EESTI STANDARD EVS-ISO/IEC 27000:2015 This document is a preview generated by EVS INFOTEHNOLOOGIA Turbemeetodid Infoturbe halduse süsteemid Ülevaade j

Seotud dokumendid
Microsoft Word - EVS_ISO_IEC_27001;2014_et_esilehed.doc

EESTI STANDARD EVS-ISO/IEC 25021:2014 This document is a preview generated by EVS SÜSTEEMI- JA TARKVARATEHNIKA Süsteemide ja tarkvara kvaliteedinõuded

Microsoft Word - EVS_ISO_6743_13;2012_et_en

Microsoft Word - EVS_ISO_3574;2008_esilehed

EESTI STANDARD EVS-ISO/IEC :2005 This document is a preview generated by EVS INFOTEHNOLOOGIA Avatud süsteemide vastastikune ühendamine Tehingut

EESTI STANDARD EVS-EN 1790:1999 This document is a preview generated by EVS Teemärgistusmaterjalid. Kasutusvalmid teekattemärgised Road marking materi

Microsoft Word - CEN_ISO_TR_15608;2013_et

Microsoft Word - EVS_ISO_31000;2010_et_esilehed

EESTI STANDARD EVS-EN :2000 This document is a preview generated by EVS Terastraat ja traattooted piirete valmistamiseks. Osa 4: Terastraadist

Microsoft Word - C035736e.doc

EESTI STANDARD EVS-ISO/IEC 38500:2009 Avaldatud eesti keeles: oktoober 2009 Jõustunud Eesti standardina: oktoober 2009 Infotehnoloogia valitsemine org

EESTI STANDARD EVS-ISO/IEC/IEEE 15289:2013 This document is a preview generated by EVS SÜSTEEMI- JA TARKVARATEHNIKA Elutsükli infosaaduste (dokumentat

EESTI STANDARD EVS 927:2017 See dokument on EVS-i poolt loodud eelvaade EHITUSLIK PÕLETATUD PÕLEVKIVI Spetsifikatsioon, toimivus ja vastavus Burnt sha

EESTI STANDARD EVS-ISO/IEC 18019:2008 TARKVARA- JA SÜSTEEMITEHNIKA Juhised rakendustarkvara kasutajadokumentatsiooni kavandamiseks ja koostamiseks (IS

ISO/IEC JTC 1/SC 27

EESTI STANDARD EVS-ISO/IEC 90003:2009 TARKVARATEHNIKA Juhised ISO 9001:2000 rakendamiseks tarkvarale See dokument on EVS-i poolt loodud eelvaade Softw

EESTI STANDARD EVS-ISO :2013 This document is a preview generated by EVS INFORMATSIOON JA DOKUMENTATSIOON Dokumentide haldamise põhimõtted ja f

EESTI STANDARD EVS-ISO :2013 This document is a preview generated by EVS VEE KVALITEET Proovivõtt Osa 10: Juhised reoveest ja heitveest proovid

Microsoft Word - EVS_EN_10204;2004_et.doc

EVS standardi alusfail

EESTI STANDARD EVS-ISO 24510:2008 This document is a preview generated by EVS JOOGIVEE- JA KANALISATSIOONITEENUSTEGA SEOTUD TEGEVUSED Juhised joogivee

EVS standardi alusfail

EVS standardi alusfail

Microsoft Word - EVS-ISO doc - pdfMachine from Broadgun Software, a great PDF writer utility!

EVS standardi alusfail

Microsoft Word - EVS_898;2014_et.doc

Microsoft Word - EVS_EN_15518_1;2011_et

Microsoft Word - EVS_ISO_16175_1;2010_et

EVS standardi alusfail

EVS standardi alusfail

Microsoft Word - EVS_921;2014_et.doc

Microsoft Word - EVS_ISO_IEC_IEEE_26511;2011_esilehed

EVS standardi alusfail

Microsoft Word - EVS-EN _ pdfMachine from Broadgun Software, a great PDF writer utility!

