ISO/IEC 27002:2022. Information security controls

所在平台: Udemy

课程主页: https://www.udemy.com/course/isoiec-27002-information-security-controls/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:ISO/IEC 27002:2022 信息安全控制 课程概述: 本课程详细介绍了ISO/IEC 27002:2022中的信息安全控制,旨在概述信息安全管理系统(ISMS)所需的93项控制措施。课程分为几个部分: 第一部分为介绍环节,呈现ISO/IEC 27000系列国际标准的概况,以及ISO/IEC 27002的定位和目的。这一部分提供了关于信息安全、网络安全和隐私等概念的定义,并解释ISMS的定义及其组成。 第二部分着重介绍ISO/IEC 27002中的37项组织控制措施,包括角色与责任、职责分离、威胁情报、项目管理中的信息安全、信息分类与标记、访问控制、信息转移、从信息安全角度看供应商关系、信息与通信技术持续性、个人信息保护和ISMS文档操作程序等。 第三部分关注于涉及为组织工作或代表组织的个人的安全控制(人力控制),涵盖内容包括背景审查、雇佣条款和条件、培训与意识提升、纪律程序及远程工作等方面。 接下来的部分讨论了针对物理安全的控制措施(物理控制),包括:保密区域、入门控制、清理办公桌与屏幕、存储介质、支持性设施及设备的安全重复使用和处置等。 第四部分涉及技术控制,包括终端设备的使用、数据掩码、信息删除、备份、密码学、日志记录、网络安全、安全开发、安全编码、测试信息保护、网络过滤、安全认证、源代码访问及特权工具程序使用等方面。 最后一部分提供有关ISO/IEC 27001和ISO/IEC 27002的认证信息,适用于组织和个人。 通过本课程,学员将能够深入了解ISO/IEC 27002框架下的信息安全控制,帮助构建和维护有效的信息安全管理系统。

课程评论(0条)

课程详情

This course details the information security controls in ISO/IEC 27002:2022.It is intended to provide an overview of the 93 controls required for an ISMS (Information Security Management System).The structure of the course includes an introductory section with a presentation of the ISO/IEC 27000 family of international standards, the position and the purpose of ISO/IEC 27002. The introductory section provides definitions for concepts like information security, cybersecurity and privacy and explains what is an ISMS and what it should consist of.The second section of the course details the 37 Organizational controls in ISO/IEC 27002 including: roles and responsibilities, duties segregation, threat intelligence, information security in project management, information classification and labelling, access control, information transfer, supplier relationships from an information security perspective, ICT continuity, privacy and protection of PII or documented operating procedures as part of an ISMS.Section three is about security controls that refer to the individuals working for or on behalf of the organization (People controls). It covers aspects like screening, terms and conditions of employment, training and awareness, disciplinary process or remote working.The next section includes controls that address physical security (Physical controls) including: secure areas, entry controls, clear desk and clear screen, storage media, supporting utilities or the secure re-use and disposal of equipment.Section number four covers Technological controls that refer to aspects like: the use of endpoint devices, data masking, information deletion, backup, cryptography, logging, networks security, secure development, secure coding, the protection of test information, web filtering, secure authentication, access to source code or the use of privileged utility programs.The final section of the course provides information on the certification to ISO/IEC 27001 and ISO/IEC 27002 for both organizations and individuals.

课程标签

0人关注该课程

主题相关的课程