Files
nexus/wiki/concepts/ISO-27001.md

41 lines
1.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "ISO-27001"
type: concept
tags:
- Security-Framework
- Compliance
- Information-Security
last_updated: 2026-04-14
---
# ISO-27001
## Definition
国际认可的信息安全管理体系ISMS标准由国际标准化组织ISO和国际电工委员会IEC发布。ISO 27001 是企业信息安全管理的基准框架。
## OpenText Implementation
- 作为 OpenText 安全姿态框架Posture Framework的基础
- 2022 年更新,新增 11 个控制方面control aspects
- 支撑 [[Global Information Security Policy (GISP)]] 的框架基础
- 支撑 [[FedRAMP]] 等行业认证
## Key Controls
- 信息安全组织Information Security Organization
- 人力资源安全Human Resource Security
- 资产管理Asset Management
- 访问控制Access Control
- 加密Cryptography
- 物理与环境安全Physical and Environmental Security
- 操作安全Operations Security
- 通信安全Communications Security
- 系统获取、开发和维护System Acquisition, Development and Maintenance
- 供应商关系Supplier Relationships
- 信息安全事件管理Information Security Incident Management
- 业务连续性管理Business Continuity Management
- 合规性Compliance
## Connections
- [[Global Information Security Policy (GISP)]]:基于 ISO 27001 构建
- [[FedRAMP]]:基于 ISO 27001 之上
- [[OpenText]]:采用该标准的企业