欢迎来到天天文库
浏览记录
ID:40556627
大小:1.30 MB
页数:23页
时间:2019-08-04
《IsoPolicy-v1.0-KPC ISMS Manual v1.0-科威特石油总公司信息安全管理体系手册》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、InformationSecurityManagementSystemContent:InformationSecurityManagementSystemManualOriginator:FahadAl-AnsariVersion:1.0Date:09May2007Confidentiality:ConfidentialReference:ISMSManualDateApproved:KuwaitPetroleumCorporationPetroleumTrainingCentre&CareerDevelopmentInformationSecurityManagementS
2、ystemManualInformationSecurityManagementSystemManualVersion1.004/12/2006Page22of23InformationSecurityManagementSystemConfidentialityStatementAllinformationcontainedinthisdocumentisconfidentialandiscontrolledunderasignedNonDisclosureAgreement.DistributionRoleNameOrganisationLocationNoofCopies
3、ConsultantNeilLunnissRedIslandConsultingLondon,UK1ProjectManagerNickRobertsRedIslandConsultingLondon,UK1SecurityLeadFahadAl-AnsariKPCAhmadi,Kuwait1ProjectManagerHussainSanasiriKPCAhmadi,Kuwait1AmendmentRecordIssueStatusVersionDateActionedByDescriptionDraft0.124/09/2006NeilLunnissInitialdraft
4、Draft0.204/12/2006NeilLunnissUpdateddraftbasedonRiskAssessmentresultsAuthorised1.009/05/2007NeilLunnissAuthorisedversionReferencesNrReferenceDocumentRefVersion1InformationTechnology–SecurityTechniques–InformationSecurityManagementSystems–RequirementsISO/IEC2700120052CodeofPracticeforInformat
5、ionSecurityManagementISO/IEC177992005InformationSecurityManagementSystemManualVersion1.004/12/2006Page22of23InformationSecurityManagementSystemTableofContents1InformationSecurityPolicyStatement42ISO/IEC27001:2005ISMSOverview52.1GeneralRequirements52.2EstablishtheISMS52.3ISMSPolicy52.4Managem
6、entFramework62.5SecurityCoordination62.6DepartmentManagementError!Bookmarknotdefined.2.7LegalRequirements73RiskAssessment83.1RiskAssessmentApproach83.2Identifytherisks83.3Analyseandevaluatetherisks93.3.1BusinessImpactAnalysis(BIA)93.3.2ThreatLevel93.3.3VulnerabilityandProbabilityAssessment.1
7、03.3.4RiskCalculation103.3.5RiskScore113.3.6RiskTreatment113.3.7ControlObjectivesandControlSelection123.3.8ResidualRisk123.3.9ContinuedAssessment124StatementofApplicability135Training&Awareness145.1Training,Awareness&Competence146Audit156.1AuditSch
此文档下载收益归作者所有