ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Book information
Description
Information security, cybersecurity and privacy protection — Information security management systems — Requirements This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations, regardless of type, size or nature. Excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document. Foreword Introduction 1 Scope 2 Normative references 3 Terms and definitions 4 Context of the organization 4.1 Understanding the organization and its context 4.2 Understanding the needs and expectations of interested parties 4.3 Determining the scope of the information security management system 4.4 Information security management system 5 Leadership 5.1 Leadership and commitment 5.2 Policy 5.3 Organizational roles, responsibilities and authorities 6 Planning 6.1 Actions to address risks and opportunities 6.1.1 General 6.1.2 Information security risk assessment 6.1.3 Information security risk treatment 6.2 Information security objectives and planning to achieve them 7 Support 7.1 Resources 7.2 Competence 7.3 Awareness 7.4 Communication 7.5 Documented information 7.5.1 General 7.5.2 Creating and updating 7.5.3 Control of documented information 8 Operation 8.1 Operational planning and control 8.2 Information security risk assessment 8.3 Information security risk treatment 9 Performance evaluation 9.1 Monitoring, measurement, analysis and evaluation 9.2 Internal audit 9.2.1 General 9.2.2 Internal audit programme 9.3 Management review 9.3.1 General 9.3.2 Management review inputs 9.3.3 Management review results 10 Improvement 10.1 Continual improvement 10.2 Nonconformity and corrective action Annex€A (normative) Information security controls reference Bibliography
Similar books
Modern C
2018 · PDF
International Space Olympiad 2023 Preliminary Level Reference Book Senior Category
2023 · PDF
QR Code bar code symbology specification - ISO/IEC 18004:2015
2015 · PDF
ISO/TS 19299: Electronic fee collection - Security framework
2015 · PDF
BS ISO 80000-1:2009 Quantities and units — Part 1: General
2009 · PDF
ISO/IEC 11172-2: Information technology — Coding of moving pictures and associated audio for digital storage media at up to about 1,5 Mbit/s
1993 · PDF
C23 - ISO/IEC 9899:2024
2024 · PDF
ISO 8601
2004 · PDF