1、 ISO/IEC 2014. CSA Group 2015. All rights reserved. Unauthorized reproduction is strictly prohibited.CAN/CSA-ISO/IEC TR 38502:15(ISO/IEC TR 38502:2014, IDT)National Standard of CanadaCAN/CSA-ISO/IEC TR 38502:15Information technology Governance of IT Frameworkand model(ISO/IEC TR 38502:2014, IDT)Lega
2、l Notice for StandardsCanadian Standards Association (operating as “CSA Group”) develops standards through a consensus standards development process approvedby the Standards Council of Canada. This process brings together volunteers representing varied viewpoints and interests to achieve consensusan
3、d develop a standard. Although CSA Group administers the process and establishes rules to promote fairness in achieving consensus, it doesnot independently test, evaluate, or verify the content of standards.Disclaimer and exclusion of liabilityThis document is provided without any representations, w
4、arranties, or conditions of any kind, express or implied, including, without limitation,implied warranties or conditions concerning this documents fitness for a particular purpose or use, its merchantability, or its non-infringementof any third partys intellectual property rights. CSA Group does not
5、 warrant the accuracy, completeness, or currency of any of the informationpublished in this document. CSA Group makes no representations or warranties regarding this documents compliance with any applicablestatute, rule, or regulation.IN NO EVENT SHALL CSA GROUP, ITS VOLUNTEERS, MEMBERS, SUBSIDIARIE
6、S, OR AFFILIATED COMPANIES, OR THEIR EMPLOYEES, DIRECTORS,OR OFFICERS, BE LIABLE FOR ANY DIRECT, INDIRECT, OR INCIDENTAL DAMAGES, INJURY, LOSS, COSTS, OR EXPENSES, HOWSOEVER CAUSED,INCLUDING BUT NOT LIMITED TO SPECIAL OR CONSEQUENTIAL DAMAGES, LOST REVENUE, BUSINESS INTERRUPTION, LOST OR DAMAGEDDATA
7、, OR ANY OTHER COMMERCIAL OR ECONOMIC LOSS,WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR ANY OTHERTHEORY OF LIABILITY, ARISING OUT OF OR RESULTING FROM ACCESS TO OR POSSESSION OR USE OF THIS DOCUMENT, EVEN IF CSA GROUPHAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, INJURY, LOSS, CO
8、STS, OR EXPENSES.In publishing and making this document available, CSA Group is not undertaking to render professional or other services for or on behalf of anyperson or entity or to perform any duty owed by any person or entity to another person or entity. The information in this document is direct
9、edto those who have the appropriate degree of experience to use and apply its contents, and CSA Group accepts no responsibility whatsoeverarising in any way from any and all use of or reliance on the information contained in this document.CSA Group is a private not-for-profit company that publishes
10、voluntary standards and related documents. CSA Group has no power, nor does itundertake, to enforce compliance with the contents of the standards or other documents it publishes.Intellectual property rights and ownershipAs between CSA Group and the users of this document (whether it be in printed or
11、 electronic form), CSA Group is the owner, or the authorizedlicensee, of all works contained herein that are protected by copyright, all trade-marks (except as otherwise noted to the contrary), and allinventions and trade secrets that may be contained in this document, whether or not such inventions
12、 and trade secrets are protected bypatents and applications for patents. Without limitation, the unauthorized use, modification, copying, or disclosure of this document mayviolate laws that protect CSA Groups and/or others intellectual property and may give rise to a right in CSA Group and/or others
13、 to seek legalredress for such use, modification, copying, or disclosure. To the extent permitted by licence or by law, CSA Group reserves all intellectualproperty rights in this document.Patent rightsAttention is drawn to the possibility that some of the elements of this standard may be the subject
14、 of patent rights. CSA Group shall not beheld responsible for identifying any or all such patent rights. Users of this standard are expressly advised that determination of the validity ofany such patent rights is entirely their own responsibility.Authorized use of this documentThis document is being
15、 provided by CSA Group for informational and non-commercial use only. The user of this document is authorized to doonly the following:If this document is in electronic form: load this document onto a computer for the sole purpose of reviewing it; search and browse this document; and print this docum
16、ent if it is in PDF format.Limited copies of this document in print or paper form may be distributed only to persons who are authorized by CSA Group to have suchcopies, and only if this Legal Notice appears on each such copy.In addition, users may not and may not permit others to alter this document
17、 in any way or remove this Legal Notice from the attached standard; sell this document without authorization from CSA Group; or make an electronic copy of this document.If you do not agree with any of the terms and conditions contained in this Legal Notice, you may not load or use this document or m
