<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="zh">
	<id>https://arolstar52-zhtest.hf.space/index.php?action=history&amp;feed=atom&amp;title=ISO%2FIEC_27001</id>
	<title>ISO/IEC 27001 - 版本历史</title>
	<link rel="self" type="application/atom+xml" href="https://arolstar52-zhtest.hf.space/index.php?action=history&amp;feed=atom&amp;title=ISO%2FIEC_27001"/>
	<link rel="alternate" type="text/html" href="https://arolstar52-zhtest.hf.space/index.php?title=ISO/IEC_27001&amp;action=history"/>
	<updated>2026-07-20T22:48:51Z</updated>
	<subtitle>本wiki上该页面的版本历史</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://arolstar52-zhtest.hf.space/index.php?title=ISO/IEC_27001&amp;diff=3563151&amp;oldid=prev</id>
		<title>imported&gt;Zennon0：​更新条目以反映 ISO/IEC 27001:2022 近况：补充2022版发布与主要变化概述，新增认证转换/过渡期信息 内容扩充 新条目</title>
		<link rel="alternate" type="text/html" href="https://arolstar52-zhtest.hf.space/index.php?title=ISO/IEC_27001&amp;diff=3563151&amp;oldid=prev"/>
		<updated>2026-02-17T15:39:25Z</updated>

		<summary type="html">&lt;p&gt;更新条目以反映 ISO/IEC 27001:2022 近况：补充2022版发布与主要变化概述，新增认证转换/过渡期信息 内容扩充 新条目&lt;/p&gt;
&lt;p&gt;&lt;b&gt;新页面&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{NoteTA&lt;br /&gt;
|G1=IT&lt;br /&gt;
}}&lt;br /&gt;
{{信息安全}}&lt;br /&gt;
{{更新|time=2023-12-06T11:57:08+00:00}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;ISO/IEC 27001&amp;#039;&amp;#039;&amp;#039;，其名稱是《資訊科技—安全技術—資訊安全管理系統—要求》（Information technology — Security techniques — Information security management systems — Requirements）是[[資訊安全]]管理的國際標準。此標準一開始是由[[國際標準化組織]]（ISO）及[[国际电工委员会]]（IEC）在2005年聯合發佈&amp;lt;ref&amp;gt;{{cite web |title=ISO/IEC 27001 International Information Security Standard published |url=https://www.bsigroup.com/en-GB/about-bsi/media-centre/press-releases/2005/11/ISOIEC-27001-International-Information-Security-Standard-published/ |website=bsigroup.com |publisher=BSI |accessdate=21 August 2020 |archive-date=2022-01-29 |archive-url=https://web.archive.org/web/20220129062023/https://www.bsigroup.com/en-GB/about-bsi/media-centre/press-releases/2005/11/ISOIEC-27001-International-Information-Security-Standard-published/ }}&amp;lt;/ref&amp;gt;，曾在2013年改版&amp;lt;ref&amp;gt;{{cite web |last1=Bird |first1=Katie |title=NEW VERSION OF ISO/IEC 27001 TO BETTER TACKLE IT SECURITY RISKS |url=https://www.iso.org/news/2013/08/Ref1767.html |website=iso.org |publisher=ISO |accessdate=21 August 2020 |archive-date=2019-09-20 |archive-url=https://web.archive.org/web/20190920073706/https://www.iso.org/news/2013/08/Ref1767.html |dead-url=no }}&amp;lt;/ref&amp;gt;，最近一次改版是在2022年&amp;lt;ref&amp;gt;{{Cite web |last=ISO/IEC |title=ISO/IEC 27001:2022 |url=https://www.iso.org/standard/27001 |access-date=2022-11-29 |website=ISO.org |language=en |archive-date=2024-05-27 |archive-url=https://web.archive.org/web/20240527111243/https://www.iso.org/standard/27001 |dead-url=no }}&amp;lt;/ref&amp;gt;。