标准编号:ISO/IEC 27002:2013
中文名称:信息技术 安全技术 信息安全控制实用规则
英文名称:Information technology — Security techniques — Code of practice for information security controls
发布日期:2013-10
标准范围
This International Standard gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization’s information security risk environment(s).This International Standard is designed to be used by organizations that intend to:a) select controls within the process of implementing an Information Security Management System based on ISO/IEC 27001;[10]b) implement commonly accepted information security controls;c) develop their own information security management guidelines.