EESTI STANDARD EVS-EN ISO 3381:2007 See dokument on EVS-i poolt loodud eelvaade RAUDTEEALASED RAKENDUSED Akustika Raudteeveeremi sisemüra mõõtmine (IS

EVS standardi alusfail

Microsoft Word - EVS_EN_14899;2006_et.doc

Microsoft Word - CEN_ISO_TS_80004_3;2014_et

EESTI STANDARD EVS 896:2008 RAHVUSVAHELINE NUMERATSIOONIPLAAN ITU-T soovituse E.164 rakendamine Eestis See dokument on EVS-i poolt loodud eelvaade The

EESTI STANDARD EVS-ISO :2013 This document is a preview generated by EVS VEE KVALITEET Proovivõtt Osa 9: Juhised mereveest proovide võtmiseks Wa

Microsoft Word - EVS_EN_ISO_14971;2012_et

Microsoft Word - EVS_EN_1317_5;2007+A2;2012_et

REQUEST FOR AN ASSIGNMENT OF LEI (fond) LEI KOODI MÄÄRAMISE TAOTLUS (fond) 1. FUND DATA / FONDI ANDMED: Legal Name / Ametlik nimi: Other Fund Names /

Microsoft Word - EVS_EN_ISO_8968_1;2002_et

Avatud ja läbipaistev e-riik: Ees6 kui rajaleidja Andrus Kaarelson RIA peadirektori asetäitja riigi infosüsteemi alal 10. oktoober 2017

Väljaandja: EÜEVAN Akti liik: otsus Teksti liik: algtekst Avaldamismärge: RT II 2002, 4, 7 Otsus nr 7/2001 (UE-EE 813/01), millega võetakse vastu ting

Microsoft Word - EVS_EN_ISO_14064_3;2012_et_en

EVS_EN_ISO_3381_2011_et.pdf

Microsoft Word - EVS-EN 13485

Microsoft Word - EVS-EN doc

EESTI STANDARD EVS-ISO :2007 TRÜKITEHNOLOOGIA Protsessi kontrollimine pooltooni värvilahutuste, proovitrükkide ja tootmistrükkide valmistamisel

EVS standardi alusfail

Väljaandja: Vabariigi Valitsus Akti liik: välisleping Teksti liik: algtekst Jõustumise kp: Avaldamismärge: RT II 2005, 31, 103 Eesti Vabari

Microsoft Word - EVS-ISO doc - pdfMachine from Broadgun Software, a great PDF writer utility!

EESTI STANDARD EVS-EN 71-8:2003+A4:2009 Avaldatud eesti keeles: detsember 2009 Jõustunud Eesti standardina: oktoober 2009 See dokument on EVS-i poolt

Microsoft Word - EVS_EN_ISO_17450_1;2011_et

Microsoft Word - EVS_EN_ISO_13857;2008_et.doc

EVS standardi alusfail

EVS standardi alusfail

EVS_812_8_2011_et.pdf

EVS standardi alusfail

EESTI KUNSTIAKADEEMIA

Microsoft Word - EVS_EN_1838;2013_et.doc

Sissejuhatus GRADE metoodikasse

Microsoft Word - EVS_EN_61557_5;2007_et.doc

Microsoft Word - EVS_ISO_IEC_10646;2012_esilehed.doc

Väljaandja: Vabariigi Valitsus Akti liik: välisleping Teksti liik: algtekst Jõustumise kp: Avaldamismärge: RT II 2008, 19, 56 Eesti Vabarii

Microsoft Word - EVS_EN_1342;2013_et

Microsoft Word - EVS_EN_61228;2008_et

Microsoft Word - EVS-HD S1

Microsoft Word - EVS_EN_13231_3;2006_et

Microsoft Word - EVS_HD_60364_7_753;2015_et

Ppt [Read-Only]

Microsoft Word - EVS_EN_ISO_9606_1;2013_et

EESTI STANDARD EVS 875-3:2010 VARA HINDAMINE Osa 3: Väärtuse liigid Property valuation Part 3: Valuation Bases

Ref. Ares(2018) /01/2018 Ш Republic of Estonia Ministry of Economic Affairs and Communications Mr Keir Fitch European Commission DG Mobility a

Microsoft Word - EVS_EN_14730_1;2006+A1;2010_et

EVS standardi alusfail

Slide 1

INVESTMENT FRIENDS CAPITAL SE MINUTES OF THE EXTRAORDINARY GENERAL MEETING OF SHAREHOLDERS Place of holding the meeting: Plock, ul. Padlewskiego 18C,

HARMONEERITUKS TUNNISTATUD STANDARDID

EVS_EN_14227_13_2006_et.pdf

Süsteemide modelleerimine: praktikum Klassiskeemid Oleg Mürk

Sihtasutuse Euroopa Kool PÕHIKIRI 1. peatükk ÜLDSÄTTED STATUTES OF THE FOUNDATION EUROOPA KOOL Chapter 1 GENERAL PROVISIONS 1.1.Sihtasutus Euroopa Koo

