ISO 42001 iPAS 資安 iPAS AI
AkiraISO 27001 互動式地圖 ISO/IEC 27001:2022 導入與稽核實務|點節點看白話解說與實務重點

ISO/IEC 27001:2013 → 2022 差異總表

2022 年版沒有改變 ISMS 的基本做法,條文 4–10 只有少數新增與調整;變動最大的是附錄 A:114 項控制重新整理成 93 項、分成四個主題,其中 11 項是全新控制。下面先看條文的差異,再用對照表逐項查附錄 A,可以切換「從 2022 查 2013」或「從 2013 查 2022」。點控制名稱會打開該節點的白話說明。

114 → 93附錄 A 控制數
14 → 4領域 → 主題
11全新控制
24由多項合併
58一對一沿用(可能改名或改寫)
6.3新增條文:變更的規劃
一、條文差異二、附錄 A 對照三、14 個領域的去向四、轉版要做的事

一、條文 4–10 的差異

條文的要求內容大多不變,下表只列有變化的地方。「類型」中,新增是 2013 版沒有的要求,修改是要求內容有增減,結構是條號或排列改變而內容大致相同。

條號2013 版2022 版的變化類型實務上要做什麼
標題標準名稱Information security management systems — Requirements名稱前加上系列標題 Information security, cybersecurity and privacy protection名稱只是系列命名調整,要求沒有因此改變;證書與文件上的標準名稱可順手更新。
4.2利害關係者決定利害關係者及其與資安有關的要求新增一項:要決定這些要求中,哪些會透過 ISMS 來處理修改利害關係者清單要多一欄「是否由 ISMS 處理、怎麼處理」,稽核常會追問這一欄。
4.4ISMS建立、實施、維持並持續改善 ISMS明確要求 ISMS 要包含所需的「過程及其交互作用」修改用流程圖或過程清單說清楚 ISMS 由哪些過程組成、彼此怎麼銜接(例如風險評鑑結果怎麼流到 SoA 與管審)。
6.1.3風險處理與 SoA附錄 A 包含控制目標與控制措施附錄 A 不再列控制目標,改稱「資訊安全控制」清單,並說明它不是完整清單修改SoA 要改成 93 項控制,重新寫每一項的納入或排除理由與實施狀態;也可以加入附錄 A 以外的自訂控制。
6.2資安目標訂定可量測、與政策一致的目標新增「目標要被監督」,並要求目標以文件化資訊形式可供取得修改每個目標要有追蹤紀錄(誰在什麼時候檢視過、進度如何),不能只在年初寫一次。
6.3變更的規劃(2013 版沒有這一條)新增條文:ISMS 需要變更時,要有規劃地進行新增建立 ISMS 變更的評估方式,例如組織調整、範圍擴大、系統汰換前先評估對 ISMS 的影響,並留下紀錄。
7.4溝通分別決定由誰溝通、以及溝通的過程兩項合併為「如何溝通」修改影響小;溝通計畫保留「溝通什麼、何時、對誰、怎麼溝通」即可。
8.1運作規劃與管制規劃、實施與管制過程;管制委外過程新增要為過程訂定準則並依準則管制;「委外過程」改為「外部提供的過程、產品或服務」修改供應商、雲端服務與外部取得的產品都要納入管制範圍,並說明各過程的運作準則。
9.2內部稽核單一條文拆成 9.2.1 一般要求與 9.2.2 內部稽核方案結構內容大致相同,主要是條號改變;內稽程序與報告引用的條號要更新。
9.3管理審查單一條文拆成 9.3.1~9.3.3;審查輸入新增「利害關係者需要與期望的變化」修改管理審查議程與會議紀錄要加上這一項輸入。
10改善10.1 不符合與矯正措施、10.2 持續改善順序對調:10.1 持續改善、10.2 不符合與矯正措施結構要求本身不變,程序書、矯正措施表單上引用的條號要改。
附錄 A控制清單114 項控制、14 個領域,附控制目標93 項控制、4 個主題,移除控制目標;新增 11 項結構重做 SoA 與風險處理計畫,並逐項確認 11 項新增控制是否適用、如何落地。
Amd 1:2024氣候變遷修訂—4.1 要判斷氣候變遷是否為相關議題;4.2 加註利害關係者可能有氣候相關要求修訂沒有轉版期,也不換證;驗證機構會在之後的例行稽核中確認組織有做這項判斷。

