欢迎来到三一文库! | 帮助中心 三一文库31doc.com 一个上传文档投稿赚钱的网站
三一文库
全部分类
  • 幼儿/小学教育>
  • 中学教育>
  • 高等教育>
  • 研究生考试>
  • 外语学习>
  • 资格/认证考试>
  • 论文>
  • IT计算机>
  • 法律/法学>
  • 建筑/环境>
  • 通信/电子>
  • 医学/心理学>
  • ImageVerifierCode 换一换
    首页 三一文库 > 资源分类 > DOCX文档下载
    分享到微信 分享到微博 分享到QQ空间

    ISOIEC 27031 2025.docx

    • 资源ID:107692       资源大小:160.24KB        全文页数:36页
    • 资源格式: DOCX        下载积分:5
    快捷下载 游客一键下载
    账号登录下载
    微信登录下载
    三方登录下载: 微信开放平台登录 QQ登录 微博登录
    二维码
    微信扫一扫登录
    下载资源需要5
    邮箱/手机:
    温馨提示:
    快捷下载时,用户名和密码都是您填写的邮箱或者手机号,方便查询和重复下载(系统自动生成)。
    如填写123,账号就是123,密码也是123。
    支付方式: 支付宝    微信支付   
    验证码:   换一换

    加入VIP免费专享
     
    账号:
    密码:
    验证码:   换一换
      忘记密码?
        
    友情提示
    2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
    3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
    4、本站资源下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。
    5、试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。

    ISOIEC 27031 2025.docx

    1、IECInternationalStandardISO/IEC27031Secondedition2025-05CybersecurityInformationandcommunicationtechnologyreadinessforbusinesscontinuityCybersecuritePreparationdestechnologiesdeinformationetdelacommunicationpourlacontinuitedactiviteReferencenumberISO/IEC27031:2025(en)COPYRIGHTPROTECTEDDOCUMENTISO/IE

    2、C2025Allrightsreserved.Unlessotherwisespecified,orrequiredinthecontextofitsimplementation,nopartofthispublicationmaybereproducedorutilizedotherwiseinanyformorbyanymeans,electronicormechanical,includingphotocopying,orpostingontheinternetoranintranet,withoutpriorwrittenpermission.Permissioncanbereques

    3、tedfromeitherISOattheaddressbeloworISO,smemberbodyinthecountryoftherequester.ISOcopyrightofficeCP401Ch.deBlandonnet8CH-1214Vernier,GenevaPhone:+4122749Ol11Email:copyrightiso.orgWebsite:www.iso.orgPublishedinSwitzerlandContentsPageForewordvIntroductionvi1 Scope12 Normativereferences13 Termsanddefinit

    4、ions14 Abbreviatedterms35 Structureofthisdocument35.1 General36 IntegrationofIRBCintoBCM36.1 General36.2 Enablinggovernance46.3 Businesscontinuitymanagementobjectives56.4 RiskmanagementandapplicablecontrolsforIRBC66.5 IncidentmanagementandrelationshiptoIRBC66.6 BCMstrategiesandalignmenttoIRBC67 Busi

    5、nessexpectationsforIRBC77.1 Riskreview77.1.1 General77.1.2 Monitoring,detectionandanalysisofthreatsandevents87.2 Inputsfrombusinessimpactanalysis87.2.1 General87.2.2 UnderstandingcriticalICTservices87.2.3 AssessingICTreadinessagainstbusinesscontinuityrequirements97.3 Coverageandinterfaces97.3.1 Gene

    6、ral97.3.2 ICTdependenciesforthescope107.3.3 Determineanycontractualaspectsofdependencies108 DefiningprerequisitesforIRBC108.1 Incidentbased-preparationbeforeincident108.1.1 General108.1.2 ICTRecoverycapabilities118.1.3 EstablishinganIRBC118.1.4 Settingobjectives118.1.5 Determiningpossibleoutcomesand

