CAN CSA-ISO IEC 27002-2008 Information technology - Security techniques - Code of practice for information security management.pdf

上传人:李朗 文档编号:590921 上传时间:2018-12-15 格式:PDF 页数:146 大小:2.11MB
下载 相关 举报
CAN CSA-ISO IEC 27002-2008 Information technology - Security techniques - Code of practice for information security management.pdf_第1页
第1页 / 共146页
CAN CSA-ISO IEC 27002-2008 Information technology - Security techniques - Code of practice for information security management.pdf_第2页
第2页 / 共146页
CAN CSA-ISO IEC 27002-2008 Information technology - Security techniques - Code of practice for information security management.pdf_第3页
第3页 / 共146页
CAN CSA-ISO IEC 27002-2008 Information technology - Security techniques - Code of practice for information security management.pdf_第4页
第4页 / 共146页
CAN CSA-ISO IEC 27002-2008 Information technology - Security techniques - Code of practice for information security management.pdf_第5页
第5页 / 共146页
亲,该文档总共146页,到这儿已超出免费预览范围,如果喜欢就下载吧!
资源描述

1、 Reference numberISO/IEC 27002:2005(E)ISO/IEC 2005INTERNATIONAL STANDARD ISO/IEC27002First edition2005-06-15Information technology Security techniques Code of practice for information security management Technologies de linformation Techniques de scurit Code de bonne pratique pour la gestion de la s

2、curit de linformation National Standard of CanadaCAN/CSA-ISO/IEC 27002:08(ISO/IEC 27002:2005)International Standard ISO/IEC 27002:2005 (first edition, 2005-06-15) has been adopted withoutmodification (IDT) as CSA Standard CAN/CSA-ISO/IEC 27002:08, which has been approved as a NationalStandard of Can

3、ada by the Standards Council of Canada.ISBN 1-55436-765-8 June 2008 International Organization for Standardization (ISO), 2005. All rights reserved. International Electrotechnical Commission (IEC), 2005. All rights reserved. NOT FOR RESALE.National Standard of CanadaCAN/CSA-ISO/IEC 27002:08(ISO/IEC

4、27002:2005)International Standard ISO/IEC 27002:2005 (first edition, 2005-06-15) has been adopted withoutmodification (IDT) as CSA Standard CAN/CSA-ISO/IEC 27002:08, which has been approved as a NationalStandard of Canada by the Standards Council of Canada.ISBN 978-1-55436-765-8 June 2008Legal Notic

5、e for StandardsCanadian Standards Association (CSA) standards are developed through a consensus standards development process approved by the Standards Council of Canada. This process brings together volunteers representing varied viewpoints and interests to achieve consensus and develop a standard.

6、 Although CSA administers the process and establishes rules to promote fairness in achieving consensus, it does not independently test, evaluate, or verify the content of standards.Disclaimer and exclusion of liabilityThis document is provided without any representations, warranties, or conditions o

7、f any kind, express or implied, including, without limitation, implied warranties or conditions concerning this documents fitness for a particular purpose or use, its merchantability, or its non-infringement of any third partys intellectual property rights. CSA does not warrant the accuracy, complet

8、eness, or currency of any of the information published in this document. CSA makes no representations or warranties regarding this documents compliance with any applicable statute, rule, or regulation. IN NO EVENT SHALL CSA, ITS VOLUNTEERS, MEMBERS, SUBSIDIARIES, OR AFFILIATED COMPANIES, OR THEIR EM

9、PLOYEES, DIRECTORS, OR OFFICERS, BE LIABLE FOR ANY DIRECT, INDIRECT, OR INCIDENTAL DAMAGES, INJURY, LOSS, COSTS, OR EXPENSES, HOWSOEVER CAUSED, INCLUDING BUT NOT LIMITED TO SPECIAL OR CONSEQUENTIAL DAMAGES, LOST REVENUE, BUSINESS INTERRUPTION, LOST OR DAMAGED DATA, OR ANY OTHER COMMERCIAL OR ECONOMI

10、C LOSS, WHETHER BASED IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR ANY OTHER THEORY OF LIABILITY, ARISING OUT OF OR RESULTING FROM ACCESS TO OR POSSESSION OR USE OF THIS DOCUMENT, EVEN IF CSA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, INJURY, LOSS, COSTS, OR EXPENSES.In publishing and maki

