|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/iso-27001-information-security-management-system-isms/
课程评论:没有评论
课程名称:ISO 27001:2013 信息安全管理系统 - ISMS 课程概述:本课程专注于ISO 27001:2013标准,介绍信息安全管理系统的基础知识。作为一门初学者课程,它将详细解释标准的各个条款及相应的控制措施,以确保合规,并提供标准在实际商业中应用的示例。这是一门良好的基础课程,有助于你建立对ISO 27001:2013标准的理解!该标准为质量管理实践提供指导,强调信息安全,无论是物理信息还是虚拟信息资产,均适用于当今各行业,尤其是在数字化程度日益提高的背景下。通过建立适当的系统,企业能够自信地迎接数字化转型,从而在国际市场上保持竞争力。然而,要有效地建立和维护该系统,需要对标准及其条款有深入的理解。若你希望达到这一目标,本课程将为你提供帮助。 课程大纲: 第一部分 > ISO 27001:2013的介绍、历史及一般概念 第二部分 > ISO 27001:2013的逐条指导 - 2-1部分 > 第1至3条 + 第4条:组织的背景 - 2-2部分 > 第5条:领导力 - 2-3部分 > 第6条:食品安全管理体系的规划 - 2-4部分 > 第7条:支持 - 2-5部分 > 第8条:操作 - 2-6部分 > 第9条:绩效评估 - 2-7部分 > 第10条:改进 - 2a部分 > ISO 27001:2013 附录A的逐条指导 - 2-8部分 > 附录A.5 信息安全政策 - 2-9部分 > 附录A.6 信息安全组织 - 2-10部分 > 附录A.7 人力资源安全 - 2-11部分 > 附录A.8 资产管理 - 2-12部分 > 附录A.9 访问控制 - 2-13部分 > 附录A.10 加密技术 - 2-14部分 > 附录A.11 物理和环境安全 - 2-15部分 > 附录A.12 操作安全 - 2-16部分 > 附录A.13 通信安全 - 2-17部分 > 附录A.14 系统采购、开发与维护 - 2-18部分 > 附录A.15 供应商关系 - 2-19部分 > 附录A.16 信息安全事件管理 - 2-20部分 > 附录A.17 商业连续性管理中的信息安全 - 2-21部分 > 附录A.18 合规性 第三部分 > 文件准备 第四部分 > 实施 第五部分 > 实施的验证 无课程大纲。
In this course, we look at the ISO 27001:2013 standard, regarding Information Security Management System. It is a beginner course, which provides an introduction to the standard, with explanations of all the various clauses and appropriate control measures to stay compliant, together with examples on how the standard may apply to a business. It is a good basic course to start with and build your understanding of the ISO 27001:2013 standard!This standard is a guideline for quality business practices, part of an organisation's Quality Management System (QMS). Specifically, it focuses on information security - be it in the form of physical, or virtual information assets. As such, it is applicable to all businesses in this day and age, where activities are increasingly digitalised.With a proper system in place, companies are able to embrace digital transformation confidently, thereby staying current and competitive internationally.Still, to know how to properly set up and keep this system in place, one needs to have a proper understanding of the standard, with its clauses. If you are looking to achieve this, here is a course that can help you.--Course Outline:Section 1 > Introduction, history and general concepts of ISO 27001:2013Section 2 > Clause-by-clause guidance for ISO 27001:2013Section 2-1 > Clause 1 to 3 + Clause 4: Context of the organisationSection 2-2 > Clause 5: LeadershipSection 2-3 > Clause 6: Planning for the Food Safety Management SystemSection 2-4 > Clause 7: SupportSection 2-5 > Clause 8: OperationsSection 2-6 > Clause 9: Performance EvaluationSection 2-7 > Clause 10: ImprovementSection 2a > Clause-by-clause guidance for ISO 27001:2013 Annex ASection 2-8 > Annex A.5 Information security policiesSection 2-9 > Annex A.6 Organisation of information securitySection 2-10 > Annex A.7 Human resource securitySection 2-11 > Annex A.8 Asset managementSection 2-12 > Annex A.9 Access controlSection 2-13 > Annex A.10 CryptographySection 2-14 > Annex A.11 Physical and environmental securitySection 2-15 > Annex A.12 Operations securitySection 2-16 > Annex A.13 Communications securitySection 2-17 > Annex A.14 System acquisition, development and maintenanceSection 2-18 > Annex A.15 Supplier relationshipsSection 2-19 > Annex A.16 Information security incident managementSection 2-20 > Annex A.17 Information security aspects of business continuity managementSection 2-21 > Annex A.18 ComplianceSections 3 > Preparation of DocumentationSection 4 > ImplementationSection 5 > Verification of your implementation