现行
ISO/IEC 27001:2022
到馆提醒
收藏跟踪
分享链接
购买正版
选择购买版本
本服务由中国标准服务网提供
电子版
英语/电子版加密PDF格式/约1分钟可下载/有水印/要装插件FileOpen/电脑需联网/限制累计3台电脑共打印5次
¥ 1,254
更多
前往中国标准服务网获取更多购买信息
支持批量购买纸质版标准
Information security, cybersecurity and privacy protection — Information security management systems — Requirements
信息安全、网络安全和隐私保护.信息安全管理系统.要求
本文件规定了在组织范围内建立、实施、维护和持续改进信息安全管理系统的要求。本文件还包括根据组织需要评估和处理信息安全风险的要求。本文件中规定的要求是通用的,旨在适用于所有组织,无论其类型、规模或性质如何。排除条款中规定的任何要求当一个组织声称符合本文件时,第4至10条是不可接受的。
This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document.