Example: dental hygienist

ISO 27002:2013 Version Change Summary - …

Information Shield Information security Policies Made Easy ISO 27002 : 2013 Version Change Summary This table highlights the control category changes between ISO 27002 :2005 and the 2013 update. Changes are color coded. Control Category Change Key Change Map Key Control Removed Minimum Changes to Domain Control Moved or Renamed Several key changes to Domain Control Added (new outline) Major changes to Domain Change 2005 Control Category 2013 Control Category LOW 5 security POLICY 5 IFNORMATION security POLICIES INFORMATION security POLICY Management direction for information security Information security policy document Policies for information security Review of the information security policy Review of the policies for information security MED 6 ORGANIZATION OF INFORMATION security 6 ORGANIZATION OF INFORMATION security INTERNAL ORGANIZATION Internal organization Management commitment to information security (Removed) Information security co-ordination (removed) Allocation of information security responsibilities.

Information Shield www.informationshield.com 888.641.0500 sales@informationshield.com Information Security Policies Made Easy ISO 27002:2013 Version Change Summary

Tags:

  Security, Change, 2013, Summary, Version, 27002, Iso 27002, 2013 version change summary

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of ISO 27002:2013 Version Change Summary - …

1 Information Shield Information security Policies Made Easy ISO 27002 : 2013 Version Change Summary This table highlights the control category changes between ISO 27002 :2005 and the 2013 update. Changes are color coded. Control Category Change Key Change Map Key Control Removed Minimum Changes to Domain Control Moved or Renamed Several key changes to Domain Control Added (new outline) Major changes to Domain Change 2005 Control Category 2013 Control Category LOW 5 security POLICY 5 IFNORMATION security POLICIES INFORMATION security POLICY Management direction for information security Information security policy document Policies for information security Review of the information security policy Review of the policies for information security MED 6 ORGANIZATION OF INFORMATION security 6 ORGANIZATION OF INFORMATION security INTERNAL ORGANIZATION Internal organization Management commitment to information security (Removed) Information security co-ordination (removed) Allocation of information security responsibilities.

2 Information security roles and responsibilities Segregation of duties (moved) Segregation of duties (Moved) Contact with authorities Contact with authorities Contact with special interest groups Contact with special interest groups Independent review of information security (moved) Information security in project management (New) MOBILE COMPUTING AND TELEWORKING (Moved) Mobile devices and teleworking Mobile computing and communications Mobile device policy Teleworking Teleworking LOW 8 Human Resource security 7 Human Resource security PRIOR TO EMPLOYMENT Prior to employment Roles and responsibilities (Removed) Screening Screening Terms and conditions of employment Terms and conditions of employment DURING EMPLOYMENT During employment Management responsibilities - Management responsibilities Information security awareness, education, and training - Information security awareness, education and training Disciplinary process Disciplinary process TERMINATION OR Change OF EMPLOYMENT Termination and Change of employment Termination responsibilities Termination or Change of employment responsibilities MED 7 Asset Management 8 Asset management RESPONSIBILITY FOR ASSETS.

3 Responsibility for assets Inventory of assets Inventory of assets Ownership of assets Ownership of assets Acceptable use of assets Acceptable use of assets Return of assets (moved) Return of assets INFORMATION CLASSIFICATION Information classification Classification guidelines Classification of information Information labeling and handling Labeling of information Handling of assets (New) MEDIA HANDLING (Moved) Media handling Management of removable media Management of removable media Disposal of media Disposal of media Information handling procedures Physical media transfer security of system documentation (Removed) HIGH 11 ACCESS CONTROL 9 ACCESS CONTROL BUSINESS REQUIREMENT FOR ACCESS CONTROL Business requirements of access control Access control policy Access control policy Access to networks and network services USER ACCESS MANAGEMENT.

4 User access management User registration User registration and de-registration User access provisioning Privilege management Management of privileged access rights User password management (moved) Management of secret authentication information of users Review of user access rights Review of user access rights Removal of access rights (Moved) Removal or adjustment of access rights USER RESPONSIBILITIES User responsibilities Password use. Use of secret authentication information (New) OPERATING SYSTEM ACCESS CONTROL System and application access control Information access restriction Information access restriction Secure log-on procedures Secure logon procedures User identification and authentication Password management system Password management system Use of system utilities Use of privileged utility programs Access control to program source code (moved) Access control to program source code Session time-out (Removed) Limitation of connection time APPLICATION AND INFORMATION ACCESS CONTROL Sensitive system isolation LOW CRYPTOGRAPHIC CONTROLS 10 Cryptography (NEW)

5 Policy on the use of cryptographic controls Policy on the use of cryptographic controls Key management Key management LOW 9 PHYSICAL AND ENVIRONMENTAL security 11 PHYSICAL AND ENVIRONMENTAL security SECURE AREAS Secure areas Physical security perimeter Physical security perimeter Physical entry controls Physical entry controls Securing offices, rooms, and facilities Securing offices, rooms and facilities Protecting against external and environmental threats Protecting against external and environ- mental threats Working in secure areas Working in secure areas Public access, delivery, and loading areas Delivery and loading areas EQUIPMENT security Equipment Equipment siting and protection. Equipment siting and protection Supporting utilities Supporting utilities Cabling security Cabling security Equipment maintenance Equipment maintenance Removal of property (Moved) Removal of assets (moved) security of equipment off-premises security of equipment and assets off premises Secure disposal or re-use of equipment Secure disposal or re- use of equipment Unattended user equipment (moved) Unattended user equipment Clear desk and clear screen policy (Moved) Clear desk and clear screen policy HIGH 10.