11、ng this document available, CSA is not undertaking to render professional or other services for or on behalf of any person or entity or to perform any duty owed by any person or entity to another person or entity. The information in this document is directed to those who have the appropriate degree

12、of experience to use and apply its contents, and CSA accepts no responsibility whatsoever arising in any way from any and all use of or reliance on the information contained in this document. CSA is a private not-for-profit company that publishes voluntary standards and related documents. CSA has no

13、 power, nor does it undertake, to enforce compliance with the contents of the standards or other documents it publishes. Intellectual property rights and ownershipAs between CSA and the users of this document (whether it be in printed or electronic form), CSA is the owner, or the authorized licensee

14、, of all works contained herein that are protected by copyright, all trade-marks (except as otherwise noted to the contrary), and all inventions and trade secrets that may be contained in this document, whether or not such inventions and trade secrets are protected by patents and applications for pa

15、tents. Without limitation, the unauthorized use, modification, copying, or disclosure of this document may violate laws that protect CSAs and/or others intellectual property and may give rise to a right in CSA and/or others to seek legal redress for such use, modification, copying, or disclosure. To

16、 the extent permitted by licence or by law, CSA reserves all intellectual property rights in this document.Patent rightsAttention is drawn to the possibility that some of the elements of this standard may be the subject of patent rights. CSA shall not be held responsible for identifying any or all s

17、uch patent rights. Users of this standard are expressly advised that determination of the validity of any such patent rights is entirely their own responsibility.Authorized use of this documentThis document is being provided by CSA for informational and non-commercial use only. The user of this docu

18、ment is authorized to do only the following:If this document is in electronic form:.load this document onto a computer for the sole purpose of reviewing it;.search and browse this document; and.print this document if it is in PDF format. Limited copies of this document in print or paper form may be

19、distributed only to persons who are authorized by CSA to have such copies, and only if this Legal Notice appears on each such copy.In addition, users may not and may not permit others to.alter this document in any way or remove this Legal Notice from the attached standard;.sell this document without

20、 authorization from CSA; or.make an electronic copy of this document.If you do not agree with any of the terms and conditions contained in this Legal Notice, you may not load or use this document or make any copies of the contents hereof, and if you do make such copies, you are required to destroy t

21、hem immediately. Use of this document constitutes your acceptance of the terms and conditions of this Legal Notice.The Canadian Standards Association (CSA), under whose auspices this National Standard has been produced, was chartered in 1919 and accredited by the Standards Council of Canada to the N

22、ational Standards system in 1973. It is a not-for-profit, nonstatutory, voluntary membership association engaged in standards development and certification activities. CSA standards reflect a national consensus of producers and users including manufacturers, consumers, retailers, unions and professi

23、onal organizations, and governmental agencies. The standards are used widely by industry and commerce and often adopted by municipal, provincial, and federal governments in their regulations, particularly in the fields of health, safety, building and construction, and the environment. Individuals, c

24、ompanies, and associations across Canada indicate their support for CSAs standards development by volunteering their time and skills to CSA Committee work and supporting the Associations objectives through sustaining memberships. The more than 7000 committee volunteers and the 2000 sustaining member

25、ships together form CSAs total membership from which its Directors are chosen. Sustaining memberships represent a major source of income for CSAs standards development activities. The Association offers certification and testing services in support of and as an extension to its standards development

26、 activities. To ensure the integrity of its certification process, the Association regularly and continually audits and inspects products that bear the CSA Mark. In addition to its head office and laboratory complex in Toronto, CSA has regional branch offices in major centres across Canada and inspe

27、ction and testing agencies in eight countries. Since 1919, the Association has developed the necessary expertise to meet its corporate mission: CSA is an independent service organization whose mission is to provide an open and effective forum for activities facilitating the exchange of goods and ser

28、vices through the use of standards, certification and related services to meet national and international needs.For further information on CSA services, write toCanadian Standards Association5060 Spectrum Way, Suite 100Mississauga, Ontario, L4W 5N6CanadaThe Standards Council of Canada (SCC) is theco

29、ordinating body of the National StandardsSystem, a coalition of independent, autonomousorganizations working towards the furtherdevelopment and improvement of voluntarystandardization in the national interest.The principal objects of the SCC are to fosterand promote voluntary standardization as a me