Microsoft Word - EVS_EN_61439_2;2009_et

Väljaandja: Vabariigi Valitsus Akti liik: välisleping Teksti liik: algtekst Avaldamismärge: RT II 2004, 35, 128 Rahvusvahelise Telekommunikatsiooni Li

IECSTD - Version 4

EVS standardi alusfail

EESTI STANDARD EVS-ISO 11094:2005 AKUSTIKA Katsetuseeskiri mootorajamiga muruniidukite, murutraktorite, muru- ja aiatraktorite, professionaalsete niid

EVS standardi alusfail

Väljaandja: Riigikogu Akti liik: välisleping Teksti liik: algtekst Avaldamismärge: RT II 1999, 15, 92 Kohtulikult karistatud isikute üleandmise Euroop

Väljaandja: Vabariigi Valitsus Akti liik: välisleping Teksti liik: algtekst Jõustumise kp: Avaldamismärge: RT II 2009, 22, 55 Eesti Vabarii

Väljaandja: Vabariigi Valitsus Akti liik: välisleping Teksti liik: algtekst Jõustumise kp: Avaldamismärge: RT II 2008, 17, 49 Eesti Vabarii

Väljavõte:

EESTI STANDARD INFOTEHNOLOOGIA Turbemeetodid Infoturbe halduse süsteemid Ülevaade ja sõnavara Information technology Security techniques Information security management systems Overview and vocabulary (ISO/IEC 27000:2014)

EESTI STANDARDI EESSÕNA NATIONAL FOREWORD See Eesti standard Infotehnoloogia. Turbemeetodid. Infoturbe halduse süsteemid. Nõuded sisaldab rahvusvahelise standardi ISO/IEC 27000:2014 Information technology Security techniques Information security management systems Overview and vocabulary identset ingliskeelset teksti. This Estonian Standard consists of the identical English text of the International Standard ISO/IEC 27000:2014 Information technology Security techniques Information security management systems Overview and vocabulary. Ettepaneku rahvusvahelise standardi ümbertrüki meetodil ülevõtuks on esitanud EVS/TK 4, standardi avaldamist on korraldanud Eesti Standardikeskus. Standard EVS-ISO/IEC 27000:2014 on jõustunud sellekohase teate avaldamisega EVS Teataja 2015. aasta veebruarikuu numbris. Proposal to adopt the International Standard by reprint method has been presented by EVS/TK 4, the Estonian standard has been published by the Estonian Centre for Standardisation. The standard has been endorsed with a notification published in the February 2015 issue of the official bulletin of the Estonian Centre for Standardisation. Standard on kättesaadav Eesti Standardikeskusest. The standard is available from the Estonian Centre for Standardisation. Käsitlusala See standard annab ülevaate infoturbe halduse süsteemidest ning ISMS-i standardiperes kasutatavatest ühistest terminitest ja määratlustest. See standard on rakendatav igat liiki ja iga suurusega organisatsioonides (näiteks äriettevõtetes, riigiasutustes, mittetulunduslikes organisatsioonides). Tagasisidet standardi sisu kohta on võimalik edastada, kasutades EVS-i veebilehel asuvat tagasiside vormi või saates e-kirja meiliaadressile standardiosakond@evs.ee. ICS 01.040.35; 35.040 Standardite reprodutseerimise ja levitamise õigus kuulub Eesti Standardikeskusele Andmete paljundamine, taastekitamine, kopeerimine, salvestamine elektroonsesse süsteemi või edastamine ükskõik millises vormis või millisel teel ilma Eesti Standardikeskuse kirjaliku loata on keelatud. Kui Teil on küsimusi standardite autorikaitse kohta, võtke palun ühendust Eesti Standardikeskusega: Aru 10, 10317 Tallinn, Eesti; www.evs.ee; telefon 605 5050; e-post info@evs.ee The right to reproduce and distribute standards belongs to the Estonian Centre for Standardisation No part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying, without a written permission from the Estonian Centre for Standardisation. If you have any questions about copyright, please contact Estonian Centre for Standardisation: Aru 10, 10317 Tallinn, Estonia; www.evs.ee; phone 605 5050; e-mail info@evs.ee

Contents Page Foreword...iv 0 Introduction...v 1 Scope... 1 2 Terms and definitions... 1 3 Information security management systems...12 3.1 Introduction...12 3.2 What is an ISMS?...13 3.3 Process approach...14 3.4 Why an ISMS is important...14 3.5 Establishing, monitoring, maintaining and improving an ISMS...15 3.6 ISMS critical success factors...18 3.7 Benefits of the ISMS family of standards...19 4 ISMS family of standards...19 4.1 General information...19 4.2 Standards describing an overview and terminology...20 4.3 Standards specifying requirements...21 4.4 Standards describing general guidelines...21 4.5 Standards describing sector-specific guidelines...23 Annex A (informative) Verbal forms for the expression of provisions...25 Annex B (informative) Term and Term ownership...26 Bibliography...30 iii

