|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/iso-27001-network-communication-security-management/
课程评论:没有评论
课程名称:ISO 27001:2013/2022- 信息安全管理系统 课程概述:本课程主要讲解ISO 27001:2013标准,采用演示和语音讲解的形式。课程的开头将提供该标准的高层次概述,接着将详细讨论不同的条款和控制措施。课程内容将定期更新,深入探讨更多领域。到目前为止,已涵盖的内容包括:附录A控制:远程办公、资产管理、密码学和通信安全。该标准旨在创建一个信息管理系统(ISMS),其目标是保护数据的机密性和完整性,同时确保数据的可用性。此系统可适用于任何规模的组织,基于其他管理系统的核心高层结构。主要条款包括:组织的背景、领导力、规划、支持、运营、绩效评估和改进。 标准的第二部分涉及控制措施,这些控制措施列在附录A中,并分为不同类别,为组织提供了一套工具,以实现其管理系统的目标。虽然列表并不详尽,但了解附录A中提到的控制措施及其对组织的适用性或有用性是非常重要的。
This course is about ISO 27001:2013. The lecture style is presentation-with-voiceover. Firstly, I'll be explaining an overview of the standard at a high level. Then I will be discussing different clauses and controls in more detail. I'll be updating this course regularly to cover more and more areas in depth. Examining the curriculum content is going to help you understand the coverage.So far, I've covered:Annex A Control: TeleworkingAnnex A Control: Asset ManagementAnnex A Control: CryptographyAnnex A Control: Communication SecurityThis standard is about creating an Information Management System. The goal of an ISMS is to protect the confidentiality & integrity of data while ensuring availability. You can apply this system to any type of organization of any size. It's based on the same core high-level structure as other management systems. The main clauses include:Context of the organizationLeadershipPlanningSupportOperationPerformance EvaluationImprovementThe second part of the standard is about controls. They are listed in Annex A, and are grouped into different categories. They provide organizations with a set of tools that can be used to achieve the objectives of their management system. The list is not exhaustive and more controls do exist and can be implemented. Regardless, it's important to understand the controls mentioned in Annex A and determine if they are applicable or useful to your organization.