INTERNATIONAL ISO/IEC STANDARD 27003 Second edition 2017-03 Information technology Security techniques Information security management systems Guidance Technologies de I'information - Techniques de sécurité --Systemes de managementdela sécuritédeIinformation-Lignesdirectrices Referencenumber IEC IS0/IEC27003:2017(E) oS1 @IS0/IEC2017 IS0/IEC27003:2017(E) COPYRIGHTPROTECTEDDOCUMENT @ IS0/IEC 2017,Published in Switzerland All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized otherwise in any form writtenpermission.PermissioncanberequestedfromeitherIsoattheaddressbeloworIso'smemberbodyinthecountryof the requester. ISO copyright office Ch. de Blandonnet 8 . CP 401 CH-1214Vernier, Geneva, Switzerland Tel.+4122 7490111 Fax +41 22 749 09 47 copyright@iso.org www.iso.org ii @IS0/IEC 2017 - All rights reserved IS0/IEC27003:2017(E) Contents Page Foreword .iv Introduction. .. 1 Scope.. 2 Normative references 3 Terms and definitions ..1 4 Context of the organization ..1 4.1 Understanding the organization and its context 1 4.2 Understanding the needs and expectations of interested parties. .3 4.3 Determining the scope of the information security management system 4 4.4 Information securitymanagement system.. .6 5 Leadership .6 5.1 Leadership and commitment .6 5.2 Policy. .8 5.3 Organizational roles, responsibilities and authorities 9 6 Planning. .10 6.1 Actions to address risks and opportunities 6.1.1 General ..10 6.1.2 Information security risk assessment ..12 6.1.3 Information security risk treatment .15 6.2 Information security objectives and planning to achieve them .18 7 Support. .21 7.1 Resources. 21 7.2 Competence .22 7.3 Awareness. 23 7.4 Communication. 24 7.5 Documented information 25 7.5.1 General 25 7.5.2 Creating and updating .27 7.5.3 Control of documented information .28 8 Operation .29 8.1 Operational planning and control 29 8.2 Information security risk assessment 31 8.3 Information security risk treatment ..31 9 Performance evaluation .32 9.1 Monitoring, measurement, analysis and evaluation. .32 9.2 Internalaudit ..33 9.3 Managementreview .36 10 Improvement. .37 10.1 Nonconformity and corrective action 10.2 Continual improvement .40 Annex A (informative) Policy framework ..42 Bibliography ..45 @ IS0/IEC 2017 - All rights reserved ili

.pdf文档 ISO IEC 27003 2017 Information technology — Security techniques — Information security management systems — Guidance

文档预览
中文文档 52 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共52页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO IEC 27003 2017 Information technology — Security techniques — Information security management systems — Guidance 第 1 页 ISO IEC 27003 2017 Information technology — Security techniques — Information security management systems — Guidance 第 2 页 ISO IEC 27003 2017 Information technology — Security techniques — Information security management systems — Guidance 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2024-08-26 01:25:51上传分享
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。