其中有列出有關[[資訊安全管理系統]]（information security management system、ISMS）架構、實施、維護以及持續改善上的要求，目的是幫助組織可以使其保管的[[資訊資產]]更加安全&amp;lt;ref&amp;gt;{{cite web |title=ISO/IEC 27001:2013 |url=https://www.iso.org/standard/54534.html |website=ISO |publisher=ISO |accessdate=9 July 2020 |archive-date=2020-11-15 |archive-url=https://web.archive.org/web/20201115170245/https://www.iso.org/standard/54534.html |dead-url=no }}&amp;lt;/ref&amp;gt;。2017年時，歐洲有更新此標準，並且出版&amp;lt;ref&amp;gt;{{cite web|title=BS EN ISO/IEC 27001:2017 – what has changed?|url=https://www.bsigroup.com/en-GB/iso-27001-information-security/BS-EN-ISO-IEC-27001-2017/|website=www.bsigroup.com|publisher=BSI Group|accessdate=29 March 2018|archive-date=2019-12-22|archive-url=https://web.archive.org/web/20191222130533/https://www.bsigroup.com/en-GB/iso-27001-information-security/BS-EN-ISO-IEC-27001-2017/|dead-url=no}}&amp;lt;/ref&amp;gt;。組織若要符合此標準的要求，在成功完成一次內部[[審計]]後，可申請由合格的認證單位進行認證。&lt;br /&gt;
&lt;br /&gt;
ISO/IEC 27001設計包括的範例不只是IT部門而已，&lt;br /&gt;
ISO/IEC 27001會要求進行以下的管理：&lt;br /&gt;
* 系統性地檢驗組織的資訊安全風險，考慮其威脅、弱點以及影響。&lt;br /&gt;
* 設計、實現連貫而且全面的資訊安全控管套件，並且／或者其他的風險管理方案（例如風險避免或風險轉移）來處理無法接受的風險。&lt;br /&gt;
* 用總體管理的流程，在現有的基礎上，確認資訊安全管理控管可以持續的符合組織的資訊安全需求。&lt;br /&gt;
&lt;br /&gt;
管理層為了認證的考量，會決定資訊安全管理系統（ISMS）的範圍，例如限制在單一的事業單位或是單一地區。ISO/IEC 27001可以針對個別部門的認證，也可以針對全公司的認證&amp;lt;ref&amp;gt;{{Cite web |url=https://www.ithome.com.tw/node/44328 |title=臺灣第四個全公司通過ISO 27001認證案例出爐 |access-date=2020-12-07 |archive-date=2022-01-24 |archive-url=https://web.archive.org/web/20220124225900/https://www.ithome.com.tw/node/44328 }}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web |url=https://www.businesstoday.com.tw/article/category/80392/post/201303280024/%E8%8A%B1%E9%8C%A2%E5%B0%B1%E8%83%BD%E6%8B%BF%E8%AD%89%E6%9B%B8%20%E5%8F%B0%E7%81%A3%E8%B3%87%E5%AE%89%E7%8E%A9%E5%81%87%E7%9A%84%EF%BC%9F |title=台灣興起全民資安運動 |access-date=2020-12-07 |archive-date=2022-01-24 |archive-url=https://web.archive.org/web/20220124225050/https://www.businesstoday.com.tw/article/category/80392/post/201303280024/%E8%8A%B1%E9%8C%A2%E5%B0%B1%E8%83%BD%E6%8B%BF%E8%AD%89%E6%9B%B8%20%E5%8F%B0%E7%81%A3%E8%B3%87%E5%AE%89%E7%8E%A9%E5%81%87%E7%9A%84%EF%BC%9F }}&amp;lt;/ref&amp;gt;。&lt;br /&gt;
&lt;br /&gt;
[[ISO/IEC 27000系列]]中的標準中可以提供設計、實現資訊安全管理系統以及其運作相關的指引，例如在有關資訊安全風險管理的{{le|ISO/IEC 27005|ISO/IEC 27005}}。&lt;br /&gt;
&lt;br /&gt;
==標準歷史==&lt;br /&gt;