30、ansof advancing the national economy, benefiting thehealth, safety, and welfare of the public, assistingand protecting the consumer, facilitating domesticand international trade, and furthering internationalcooperation in the field of standards.A National Standard of Canada (NSC) is a standardprepar

31、ed or reviewed by an accredited Standards Development Organization (SDO) and approved by the SCC according to the requirements of CAN-P-2. Approval does not refer to the technical content of the standard; this remains the continuing responsibility of the SDO. An NSC reflects a consensus of a number

32、of capable individuals whose collective interests provide, to the greatest practicable extent, a balance of representation of general interests, producers, regulators, users (including consumers), and others with relevant interests, as may be appropriate to the subject in hand. It normally is a stan

33、dard which is capable of making a significant and timely contribution to the national interest.Those who have a need to apply standards areencouraged to use NSCs. These standards are subjectto periodic review. Users of NSCs are cautionedto obtain the latest edition from the SDO which publishes the s

34、tandard.The responsibility for approving standards as National Standards of Canada rests with theStandards Council of Canada270 Albert Street, Suite 200Ottawa, Ontario, K1P 6N7CanadaCette Norme nationale du Canada est offerte en anglais et en franais.Although the intended primary application of this

35、 Standard is stated in its Scope, it is importantto note that it remains the responsibility of the users to judge its suitability for their particular purpose.Registered trade-mark of Canadian Standards AssociationApproved byStandards Council of CanadaNational Standard of CanadaPublished in June 200

36、8 by Canadian Standards AssociationA not-for-profit private sector organization5060 Spectrum Way, Suite 100, Mississauga, Ontario, Canada L4W 5N61-800-463-6727 416-747-4044Visit our Online Store at www.ShopCSA.caCAN/CSA-ISO/IEC 27002:08Information technology Security techniques Code of practice for

37、information security managementPrepared by International Organization for Standardization/ International Electrotechnical CommissionReviewed byCAN/CSA-ISO/IEC 27002:08Information technology Security techniques Code of practice for information security managementJune 2008 Canadian Standards Associati

38、on CSA/3CAN/CSA-ISO/IEC 27002:08Information technology Security techniques Code of practice for information security managementCSA PrefaceStandards development within the Information Technology sector is harmonized with international standards development. Through the CSA Technical Committee on Info

39、rmation Technology (TCIT), Canadians serve as the Canadian Advisory Committee (CAC) on ISO/IEC Joint Technical Committee 1 on Information Technology (ISO/IEC JTC1) for the Standards Council of Canada (SCC), the ISO member body for Canada and sponsor of the Canadian National Committee of the IEC. Als

40、o, as a member of the International Telecommunication Union (ITU), Canada participates in the International Telegraph and Telephone Consultative Committee (ITU-T).This International Standard was reviewed by the CSA TCIT under the jurisdiction of the Strategic Steering Committee on Information Techno

41、logy and deemed acceptable for use in Canada. From time to time, ISO/IEC may publish addenda, corrigenda, etc. The CSA TCIT will review these documents for approval and publication. For a listing, refer to the CSA Information Products catalogue or CSA Info Update or contact a CSA Sales representativ

42、e. This Standard has been formally approved, without modification, by the Technical Committee and has been approved as a National Standard of Canada by the Standards Council of Canada.June 2008 Canadian Standards Association 2008All rights reserved. No part of this publication may be reproduced in a

43、ny form whatsoever without the prior permission of the publisher. ISO/IEC material is reprinted with permission. Where the words “this International Standard” appear in the text, they should be interpreted as “this National Standard of Canada”.Inquiries regarding this National Standard of Canada sho

44、uld be addressed toCanadian Standards Association5060 Spectrum Way, Suite 100, Mississauga, Ontario, Canada L4W 5N61-800-463-6727 416-747-4000www.csa.caTo purchase CSA Standards and related publications, visit CSAs Online Store at www.ShopCSA.ca or call toll-free 1-800-463-6727 or 416-747-4044.Refer

45、ence numberISO/IEC 27002:2005(E)ISO/IEC 2005INTERNATIONAL STANDARD ISO/IEC27002First edition2005-06-15Information technology Security techniques Code of practice for information security management Technologies de linformation Techniques de scurit Code de bonne pratique pour la gestion de la scurit

46、de linformation ISO/IEC 27002:2005(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing t

47、he editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file

48、can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretar

49、iat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2005 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.org Web www.

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 标准规范 > 国际标准 > 其他

copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1