    7、benefitsofIRBC128.1.6 Equipmentredundancyplanning138.1.7 DeterminingthescopeofICTservicesrelatedtotheobjectives138.2 DeterminingtargetICTRTOandRPO149 DeterminingIRBCstrategies159.1 General159.2 IRBCstrategyoptions159.2.1 General159.2.2 Skillsandknowledge169.2.3 Facilities169.2.4 Technology179.2.5 Da

    8、ta179.2.6 Processes189.2.7 Suppliers1810 DeterminingtheICTcontinuityplan1910.1 Prerequisitesforthedevelopmentofplans1910.1.1 Determiningandsettingtherecoveryorganization1910.1.2 Determiningtimeframesforplandevelopment,reportingandtesting1910.1.3 Resources2010.1.4 CompetencyofIRBCstaff.2010.1.5 Techn

    9、ologicalsolutions2110.2 Recoveryplanactivation2110.2.1 ICTBCPActivation2110.2.2 Escalation2110.3 ICTrecoveryplans2210.3.1 RPOandRTOplansforICT2210.3.2 Facilities2210.3.3 Technology2210.3.4 Data2210.3.5 Responseandrecoveryprocedures2310.3.6 People2310.4 Temporaryworkaroundplans2310.5 Externalcontacts

    10、andprocedures2311 Testing,exercise,andauditing2311.1 Performancecriteria2311.2 Testingdependencies2411.2.1 Testandexercise2411.2.2 Testandexerciseprogram2411.2.3 Scopeofexercises2511.2.4 Planninganexercise2511.2.5 Alertbasedanddifferentrecoverystages2611.2.6 Managinganexercise2711.3 Learningfromtest

    11、s2811.4 AuditingtheIRBC2811.5 Controlofdocumentedinformation2912 FinalMBCO2913 TopmanagementresponsibilitiesregardingevaluatingtheIRBC2913.1 General2913.2 Managementresponsibilities29Annex A (informative)ComparingRTOandRPOtobusinessobjectivesforICTrecovery31Annex B (informative)RiskreportingforFMEA3

    12、2Bibliography33ForewordISO(theInternationalOrganizationforStandardization)andIEC(theInternationalElectrotechnicalCommission)formthespecializedsystemforworldwidestandardization.NationalbodiesthataremembersofISOorIECparticipateinthedevelopmentofInternationalStandardsthroughtechnicalcommitteesestablish

    13、edbytherespectiveorganizationtodealwithparticularfieldsoftechnicalactivity.ISOandIECtechnicalcommitteescollaborateinfieldsofmutualinterest.Otherinternationalorganizations,governmentalandnon-governmentabinliaisonwithISOandIEC,alsotakepartinthework.Theproceduresusedtodevelopthisdocumentandthoseintende

    14、dforitsfurthermaintenancearedescribedintheISO/IECDirectives,Part1.Inparticular,thedifferentapprovalcriterianeededforthedifferenttypesofdocumentshouldbenoted.ThisdocumentwasdraftedinaccordancewiththeeditorialrulesoftheISO/IECDirectives,Part2(seeWWW.iso.org/directivesorwww.iec.ch/membersexpvrtsrefdocs

    15、).ISOandIECdrawattentiontothepossibilitythattheimplementationofthisdocumentmayinvolvetheuseof(八)patent(三).ISOandIECtakenopositionconcerningtheevidence,validityorapplicabilityofanyclaimedpatentrightsinrespectthereof.Asofthedateofpublicationofthisdocument,ISOandIEChadnotreceivednoticeof(八)patent(三)whi

    16、chmayberequiredtoimplementthisdocument.However,Implementersarecautionedthatthismaynotrepresentthelatestinformation,whichmaybeobtainedfromthepatentdatabaseavailableatWWW.isoorg/patentsandhttps:PatentS.iec.ch.ISOandIECshallnotbeheldresponsibleforidentifyinganyorallsuchpatentrights.Anytradenameusedinth

    17、isdocumentisinformationgivenfortheconvenienceofusersanddoesnotconstituteanendorsement.Foranexplanationofthevoluntarynatureofstandards,themeaningofISOspecifictermsandexpressionsrelatedtoconformityassessment,aswellasinformationaboutISOsadherencetotheWorldTradeOrganization(WTO)principlesintheTechnicalB

