免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 3117 | 回复: 0
打印 上一主题 下一主题

ISO 27000 & BS7799-3: STANDARD IN TRANSITION [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2005-10-18 13:47 |只看该作者 |倒序浏览
________________________\r\n\r\nTHE ISO 17799 NEWSLETTER\r\n________________________\r\n\r\nWelcome to the eleventh issue of ISO 17799 News, designed to keep you abreast of news and developments with respect to ISO17799 and information security. \r\n\r\nThis edition is an \'Interview Special\', in that we have started what will be an occasional series of exclusive interviews with prime movers and influencers within the 17799 arena. These will hopefully provide a much better insight into the standard in terms of its development, its implementation, and its future.\r\n\r\n \r\n1) A STANDARD IN TRANSITION\r\n===========================\r\n\r\nMany people have questioned recent changes and proposed changes, with respect to both ISO 17799 and BS7799. With so much happening in a relatively short period, it was perhaps inevitable that confusion would arise. Hopefully, we can clarify this and explain how events are likely to unfold.\r\n\r\nEssentially we had an \'upgrade\' to ISO 17799 in June of this year. This has been published and is now current. This event was part of the normal sequence of events for standards, which do not tend to be static indefinitely. \r\n\r\nPerhaps the bigger changes, conceptually, are in the future. These are framed by the intention of re-numbering the standards so that they are sequentially aligned. ISO has set aside the numbers from ISO 27000 to support this. These are now specifically reserved for information security standards.\r\n\r\nThe current intention is as follows:\r\n\r\nISO 27001 \r\nThis will be the number given to the revision of the current BS7799-2 standard. This is the requirements document for an information security management system (ISMS). The current state of play is that the final draft has been available for comment for some time, and can indeed be purchased. The final published version is expected later in the year. \r\n\r\nISO 27002\r\nThis number is actually earmarked for ISO 17799 itself (ie: Security Techniques - The code of practice for information security management). At some point in the future, possibly with a revision, 17799 will become 27002. This change is not imminent.\r\n\r\nISO 27003\r\nThis is set aside for a new standard/document covering risk management.\r\n\r\nISO 27004\r\nThis number will be assigned to a standard covering Information Security Management Metrics and Measurements (how, what and when to measure ISMS processes and controls). It is not expected until 2007 at the earliest.\r\n\r\nISO 27005\r\nThis is likely to provide implementation guidelines, with a potential publication date of mid 2007. \r\n\r\nAs part of the overall process, a BS7799-3 standard is being developed, and has a planned publication date of the very end of this year, or early next year. It is expected that this will evolve into the above ISO 27005. \r\n\r\nFw from 17799 news.
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP