公共安全标准网
IEO International ISO Standard ISO/IEC 27019 Information security, cybersecurity Second edition 2024-10 and privacy protection - Information security controls for the energy utility industry Sécurité de I'information, cyberseécurité et protection de la vie privée - Mesures de sécurité de I'information pour I'industrie des operateurs de I'énergie Reference number ISO/IEC 27019:2024(en) @ ISO/IEC 2024 IS0/IEC 27019:2024(en) COPYRIGHT PROTECTED DOCUMENT @IS0/IEC2024 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or Iso's member body in the country ofthe requester. ISO copyright office CP 401 : Ch. de Blandonnet 8 CH-1214 Vernier, Geneva Phone:+41227490111 Email: [email protected] Website: www.iso.org Published in Switzerland @ IS0/IEC 2024 - All rights reserved ii IS0/IEC 27019:2024(en) Contents Page Foreword. ..vi ..vi Introduction Scope. 1 2 Normative references 2 3 Terms, definitions and abbreviated terms 2 .2 3.1 Termsand definitions 3.2 Abbreviated terms.. 4 4 Structure of this document 4 5 Organizational controls 4 5.1 Policies for information security 4 5.2 Information security roles and responsibilities. 5.3 Segregation of duties 4 5.4 Management responsibilities. 5.5 Contact with authorities. .5 5.6 Contact with special interest groups 5 5.7 Threat intelligence.. 5 5.8 Information security in project management 5 5.9 Inventory of information and other associated assets 6 5.10 Acceptable use of information and other associated assets 6 5.11 Return of assets. 6 5.12 Classification of information. 6 5.13 Labelling of information .7 5.14 Information transfer 7 5.15 Access control. 5.16 Identity management. 5.17 Authenticationinformation 8 5.18 Access rights. 8 5.19 Information security in supplier relationships. .8 5.20 Addressing information security within supplier agreements Managing information security in the ICT supply chain 9 5.21 5.22 Monitoring, review and change management of supplier services. 9 5.23 Information security for use of cloud services. 9 5.24 Information security incident management planning and preparation 9 5.25 Assessment and decision on information security events. 9 5.26 Response to information security incidents. 9 5.27 Learning from information security incidents .9 5.28 Collection of evidence. .9 5.29 Information security during disruption. 9 5.30 ICT readiness for business continuity. 9 5.31 Legal, statutory, regulatory and contractual requirements. .10 5.32 Intellectual property rights 10 5.33 Protection of records. 10 5.34 Privacy and protection of PII .10 5.35 Independent review of information security .10 5.36 Compliance with policies, rules and standards for information security .10 5.37 Documented operating procedures. 10 5.38 ENR - Identification of risks related to external business partners. 10 5.39 ENR - Addressing security when dealing with customers. .11 People controls 12 6 6.1 Screening. 12 6.2 Terms and conditions of employment. 12 6.3 Information security awareness, education and training 12 6.4 Disciplinary process. 12 @ IS0/IEC 2024 - All rights reserved iii

.pdf文档 ISO_IEC 27019 2024

文档预览
中文文档 48 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共48页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO_IEC 27019 2024 第 1 页 ISO_IEC 27019 2024 第 2 页 ISO_IEC 27019 2024 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2025-02-20 13:27:08上传分享
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。