    18、arrierstoTrade(TBT)seeWWW.iso.org/iso/foreword.htmLIntheIEC,seeWWW.iecchundvrstanding-standards.ThisdocumentwaspreparedbyJointTechnicalCommitteeISO/IECJTC1,Informationtechnology,SubcommitteeSC27,Informationsecurity,cybersecurityandprivacyprotection.Thissecondeditioncancelsandreplacesthefirstedition(

    19、ISO/IEC27031:2011),whichhasbeentechnicallyrevised.Themainchangesareasfollows:一thestructureofthedocumenthasbeenchanged;一thescopehasbeenchangedforclarification;一technicalcontenthasbeenaddedin6.4,656.6,9.2and10.1.5.Anyfeedbackorquestionsonthisdocumentshouldbedirectedtotheusersnationalstandardsbody.Acom

    20、pletelistingofthesebodiescanbefoundatWWW.isoQrgmDmbers.htmlandWWW.iecchnational-committees.IntroductionOvertheyears,informationandcommunicationtechnology(ICT)hasbecomeanintegralpartofmanyoftheactivitieswithinthecriticalinfrastructuresinallorganizationalsectors,whetherpublicorprivate.Theproliferation

    21、oftheinternetandotherelectronicnetworkingservices,aswellasthecapabilitiesofsystemsandapplications,hasalsoresultedinorganizationsbecomingmorereliantonreliable,safeandsecureICTinfrastructures.Meanwhile,theneedforbusinesscontinuitymanagement(BCM),includingincidentpreparedness,disasterrecoveryplanning,a

    22、ndemergencyresponseandmanagement,hasbeenrecognizedandsupportedwiththedevelopmentandendorsementofspecificdomainsofknowledge,expertise,andstandards,includingISO22313.FailuresofICTservices,includingthosecausedbysecurityissuessuchassystemsintrusionandmalwareinfections,impactthecontinuityofbusinessoperat

    23、ions.Thus,managingICTandrelatedcontinuity,aswellasothersecurityaspects,formakeypartofbusinesscontinuityrequirements.Furthermore,inthemajorityofcases,thecriticalprocessesandactivitiesthatrequirebusinesscontinuityareusuallydependentuponICT.ThisdependencemeansthatdisruptionstoICTcanconstitutestrategicr

    24、iskstothereputationoftheorganizationanditsabilitytooperate.TheadventandincreasingdominanceofInternet-basedICTservices(cloudICTservices)hascausedthenatureofpreparednesstochangefromrelyingoninternalprocessestoarelianceonthequalityandrobustnessofservicesfromotherorganizationsandtheassociatedbusinessrel

    25、ationshipswithsuchorganizations.ICTreadinessisanessentialcomponentformanyorganizationsintheimplementationOfbusinesscontinuitymanagementandinformationsecuritymanagement.Asaresult,effectiveBCMisfrequentlydependentuponeffectiveICTreadinesstoensurethattheorganizationsobjectivescancontinuetobemetduringdi

    26、sruptions.ThisisparticularlyimportantastheconsequencesofdisruptionstoICToftenhavetheaddedcomplicationofbeinginvisibleordifficulttodetect.ForanorganizationtoachieveICTreadinessforbusinesscontinuity(IRBC),itshouldputinplaceasystematicprocesstoprevent,predictandmanageICTdisruptionsandincidentswhichhave

    27、thepotentialtodisruptICTservices.ThiscanbeachievedbycoordinatingIRBCwiththeinformationsecurityandBCMprocesses.Inthisway,IRBCsupportsBCMbyensuringthattheICTservicescanberecoveredtopredeterminedlevelswithintimescalesrequiredandagreedbytheorganization.Ifanorganizationisusingrelevantinformationsecuritya