18、ake anycopies of the contents hereof, and if you do make such copies, you are required to destroy them immediately. Use of this documentconstitutes your acceptance of the terms and conditions of this Legal Notice.Standards Update ServiceCAN/CSA-ISO/IEC TR 38502:15December 2015Title: Information tech
19、nology Governance of IT Framework and modelTo register for e-mail notification about any updates to this publication go to shop.csa.ca click on CSA Update ServiceThe List ID that you will need to register for updates to this publication is 2424075.If you require assistance, please e-mail techsupport
20、csagroup.org or call 416-747-2233.Visit CSA Groups policy on privacy at www.csagroup.org/legal to find out how we protect yourpersonal information.Canadian Standards Association (operating as “CSA Group”), underwhose auspices this National Standard has been produced, waschartered in 1919 and accredi
21、ted by the Standards Council ofCanada to the National Standards system in 1973. It is a not-for-profit, nonstatutory, voluntary membership association engaged instandards development and certification activities.CSA Group standards reflect a national consensus of producers andusers including manufac
22、turers, consumers, retailers, unions andprofessional organizations, and governmental agencies. Thestandards are used widely by industry and commerce and oftenadopted by municipal, provincial, and federal governments in theirregulations, particularly in the fields of health, safety, building andconst
23、ruction, and the environment.Individuals, companies, and associations across Canada indicatetheir support for CSA Groups standards development byvolunteering their time and skills to Committee work and supportingCSA Groups objectives through sustaining memberships. The morethan 7000 committee volunt
24、eers and the 2000 sustainingmemberships together form CSA Groups total membership fromwhich its Directors are chosen. Sustaining memberships represent amajor source of income for CSA Groups standards developmentactivities.CSA Group offers certification and testing services in support of andas an ext
25、ension to its standards development activities. To ensurethe integrity of its certification process, CSA Group regularly andcontinually audits and inspects products that bear theCSA Group Mark.In addition to its head office and laboratory complex in Toronto, CSAGroup has regional branch offices in m
26、ajor centres across Canadaand inspection and testing agencies in eight countries. Since 1919,CSA Group has developed the necessary expertise to meet itscorporate mission: CSA Group is an independent serviceorganization whose mission is to provide an open and effectiveforum for activities facilitatin
27、g the exchange of goods and servicesthrough the use of standards, certification and related services tomeet national and international needs.For further information on CSA Group services, write toCSA Group178 Rexdale Boulevard,Toronto, Ontario, M9W 1R3CanadaA National Standard of Canada is a standar
28、d developed by an SCC-accredited Standards Development Organization (SDO), andapproved by the Standards Council of Canada (SCC), in accordancewith SCCs: Requirements and Guidance Accreditation forStandards Development Organizations, and Requirements andGuidance Approval of National Standards of Cana
29、da Designation.More information on National Standard requirements can be foundat www.scc.ca.An SCC-approved standard reflects the consensus of a number ofexperts whose collective interests provide, to the greatestpracticable extent, a balance of representation of affectedstakeholders. National Stand
30、ards of Canada are intended to make asignificant and timely contribution to the Canadian interest.SCC is a Crown corporation within the portfolio of Industry Canada.With the goal of enhancing Canadas economic competitiveness andsocial well-being, SCC leads and facilitates the development and useof n
31、ational and international standards. SCC also coordinatesCanadian participation in standards development, and identifiesstrategies to advance Canadian standardization efforts.Accreditation services are provided by SCC to various customers,including product certifiers, testing laboratories, and stand
32、ardsdevelopment organizations. A list of SCC programs and accreditedbodies is publicly available at www.scc.ca.Users should always obtain the latest edition of a National Standardof Canada from the standards development organization responsiblefor its publication, as these documents are subject to p
33、eriodicreview.Standards Council of Canada600-55 Metcalfe StreetOttawa, Ontario, K1P 6L5CanadaCette Norme Nationale du Canada nest disponible quen anglais. Le Groupe CSA publiera la version en franais ds quelle sera produite parlorganisme rdacteur.Although the intended primary application of this Sta
34、ndard is stated in its Scope, it is important to note that it remains the responsibility ofthe users to judge its suitability for their particular purpose.TMA trade-mark of the Canadian Standards Association, operating as “CSA Group”ICS 35.020ISBN 978-1-4883-0063-9 2015 CSA GroupAll rights reserved.
