EN ISO IEC 27001-2017 en Information technology - Security techniques - Information security management systems - Requirements《信息技术-安全技术-信息安全管理体系要求(ISO IEC 27001 2013包括肺心病 肺2 2015 .pdf
《EN ISO IEC 27001-2017 en Information technology - Security techniques - Information security management systems - Requirements《信息技术-安全技术-信息安全管理体系要求(ISO IEC 27001 2013包括肺心病 肺2 2015 .pdf》由会员分享,可在线阅读,更多相关《EN ISO IEC 27001-2017 en Information technology - Security techniques - Information security management systems - Requirements《信息技术-安全技术-信息安全管理体系要求(ISO IEC 27001 2013包括肺心病 肺2 2015 .pdf(34页珍藏版)》请在麦多课文档分享上搜索。
1、BS ISO/IEC 27001:2013Incorporating corrigenda September 2014 and December 2015Incorporating corrigendum September 2014BS ISO/IEC 27001:2013BS EN ISO/IEC 27001:2017Information technology Security techniques Information security management systems Requirements (ISO/IEC 27001:2013) BSI Standards Public
2、ationWB11885_BSI_StandardCovs_2013_AW.indd 1 15/05/2013 15:06BS EN ISO/IEC 27001:2017 BRITISH STANDARDNational forewordThis British Standard is the UK implementation of EN ISO/IEC 27001:2017. It is identical to ISO/IEC 27001:2013, incorporating corrigenda September 2014 and December 2015. It superse
3、des BS ISO/IEC 27001:2013 which is withdrawn.The UK participation in its preparation was entrusted by Technical Committee IST/33, IT - Security techniques, to Subcommittee IST/33/-/1, Requirements, security services and guidelines.A list of organizations represented on this subcommittee can be obtai
4、ned on request to its secretary.This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application. The British Standards Institution 2017. Published by BSI Standards Limited 2017ISBN 978 0 580 95518 1ICS 03.100.70; 35.030Compli
5、ance with a British Standard cannot confer immunity from legal obligations.This British Standard was published under the authority of the Standards Policy and Strategy Committee on 1 October 2013.Amendments/corrigenda issued since publicationDate Text affected31 October 2014 Implementation of ISO/IE
6、C corrigendum September 2014: third column of A.8.1.1 in Table A.1 amended31 January 2016 Implementation of ISO/IEC corrigendum December 2015: Subclause 6.1.3 corrected31 March 2017 This corrigendum renumbers BS ISO/IEC 27001:2013 as BS EN ISO/IEC 27001:2017.EUROPEAN STANDARD NORME EUROPENNE EUROPIS
7、CHE NORM EN ISO/IEC 27001 February 2017 ICS 03.100.70; 35.030 English Version Information technology - Security techniques - Information security management systems - Requirements (ISO/IEC 27001:2013 including Cor 1:2014 and Cor 2:2015) Technologies de linformation - Techniques de scurit - Systmes d
8、e management de la scurit de linformation - Exigences (ISO/IEC 27001:2013 y compris Cor 1:2014 et Cor 2:2015) Informationstechnik - Sicherheitsverfahren - Informationssicherheits-Managementsysteme - Anforderungen (ISO/IEC 27001:2013 einschlielich Cor 1:2014 und Cor 2:2015) This European Standard was
9、 approved by CEN on 26 January 2017. CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical references concer
10、ning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to any CEN and CENELEC member. This European Standard exists in three official versions (English, French, German). A version in any other language made by translation under the responsibility of a CEN
11、 and CENELEC member into its own language and notified to the CEN-CENELEC Management Centre has the same status as the official versions. CEN and CENELEC members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugosl
12、av Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and United Kingdom. EUROPEAN COMMITTEE FOR STANDARDIZATION COMIT E
13、UROPEN DE NORMALISATION EUROPISCHES KOMITEE FR NORMUNG CEN-CENELEC Management Centre: Avenue Marnix 17, B-1000 Brussels 2017 CEN and CENELEC All rights of exploitation in any form and by any means reserved worldwide for CEN and CENELEC national Members. Ref. No. EN ISO/IEC 27001:2017 E ISO/IEC 27001
14、:2013(E) ISO/IEC 2013 All rights reserved iiiContents PageForeword iv0 Introduction .v1 Scope . 12 Normative references 13 Terms and definitions . 14 Context of the organization . 14.1 Understanding the organization and its context . 14.2 Understanding the needs and expectations of interested partie
15、s 14.3 Determining the scope of the information security management system 14.4 Information security management system . 25 Leadership 25.1 Leadership and commitment . 25.2 Policy . 25.3 Organizational roles, responsibilities and authorities 36 Planning . 36.1 Actions to address risks and opportunit
16、ies . 36.2 Information security objectives and planning to achieve them . 57 Support . 57.1 Resources . 57.2 Competence . 57.3 Awareness . 57.4 Communication 67.5 Documented information . 68 Operation . 78.1 Operational planning and control 78.2 Information security risk assessment. 78.3 Information
17、 security risk treatment 79 Performance evaluation . 79.1 Monitoring, measurement, analysis and evaluation . 79.2 Internal audit 89.3 Management review . 810 Improvement 910.1 Nonconformity and corrective action . 910.2 Continual improvement 9Annex A (normative) Reference control objectives and cont
18、rols 10Bibliography .23BS ISO/IEC 27001:2013EN ISO/IEC 27001:2017 (E) 3 European foreword The text of ISO/IEC 27001:2013 including Cor 1:2014 and Cor 2:2015 has been prepared by Technical Committee ISO/IEC JTC 1 “Information technology” of the International Organization for Standardization (ISO) and
19、 the International Electrotechnical Commission (IEC) and has been taken over as EN ISO/IEC 27001:2017. This European Standard shall be given the status of a national standard, either by publication of an identical text or by endorsement, at the latest by August 2017, and conflicting national standar
20、ds shall be withdrawn at the latest by August 2017. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. CEN and/or CENELEC shall not be held responsible for identifying any or all such patent rights. According to the CEN-CENELEC Inter
21、nal Regulations, the national standards organizations of the following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ir
22、eland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and the United Kingdom. Endorsement notice The text of ISO/IEC 27001:2013 including Cor 1:2014 and Cor 2:2015 has been approved by CEN as
23、 EN ISO/IEC 27001:2017 without any modification. BS EN ISO/IEC 27001:2017EN ISO/IEC 27001:2017 (E)ISO/IEC 27001:2013(E) ISO/IEC 2013 All rights reserved iiiContents PageForeword iv0 Introduction .v1 Scope . 12 Normative references 13 Terms and definitions . 14 Context of the organization . 14.1 Unde
24、rstanding the organization and its context . 14.2 Understanding the needs and expectations of interested parties 14.3 Determining the scope of the information security management system 14.4 Information security management system . 25 Leadership 25.1 Leadership and commitment . 25.2 Policy . 25.3 Or
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ENISOIEC270012017ENINFORMATIONTECHNOLOGYSECURITYTECHNIQUESINFORMATIONSECURITYMANAGEMENTSYSTEMSREQUIREMENTS

链接地址:http://www.mydoc123.com/p-727097.html