EVS-ISO/IEC 27000:2015 Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopted by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights. ISO/IEC 27000 was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques. This third edition cancels and replaces the second edition (ISO/IEC 27000:2012), which has been technically revised. iv

0 Introduction 0.1 Overview International Standards for management systems provide a model to follow in setting up and operating a management system. This model incorporates the features on which experts in the field have reached a consensus as being the international state of the art. ISO/IEC JTC 1/SC 27 maintains an expert committee dedicated to the development of international management systems standards for information security, otherwise known as the Information Security Management System (ISMS) family of standards. Through the use of the ISMS family of standards, organizations can develop and implement a framework for managing the security of their information assets including financial information, intellectual property, and employee details, or information entrusted to them by customers or third parties. These standards can also be used to prepare for an independent assessment of their ISMS applied to the protection of information. 0.2 ISMS family of standards The ISMS family of standards (see Clause 4) is intended to assist organizations of all types and sizes to implement and operate an ISMS and consists of the following International Standards, under the general title Information technology Security techniques (given below in numerical order): ISO/IEC 27000, Information security management systems Overview and vocabulary ISO/IEC 27001, Information security management systems Requirements ISO/IEC 27002, Code of practice for information security controls ISO/IEC 27003, Information security management system implementation guidance ISO/IEC 27004, Information security management Measurement ISO/IEC 27005, Information security risk management ISO/IEC 27006, Requirements for bodies providing audit and certification of information security management systems ISO/IEC 27007, Guidelines for information security management systems auditing ISO/IEC TR 27008, Guidelines for auditors on information security controls ISO/IEC 27010, Information security management for inter-sector and inter-organizational communications ISO/IEC 27011, Information security management guidelines for telecommunications organizations based on ISO/IEC 27002 ISO/IEC 27013, Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000 1 ISO/IEC 27014, Governance of information security ISO/IEC TR 27015, Information security management guidelines for financial services ISO/IEC TR 27016, Information security management Organizational economics NOTE The general title Information technology Security techniques indicates that these standards were prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology, Subcommittee SC 27, IT Security techniques. International Standards not under the same general title that are also part of the ISMS family of standards are as follows: ISO 27799:2008, Health informatics Information security management in health using ISO/IEC 27002 v

0.3 Purpose of this International Standard This International Standard provides an overview of information security management systems, and defines related terms. NOTE Annex A provides clarification on how verbal forms are used to express requirements and/or guidance in the ISMS family of standards. The ISMS family of standards includes standards that: a) define requirements for an ISMS and for those certifying such systems; b) provide direct support, detailed guidance and/or interpretation for the overall process to establish, implement, maintain and improve an ISMS; c) address sector-specific guidelines for ISMS; and d) address conformity assessment for ISMS. The terms and definitions provided in this International Standard: cover commonly used terms and definitions in the ISMS family of standards; do not cover all terms and definitions applied within the ISMS family of standards; and do not limit the ISMS family of standards in defining new terms for use. vi

INTERNATIONAL STANDARD Information technology Security techniques Information security management systems Overview and vocabulary 1 Scope This International Standard provides the overview of information security management systems, and terms and definitions commonly used in the ISMS family of standards. This International Standard is applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, notfor-profit organizations). 2 Terms and definitions For the purposes of this document, the following terms and definitions apply. 2.1 access control means to ensure that access to assets is authorized and restricted based on business and security requirements 2.2 analytical model algorithm or calculation combining one or more base measures (2.10) and/or derived measures (2.22) with associated decision criteria 2.3 attack attempt to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset 2.4 attribute property or characteristic of an object (2.55) that can be distinguished quantitatively or qualitatively by human or automated means [SOURCE: ISO/IEC 15939:2007, modified entity has been replaced by object in the definition.] 2.5 audit systematic, independent and documented process (2.61) for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled Note 1 to entry: An audit can be an internal audit (first party) or an external audit (second party or third party), and it can be a combined audit (combining two or more disciplines). Note 2 to entry: Audit evidence and audit criteria are defined in ISO 19011. 2.6 audit scope extent and boundaries of an audit (2.5) [SOURCE: ISO 19011:2011] 1