 Overview International Standa
13、rds for management systems provide a model to follow in setting up and operating a management system. This model incorporates the features on which experts in the field have reached a consensus as being the international state of the art. ISO/IEC JTC 1 SC 27 maintains an expert committee dedicated t
14、o the development of international management systems standards for information security, otherwise known as the Information Security Management System (ISMS) family of standards. Through the use of the ISMS family of standards, organizations can develop and implement a framework for managing the se
15、curity of their information assets and prepare for an independent assessment of their ISMS applied to the protection of information, such as financial information, intellectual property, and employee details, or information entrusted to them by customers or third parties. 0.2 ISMS family of standard
16、s The ISMS family of standards1)is intended to assist organizations of all types and sizes to implement and operate an ISMS. The ISMS family of standards consists of the following International Standards, under the general title Information technology Security techniques: ISO/IEC 27000:2009, Informa
17、tion security management systems Overview and vocabulary ISO/IEC 27001:2005, Information security management systems Requirements ISO/IEC 27002:2005, Code of practice for information security management ISO/IEC 27003, Information security management system implementation guidance ISO/IEC 27004, Info
18、rmation security management Measurement ISO/IEC 27005:2008, Information security risk management ISO/IEC 27006:2007, Requirements for bodies providing audit and certification of information security management systems ISO/IEC 27007, Guidelines for information security management systems auditing ISO
19、/IEC 27011, Information security management guidelines for telecommunications organizations based on ISO/IEC 27002 NOTE The general title “Information technology Security techniques” indicates that these standards were prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subc
20、ommittee SC 27, IT Security techniques. 1) Standards identified throughout this subclause with no release year indicated are still under development. Information technology Security techniques Information security management systems Overview and vocabulary 4 DIN ISO/IEC 27000:2011-07 0.3 Purpose of
21、this International Standard This International Standard provides an overview of information security management systems, which form the subject of the ISMS family of standards, and defines related terms. NOTE Annex A provides clarification on how verbal forms are used to express requirements and/or
22、guidance in the ISMS family of standards. The ISMS family of standards includes standards that: a) define requirements for an ISMS and for those certifying such systems; b) provide direct support, detailed guidance and/or interpretation for the overall Plan-Do-Check-Act (PDCA) processes and requirem
23、ents; c) address sector-specific guidelines for ISMS; and d) address conformity assessment for ISMS. The terms and definitions provided in this International Standard: cover commonly used terms and definitions in the ISMS family of standards; will not cover all terms and definitions applied within t
24、he ISMS family of standards; and do not limit the ISMS family of standards in defining terms for own use. Standards addressing only the implementation of controls, as opposed to addressing all controls, from ISO/IEC 27002 are excluded from the ISMS family of standards. To reflect the changing status
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- DINISOIEC270002011INFORMATIONTECHNOLOGYSECURITYTECHNIQUESINFORMATIONSECURITYMANAGEMENTSYSTEMSOVERVIEWANDVOCABULARYISOIEC270002009

链接地址:http://www.mydoc123.com/p-685228.html