Guides full-lifecycle ISO 27001:2022 ISMS implementation: scoping, risk assessment, Annex A controls, SoA, audits, and certification.
npx claudepluginhub killvxk/cybersecurity-skills-zhThis skill uses the workspace's default tool permissions.
ISO/IEC 27001:2022 是建立、实施、维护和持续改进信息安全管理体系(ISMS)的国际标准。本技能涵盖从范围界定到认证的完整生命周期,包括附录 A 控制措施选择、风险评估方法论、适用性声明(SoA)的创建和持续改进流程。
Guides ISO 27001:2022 ISMS implementation from scoping to certification, covering clauses 4-10, Annex A controls, risk assessment, and SoA creation. Useful for compliance and security architecture.
Guides full ISO 27001:2022 ISMS lifecycle: scoping, clauses 4-10, Annex A controls, risk assessment, SoA, audits, and certification.
Provides expert guidance on ISO 27001 ISMS clauses 4-10, 93 Annex A controls, certification process, risk assessment, audits, and continual improvement for information security compliance.
Share bugs, ideas, or general feedback.
ISO/IEC 27001:2022 是建立、实施、维护和持续改进信息安全管理体系(ISMS)的国际标准。本技能涵盖从范围界定到认证的完整生命周期,包括附录 A 控制措施选择、风险评估方法论、适用性声明(SoA)的创建和持续改进流程。
管理体系要求定义了必须做什么:
2022 年修订版将 93 项控制措施重新整合为四类:
| 类别 | 控制措施数 | 示例 |
|---|---|---|
| 组织类(A.5) | 37 项 | 政策、角色、威胁情报、云安全 |
| 人员类(A.6) | 8 项 | 筛查、意识培训、远程工作、报告 |
| 物理类(A.7) | 14 项 | 安全边界、入口控制、设备安全 |
| 技术类(A.8) | 34 项 | 访问控制、加密、日志记录、安全开发 |
新增了 11 项控制措施: