四虎国产精品永久地址998_chinesexxx少妇露脸_日本丁香久久综合国产精品_一区二区久久久久_四虎av影视_久久久久国产一区二区三区不卡

中培偉業IT資訊頻道
您現在的位置:首頁 > IT資訊 > 精選文章 > ISO/IEC27001:信息安全管理體系要求-組織環境

ISO/IEC27001:信息安全管理體系要求-組織環境

2022-11-09 19:09:56 | 來源:企業IT培訓
Information technology — Security techniques — Information security management systems — Requirement- Context of the organization
信息安全管理體系要求-組織環境
 
3Context of the organization
3組織環境
3.1Understanding the organization and its context
3.1理解組織及其環境
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system.
組織應確定與其目標相關并影響其實現信息安全管理體系預期結果的能力的外部和內部問題。
NOTE Determining these issues refers to establishing the external and internal context of the organization considered in Clause 5.4.1 of ISO 31000:2018.
注:確定這些問題涉及到建立組織的外部和內部環境,在 ISO 31000:2018的5.4.1 中考慮了這一事項。
3.2Understanding the needs and expectations of interested parties 
3.2 理解相關方的需求和期望
The organization shall determine:
a)interested parties that are relevant to the information security management system;
b)the relevant requirements of these interested parties;
c)which of these requirements will be addressed through the information security management system.
NOTE The requirements of interested parties can include legal and regulatory requirements and contractual obligations.
組織應確定:
a)與信息安全管理體系有關的相關方;
b)這些相關方與信息安全有關的要求
c)其中哪些要求將通過信息安全管理系統來解決。
注:相關方的要求可能包括法律法規要求和合同義務。
3.3Determining the scope of the information security management system
3.3 確定信息安全管理體系的適用范圍
The organization shall determine the boundaries and applicability of the information security management system to establish its scope.
When determining this scope, the organization shall consider:
a)the external and internal issues referred to in 4.1;
b)the requirements referred to in 4.2;
c)interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations.
The scope shall be available as documented information.
組織應確定信息安全管理體系的邊界和適用性,以建立其范圍。
當確定該范圍時,組織應考慮:
a)在4.1中提及的外部和內部問題;
b)在4.2中提及的要求;
c)組織所執行的活動之間以及與其它組織的活動之間的接口和依賴性
該范圍應文件化并保持可用性。
3.4Information security management system
3.4信息安全管理體系
The organization shall establish, implement, maintain and continually improve an information security man
 
溫馨提示:獲取完整版ISO27001最新2022版中英文對照資料,可咨詢中培課程顧問或撥打客服電話了解18513851518

主站蜘蛛池模板: 南阳市| 嘉定区| 东乌珠穆沁旗| 芒康县| 乌鲁木齐市| 阜南县| 阳原县| 潮州市| 玛纳斯县| 芒康县| 宜春市| 昂仁县| 广水市| 彭泽县| 迁西县| 新兴县| 左云县| 洱源县| 肥东县| 武城县| 云龙县| 临夏市| 闻喜县| 乐清市| 湘潭市| 孟州市| 神池县| 岐山县| 剑河县| 澄迈县| 集贤县| 抚宁县| 连城县| 民乐县| 陆河县| 库尔勒市| 阿巴嘎旗| 华亭县| 睢宁县| 阿拉尔市| 阿图什市|