ISO/IEC 27001中有許多內容是源自英國標準{{le|BS 7799|BS 7799}}。&lt;br /&gt;
&lt;br /&gt;
BS 7799是由[[BSI集團]]提出的標準&amp;lt;ref&amp;gt;{{cite web|url=http://www.bsigroup.com/en/About-BSI/News-Room/BSI-Fast-Facts2/|title=Facts and figures|work=bsigroup.com|accessdate=2020-12-06|archive-date=2012-10-20|archive-url=https://web.archive.org/web/20121020074841/http://www.bsigroup.com/en/about-bsi/News-Room/BSI-Fast-Facts2/|dead-url=no}}&amp;lt;/ref&amp;gt;。由{{le|貿易和工業部 (英國)|Department of Trade and Industry (United Kingdom)|英國貿易和工業部}}在1995年時改寫，分為幾個部份。&lt;br /&gt;
&lt;br /&gt;
BS7799的第一部份包括資訊安全管理的最佳實務，在1998年修訂。各國的標準機構針對其內容進行長期的討論，最後由ISO在2000年修訂為ISO/IEC 17799《資訊科技—資訊安全管理實務準則》（Information Technology - Code of practice for information security management）。在2005年6月再次修訂，最後在2007年7月整合在ISO 27000的系列標準中（[[ISO/IEC 27002]]）。&lt;br /&gt;
&lt;br /&gt;
BS7799的第二部份最早是由BSI在1999年發佈，稱為BS 7799第二部《資訊安全管理系統—規範及使用指引》（Information Security Management Systems - Specification with guidance for use）。BS 7799-2注重如何實現資訊安全管理系統（ISMS），在BS 7799-2中稱為資訊管理結構及控制。這部份後來成為ISO/IEC 27001:2005。BS 7799第二部份後來在2005年11月被ISO修改為ISO/IEC 27001。&lt;br /&gt;
&lt;br /&gt;
BS 7799第三部份是在2005年後發佈，包括了風險分析及管理，後來變成ISO/IEC 27001:2005。&lt;br /&gt;
&lt;br /&gt;
BS標準中，很少內容有引用ISO/IEC 27001。&lt;br /&gt;
&lt;br /&gt;
== ISO/IEC 27001:2022 主要变化&amp;lt;ref name=&amp;quot;ISO_news_2022&amp;quot;&amp;gt;{{cite web |title=ISO/IEC 27001: What’s new in IT security? |url=https://www.iso.org/contents/news/2022/10/new-iso-iec-27001.html |website=ISO |date=2022-10-25 |access-date=2026-02-17 |publisher=International Organization for Standardization}}&amp;lt;/ref&amp;gt; ==&lt;br /&gt;
ISO/IEC 27001 于2022年发布新版（ISO/IEC 27001:2022）。相较2013版，2022版的主要变化之一是附录A控制措施与 ISO/IEC 27002:2022 对齐：控制措施由原先的114项调整为93项，并将原本按14个领域的分类方式重组为4个主题类别（组织、人员、实体与技术）。&amp;lt;ref name=&amp;quot;ISO27001_standard&amp;quot;&amp;gt;{{cite web |title=ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements |url=https://www.iso.org/standard/27001 |website=ISO |date=2022 |access-date=2026-02-17 |publisher=International Organization for Standardization}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2022版亦对附录A控制措施进行新增、合并与更新（常见归纳为：11项新增、24项由既有控制合并、58项更新），并以更结构化的方式呈现控制信息（例如提供“目的”与“属性”等字段以利于映射与管理）。在管理体系条款方面，2022版增加了“变更策划（Planning of changes）”相关要求，以强调信息安全管理体系（ISMS）在发生变更时应进行计划化管理。&amp;lt;ref&amp;gt;{{Cite web |title=ISO/IEC 27001: What’s new in IT security? |url=https://www.iso.org/contents/news/2022/10/new-iso-iec-27001.html |website=ISO |date=2022-10-25 |language=en |access-date=2026-02-17}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== 认证转换与过渡期 ==&lt;br /&gt;
在 ISO/IEC 27001:2022 发布后，认可与认证体系对已按 ISO/IEC 27001:2013 获证的组织设置了向2022版转换（transition）的过渡安排。国际认可论坛（IAF）的强制性文件指出，过渡期通常自标准发布当月月底起算36个月，并明确规定转换完成的截止日期为2025年10月31日&lt;br /&gt;