二、附錄 A 控制對照

類型說明:新增是 2013 版找不到對應的控制;合併是由兩項以上舊控制整併而成;沿用是一對一對應,名稱或內容可能改寫。A.18.2.3 技術遵循性審查同時拆到 5.36 與 8.8,所以在「從 2013 查 2022」裡會對到兩項。

2022 條號控制名稱主題類型2013 對應
5.1Policies for information security
訂出整體資安政策與各主題政策,經管理階層核准、公告給相關人員,並定期檢討。
組織合併A.5.1.1Policies for information securityA.5.1.2Review of the policies for information security
5.2Information security roles and responsibilities
依組織需要定義並分派資安相關的角色與責任,讓每項資安工作都有明確的負責人。
組織沿用A.6.1.1Information security roles and responsibilities
5.3Segregation of duties
把容易互相衝突的工作分給不同的人,降低一個人就能完成舞弊或嚴重錯誤的機會。
組織沿用A.6.1.2Segregation of duties
5.4Management responsibilities
各級主管要要求部屬依政策與程序落實資安,而不是把資安全丟給 IT 部門處理。
組織沿用A.7.2.1Management responsibilities
5.5Contact with authorities
預先建立與主管機關、執法與監管單位的聯絡管道,出事時知道要找誰、何時通報。
組織沿用A.6.1.3Contact with authorities
5.6Contact with special interest groups
參與資安社群、產業協會或專業論壇,持續取得新知、預警資訊與同業經驗。
組織沿用A.6.1.4Contact with special interest groups
5.7Threat intelligence
2022 新增:蒐集並分析與組織相關的威脅資訊,轉化成能調整防護的具體行動。
組織新增2013 版沒有對應
5.8Information security in project management
在各類專案的規劃與執行過程中納入資安考量,不等到上線前才發現問題。
組織合併A.6.1.5Information security in project managementA.14.1.1Information security requirements analysis and specification
5.9Inventory of information and other associated assets
建立並維護資訊及相關資產的清冊,每一項都指定擁有者,作為風險評鑑與保護的基礎。
組織合併A.8.1.1Inventory of assetsA.8.1.2Ownership of assets
5.10Acceptable use of information and other associated assets
訂出資訊與資產可以怎麼用、不可以怎麼用的規則,並讓使用者知道且遵守。
組織合併A.8.1.3Acceptable use of assetsA.8.2.3Handling of assets
5.11Return of assets
人員離職、調職或合約結束時,收回其持有的組織資產,包括設備、門禁卡與資訊。
組織沿用A.8.1.4Return of assets
5.12Classification of information
依資訊的機密性、完整性、可用性需求與利害關係者期望,把資訊分成不同等級。
組織沿用A.8.2.1Classification of information
5.13Labelling of information
依分級制度在文件、檔案、媒體或系統上標示級別,讓人和系統都能辨識該如何處理。
組織沿用A.8.2.2Labelling of information
5.14Information transfer
對組織內外的資訊傳遞訂出規則、程序或協議,涵蓋電子、實體媒體與口頭等各種方式。
組織合併A.13.2.1Information transfer policies and proceduresA.13.2.2Agreements on information transferA.13.2.3Electronic messaging
5.15Access control
依業務與資安需求訂出存取控制規則,決定誰在什麼條件下可以存取哪些資訊與資產。
組織合併A.9.1.1Access control policyA.9.1.2Access to networks and network services
5.16Identity management
管理使用者與系統身分從建立、異動到刪除的完整生命週期,確保每個身分都能對應到負責人。
組織沿用A.9.2.1User registration and de-registration
5.17Authentication information
管理密碼、權杖、憑證等鑑別資訊的發放、保管與使用規則,避免被猜到、外洩或共用。
組織合併A.9.2.4Management of secret authentication information of usersA.9.3.1Use of secret authentication informationA.9.4.3Password management system
5.18Access rights
依存取控制規則辦理權限的申請、核准、變更、定期審查與移除,讓權限隨職務變化而調整。
組織合併A.9.2.2User access provisioningA.9.2.5Review of user access rightsA.9.2.6Removal or adjustment of access rights
5.19Information security in supplier relationships
建立管理供應商資安風險的流程,從選商、評估到關係結束,都考慮供應商能接觸到的資訊與系統。
組織沿用A.15.1.1Information security policy for supplier relationships