6 Operations security 12 Operations security HIGH OPERATIONAL PROCEDURES AND RESPONSIBILITIES Operational procedures and responsibilities Documented operating procedures Documented operating procedures Change management Change management Capacity management Capacity management Separation of development, test, and operational facilities Separation of development, testing and operational environments SYSTEM PLANNING AND ACCEPTANCE. System acceptance PROTECTION AGAINST MALICIOUS AND MOBILE CODE Protection from malware Controls against malicious code. Controls against mal-Ware Controls against mobile code (combined) BACK-UP Backup Information back-up Information backup MONITORING Logging and monitoring Audit logging Event logging Monitoring system use (combined) Protection of log information Protection of log information Administrator and operator logs Administrator and operator logs Fault logging (Removed) Clock synchronization Clock synchronisation security OF SYSTEM FILES Control of operational software Control of operational software Installation of soft-ware on operational systems TECHNICAL VULNERABILITY MANAGEMENT Technical vulnerability management Control of technical vulnerabilities Management of technical vulnerabilities Restrictions on software installation INFORMATION SYSTEMS AUDIT CONSIDERATIONS (Moved)

7 Information systems audit considerations Information systems audit controls Information systems audit controls Protection of information systems audit tools HIGH NETWORK ACCESS CONTROL. 13 Communications security Policy on use of network services Network security management User authentication for external connections Network controls Equipment identification in networks security of network services Remote diagnostic and configuration port protection Segregation in networks Segregation in net works Network connection control Network routing control EXCHANGE OF INFORMATION (Moved) Information transfer Information exchange policies and procedures Information transfer policies and procedures Exchange agreements Agreements on information transfer Physical media in transit (removed) Electronic messaging Electronic messaging Business information systems (removed)

8 Confidentiality or non- disclosure agreements HIGH 12 INFORMATION SYSTEMS ACQUISITION, DEVELOPMENT AND MAINTENANCE 14 System acquisition, development and maintenance security REQUIREMENTS OF INFORMATION SYSTEMS security requirements of information systems security requirements analysis and specification Information security requirements analysis and specification CORRECT PROCESSING IN APPLICATIONS (Removed) Securing application services on public networks Input data validation Protecting application services transactions Control of internal processing Message integrity Output data validation security OF SYSTEM FILES (Moved) Control of operational software Access control to program source code security in development and support processes security IN DEVELOPMENT AND SUPPORT PROCESSES Secure development policy Change control procedures System Change control procedures Technical review of applications after operating system changes Technical review of applications after operating platform changes Restrictions on changes to software packages Restrictions on changes to software packages Information leakage (Removed) Secure system engineering principles Secure development environment Outsourced software development Outsourced development System security testing System acceptance testing Test data (New)

9 Protection of system test data Protection of test data MED EXTERNAL PARTIES 15 Supplier relationships Identification of risks related to external parties Information security in supplier relationships Addressing security when dealing with customers Information security policy for supplier relationships Addressing security in third party agreements Addressing security within supplier agreements Information and communication technology supply chain (New) THIRD PARTY SERVICE DELIVERY MANAGEMENT Service delivery Supplier service delivery management Monitoring and review of third party services Monitoring and review of supplier services Managing changes to third party services Managing changes to supplier services LOW 13 INFORMATION security INCIDENT MANAGEMENT 13 INFORMATION security INCIDENT MANAGEMENT MANAGEMENT OF INFORMATION security INCIDENTS AND IMPROVEMENTS Management of information security incidents and improvements Responsibilities and procedures Responsibilities and Procedures Reporting information security events Reporting information security events Reporting security weaknesses Reporting information security weaknesses REPORTING INFORMATION security EVENTS AND WEAKNESSES.

10 Assessment of and decision on information security events (new) Response to information security incidents (new) Learning from information security incidents Learning from information security incidents Collection of evidence Collection of evidence MED 14 BUSINESS CONTINUITY MANAGEMENT INFORMATION security ASPECTS OF BUSINESS CONTINUITY MANAGEMENT 17 Information security aspects of business continuity management Including information security in the business continuity management process Information security continuity Business continuity and risk assessment Planning information security continuity Developing and implementing continuity plans including information security Implementing information security continuity Business continuity planning framework Testing, maintaining and re-assessing business continuity plans Verify, review and evaluate information security continuity Redundancies (new)


Related search queries