EN ISO IEC 27002-2017 en Information technology - Security techniques - Code of practice for information security controls《信息技术-安全技术-信息安全控制规范(ISO IEC 27002 2013包括肺心病 肺2 2015 1 201.pdf
《EN ISO IEC 27002-2017 en Information technology - Security techniques - Code of practice for information security controls《信息技术-安全技术-信息安全控制规范(ISO IEC 27002 2013包括肺心病 肺2 2015 1 201.pdf》由会员分享,可在线阅读,更多相关《EN ISO IEC 27002-2017 en Information technology - Security techniques - Code of practice for information security controls《信息技术-安全技术-信息安全控制规范(ISO IEC 27002 2013包括肺心病 肺2 2015 1 201.pdf(94页珍藏版)》请在麦多课文档分享上搜索。
1、BS ISO/IEC 27002:2013Incorporating corrigendum September 2014BS ISO/IEC 27002:2013Incorporating corrigenda September 2014 and November 2015BS EN ISO/IEC 27002:2017Information technology Security techniques Code of practice for information security controls (ISO/IEC 27002:2013)BSI Standards Publicati
2、onWB11885_BSI_StandardCovs_2013_AW.indd 1 15/05/2013 15:06BS EN ISO/IEC 27002:2017 BRITISH STANDARDNational forewordThis British Standard is the UK implementation of EN ISO/IEC 27002:2017. It is identical to ISO/IEC 27002:2013, incorporating corrigenda September 2014 and November 2015. It supersedes
3、 BS ISO/IEC 27002:2013 which is withdrawn.The start and finish of text introduced or altered by corrigendum is indicated in the text by tags. Text altered by ISO/IEC corrigendum September 2014 is indicated in the text by .The UK participation in its preparation was entrusted by Technical Committee I
4、ST/33, IT - Security techniques, to Subcommittee IST/33/-/1, Requirements, security services and guidelines.A list of organizations represented on this subcommittee can be obtained on request to its secretary.This publication does not purport to include all the necessary provisions of a contract. Us
5、ers are responsible for its correct application. The British Standards Institution 2017. Published by BSI Standards Limited 2017ISBN 978 0 580 95520 4ICS 35.030Compliance with a British Standard cannot confer immunity from legal obligations.This British Standard was published under the authority of
6、the Standards Policy and Strategy Committee on 1 October 2013.Amendments/corrigenda issued since publicationDate Text affected31 October 2014 Implementation of ISO/IEC corrigendum September 201430 November 2015 Implementation of ISO/IEC corrigendum November 2015: Subclause 14.2.8 modified31 March 20
7、17 This corrigendum renumbers BS ISO/IEC 27002:2013 as BS EN ISO/EC 27002:2017.EUROPEAN STANDARD NORME EUROPENNE EUROPISCHE NORM EN ISO/IEC 27002 February 2017 ICS 03.100.70; 35.030 English Version Information technology - Security techniques - Code of practice for information security controls (ISO
8、/IEC 27002:2013 including Cor 1:2014 and Cor 2:2015) Technologies de linformation - Techniques de scurit - Code de bonne pratique pour le management de la scurit de linformation (ISO/IEC 27002:2013 y compris Cor 1:2014 et Cor 2:2015) Informationstechnik - Sicherheitsverfahren - Leitfaden fr Informat
9、ionssicherheitsmanahmen (ISO/IEC 27002:2013 einschlielich Cor 1:2014 und Cor 2:2015) This European Standard was approved by CEN on 26 January 2017. CEN and CENELEC members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard t
10、he status of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such national standards may be obtained on application to the CEN-CENELEC Management Centre or to any CEN and CENELEC member. This European Standard exists in three official versions (
11、English, French, German). A version in any other language made by translation under the responsibility of a CEN and CENELEC member into its own language and notified to the CEN-CENELEC Management Centre has the same status as the official versions. CEN and CENELEC members are the national standards
12、bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Serbia, Slovakia,
13、Slovenia, Spain, Sweden, Switzerland, Turkey and United Kingdom. EUROPEAN COMMITTEE FOR STANDARDIZATION COMIT EUROPEN DE NORMALISATION EUROPISCHES KOMITEE FR NORMUNG CEN-CENELEC Management Centre: Avenue Marnix 17, B-1000 Brussels 2017 CEN and CENELEC All rights of exploitation in any form and by an
14、y means reserved worldwide for CEN and CENELEC national Members. Ref. No. EN ISO/IEC 27002:2017 E ISO/IEC 27002:2013(E) ISO/IEC 2013 All rights reserved iiiContents PageForeword v0 Introduction .vi1 Scope . 12 Normative references 13 Terms and definitions . 14 Structure of this standard . 14.1 Claus
15、es . 14.2 Control categories 15 Information security policies 25.1 Management direction for information security . 26 Organization of information security . 46.1 Internal organization . 46.2 Mobile devices and teleworking 67 Human resource security 97.1 Prior to employment 97.2 During employment . 1
16、07.3 Termination and change of employment 138 Asset management 138.1 Responsibility for assets 138.2 Information classification .158.3 Media handling 179 Access control .199.1 Business requirements of access control 199.2 User access management 219.3 User responsibilities . 249.4 System and applicat
17、ion access control 2510 Cryptography .2810.1 Cryptographic controls . 2811 Physical and environmental security .3011.1 Secure areas 3011.2 Equipment 3312 Operations security 3812.1 Operational procedures and responsibilities 3812.2 Protection from malware 4112.3 Backup . 4212.4 Logging and monitorin
18、g . 4312.5 Control of operational software 4512.6 Technical vulnerability management .4612.7 Information systems audit considerations 4813 Communications security 4913.1 Network security management . 4913.2 Information transfer .5014 System acquisition, development and maintenance 5414.1 Security re
19、quirements of information systems .5414.2 Security in development and support processes .5714.3 Test data .6215 Supplier relationships .6215.1 Information security in supplier relationships 62BS ISO/IEC 27002:2013BS EN ISO/IEC 27002:2017EN ISO/IEC 27002:2017 (E)EN ISO/IEC 27002:2017 (E) 3 European f
20、oreword The text of ISO/IEC 27002:2013 including Cor 1:2014 and Cor 2:2015 has been prepared by Technical Committee ISO/IEC JTC 1 “Information technology” of the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) and has been taken over as EN
21、 ISO/IEC 27002:2017. This European Standard shall be given the status of a national standard, either by publication of an identical text or by endorsement, at the latest by August 2017, and conflicting national standards shall be withdrawn at the latest by August 2017. Attention is drawn to the poss
22、ibility that some of the elements of this document may be the subject of patent rights. CEN and/or CENELEC shall not be held responsible for identifying any or all such patent rights. According to the CEN-CENELEC Internal Regulations, the national standards organizations of the following countries a
23、re bound to implement this European Standard: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, P
24、ortugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and the United Kingdom. Endorsement notice The text of ISO/IEC 27002:2013 including Cor 1:2014 and Cor 2:2015 has been approved by CEN as EN ISO/IEC 27002:2017 without any modification. ISO/IEC 27002:2013(E) ISO/IEC 201
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ENISOIEC270022017ENINFORMATIONTECHNOLOGYSECURITYTECHNIQUESCODEOFPRACTICEFORINFORMATIONSECURITYCONTROLS

链接地址:http://www.mydoc123.com/p-727098.html