5.20Addressing information security within supplier agreements
依供應商類型與風險,在合約中寫明資安要求、雙方責任、通報義務與稽核權等條款。
組織沿用A.15.1.2Addressing security within supplier agreements
5.21Managing information security in the ICT supply chain
管理資訊與通訊技術產品和服務的供應鏈風險,延伸到供應商的供應商、元件來源與軟體組成。
組織沿用A.15.1.3Information and communication technology supply chain
5.22Monitoring, review and change management of supplier services
定期監督與審查供應商的資安表現與服務品質,並管理供應商服務的變更。
組織合併A.15.2.1Monitoring and review of supplier servicesA.15.2.2Managing changes to supplier services
5.23Information security for use of cloud services
2022 新增:對雲端服務的取得、使用、管理到退出建立流程,並釐清與雲端服務商的責任分工。
組織新增2013 版沒有對應
5.24Information security incident management planning and preparation
事先規劃事件管理的流程、角色、溝通與工具,讓組織在事故發生時能快速且一致地處理。
組織沿用A.16.1.1Responsibilities and procedures
5.25Assessment and decision on information security events
評估通報上來的資安事件,判斷是否構成資安事故,並依分級決定後續處理方式。
組織沿用A.16.1.4Assessment of and decision on information security events
5.26Response to information security incidents
依文件化的程序處理資安事故,包括遏止、根除、復原、溝通與紀錄。
組織沿用A.16.1.5Response to information security incidents
5.27Learning from information security incidents
分析處理過的資安事故,找出根本原因與改善機會,用來強化控制並降低再發生的機率。
組織沿用A.16.1.6Learning from information security incidents
5.28Collection of evidence
訂定程序來識別、收集、取得並保存與資安事件有關的證據,確保證據可信且可用於法律程序。
組織沿用A.16.1.7Collection of evidence
5.29Information security during disruption
規劃在營運中斷或危機期間,仍能把資安維持在適當水準,不因為趕著恢復而開大門。
組織合併A.17.1.1Planning information security continuityA.17.1.2Implementing information security continuityA.17.1.3Verify, review and evaluate information security continuity
5.30ICT readiness for business continuity
2022 新增:依營運持續目標規劃、實作、維護並測試 ICT 的備妥程度,確保中斷後能及時恢復。
組織新增2013 版沒有對應
5.31Legal, statutory, regulatory and contractual requirements
鑑別並記錄與資安相關的法律、法規與合約要求,說明組織如何滿足,並保持更新。
組織合併A.18.1.1Identification of applicable legislation and contractual requirementsA.18.1.5Regulation of cryptographic controls
5.32Intellectual property rights
建立適當程序保護智慧財產權,包括合法使用軟體授權與他人著作,以及保護組織自己的智財。
組織沿用A.18.1.2Intellectual property rights
5.33Protection of records
保護紀錄不被遺失、毀損、偽造、未經授權的存取或提前銷毀,並依要求保存足夠期間。
組織沿用A.18.1.3Protection of records
5.34Privacy and protection of PII
依適用的法規與合約要求,識別並滿足保護個人資料與隱私的要求。
組織沿用A.18.1.4Privacy and protection of personally identifiable information
5.35Independent review of information security
定期或在重大變更時,由獨立的人員對資安管理方式與實作進行審查。
組織沿用A.18.2.1Independent review of information security
5.36Compliance with policies, rules and standards for information security
定期檢查組織是否遵守自己的資安政策、主題政策、規則與標準,發現不符時採取改善行動。
組織合併A.18.2.2Compliance with security policies and standardsA.18.2.3Technical compliance review
5.37Documented operating procedures
把資訊處理設施的重要作業程序寫成文件,並讓需要的人員能夠取得與遵循。
組織沿用A.12.1.1Documented operating procedures
