Brezavšček Alenka, Vidmar Doroteja
{"title":"Spremembe, ki jih prinašajo nove različice v družini standardov za informacijsko varnost ISO/IEC 27000","authors":"Brezavšček Alenka, Vidmar Doroteja","doi":"10.18690/um.fov.3.2023.15","DOIUrl":null,"url":null,"abstract":"The family of standards ISO /IEC 27000 represents the most comprehensive series of standards in the field of information security. Their advantage is their general applicability, as they can be implemented quickly and efficiently in any organisation, regardless of its sector or size. The ISO /IEC 27000 family provides organisations with a practical and established framework for information security assessment and certification. As a result, the use of these standards in practise is widespread globally. In 2022, the ISO /IEC 27000 family underwent significant changes, with two of the most important standards receiving new versions. A new version of ISO /IEC 27002 was published in February 2022, and ISO /IEC 27001 in October 2022. The revisions are very important for organisations implementing the requirements of the standards as part of information security management. The aim of this paper is to provide a comprehensive overview of the changes introduced by the new versions ISO /IEC 27001:2022 and ISO /IEC 27002:2022 compared to the 2013 versions. We found that most of the changes were made to Annex A of the ISO /IEC 27001, which required a completely new structure for the ISO /IEC 27002. We have briefly summarized the impact of these changes on organizations applying these standards in their business operations.","PeriodicalId":447088,"journal":{"name":"42nd International Conference on Organizational Science Development","volume":"268 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"42nd International Conference on Organizational Science Development","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.18690/um.fov.3.2023.15","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

ISO /IEC 27000系列标准代表了信息安全领域最全面的系列标准。它们的优势在于它们的普遍适用性,因为它们可以在任何组织中快速有效地实施,无论其部门或规模如何。ISO /IEC 27000系列为组织提供了一个实用和既定的信息安全评估和认证框架。因此,这些标准在实践中的使用在全球范围内广泛使用。2022年,ISO /IEC 27000系列经历了重大变化,其中两个最重要的标准获得了新版本。新版ISO /IEC 27002于2022年2月发布,ISO /IEC 27001于2022年10月发布。修订对于实施标准要求的组织作为信息安全管理的一部分是非常重要的。本文的目的是全面概述新版本ISO /IEC 27001:2022和ISO /IEC 27002:2022与2013版本相比所带来的变化。我们发现大部分的变化都发生在ISO /IEC 27001的附件A上,这就要求ISO /IEC 27002有一个全新的结构。我们简要地总结了这些变化对在其业务操作中应用这些标准的组织的影响。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Spremembe, ki jih prinašajo nove različice v družini standardov za informacijsko varnost ISO/IEC 27000
The family of standards ISO /IEC 27000 represents the most comprehensive series of standards in the field of information security. Their advantage is their general applicability, as they can be implemented quickly and efficiently in any organisation, regardless of its sector or size. The ISO /IEC 27000 family provides organisations with a practical and established framework for information security assessment and certification. As a result, the use of these standards in practise is widespread globally. In 2022, the ISO /IEC 27000 family underwent significant changes, with two of the most important standards receiving new versions. A new version of ISO /IEC 27002 was published in February 2022, and ISO /IEC 27001 in October 2022. The revisions are very important for organisations implementing the requirements of the standards as part of information security management. The aim of this paper is to provide a comprehensive overview of the changes introduced by the new versions ISO /IEC 27001:2022 and ISO /IEC 27002:2022 compared to the 2013 versions. We found that most of the changes were made to Annex A of the ISO /IEC 27001, which required a completely new structure for the ISO /IEC 27002. We have briefly summarized the impact of these changes on organizations applying these standards in their business operations.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信