&lt;br /&gt;
AF 文件亦要求认证机构与获证组织在过渡期间进行差距分析，并在转换审核中更新相关文件（例如适用性声明 SoA），以证明信息安全管理体系符合 ISO/IEC 27001:2022 的要求。过渡期结束后，仍依据2013版的认证证书将按过渡规则处理（例如到期或撤销），实际处置方式以认可与认证体系的规定为准。&amp;lt;ref name=&amp;quot;IAF_MD26_2023_issue2&amp;quot;&amp;gt;{{cite report |url=https://iaf.nu/iaf_system/uploads/documents/IAF_MD26_Issue_2_15012023.pdf |title=IAF MD 26:2023 (Issue 2): Transition Requirements for ISO/IEC 27001:2022 |date=2023-02-15 |publisher=International Accreditation Forum (IAF) |access-date=2026-02-17 |format=PDF}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==認證==&lt;br /&gt;
許多{{le|認可註冊商|Accredited Registrar}}可以認證資訊安全管理系統是否符合ISO/IEC 27001&amp;lt;ref&amp;gt;{{Cite journal|last=Ferreira|first=Lindemberg Naffah|last2=da Silva Constante|first2=Silvana Maria|last3=de Moraes Zebral|first3=Alessandro Marcio|last4=Braga|first4=Rogerio Zupo|last5=Alvarenga|first5=Helenice|last6=Ferreira|first6=Soraya Naffah|date=October 2013|title=ISO 27001 certification process of Electronic Invoice in the State of Minas Gerais|url=https://ieeexplore.ieee.org/document/6922072/|journal=2013 47th International Carnahan Conference on Security Technology (ICCST)|location=Medellin|publisher=IEEE|pages=1–4|doi=10.1109/CCST.2013.6922072|isbn=978-1-4799-0889-9|access-date=2020-12-06|archive-date=2020-03-27|archive-url=https://web.archive.org/web/20200327192309/https://ieeexplore.ieee.org/document/6922072/|dead-url=no}}&amp;lt;/ref&amp;gt;。若是針對ISO/IEC 27001各國版本（例如日本的JIS Q 27001）的認證，在功能上等效於針對ISO/IEC 27001的認證。&lt;br /&gt;
&lt;br /&gt;
有些國家會將認證管理系統的組織稱為「認證機構」（certification bodies），有些則稱為「登記機構」（registration bodies）、「評估及登記機構」（assessment and registration bodies）、「認證／登記機構」（certification/ registration bodies）等。&lt;br /&gt;
&lt;br /&gt;
==相關條目==&lt;br /&gt;
* {{le|ISO JTC 1/SC 27||ISO JTC 1/SC 27}}：資訊技術安全技術&lt;br /&gt;
* [[ISO/IEC 27000系列]]&lt;br /&gt;
* [[ISO 9000]]&lt;br /&gt;
* {{le|BS 7799|BS 7799}}&lt;br /&gt;
* [[網路安全標準]]&lt;br /&gt;
* [[國際標準化組織]]&lt;br /&gt;
* {{le|ISO標準列表|List of ISO standards}}&lt;br /&gt;
* [[數據安全]]&lt;br /&gt;
* [[可信資訊安全評估交換]]&lt;br /&gt;
&lt;br /&gt;
==參考資料==&lt;br /&gt;
{{Reflist}}&lt;br /&gt;
&lt;br /&gt;
==外部連結==&lt;br /&gt;
* [https://www.iso.org/isoiec-27001-information-security.html ISO website]{{Wayback|url=https://www.iso.org/isoiec-27001-information-security.html |date=20201202044545 }}&lt;br /&gt;
&lt;br /&gt;
{{ISO standards}}&lt;br /&gt;
&lt;br /&gt;
{{DEFAULTSORT:ISO IEC 27001}}&lt;br /&gt;
[[Category:資訊科技管理]]&lt;br /&gt;
[[Category:ISO/IEC标准|#27001]]&lt;/div&gt;</summary>
		<author><name>imported&gt;Zennon0</name></author>
	</entry>
</feed>