标准编号:ISO/IEC 27005:2011
中文名称:信息技术 安全技术 信息安全风险管理
英文名称:Information technology — Security techniques — Information security risk management
发布日期:2011-06
标准范围
This International Standard provides guidelines for information security risk management.This International Standard supports the general concepts specified in ISO/IEC 27001 and is designed toassist the satisfactory implementation of information security based on a risk management approach.Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 andISO/IEC 27002 is important for a complete understanding of this International Standard.This International Standard is applicable to all types of organizations (e.g. commercial enterprises,government agencies, non-profit organizations) which intend to manage risks that could compromise theorganization’s information security.