说明:收录全球国际标准 提供单次或批量下载
INTERNATIONAL ISO/IEC STANDARD 27002 Third edition 2022-02 Information security, cybersecurity and privacy protection Information security controls Sécurite de I'information, cybersécurite et protection de la vie privée - Mesures de sécurité de I'information Reference number IEC IS0/IEC 27002:2022(E) ISO @IS0/IEC 2022 IS0/IEC 27002:2022(E) COPYRIGHT PROTECTED DOCUMENT @IS0/IEC2022 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may the internet or an intranet, withoutpriorwrittenpermission.Permission can be requested from eitherIso at the addressbelow orIso's memberbody inthe country oftherequester ISO copyright office CP 401 · Ch. de Blandonnet 8 CH-1214Vernier,Geneva Phone: +41 22 749 01 11 Email: [email protected] Website: www.iso.org PublishedinSwitzerland i @ IS0/IEC 2022 - All rights reserved IS0/IEC 27002:2022(E) Contents Page Foreword vi Introduction. ..vii 1 Scope.. 1 2 Normative references ..1 3 Terms, definitions and abbreviated terms 1 3.1 Terms and definitions. 1 3.2 Abbreviated terms... .6 4 Structure of this document. 7 4.1 Clauses. 7 4.2 Themes and attributes .8 4.3 Control layout. .9 5 Organizational controls 9 5.1 Policies for information security 9 5.2 Information security roles and responsibilities 11 5.3 Segregation of duties. 12 5.4 Management responsibilities .13 5.5 Contact with authorities. 14 5.6 Contact with special interest groups. 15 5.7 Threat intelligence. 15 5.8 Information security in project management 17 5.9 Inventory of information and other associated assets 18 5.10 Acceptable use of information and other associated assets 20 5.11 Return of assets. 21 5.12 Classification of information 22 5.13 Labelling of information 23 5.14 Information transfer 24 5.15 Access control 27 5.16 Identity management. 29 5.17 Authentication information. 30 5.18 Access rights. 32 5.19 Information security in supplier relationships. 33 5.20 Addressing information security within supplier agreements 35 5.21 Managing information security in the ICT supply chain. 37 5.22 Monitoring, review and change management of supplier services 39 5.23 Information security for use of cloud services. 41 5.24 Information security incident management planning and preparation 43 5.25 Assessment and decision on information security events 44 5.26 Response to information security incidents. 45 5.27 Learning from information security incidents. 46 5.28 Collection of evidence. 46 5.29 Information security during disruption. .48 5.30 ICT readiness for business continuity 48 5.31 Legal, statutory, regulatory and contractual requirements 50 5.32 Intellectual property rights. 51 5.33 Protection of records. 53 5.34 Privacy and protection of PII 54 5.35 Independent review of information security .55 5.36 Compliance with policies, rules and standards for information security 56 5.37 Documented operating procedures... 57 6 People controls .58 6.1 Screening 58 6.2 Terms and conditions of employment. 59 @ IS0/IEC 2022 - All rights reserved ii IS0/IEC 27002:2022(E) 6.3 Information security awareness, education and training .60 6.4 Disciplinary process. 62 6.5 Responsibilities after termination or change of employment ..63 6.6 Confidentiality or non-disclosure agreements... .63 6.7 Remote working. ..65 6.8 Information security event reporting. .66 7 Physical controls. .67 7.1 Physical security perimeters. .67 7.2 Physical entry .68 7.3 Securing offices, rooms and facilities .70 7.4 Physical security monitoring .70 7.5 Protecting against physical and environmental threats ..71 7.6 Working in secure areas.. .72 7.7 Clear desk and clear screen ..73 7.8 Equipment siting and protection .74 7.9 Security of assets off-premises ..75 7.10 Storage media .76 7.11 Supporting utilities. .77 7.12 Cabling security .78 7.13 Equipment maintenance. .79 7.14 Secure disposal or re-use of equipment .80 8 Technological controls .81 8.1 User endpoint devices .81 8.2 Privileged access rights

.pdf文档 ISO IEC 27002 2022 Information security, cybersecurity and privacy protection — Information security controls

文档预览
中文文档 5 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共5页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO IEC 27002 2022 Information security, cybersecurity and privacy protection — Information security controls 第 1 页 ISO IEC 27002 2022 Information security, cybersecurity and privacy protection — Information security controls 第 2 页 ISO IEC 27002 2022 Information security, cybersecurity and privacy protection — Information security controls 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2026-01-05 22:38:38上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。