IEC DRAFT TSO International Standard ISO/IEC DIS 27017 Information security, cybersecurity ISO/IEC JTC 1/SC 27 and privacy protection Secretariat: DIN Information security controls based Voting begins on: 2025-02-03 on IS0/IEC 27002 for cloud services Voting terminates on: ICS: 35.030 2025-04-28 UMENT IS A DRAFT CIRCULATED FORCOMMENTSANDAPPROVAL.IT ISTHEREFORE SUBIECT TO CHANGE INTERNATIONAL STANDARD UNTIL Thisdocumentiscirculatedasreceivedfromthecommittee secretariat. IEIREVALUATIONAS INTERNATIONAL ISO/CENPARALLELPROCESSING ITIALTOBECOMESTANDARDSTO NCEMAYBEMADEIN F THIS DRAFT ARE INVITED NOTIFICATION OF ANYRELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE AND TO PROVIDE SUPPORTING DOCUMENTATION. Reference number @ISO/IEC 2025 ISO/IEC DIS 27017:2025(en) IS0/IEC DIS 27017:2025(en) COPYRIGHT PROTECTED DOCUMENT @IS0/IEC2025 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or Iso's member body in the country ofthe requester. ISO copyright office CP 40i: Ch. de Blandonnet 8 CH-1214 Vernier, Geneva Phone: +41 22 749 01 11 Email:
[email protected] Website: www.iso.org Published in Switzerland @ IS0/IEC 2025 - All rights reserved i IS0/IEC DIS 27017:2025(en) Contents Page Foreword. .vi Introduction. .vii 1 Scope. 1 2 Normative references 1 3 Terms, definitions and abbreviated terms 1 3.1 Termsanddefinitions 1 3.2 Abbreviated terms. 2 4 Cloud computing specific concepts 2 4.1 General .2 4.1.1 Overview 4.1.2 Structure of this International Standard 2 4.2 Cloud computing specific concepts 3 4.2.1 Supplier relationships in cloud services 3 4.2.2 Relationships between CSCs and CSPs. 3 4.2.3 Managing information security risks in cloud services 4 5 Cloud service specific guidance related to organizational controls 5 5.1 Policies for information security. 5 5.2 Information security roles and responsibilities. 6 5.3 Segregation of duties 6 5.4 Management responsibilities 6 5.5 Contact with authorities. 5.6 Contact with special interest groups. 6 5.7 Threat intelligence. 6. 5.8 Information security in project management 7 5.9 Inventory of information and other associated assets 7 5.10 Acceptable use of information and other associated assets 7 5.11 Return of assets. 5.12 Classification of information. 8 5.13 Labelling of information 8 5.14 Information transfer 8 5.15 Accesscontrol. 5.16 Identity management 8 5.17 Authenticationinformation 8 5.18 Access rights 9 5.19 Information security in supplier relationships. .9 5.20 Addressing information security within supplier agreements 9 5.21 Managing information security in the ICT supply chain... .10 5.22 Monitoring, review and change management of supplier services. .10 5.23 Information security for use of cloud services.. .10 5.24 Information security incident management planning and preparation .10 5.25 Assessmentanddecisiononinformationsecurityevents. .10 5.26 Response to information security incidents. 11 5.27 Learningfrominformationsecurityincidents .11 5.28 Collection of evidence. .11 5.29 Information security during disruption .11 5.30 ICT readiness for business continuity .11 5.31 Identification of legal, statutory, regulatory and contractual requirements 11 5.32 Intellectual property rights.. 12 5.33 Protection of records. 13 5.34 Privacy and protection of PII. 13 5.35 Independentreviewofinformationsecurity 13 5.36 Compliance with policies and standards for information security. 13 5.37 Documented operating procedures. 13 @ IS0/IEC 2025 - All rights reserved iii IS0/IEC DIS 27017:2025(en) 6 Cloud service specific guidance related to people controls 14 6.1 Screening 14 6.2 Terms and conditions of employment.. 14 6.3 Information security awareness, education
ISO_IEC DIS 27017-2025
文档预览
中文文档
44 页
50 下载
1000 浏览
0 评论
309 收藏
3.0分
温馨提示:本文档共44页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
本文档由 人生无常 于 2026-06-07 00:25:04上传分享