    28、ndbusinesscontinuitystandards,theestablishmentofIRBCshouldpreferablytakeintoconsiderationexistingorintendedprocesseslinkedtothesestandards.ThislinkagecansupporttheestablishmentofIRBCandalsoavoidanydualprocessesfortheorganization.ThisdocumentdescribestheconceptsandprinciplesofICTreadinessforbusinessc

    29、ontinuity(IRBC)andprovidesaframeworkofmethodsandprocessestoidentifyandspecifyaspectsforimprovinganorganizationsICTreadinesstoensurebusinesscontinuity.ThisdocumentcomplementstheinformationsecuritycontrolsrelatingtobusinesscontinuityinISO/IEC27002.Italsosupportstheinformationsecurityriskmanagementproc

    30、essspecifiedinISO/IEC27005.BaseduponICTreadinessobjectives,thisdocumentalsoextendsthepracticesofinformationsecurityincidentmanagementintoICTreadinessplanning,trainingandoperation.CybersecurityInformationandcommunicationtechnologyreadinessforbusinesscontinuity1 ScopeThisdocumentdescribestheconceptsan

    31、dprinciplesofinformationandcommunicationtechnology(ICT)readinessforbusinesscontinuity(IRBC).ItprovidesaframeworkofmethodsandprocessestoidentifyandspecifyaspectsforimprovinganorganizationsICTreadinesstoensurebusinesscontinuity.ThisdocumentservesthefollowingbusinesscontinuityobjectivesforICT:一minimumb

    32、usinesscontinuityobjective(MBCO),一recoverypointobjective(RPO),recoverytimeobjective(RTo)aspartoftheICTbusinesscontinuityplanning.Thisdocumentisapplicabletoalltypesandsizesoforganizations.ThisdocumentdescribeshowICTdepartmentsplanandpreparetocontributetotheresilienceobjectivesoftheorganization.2 Norm

    33、ativereferencesThefollowingdocumentsarereferredtointhetextinsuchawaythatsomeoralloftheircontentconstitutesrequirementsofthisdocument.Fordatedreferences,onlytheeditioncitedapplies.Forundatedreferences,thelatesteditionofthereferenceddocument(includinganyamendments)applies.ISO/IEC27000,Informationtechn

    34、ologySecuritytechniquesInformationsecuritymanagementsystemsOverviewandvocabularyISO/IEC27002,Informationsecurity,cybersecurityandprivacyprotectionInformationsecuritycontrolsISO/IEC27005,Informationsecurity,cybersecurityandprivacyprotectionGuidanceonmanaginginformationsecurityrisksISO/IEC27035-1:2023

    35、InformationtechnologyInformationsecurityincidentmanagementPart1:PrinciplesandprocessISO22300,SecurityandresilienceVocabularyISO22301,SecurityandresilienceBusinesscontinuitymanagementsystemsRequirements3 TermsanddefinitionsForthepurposesofthisdocument,thetermsanddefinitionsgiveninISO/IEC27000,ISO/IE

    36、C27002,ISO/IEC27005JSOIEC27035-LISO22300JSO223OLandthefollowingapply.ISOandIECmaintainterminologydatabasesforuseinstandardizationatthefollowingaddresses:一ISOOnlinebrowsingplatform:availableathttps:WWW.iso.org/obp一IECElectropedia:availableathttps:WWW.electropedia.org/3.1failuremodemannerbywhichafailu

    37、reisobservedNote1toentry:Thisgenerallydescribesthewayfailureoccursanditsimpactontheoperationofthesystem.3.2informationandcommunicationtechnologydisasterrecoveryabilityoftheinformationandcommunicationtechnologyelementsofanorganizationtosupportitscriticalprocessesandactivitiestoanacceptablelevelwithin

    38、apredeterminedperiodoftimefollowingadisruption3.3informationandcommunicationtechnologyreadinessstateofaninformationandcommunicationtechnology(ICT)functioninwhichithastheknowledge,skills,processes,architecture,infrastructureandtherelatedtechnologiesinpreparationforapotentialeventthatwouldleadtoeither

