ISO/IEC 27035-2:2016 信息技术 安全技术 信息安全事件管理 第2部分:事件响应用计划和准备指南

标准编号:ISO/IEC 27035-2:2016

中文名称:信息技术 安全技术 信息安全事件管理 第2部分:事件响应用计划和准备指南

英文名称:Information technology — Security techniques — Information security incident management — Part 2: Guidelines to plan and prepare for incident response

发布日期:2016-11

标准范围

ISO/IEC 27035-2:2016提供了计划和准备事件响应的指南。这些指导方针基于;“计划和准备”;阶段和;“经验教训”;“的阶段”;“信息安全事件管理阶段”;模型见ISO/IEC 27035-1。“文件”中的要点;“计划和准备”;阶段包括:-信息安全事件管理政策和最高管理层的承诺;-信息安全政策,包括与风险管理相关的政策,在公司层面和系统、服务和网络层面进行更新;-信息安全事件管理计划;-事故响应小组(IRT)的建立;-与内部和外部组织建立关系和联系;-技术和其他支持(包括组织和运营支持);-信息安全事件管理意识简报和培训;-信息安全事件管理计划测试。ISO/IEC 27035本部分给出的原则是通用的,适用于所有组织,无论其类型、规模或性质如何。各组织可根据其与信息安全风险状况相关的业务类型、规模和性质,调整ISO/IEC 27035本部分给出的指南。ISO/IEC 27035的本部分也适用于提供信息安全事件管理服务的外部组织。

ISO/IEC 27035-2:2016 provides the guidelines to plan and prepare for incident response. The guidelines are based on the "Plan and Prepare" phase and the "Lessons Learned" phase of the "Information security incident management phases" model presented in ISO/IEC 27035?1.The major points within the "Plan and Prepare" phase include the following:- information security incident management policy and commitment of top management;- information security policies, including those relating to risk management, updated at both corporate level and system, service and network levels;- information security incident management plan;- incident response team (IRT) establishment;- establish relationships and connections with internal and external organizations;- technical and other support (including organizational and operational support);- information security incident management awareness briefings and training;- information security incident management plan testing.The principles given in this part of ISO/IEC 27035 are generic and intended to be applicable to all organizations, regardless of type, size or nature. Organizations can adjust the guidance given in this part of ISO/IEC 27035 according to their type, size and nature of business in relation to the information security risk situation. This part of ISO/IEC 27035 is also applicable to external organizations providing information security incident management services.

标准预览图


立即下载标准文件