全网唯一标准王
IEC International ISO Standard IS0/IEC27018 Information security, cybersecurity Third edition 2025-08 and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors Sécurité de I'information, cybersécurité et protection de la vie privée - Lignes directrices en matiere de protection des informations personnelles identifiables (PIl) dans I'informatique en nuage public agissant comme processeur de PlI Reference number ISO/IEC 27018:2025(en) @ISO/IEC 2025 IS0/IEC 27018:2025(en) COPYRIGHTPROTECTEDDOCUMENT IS0/IEC2025 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may the internet or an intranet, without prior written permission. Permission can be requested from either IsO at the address below or ISO's member body in the country of the requester. ISO copyright office CP 40i : Ch. de Blandonnet 8 CH-1214 Vernier, Geneva Phone: +41 22 749 01 11 Email: [email protected] Website: www.iso.org Published in Switzerland @ IS0/IEC 2025 - All rights reserved i IS0/IEC 27018:2025(en) Contents Page Foreword. Introduction ..vi 1 Scope. .1 2 Normative references .1 3 Terms and definitions .1 Overview. .3 4.1 Structure of this document 4.2 Control layout .10 5 Organizational controls .11 5.1 Policies for information security. ..11 5.2 Information security roles and responsibilities. ..11 5.3 Segregation of duties. 11 5.4 Management responsibilities .11 5.5 Contact with authorities.. ..11 5.6 Contact with special interest groups. .12 5.7 Threat intelligence. .12 5.8 Information security in project management .12 5.9 Inventory of information and other associated assets. 12 5.10 Acceptable use of information and other associated assets 12 5.11 Returnofassets. 12 5.12 Classification of information 12 5.13 Labelling of information . .12 5.14 Information transfer 12 5.15 Accesscontrol. 12 5.16 Identity management. 13 5.17 Authentication information .13 5.18 Access rights. 13 5.19 Information security in supplier relationships 13 5.20 Addressing information security within supplier agreements .13 5.21 Managing information security in the ICT supply chain. 13 5.22 Monitoring, review and change management of supplier services .13 5.23 Information security for use of cloud services. 13 5.24 Information security incident management planning and preparation .13 5.25 Assessment and decision on information security events 13 5.26 Responsetoinformationsecurityincidents .14 5.27 Learning from information security incidents. .14 5.28 Collection of evidence.. .14 5.29 Information security during disruption .14 5.30 ICT readiness for business continuity .14 5.31 Legal, statutory, regulatory and contractual requirements. ..14 5.32 Intellectual property rights .14 5.33 Protection of records. .14 5.34 Privacy and protection of PII ..14 5.35 Independent review of information security .14 5.36 Compliance with policies, rules and standards for information security .15 5.37 Documented operating procedures 15 6 People controls. .15 6.1 Screening 15 6.2 Terms and conditions of employment. .15 6.3 Information security awareness, education and training 15 6.4 Disciplinary process 15 6.5 Responsibilities after termination or change of employment 15 6.6 Confidentiality or non-disclosure agreements.. .15 @ IS0/IEC 2025 - All rights reserved iii IS0/IEC 27018:2025(en) 6.7 Remote working 15 6.8 Information security event reporting .16 7 Physical controls. 16 7.1 Physical security perimeters .16 7.2 Physicalentry .16 7.3 Securing offices, rooms and facilities .16 7.4 Physical security monitoring. ..16 7.5 Protecting against physical and environmental threats ..16 7.6 Working in secure areas. .16 7.7 Clear desk and clear screen. .16 7.8 Equipment siting and protection .16 7.9 Security of assets off-premises. ..16 7.10 Storage media. .16 7.11 Supporting utilities .16 7.12 Cabiing security. .16 7.13 Equipment maintenance. ..17 7

.pdf文档 ISO IEC 27018-2025

文档预览
中文文档 44 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共44页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO IEC 27018-2025 第 1 页 ISO IEC 27018-2025 第 2 页 ISO IEC 27018-2025 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2026-06-07 00:13:46上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。