6.1Screening
錄用前依職務敏感度與法規限制,查證候選人的身分、學經歷等資料,查核深度要與風險相稱。
人員沿用A.7.1.1Screening
6.2Terms and conditions of employment
在勞動契約、聘書或到職承諾書中寫明人員的資安責任,讓責任從到職第一天就有依據。
人員沿用A.7.1.2Terms and conditions of employment
6.3Information security awareness, education and training
依角色規劃資安認知、教育與訓練,隨威脅與政策更新內容,並確認人員真的理解。
人員沿用A.7.2.2Information security awareness, education and training
6.4Disciplinary process
違反資安政策時,有事先公告、查明事實並依情節一致處理的流程,兼具嚇阻與究責作用。
人員沿用A.7.2.3Disciplinary process
6.5Responsibilities after termination or change of employment
人員離職或調動時,告知哪些資安義務仍持續有效,並把原本負責的資安職責交接出去。
人員沿用A.7.3.1Termination or change of employment responsibilities
6.6Confidentiality or non-disclosure agreements
依組織保護資訊的需要訂定保密或不揭露協議,讓員工與外部對象清楚哪些資訊不能外流。
人員沿用A.13.2.4Confidentiality or non-disclosure agreements
6.7Remote working
人員在辦公室以外的地點工作時,透過規則與技術措施,維持與辦公室相當的資訊保護。
人員沿用A.6.2.2Teleworking
6.8Information security event reporting
提供簡單、人人都知道的管道,讓人員能及時回報觀察到或懷疑的資訊安全事件。
人員合併A.16.1.2Reporting information security eventsA.16.1.3Reporting information security weaknesses
7.1Physical security perimeters
依資訊與資產的重要性劃出實體區域的邊界,邊界上的牆、門窗與出入口要真的擋得住人。
實體沿用A.11.1.1Physical security perimeter
7.2Physical entry
用門禁、訪客管理與收發貨區規劃,確保只有獲得授權的人能進入受保護的區域。
實體合併A.11.1.2Physical entry controlsA.11.1.6Delivery and loading areas
7.3Securing offices, rooms and facilities
規劃辦公室、會議室與機房時就把資安納入考量,避免機密被看見、聽見或被輕易找到。
實體沿用A.11.1.3Securing offices, rooms and facilities
7.4Physical security monitoring
2022 新增。用監視器、入侵警報等持續監看場所,及早發現並嚇阻未經授權的實體進入。
實體新增2013 版沒有對應
7.5Protecting against physical and environmental threats
針對火災、淹水、地震、停電與蓄意破壞等威脅,在選址、設計與維運上預先做好防護。
實體沿用A.11.1.4Protecting against external and environmental threats
7.6Working in secure areas
為機房、實驗室等安全區域訂定專屬的作業規則,管住已經獲准進入的人在裡面做什麼。
實體沿用A.11.1.5Working in secure areas
7.7Clear desk and clear screen
離開座位時收好機密文件與儲存媒體、鎖定螢幕,避免資訊被他人看見或順手取走。
實體沿用A.11.2.9Clear desk and clear screen policy
7.8Equipment siting and protection
把設備放在能降低環境風險與未授權接觸的位置,並依設備重要性加上適當的防護。
實體沿用A.11.2.1Equipment siting and protection
7.9Security of assets off-premises
筆電、手機與帶出公司的設備,在辦公室以外也要有防遺失、防竊與防窺看的保護措施。
實體沿用A.11.2.6Security of equipment and assets off-premises
7.10Storage media
隨身碟、外接硬碟、光碟等儲存媒體,從取得、使用、運送到銷毀,都依資訊分類來管理。
實體合併A.8.3.1Management of removable mediaA.8.3.2Disposal of mediaA.8.3.3Physical media transferA.11.2.5Removal of assets
7.11Supporting utilities
電力、空調、通訊與供水等支援設施要穩定可靠,避免它們故障而拖垮資訊處理設備。
實體沿用A.11.2.2Supporting utilities
7.12Cabling security
保護電源線與網路線不被截聽、干擾或破壞,並清楚標示,方便維護與查核。
實體沿用A.11.2.3Cabling security
7.13Equipment maintenance
依廠商建議定期維護設備,並管控維修人員、送修過程與維修完成後的檢查。
實體沿用A.11.2.4Equipment maintenance
7.14Secure disposal or re-use of equipment
設備報廢、轉售或轉給他人使用前,確認其中的敏感資料與授權軟體都已被安全清除。
實體沿用A.11.2.7Secure disposal or re-use of equipment
8.1User endpoint devices
員工使用的筆電、手機、平板要有一致的安全設定與管理方式,遺失或被入侵時資料仍受保護。
