GB/T 31496-2015 in English
SUPERSEDEDInformation technology―Security techniques―Information security management system implementation guidance
- Issued on:2015-05-15
- Implemented on:2016-01-01
- File Format:PDF
- Delivery:Via email within 5 business days
$670.00
《GB/T 31496-2015信息技术 安全技术 信息安全管理体系实施指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
本标准依据 GB/T22080―2008,关注设计和实施一个成功的信息安全管理体系(ISMS)所需要的
关键方面。本标准描述了ISMS规范及其设计的过程,从开始到产生实施计划。本标准为实施ISMS
描述了获得管理者批准的过程,为实施ISMS定义了一个项目(本标准称作ISMS项目),并就如何规划
该ISMS项目提供了相应的指导,产生最终的ISMS项目实施计划。
本标准可供实施一个ISMS的组织使用,适用于各种规模和类型的组织(例如,商业企业、政府机
构、非赢利组织)。每个组织的复杂性和风险都是独特的,并且其特定的要求将驱动ISMS的实施。小
型组织将发现,本标准中所提及的活动可适用于他们,并可进行简化。大型组织或复杂的组织可能会发
现,为了有效地管理本标准中的活动,需要层次化的组织架构或管理体系。然而,无论是大型组织还是
小型组织,都可应用本标准来规划相关的活动。
本标准提出了一些建议及其说明,但并没有规定任何要求。期望把本标准与 GB/T22080―2008
和 GB/T22081―2008一起使用,但不期望修改和/或降低 GB/T22080―2008中所规定的要求,或修
改和/或降低 GB/T22081―2008所提供的建议。因此,不宜声称符合这一标准。
Scope
This standard is based on GB/T 22080-2008 and focuses on the key aspects needed to design and implement a successful information security management system (ISMS). This International Standard describes the ISMS specification and the process for its design, from inception to the generation of an implementation plan. This standard describes the process of obtaining management approval for the implementation of ISMS, defines a project for the implementation of ISMS (this standard is called ISMS project), and provides corresponding guidance on how to plan the ISMS project, resulting in the final ISMS project implementation plan . This International Standard can be used by organizations implementing an ISMS, and is applicable to organizations of all sizes and types (eg, commercial enterprises, government agencies, not-for-profit organizations). Every organization is unique in its complexity and risks, and its specific requirements will drive the implementation of an ISMS. Smaller organizations will find that the activities mentioned in this standard are applicable to them and can be simplified. Large or complex organizations may find that a hierarchical organizational structure or management system is required in order to effectively manage the activities covered by this International Standard. However, both large and small organizations can apply this International Standard to plan related activities. This standard makes some recommendations and clarifications, but does not specify any requirements. It is expected to use this standard together with GB/T 22080-2008 and GB/T 22081-2008, but it is not expected to modify and/or reduce the requirements specified in GB/T 22080-2008, or to modify and/or reduce GB/T 22081-2008 provides advice. Therefore, it is inappropriate to claim compliance with this standard.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 31495.1-2015 in English
Information security technology―Indicator system of information security assurance and evaluation methods―Part 1:Concepts and model
2015-05-15 -

GB/T 38540-2020 in English
Information security technology—Technical specification secure electronic seal signature cryptography
2020-03-06 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 29241-2012 in English
Information security technology—Public key infrastructure—PKI interoperability evaluation criteria
2012-12-31 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 38249-2019 in English
Information security technology—Security guide of cloud computing services for government website
2019-10-18 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10