35、 No part of this publication may be reproduced in any form whatsoeverwithout the prior permission of the publisher.Published in December 2015 by CSA GroupA not-for-profit private sector organization178 Rexdale Boulevard,Toronto, Ontario, Canada M9W 1R3To purchase standards and related publications,
36、visit our Online Store at shop.csa.caor call toll-free 1-800-463-6727 or 416-747-4044.TMA trade-mar k of the Canadian S tandards Association, operating as “CSA Group”Reviewed byPrepared byInternational Organization for Standardization/International Electrotechnical CommissionApproved byInformation t
37、echnology Governance of IT Framework and model(ISO/IEC TR 38502:2014, IDT)CAN/CSA-ISO/IEC TR 38502:15National Standard of CanadaCAN/CSA-ISO/IEC TR 38502:15Information technology Governance of IT Frameworkand modelDecember 2015 2015 CSA GroupCSA/5CAN/CSA-ISO/IEC TR 38502:15Information technology Gove
38、rnance ofIT Framework and model(ISO/IEC TR 38502:2014, IDT)CSA PrefaceStandards development within the Information Technology sector is harmonized with internationalstandards development. Through the CSA Technical Committee on Information Technology (TCIT),Canadians serve as the Canadian Advisory Co
39、mmittee (CAC) on ISO/IEC Joint Technical Committee 1 onInformation Technology (ISO/IEC JTC1) for the Standards Council of Canada (SCC), the ISO member bodyfor Canada and sponsor of the Canadian National Committee of the IEC. Also, as a member of theInternational Telecommunication Union (ITU), Canada
40、 participates in the International Telegraph andTelephone Consultative Committee (ITU-T).For brevity, this Standard will be referred to as “CAN/CSA-ISO/IEC TR 38502” throughout.At the time of publication, ISO/IEC TR 38502:2014 is available from ISO and IEC in English only. CSAGroup will publish the
41、French version when it becomes available from ISO and IEC.This Technical Report was reviewed by the TCIT under the jurisdiction of the Strategic SteeringCommittee on Information Technology and deemed acceptable for use in Canada. From time to time,ISO/IEC may publish addenda, corrigenda, etc. The TC
42、IT will review these documents for approval andpublication. For a listing, refer to the Current Standards Activities page at standardsactivities.csa.ca.This Standard has been formally approved, without modification, by the Technical Committee and hasbeen approved as a National Standard of Canada by
43、the Standards Council of Canada. 2015 CSA GroupAll rights reserved. No part of this publication may be reproduced in any form whatsoever without theprior permission of the publisher. ISO/IEC material is reprinted with permission. Where the words “thisTechnical Report” appear in the text, they should
44、 be interpreted as “this National Standard of Canada”.Inquiries regarding this National Standard of Canada should be addressed toCSA Group178 Rexdale Boulevard,Toronto, Ontario, Canada M9W 1R31-800-463-6727 416-747-4000http:/csa.caTo purchase standards and related publications, visit our Online Stor
45、e at shop.csa.ca or call toll-free1-800-463-6727 or 416-747-4044.This Standard is subject to review five years from the date of publication, and suggestions for itsimprovement will be referred to the appropriate committee. To submit a proposal for change, pleaseCAN/CSA-ISO/IEC TR 38502:15Information
46、 technology Governance of IT Frameworkand modelDecember 2015 2015 CSA GroupCSA/6send the following information to inquiriescsagroup.org and include “Proposal for change” in thesubject line:a) Standard designation (number);b) relevant clause, table, and/or figure number;c) wording of the proposed cha
47、nge; andd) rationale for the change.CSA Technical Committee on InformationTechnologyJ. MacFie Microsoft Canada,Ottawa, OntarioCategory: Producer InterestChairF. Coalliercole de technologie Suprieure (Universit duQubec) (TS),Montral, QubecCategory: General InterestVice-ChairS. Michell Maurya Software
48、 Inc.,Ottawa, OntarioCategory: General InterestVice-ChairO. Avellaneda Industry Canada,Ottawa, OntarioAssociateW. Badawy Intelliview Technologies Inc.,Calgary, AlbertaAssociateR. Balderston Canadian Banknote Company Limited,Ottawa, OntarioAssociateA. Barbir Aetna Insurance,Ottawa, OntarioAssociateL.
49、 Bertsch Horizon Technologies Inc.,Victoria, British ColumbiaAssociateJ. Berube IDEgenic Inc.,Gatineau, QubecCategory: General InterestS. Boeyen Entrust,Ottawa, OntarioAssociateW.J. Bryans Electro-Federation Canada,Toronto, OntarioAssociateT. Capel Comgate Engineering Ltd.,Ottawa, OntarioAssociateJ.A. Carter University of Saskatchewan,Saskatoon, SaskatchewanAssociateA. Cheetham Toronto, Ontario AssociateV. Chiew Calgary, Alberta AssociateP. Cotton Microsoft Canada,Nepean, OntarioAssociateD. Ferguson Lyngsoe Systems L
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1