没有合适的资源?快使用搜索试试~ 我知道了~
首页ISO_IEC_27000_2016 英文版
ISO_IEC_27000_2016 英文版
需积分: 9 54 浏览量
更新于2023-03-16
评论 2
收藏 951KB PDF 举报
ISO/IEC 27000 2016版 第四次 Information technology — Security techniques — Information security management systems — Overview and vocabulary
资源详情
资源评论
资源推荐

Information technology — Security
techniques — Information security
management systems — Overview
and vocabulary
Technologies de l’information — Techniques de sécurité — Systèmes de
gestion de sécurité de l’information — Vue d’ensemble et vocabulaire
INTERNATIONAL
STANDARD
ISO/IEC
27000
Reference number
ISO/IEC 27000:2016(E)
Fourth edition
2016-02-15
©
ISO/IEC 2016

ii © ISO/IEC 2016 – All rights reserved
COPYRIGHT PROTECTED DOCUMENT
© ISO/IEC 2016, Published in Switzerland
the requester.
Ch. de Blandonnet 8 • CP 401
CH-1214 Vernier, Geneva, Switzerland
Tel. +41 22 749 01 11
Fax +41 22 749 09 47
www.iso.org
ISO/IEC 27000:2016(E)

ISO/IEC 27000:2016(E)
Foreword ..........................................................................................................................................................................................................................................v
0 Introduction
.............................................................................................................................................................................................................. 1
0.1 Overview
...................................................................................................................................................................................................... 1
................................................................................................................................................................ 1
0.3 Purpose of this International Standard
............................................................................................................................. 2
1 Scope
................................................................................................................................................................................................................................. 2
2 Termsanddefinitions
..................................................................................................................................................................................... 2
3 Information security management systems
.........................................................................................................................14
3.1 General
........................................................................................................................................................................................................ 14
3.2 What is an ISMS? ................................................................................................................................................................................ 14
3.2.1 Overview and principles
........................................................................................................................................ 14
3.2.2 Information
........................................................................................................................................................................ 15
.................................................................................................................................................. 15
3.2.4 Management
..................................................................................................................................................................... 15
.................................................................................................................................................. 16
3.3 Process approach
............................................................................................................................................................................... 16
.......................................................................................................................................................... 16
3.5 Establishing, monitoring, maintaining and improving an ISMS ................................................................ 17
3.5.1 Overview ..............................................................................................................................................................................17
.................................................................................17
.......................................................................................................... 18
.............................................................................................................. 18
3.5.5 Selecting and implementing controls .........................................................................................................18
3.5.6 Monitor, maintain and improve the effectiveness of the ISMS .............................................. 19
3.5.7 Continual improvement ..........................................................................................................................................19
3.6 ISMS critical success factors ..................................................................................................................................................... 20
....................................................................................................................... 20
4 ISMS family of standards
...........................................................................................................................................................................21
4.1 General information ........................................................................................................................................................................ 21
..........................................................................................22
4.2.1 ISO/IEC 27000 (this International Standard) ..................................................................................... 22
................................................................................................................................... 22
4.3.1 ISO/IEC 27001 ................................................................................................................................................................ 22
4.3.2 ISO/IEC 27006 ................................................................................................................................................................ 22
4.4 Standards describing general guidelines ...................................................................................................................... 22
4.4.1 ISO/IEC 27002 ................................................................................................................................................................ 22
4.4.2 ISO/IEC 27003 ................................................................................................................................................................ 23
4.4.3 ISO/IEC 27004 ................................................................................................................................................................ 23
4.4.4 ISO/IEC 27005 ................................................................................................................................................................ 23
4.4.5 ISO/IEC 27007 ................................................................................................................................................................ 23
4.4.6 ISO/IEC TR 27008 ....................................................................................................................................................... 23
4.4.7 ISO/IEC 27013 ................................................................................................................................................................ 24
4.4.8 ISO/IEC 27014 ................................................................................................................................................................ 24
4.4.9 ISO/IEC TR 27016
....................................................................................................................................................... 24
.................................................................................................... 25
4.5.1 ISO/IEC 27010 ................................................................................................................................................................ 25
4.5.2 ISO/IEC 27011 ................................................................................................................................................................ 25
4.5.3 ISO/IEC TR 27015 ....................................................................................................................................................... 25
4.5.4 ISO/IEC 27017
................................................................................................................................................................ 25
4.5.5 ISO/IEC 27018
................................................................................................................................................................ 26
4.5.6 ISO/IEC TR 27019 ....................................................................................................................................................... 26
4.5.7 ISO 27799 ............................................................................................................................................................................ 26
© ISO/IEC 2016 – All rights reserved iii
Contents Page

ISO/IEC 27000:2016(E)
Annex A (informative) Verbal forms for the expression of provisions...........................................................................28
Annex B (informative) Term and term ownership
..............................................................................................................................29
Bibliography
.............................................................................................................................................................................................................................33
iv
© ISO/IEC 2016 – All rights reserved

ISO/IEC 27000:2016(E)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
members of ISO or IEC participate in the development of International Standards through technical
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for
editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).
Introduction and/or on the ISO list of patent declarations received (see www.iso.org/patents).
constitute an endorsement.
assessment, as well as information about ISO’s adherence to the WTO principles in the Technical
Barriers to Trade (TBT) see the following URL:
The committee responsible for this document is ISO/IEC JTC 1, Information technology, SC 27, IT
Security techniques.
This fourth edition cancels and replaces the third edition (ISO/IEC 27000:2014), which has been
© ISO/IEC 2016 – All rights reserved v
剩余41页未读,继续阅读











安全验证
文档复制为VIP权益,开通VIP直接复制

评论0