ISO/IEC 27002:2005 介绍

(一) 标准版本及名称

ISO/IEC 27002:2005 Information technology — Security techniques — Code of practice for information security management 信息技术—安全技术—信息安全管理实践规范

(二) 新版标准发布日期

2005年6月15日

(三) 控制措施的数量

ISO/IEC 27002:2005 共有11章,134项控制措施。

11 个控制措施章节是:

1. security policy;

2. organization of information security;

3. asset management;

4. human resources security;

5. physical and environmental security;

6. communications and operations management;

7. access control;

8. information systems acquisition, development and maintenance;

9. information security incident management;

10. business continuity management;

11. Compliance.