首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 EN ISO/IEC 27040:2016
到馆阅读
收藏跟踪
购买正版
Information technology - Security techniques - Storage security (ISO/IEC 27040:2015) 信息技术 - 安全技术 - 存储安全(ISO/IEC 27040:2015)
发布日期: 2016-08-24
实施日期: 2016-08-24
ISO/IEC 27040:2015提供了详细的技术指导,说明组织如何通过对数据存储安全的规划、设计、文档编制和实施采用经过充分验证和一致的方法来定义适当的风险缓解水平。存储安全适用于对存储信息的保护(安全),以及通过与存储相关的通信链路传输的信息的安全。存储安全包括设备和介质的安全、与设备和介质相关的管理活动的安全、应用程序和服务的安全,以及在设备和介质使用寿命期间和使用结束后与最终用户相关的安全。 存储安全与拥有、操作或使用数据存储设备、介质和网络的任何人都相关。这包括高级经理、存储产品和服务的收购方以及其他非技术性经理或用户,此外还包括对信息安全或存储安全、存储操作负有特定责任的经理和管理员,或负责组织的总体安全计划和安全策略制定的经理和行政人员。 它还与参与存储网络安全体系结构方面的规划、设计和实施的任何人员相关。 ISO/IEC 27040:2015提供了存储安全概念和相关定义的概述。它包括与典型存储场景和存储技术领域相关的威胁、设计和控制方面的指导。此外,它还提供了对其他国际标准和技术报告的参考,这些标准和报告阐述了可应用于存储安全的现有做法和技术。
ISO/IEC 27040:2015 provides detailed technical guidance on how organizations can define an appropriate level of risk mitigation by employing a well-proven and consistent approach to the planning, design, documentation, and implementation of data storage security. Storage security applies to the protection (security) of information where it is stored and to the security of the information being transferred across the communication links associated with storage. Storage security includes the security of devices and media, the security of management activities related to the devices and media, the security of applications and services, and security relevant to end-users during the lifetime of devices and media and after end of use. Storage security is relevant to anyone involved in owning, operating, or using data storage devices, media, and networks. This includes senior managers, acquirers of storage product and service, and other non-technical managers or users, in addition to managers and administrators who have specific responsibilities for information security or storage security, storage operation, or who are responsible for an organization's overall security program and security policy development. It is also relevant to anyone involved in the planning, design, and implementation of the architectural aspects of storage network security. ISO/IEC 27040:2015 provides an overview of storage security concepts and related definitions. It includes guidance on the threat, design, and control aspects associated with typical storage scenarios and storage technology areas. In addition, it provides references to other International Standards and technical reports that address existing practices and techniques that can be applied to storage security.
分类信息
关联关系
研制信息
归口单位: CEN/SS F12-
相似标准/计划/法规
现行
DIN EN ISO/IEC 27040
Information technology - Security techniques - Storage security (ISO/IEC 27040:2015)
信息技术.安全技术.存储安全(ISO/IEC 27040-2015)
2017-03-01
现行
EN ISO/IEC 27017-2021
Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2015)
信息技术 - 安全技术 - 基于ISO/IEC 27002云服务的信息安全控制实践规范(ISO/IEC 27017:2015)
2021-01-20
现行
EN ISO/IEC 27043-2016
Information technology - Security techniques - Incident investigation principles and processes (ISO/IEC 27043:2015)
信息技术 - 安全技术 - 事故调查原则和流程(ISO/IEC 27043:2015)
2016-08-24
现行
BS 12/30209825 DC
BS ISO/IEC 27014. Information technology. Security techniques. Governance of information security
BS ISO/IEC 27014 信息技术 安全技术 信息安全治理
2012-01-10
现行
BS 12/30192064 DC
BS ISO/IEC 27001. Information technology. Security techniques. Information security management systems. Requirements
BS ISO/IEC 27001 信息技术 安全技术 信息安全管理系统 要求
2013-01-21
现行
BS 12/30186137 DC
BS ISO/IEC 27002. Information technology. Security techniques. Code of practice for information security controls
BS ISO/IEC 27002 信息技术 安全技术 信息安全控制实施规程
2013-01-21
现行
DIN EN ISO/IEC 27043
Information technology - Security techniques - Incident investigation principles and processes (ISO/IEC 27043:2015)
信息技术.安全技术.事件调查原则和过程(ISO/IEC 27043-2015)
2016-12-01
现行
EN ISO/IEC 27042-2016
Information technology - Security techniques - Guidelines for the analysis and interpretation of digital evidence (ISO/IEC 27042:2015)
信息技术 - 安全技术 - 数字证据分析和解释指南(ISO/IEC 27042:2015)
2016-08-24
现行
ISO/IEC TR 27103-2018
Information technology — Security techniques — Cybersecurity and ISO and IEC Standards
信息技术 安全技术 网络安全和ISO和IEC标准
2018-02-22
现行
AS/NZS ISO/IEC 27005-2012
Information technology - Security techniques -Information security risk management (ISO/IEC 27005:2011, MOD)
信息技术.安全技术.信息安全风险管理(ISO/IEC 27005-2011 MOD)
2012-06-29
现行
UNE-ISO/IEC 27001-2007
Information technology. Security techniques. Information security management systems. Requirements. (ISO/IEC 27001:2005)
信息技术 安全技术 信息安全管理系统 要求 (ISO/IEC 27001-2005)
2007-11-28
现行
DIN EN ISO/IEC 27042
Information technology - Security techniques - Guidelines for the analysis and interpretation of digital evidence (ISO/IEC 27042:2015)
信息技术.安全技术.数字证据的分析和解释指南(ISO/IEC 27042-2015)
2016-12-01
现行
AS ISO/IEC 27011-2017
Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for telecommunications organizations
信息技术.安全技术.基于 ISO/IEC 27002 电信组织
2017-05-11
现行
BS 10/30168681 DC
BS ISO/IEC 29100. Information technology. Security techniques. Privacy framework
BS ISO/IEC 29100 信息技术 安全技术 隐私框架
2010-11-15
现行
EN ISO/IEC 27011-2020
Information technology - Security techniques - Code of practice for Information security controls based on ISO/IEC 27002 for telecommunications organizations (ISO/IEC 27011:2016)
信息技术 - 安全技术 - 基于ISO/IEC 27002的电信组织信息安全控制实践规范(ISO/IEC 27011:2016)
2020-05-27
现行
KS X ISO/IEC 27007(2019 Confirm)
정보기술 — 보안기술 — 정보보호 경영시스템 심사에 관한 가이드라인
信息技术 - 安全技术 - 信息安全管理体系审核指南(ISO/IEC 27007:2011)
2014-12-12
现行
ISO/IEC 27003-2017
Information technology — Security techniques — Information security management systems — Guidance
信息技术 - 安全技术 - 信息安全管理体系实施指南(ISO/IEC 27003:2010)
2017-04-12
现行
BS 08/30133461 DC
BS ISO/IEC 27003. Information technology. Security techniques. Information security management system implementation guidance
BS ISO/IEC 27003 信息技术 安全技术 信息安全管理体系实施指南
2008-11-18
现行
ITU-T X.1051
Information technology - Security techniques - Information security management guidelines for telecommunications organizations based on ISO/IEC 27002
信息技术.安全技术.基于ISO/IEC 27002的电信组织信息安全管理指南
2008-02-13
现行
BS 08/30146238 DC
BS ISO/IEC 27000. Information technogy. Security techniques. Information security management system. Overview and vocabulary
BS ISO/IEC 27000 信息技术 安全技术 信息安全管理系统 概述和词汇
2008-06-09