ISO/IEC 27001 Ersetzt / Remplace / Replaces: Ausgabe / Edition: SN ISO/IEC 2700
ISO/IEC 27001 Ersetzt / Remplace / Replaces: Ausgabe / Edition: SN ISO/IEC 27001:2005 2013-11 ICS Code: 35.040 Information technology - Security techniques - Information security management systems - Requirements In der vorliegenden Schweizer Norm ist die ISO/IEC 27001:2013 identisch abgedruckt. Dans la présente Norme Suisse le ISO/IEC 27001:2013 est reproduit identiquement. In this Swiss standard ISO/IEC 27001:2013 is reprinted identically. Für diese Norm ist das Normen-Komitee INB/NK 149 << Informationstechnologie >> des interdisziplinären Normenbereichs zuständig. La présente norme est de la compétence du comité de normalisation INB/NK 149 << Technologie de l'information >> du secteur interdisciplinaire de normalisation. The standardization committee INB/NK 149 << Information technology >> of the interdisciplinary sector is in charge of the present standard. 0012 SNV Ref Nr. / No. de réf / No ref.: Herausgeber / Editeur / Editor Vertrieb / Distribution © SNV Anzahl Seiten / Nombre de pages / Number of pages: SNV Schweizerische Normen-Vereinigung Bürglistrasse 29 CH-8400 Winterthur SNV Schweizerische Normen-Vereinigung Bürglistrasse 29 CH-8400 Winterthur SN ISO/IEC 27001:2013 en Preisklasse / Classe de prix / Price class: Gültig ab / Valide de / Valid from: 2013-11-01 23 – Leerseite / Page blanche – Information technology — Security techniques — Information security management systems — Requirements Technologies de l’information — Techniques de sécurité — Systèmes de management de la sécurité de l’information — Exigences © ISO/IEC 2013 INTERNATIONAL STANDARD ISO/IEC 27001 Second edition 2013-10-01 Reference number ISO/IEC 27001:2013(E) ISO/IEC 27001:2013(E) ii © ISO/IEC 2013 – All rights reserved COPYRIGHT PROTECTED DOCUMENT © ISO/IEC 2013 Ǥ ϐǡ ǡ ǡ ǡǡ Ǥ ǯ Ǥ ϐ ͷȈ Ǧͳʹͳͳ ʹͲ Tel. + 41 22 749 01 11 ΪͶͳʹʹͶͻͲͻͶ Ǧ ̷Ǥ Web www.iso.org ISO/IEC 27001:2013(E) © ISO/IEC 2013 – All rights reserved iii Contents Foreword ........................................................................................................................................................................................................................................iv 0 Introduction ...............................................................................................................................................................................................................v 1 Scope .................................................................................................................................................................................................................................1 2 Normative references ......................................................................................................................................................................................1 ͵ ϐ .....................................................................................................................................................................................1 4 Context of the organization .......................................................................................................................................................................1 ͶǤͳ .......................................................................................................1 ͶǤʹ ..............................................................1 ͶǤ͵ ..........................................1 ͶǤͶ ..................................................................................................................... 2 5 Leadership ..................................................................................................................................................................................................................2 ͷǤͳ ..................................................................................................................................................... 2 ͷǤʹ ............................................................................................................................................................................................................... 2 ͷǤ͵ ǡ.......................................................................................... 3 6 Planning .........................................................................................................................................................................................................................3 Ǥͳ ................................................................................................................... 3 Ǥʹ ...................................................................