INTERNATIONAL STANDARD ISO/IEC 27002 Third edition 2022-02 Information security, cybersecurity and privacy protection — Information security controls m o c . 5 Sécurité de l'information, cybersécurité et protection de la vie privée — Mesures de sécurité de l'information h t i g b u Reference number ISO/IEC 27002:2022(E) © ISO/IEC 2022 ISO/IEC 27002:2022(E) m o c . 5 --`,,,,`,,,`,``,`,`,`,,,`,,,,-`-`,,`,,`,`,,`--- b u h t i g COPYRIGHT PROTECTED DOCUMENT © ISO/IEC 2022 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or ISO’s member body in the country of the requester. ISO copyright office CP 401 • Ch. de Blandonnet 8 CH-1214 Vernier, Geneva Phone: +41 22 749 01 11 Email: [email protected] Website: www.iso.org Published in Switzerland ii   © ISO/IEC 2022 – All rights reserved ISO/IEC 27002:2022(E) Contents Page Foreword........................................................................................................................................................................................................................................ vi Introduction..............................................................................................................................................................................................................................vii 1 Scope.................................................................................................................................................................................................................................. 1 3 4 5 Normative references...................................................................................................................................................................................... 1 Terms, definitions and abbreviated terms............................................................................................................................... 1 3.1 Terms and definitions....................................................................................................................................................................... 1 3.2 Abbreviated terms............................................................................................................................................................................... 6 Structure of this document........................................................................................................................................................................ 7 4.1 Clauses............................................................................................................................................................................................................ 7 4.2 Themes and attributes..................................................................................................................................................................... 8 4.3 Control layout........................................................................................................................................................................................... 9 --`,,,,`,,,`,``,`,`,`,,,`,,,,-`-`,,`,,`,`,,`--- 2 m o c . 5 Organizational controls................................................................................................................................................................................ 9 5.1 Policies for information security............................................................................................................................................. 9 5.2 Information security roles and responsibilities..................................................................................................... 11 5.3 Segregation of duties...................................................................................................................................................................... 12 5.4 Management responsibilities.................................................................................................................................................. 13 5.5

pdf文档 ISO IEC 27002-2022(英文版)

文档预览
中文文档 164 页 50 下载 1000 浏览 0 评论 0 收藏 3.0分
温馨提示:本文档共164页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO IEC 27002-2022(英文版) 第 1 页 ISO IEC 27002-2022(英文版) 第 2 页 ISO IEC 27002-2022(英文版) 第 3 页
下载文档到电脑,方便使用
本文档由 路人甲 于 2022-06-17 06:09:21上传分享
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。