ISO/IEC 17799:2005 信息技术-信息安全管理实用规程

标准编号:ISO/IEC 17799:2005

中文名称:信息技术-信息安全管理实用规程

英文名称:Information technology — Security techniques — Code of practice for information security management

发布日期:2005-06

标准范围

ISO/IEC 17799:2005为在组织中启动、实施、维护和改进信息安全管理建立了指导方针和一般原则。概述的目标为普遍接受的信息安全管理目标提供了一般指导。ISO/IEC 17799:2005包含以下信息安全管理领域的控制目标和控制的最佳实践:安全策略;信息安全组织;资产管理;人力资源保障;物理和环境安全;通信和运营管理;访问控制;信息系统的获取、开发和维护;信息安全事件管理;业务连续性管理;合规。ISO/IEC 17799中的控制目标和控制:2005年的计划旨在满足风险评估确定的要求。ISO/IEC 17799:2005旨在作为制定组织安全标准和有效安全管理实践的共同基础和实用指南,并帮助建立对组织间活动的信心。

ISO/IEC 17799:2005 establishes guidelines and general principles for initiating, implementing, maintaining, and improving information security management in an organization. The objectives outlined provide general guidance on the commonly accepted goals of information security management. ISO/IEC 17799:2005 contains best practices of control objectives and controls in the following areas of information security management:

  • security policy;
  • organization of information security;
  • asset management;
  • human resources security;
  • physical and environmental security;
  • communications and operations management;
  • access control;
  • information systems acquisition, development and maintenance;
  • information security incident management;
  • business continuity management;
  • compliance.
The control objectives and controls in ISO/IEC 17799:2005 are intended to be implemented to meet the requirements identified by a risk assessment. ISO/IEC 17799:2005 is intended as a common basis and practical guideline for developing organizational security standards and effective security management practices, and to help build confidence in inter-organizational activities.

标准预览图


立即下载标准文件