Information security, cybersecurity and privacy protection - Information security management systems - Requirements
信息安全、网络安全和隐私保护.信息安全管理系统.要求
ISO/IEC 27001:2022本文件规定了在组织范围内建立、实施、维护和持续改进信息安全管理系统的要求。本文件还包括针对组织需求量身定制的信息安全风险评估和处理要求。本文件中规定的要求是通用的,旨在适用于所有组织,无论其类型、规模或性质如何。当组织声称符合本文件要求时,不接受排除第4条至第10条规定的任何要求。
ISO/IEC 27001:2022 This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.