GB/T 29246-2023 in English
VALIDInformation security technology—Information security management systems—Overview and vocabulary
- Issued on:2023-12-28
- Implemented on:2024-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$495.00
《GB/T 29246-2023信息安全技术 信息安全管理体系 概述和词汇》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准委。
Information security technology - Information security management systems - Overview and vocabulary
1 Scope
This document provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards.
This document is applicable to all types and sizes of organization (e.g. commercial enterprises, government agencies, not- for-profit organizations).
The terms and definitions provided in this document
—cover commonly used terms and definitions in the ISMS family of standards;
—do not cover all terms and definitions applied within the ISMS family of standards; and
—do not limit the ISMS family of standards in defining new terms for use.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
3.1
access control
means to ensure that access to assets is authorized and restricted based on business and security requirements (3.56)
3.2
attack
attempt to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset
3.3
audit
systematic, independent and documented process (3.54) for obtaining audit evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled
Note 1: An audit can be an internal audit (first party) or an external audit (second party or third party), and it can be a combined audit (combining two or more disciplines).
Note 2: An internal audit is conducted by the organization (3.50) itself, or by an external party on its behalf.
Note 3: “Audit evidence" and “audit criteria” are defined in ISO 19011:2018.
3.4
audit scope
extent and boundaries of an audit(3.3)
[Source: ISO 19011: 2018, 3.5, modified - the note has been deleted]
3.5
authentication
provision of assurance that a claimed characteristic of an entity is correct
3.6
authenticity
property that an entity is what it claims to be
3.7
availability
property of being accessible and usable on demand by an authorized entity
3.8
base measure
measure (3.42) defined in terms of an attribute and the method for quantifying it
Note: A base measure is functionally independent of other measures
[Source: ISO/IEC/IEEE 15939: 2017, 3.3, modified - Note 2 has been deleted]
3.9
competence
ability to apply knowledge and skills to achieve intended results
3.10
confidentiality
property that information is not made available or disclosed to unauthorized individuals, entities, or processes (3.54)
3.11
conformity
fulfilment of a requirement (3.56)
3.12
consequence
outcome of an event (3.21) affecting objectives (3.49)
Note 1: An event (3.21) can lead to a range of consequences.
Note 2: A consequence can be certain or uncertain and, in the context of information security (3.28), is usually negative.
Note 3: Consequences can be expressed qualitatively or quantitatively.
Note 4: Initial consequences can escalate through knock-on effects.
[Source: ISO Guide 73: 2009, 3.6.1.3, modified - Note 2 has been changed]
3.13
continual improvement
recurring activity to enhance performance (3.52)
3.14
control
measure that is modifying risk (3.61)
Note 1: Controls include any process (3.54), policy (3.53), device, practice, or other actions which modify risk (3.61).
Note 2: It is possible that controls not always exert the intended or assumed modifying effect.
[Source: ISO Guide 73: 2009, 3.8.1.1, modified - Note 2 has been changed]
3.15
control objective
statement describing what is to be achieved as a result of implementing controls (3.14)
3.16
correction
action to eliminate a detected nonconformity (3.47)
3.17
corrective action
action to eliminate the cause of a nonconformity (3.47) and to prevent recurrence
3.18
derived measure
measure (3.42) that is defined as a function of two or more values of base measures (3.8)
[Source: ISO/IEC/IEEE 15939: 2017, 3.8, modified – the note has been deleted]
3.19
documented information
information required to be controlled and maintained by an organization (3.50) and the medium on which it is contained
Note 1: Documented information can be in any format and media and from any source.
Note 2: Documented information can refer to
- the management system (3.41), including related processes (3.54);
- information created in order for the organization(3.50) to operate (documentation);
- evidence of results achieved (records).
3.20
effectiveness
extent to which planned activities are realized and planned results achieved
3.21
event
occurrence or change of a particular set of circumstances
Note 1: An event can be one or more occurrences, and can have several causes.
Note 2: An event can consist of something not happening.
Note 3: An event can sometimes be referred to as an “incident" or “accident”.
[Source: ISO Guide 73: 2009, 3.5.1.3, modified - Note 4 has been deleted]
3.22
external context
external environment in which the organization seeks to achieve its objectives (3.49)
Note: External context may include the following:
- the cultural, social, political, legal, regulatory, financial, technological, economic, natural and competitive environment, whether international, national, regional or local;
- key drivers and trends having impact on the objectives (3.49) of the organization (3.50);
- relationships with, and perceptions and values of, external stakeholders(3.37).
[Source: ISO Guide 73: 2009, 3.3.1.1]
3.23
governance of information security
system by which an organization's (3.50) information security (3.28) activities are directed and controlled
3.24
governing body
person or group of people who are accountable for the performance (3.52) and conformity (3.11) of the organization (3.50)
Note: The governing body can, in some jurisdictions, be a board of directors.
3.25
indicator
measure (3.42) that provides an estimate or evaluation

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 39204-2022 in English
Information security technology—Cybersecurity requirements for critical information infrastructure protection
2022-10-12 -

GB/T 28451-2023 in English
Information security technology—Technical specification for network intrusion prevention system
2023-05-23 -

GB/T 30272-2021 in English
Information security technology—Public key infrastructure—Testing and assessment of compliance with standards
2021-08-20 -

GB/Z 41288-2022 in English
Information security technology—Guidelines of cyber security protection for important industrial control system
2022-03-08 -

GB/T 41387-2022 in English
Information security technology—Smart home general security specification
2022-04-15 -

GB/T 35274-2023 in English
Information security technology—Security capability requirements for big data services
2023-08-06 -

GB/T 24364-2023 in English
Information security technology—Implementation guide for information security risk management
2023-05-23 -

GB/T 31167-2023 in English
Information security technology—Security guidance for cloud computing services
2023-05-23 -

GB/T 32914-2023 in English
Information security technology —Capability requirements of cybersecurity service
2023-09-07 -

GB/T 17902.1-2023 in English
Information technology―Security techniques―Digital signatures with appendix―Part 1:General
2023-03-17