Practici de implementare a cerințelor standardului internațional ISO/IEC 27001:2013 „Sisteme de management al securităţii informaţiei. Cerinţe”
Închide
Articolul precedent
Articolul urmator
860 16
Ultima descărcare din IBN:
2024-02-06 15:40
SM ISO690:2012
GUZUN, Mihail, FRIPTULEAC, Lilian, TARGON, Ion. Practici de implementare a cerințelor standardului internațional ISO/IEC 27001:2013 „Sisteme de management al securităţii informaţiei. Cerinţe”. In: Mediul strategic de securitate: tendinţe şi provocări, 18 mai 2017, Chișinău. Chișinău, Republica Moldova: Academia Militară a Forţelor Armate „Alexandru cel Bun”, 2017, pp. 136-146. ISBN 978-9975-3174-2-9.
EXPORT metadate:
Google Scholar
Crossref
CERIF

DataCite
Dublin Core
Mediul strategic de securitate: tendinţe şi provocări 2017
Conferința "Mediul strategic de securitate: tendinţe şi provocări"
Chișinău, Moldova, 18 mai 2017

Practici de implementare a cerințelor standardului internațional ISO/IEC 27001:2013 „Sisteme de management al securităţii informaţiei. Cerinţe”

Practices for implementing the requirements of the international standard ISO/IEC 27001: 2013 ”Information security mangement systems. Requirments”


Pag. 136-146

Guzun Mihail, Friptuleac Lilian, Targon Ion
 
Institutul de Dezvoltare a Societăţii Informaţionale, Î.S.
 
Proiecte:
 
Disponibil în IBN: 5 iunie 2018


Rezumat

Nowadays, there is necessary a systemic approach in the field of information protection. It is required for the sustainable development and stable continuity of an organization’s activity to ensure the availability, confidentiality and continued integrity of information resources. The ISO/IEC 27 000 family of standards represents a systematization of the best practices accumulated over the years in this field. The mentioned standards help organizations seeking to establish and continuously improve an information security management system. The paper describes the stages of design and implementation of an information security management system, based on the requirements of the international standard ISO/IEC 27001: 2013. There is a simultaneous application of some technical and organizational methods, aimed at regulating of various activities with a direct or indirect impact on security of the organization’s information resources. 

Cuvinte-cheie
ISO/IEC 27 000 family standards, security incident, SMSI audit and analysis, information security risk, risk identification,

management system, risk analysis, risk management