    39、anintolerabledisruptionofICToranintolerabledatalossNote1toentry:ThisdoesnotmeanthattheICTfunctionisallknowingandabletodoeverything,butratheritisfitforpurposeandinreadinessforthepreparation,theresponseandtherecoveryathand,ifsuchacontingencyoccurs.3.4minimumbusinesscontinuityobjectiveMBCOminimumlevelo

    40、fservicesand/orproductsthatisacceptabletotheorganizationtoachieveitsbusinessobjectivesduringadisruption3.5recoverypointobjectiveRPOpointtowhichinformationusedbyanactivityisrestoredtoenabletheactivitytooperateonresumptionNote1toentry:Canalsobereferredtoas“maximumdataloss.3.6recoverytimeobjectiveRTOpe

    41、riodoftimefollowinganincidentwithinwhichaproductandserviceoranactivityisresumed,orresourcesarerecovered3.7restorationlevelofrecoveryofdata,ICTsystemsandbusinessoperationstothenormalstateafteradisruptionwithaminimalloss,ifany3.8triggereventthatcausesthesystemtoinitiatearesponseNote1toentry:Alsoknowna

    42、striggeringevent.4 AbbreviatedtermsBCPbusinesscontinuityplanBIAbusinessimpactanalysisHVACheating,ventilationandair-conditioningICTinformationandcommunicationtechnologyIRBCICTreadinessforbusinesscontinuityMBCOminimumbusinesscontinuityobjectiveRPOrecoverypointobjectiveRTOrecoverytimeobjective5 Structu

    43、reofthisdocument5.1 GeneralTheintentionofeachclauseofthisdocumentisasfollows:一ClaUSe6explainshowIRBCislinkedtoBCMandotherorganizationalprocessesthatarerelatedtoIRBC;一ClaUSe7explainshowthebusinesscontinuityfortheorganizationsetsobjectivesthatIRBCshouldtrytomeet;一ClaUSe8providesguidanceonwhatisneededt

    44、odefinetheICTcurrentcharacteristicsthataffecttheIRBC;一ClaUSe9providesguidanceondifferentstrategiesthatcanbeusedandshouldbedeterminedforIRBCpendingtheobjectivesandcurrentcharacteristicsofICTthatICTcontinuityplansshouldfollow;一ClaUSe10providesguidanceonhowtodesignICTcontinuityplansbasedondeterminedstr

    45、ategiesandhowtoaddressdifferenttypesofadversesituationstomeetthecontinuityobjectivesforICT;一ClaUSe11providesguidanceonhowtotestandfinalizetheICTcontinuityplans;一ClaUSe12providesguidanceonhowtoestablishfinalRPOsandRTOsbasedontheICTcontinuityplansanddeterminetheabilitytomeetthebusinessrequirements;一Cl

    46、aUSe13providesguidanceonthefeedbackofIRBCtotopmanagementtoapprovetheplansorrisktreatmentdecisions,ifthebusinessobjectiveshavenotbeenmet.SpecificplanningandverificationsofICTareinstrumentaltobuildandensurethatICTcanfaceevents.Withoutsuchreadiness,theorganizationwouldsufferintolerabledisruptionsofprio

    47、ritisedactivitiesordatalosses.Suchevents,potentiallycomingfromtechnicalfailuresorcybersecurityincidents,shouldmotivatetheICTfunctiontointerfaceitsgovernance,planningandoperationwithrequirementscomingfromthedecisionmakingactivityofbusinesscontinuitymanagementandinformationsecuritymanagement.6 Integra

    48、tionofIRBCintoBCM6.1 GeneralDisruptionrelatedriskwithininformationsecurityandICTprimarilyrelatestoavailabilitywhenanadversesituationoccursthatdisruptstheavailabilityofICTservicestobusinessactivities.Therelatedriskshavethecharacteristicsofverylowlikelihood,meaningthattheycanhappenveryrarelyorevennever,but


    注意事项

    本文(ISOIEC 27031 2025.docx)为本站会员(奥沙丽水)主动上传,三一文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三一文库(点击联系客服),我们立即给予删除!




    宁ICP备18001539号-1

    三一文库
    收起
    展开