ͷ 7 Support ...........................................................................................................................................................................................................................5 7.1 Resources ..................................................................................................................................................................................................... ͷ 7.2 Competence ............................................................................................................................................................................................... ͷ Ǥ͵ ................................................................................................................................................................................................... ͷ ǤͶ ...................................................................................................................................................................................... Ǥͷ ............................................................................................................................................................... 8 Operation .....................................................................................................................................................................................................................7 ͺǤͳ .......................................................................................................................................... 7 ͺǤʹ ................................................................................................................................. 7 ͺǤ͵ .................................................................................................................................... 7 9 Performance evaluation ...............................................................................................................................................................................7 ͻǤͳ ǡǡ ............................................................................................... 7 ͻǤʹ ............................................................................................................................................................................................ 8 ͻǤ͵ ........................................................................................................................................................................... 8 10 Improvement ............................................................................................................................................................................................................9 ͳͲǤͳ ................................................................................................................................. 9 ͳͲǤʹ .................................................................................................................................................................. 9 Annex A ȋȌ Reference control objectives and controls ........................................................................................10 Bibliography .............................................................................................................................................................................................................................23 ISO/IEC 27001:2013(E) Foreword ȋ Ȍ ȋ Ȍ Ǥ ϐ Ǥ ϐǤ ǡǦǡ ǡ Ǥ ϐ ǡ ǡ ISO/IEC JTC 1. Ȁ ǡʹǤ Ǥ Ǥ ͷ Ψ Ǥ Ǥ Ǥ Ȁ ʹͲͲͳ Ȁ ͳǡ Information technologyǡ ʹǡIT Security techniques. ϐ ȋ Ȁ ʹͲͲͳǣʹͲͲͷȌǡ Ǥ iv © ISO/IEC 2013 – All rights reserved ISO/IEC 27001:2013(E) 0 Introduction 0.1 General ǡǡ Ǥ Ǥ ǯ ϐ ǯ ǡ ǡ Ǥϐ Ǥ ϐǡ ϐ Ǥ ǯ ǡǡ Ǥ Ǥ ǯ ǯ Ǥ ϐ Ǥ Ǥ Ȁ ʹͲͲͲ ǡ ȋ ISO/IEC 27003[2]ǡ Ȁ ʹͲͲͶ[3] Ȁ ʹͲͲͷ[4]ȌǡϐǤ 0.2 Compatibility with other management system standards Ǧ ǡ Ǧ ǡ ǡ ǡ ϐϐ Ȁ ǡͳǡ ǡ Ǥ ϐ Ǥ © ISO/IEC 2013 – All rights reserved v Information technology — Security techniques — Information security management systems — Requirements 1 Scope ϐ ǡ ǡ Ǥ Ǥ ǡ ǡǤ ϐͶ to 10 Ǥ 2 Normative references ǡǡ Ǥ ǡ Ǥ ǡ ȋ ȌǤ Ȁ ʹͲͲͲǡ Information technology — Security techniques — Information security management systems — Overview and vocabulary ͵ ϐ ǡϐ Ȁ ʹͲͲͲǤ 4 Context of the organization 4.1 Understanding the organization and its context ȋȌ Ǥ ͷǤ͵ ͵ͳͲͲͲǣʹͲͲͻ[ͷ]. 4.2 Understanding the needs and expectations of interested parties ǣ Ȍ Ǣ Ȍ Ǥ Ǥ 4.3 Determining the scope of the information security management system Ǥ INTERNATIONAL STANDARD ISO/IEC 27001:2013(E) © ISO/IEC 2013 – All rights reserved 1 ISO/IEC 27001:2013(E) ǡ ǣ Ȍ 4.1Ǣ Ȍ 4.2Ǣ Ȍ ǡ Ǥ Ǥ 4.4 Information security management system ǡǡ ǡ Ǥ 5 Leadership 5.1 Leadership and commitment ǣ Ȍ Ǣ Ȍ ǯ Ǣ Ȍ Ǣ Ȍ Ǣ Ȍ ȋȌǢ Ȍ Ǣ Ȍ Ǣ Ȍ Ǥ 5.2 Policy ǣ Ȍ Ǣ Ȍ ȋǤʹȌ Ǣ Ȍ Ǣ Ȍ Ǥ ǣ Ȍ Ǣ 2 © ISO/IEC 2013 – All rights reserved ISO/IEC 27001:2013(E) Ȍ Ǣ Ȍ ǡǤ 5.3 Organizational roles, responsibilities and authorities Ǥ ǣ Ȍ Ǣ Ȍ Ǥ Ǥ 6 Planning 6.1 Actions to address risks and opportunities 6.1.1 General ǡ issues referred to in 4.14.2 ǣ Ȍ ȋȌǢ Ȍ ǡ ǡ Ǣ Ȍ Ǥ ǣ Ȍ Ǣ e) how to ͳȌ Ǣ ʹȌ Ǥ 6.1.2 Information security risk assessment ϐ ǣ Ȍ ǣ ͳȌ Ǣ ʹȌ Ǣ Ȍ ǡ Ǣ © ISO/IEC 2013 – All rights reserved 3 ISO/IEC 27001:2013(E) Ȍ ϐ ǣ ͳȌ ϐǡ Ǣ ʹȌ Ǣ Ȍ ǣ ͳȌ ϐǤͳǤʹ c) 1) were Ǣ ʹȌ ϐǤͳǤʹ ȌͳȌǢ ͵Ȍ Ǣ Ȍ ǣ ͳȌ ǤͳǤʹȌǢ ʹȌ Ǥ Ǥ 6.1.3 Information security risk treatment ϐ ǣ Ȍ ǡ Ǣ Ȍ ȋȌ Ǣ ǡ Ǥ Ȍ ǤͳǤ͵Ȍ Ǣ NOTE 1 Ǥ Ǥ ʹ Ǥ controls listed in Ǥ Ȍ ȋǤͳǤ͵Ȍ ȌȌ ϐ ǡǡϐ of controls from Ǣ Ȍ Ǣ Ȍ ǯ Ǥ process. ͵ͳͲͲͲ[ͷ]. 4 © ISO/IEC 2013 – All rights reserved ISO/IEC 27001:2013(E) 6.2 Information security objectives and planning to achieve them Ǥ ǣ Ȍ Ǣ Ȍ ȋ ȌǢ Ȍ ǡ Ǣ Ȍ Ǣ Ȍ Ǥ Ǥ ǡǣ Ȍ Ǣ Ȍ Ǣ Ȍ Ǣ Ȍ Ǣ Ȍ Ǥ 7 Support 7.1 Resources ǡǡ Ǥ 7.2 uploads/Management/ 1-norma-iso27001-2013.pdf
Documents similaires










-
28
-
0
-
0
Licence et utilisation
Gratuit pour un usage personnel Attribution requise- Détails
- Publié le Sep 21, 2021
- Catégorie Management
- Langue French
- Taille du fichier 0.4146MB