ISO/IEC 27014:2020 信息安全,网络安全和隐私保护 信息安全的治理
标准编号:ISO/IEC 27014:2020
中文名称:信息安全,网络安全和隐私保护 信息安全的治理
英文名称:Information security, cybersecurity and privacy protection — Governance of information security
发布日期:2020-12
标准范围
本文件就信息安全治理的概念、目标和流程提供了指导,组织可以通过这些指导来评估、指导、监控和交流组织内与信息安全相关的流程。本文档的目标受众是:-理事机构和最高管理层;-负责评估、指导和监控基于ISO/IEC 27001的信息安全管理系统(ISMS)的人员;-负责在基于ISO/IEC 27001的ISMS范围之外但在治理范围内进行的信息安全管理的人员。本文档适用于所有类型和规模的组织。本文档中对ISMS的所有引用均适用于基于ISO/IEC 27001的ISMS。本文件侧重于附件B中给出的三类ISMS组织。但是,其他类型的组织也可以使用本文档。
This document provides guidance on concepts, objectives and processes for the governance of information security, by which organizations can evaluate, direct, monitor and communicate the information security-related processes within the organization.
The intended audience for this document is:
- governing body and top management;
- those who are responsible for evaluating, directing and monitoring an information security management system (ISMS) based on ISO/IEC 27001;
- those responsible for information security management that takes place outside the scope of an ISMS based on ISO/IEC 27001, but within the scope of governance.
This document is applicable to all types and sizes of organizations.
All references to an ISMS in this document apply to an ISMS based on ISO/IEC 27001.
This document focuses on the three types of ISMS organizations given in Annex B. However, this document can also be used by other types of organizations.
标准预览图