技術合併A.6.2.1Mobile device policyA.11.2.8Unattended user equipment
8.2Privileged access rights
系統管理員、資料庫管理者等高權限帳號要另外核准、限制範圍、留下紀錄並定期覆核。
技術沿用A.9.2.3Management of privileged access rights
8.3Information access restriction
在 ERP、檔案伺服器等系統裡依角色設定權限,讓每個人只碰得到工作需要的資料與功能。
技術沿用A.9.4.1Information access restriction
8.4Access to source code
誰能讀、誰能改原始碼要管清楚,搭配分支保護與程式碼審查,防止竄改、外流或被植入後門。
技術沿用A.9.4.5Access control to program source code
8.5Secure authentication
登入機制要依資訊敏感度與風險設計,例如啟用多因子驗證、限制錯誤嘗試、保護登入過程。
技術沿用A.9.4.2Secure log-on procedures
8.6Capacity management
監看並預估運算、儲存、網路與人力資源的使用量,避免資源不足造成服務中斷或效能惡化。
技術沿用A.12.1.3Capacity management
8.7Protection against malware
結合偵測工具、使用者認知與系統管控,防止病毒、勒索軟體等惡意程式進入並擴散。
技術沿用A.12.2.1Controls against malware
8.8Management of technical vulnerabilities
掌握手上系統有哪些已知漏洞,依嚴重與暴露程度排定修補或暫時緩解,縮短被攻擊的空窗。
技術合併A.12.6.1Management of technical vulnerabilitiesA.18.2.3Technical compliance review
8.9Configuration management
2022 新增。替各類系統訂出安全設定基準,定期比對實際設定有沒有偏離,改設定要走變更流程。
技術新增2013 版沒有對應
8.10Information deletion
2022 新增。替資料訂保存期限,到期就用合適方法確實刪除或銷毀;留得越少,外洩時損失越小。
技術新增2013 版沒有對應
8.11Data masking
2022 新增。用部分遮蔽、假名化、匿名化等手法,讓客服、測試等角色只看到工作需要的那部分資料。
技術新增2013 版沒有對應
8.12Data leakage prevention
2022 新增。盯住郵件、網頁上傳、USB 等外流通道,偵測並攔下敏感資訊被不當帶出組織。
技術新增2013 版沒有對應
8.13Information backup
重要資料與系統要有可用的副本,並定期實際還原驗證,確保誤刪、故障或勒索時救得回來。
技術沿用A.12.3.1Information backup
8.14Redundancy of information processing facilities
找出關鍵系統的單點故障,依業務能承受的停機程度準備雙電源、雙線路、叢集或異地備援。
技術沿用A.17.2.1Availability of information processing facilities
8.15Logging
登入、權限變更、錯誤與告警都要留下紀錄,集中保存、防止竄改,出事時才查得到經過。
技術合併A.12.4.1Event loggingA.12.4.2Protection of log informationA.12.4.3Administrator and operator logs
8.16Monitoring activities
2022 新增。先掌握系統與使用者的正常樣態,持續找出偏離的異常行為,並及時判斷是否為資安事件。
技術新增2013 版沒有對應
8.17Clock synchronization
讓伺服器、網路與安全設備都向同一個可信時間來源對時,事件調查時日誌才拼得出正確時間線。
技術沿用A.12.4.4Clock synchronisation
8.18Use of privileged utility programs
磁碟編輯、密碼重設這類能越過系統控制的工具,只給少數人在受控條件下使用並留下紀錄。
技術沿用A.9.4.4Use of privileged utility programs
8.19Installation of software on operational systems
在正式運作的系統上安裝或更新軟體要走管控程序,限制誰能裝、裝什麼,並保留回復能力。
技術合併A.12.5.1Installation of software on operational systemsA.12.6.2Restrictions on software installation
8.20Networks security
網路設備的設定、管理介面、防火牆規則與架構圖都要受控,別讓內部網路成為攻擊者的通行道。
技術沿用A.13.1.1Network controls
8.21Security of network services
向電信或雲端業者取得的網路服務,要把安全功能與服務水準寫進合約,並定期確認有做到。
技術沿用A.13.1.2Security of network services
8.22Segregation of networks
依信任程度、用途與敏感度把網路切成不同區段,限制區段之間的流量,降低攻擊擴散。
技術沿用A.13.1.3Segregation in networks
8.23Web filtering
2022 新增。依網站分類與威脅情資擋掉惡意、釣魚等高風險網站,降低員工上網誤觸的機會。
技術新增2013 版沒有對應
8.24Use of cryptography
什麼資料要加密、用哪種演算法、金鑰怎麼產生保管與更換,都要有明確規則並確實執行。
技術合併A.10.1.1Policy on the use of cryptographic controlsA.10.1.2Key management
8.25Secure development life cycle
把需求、設計、撰寫、測試、上線各階段該做的安全活動固定下來,不靠個人習慣決定。
技術沿用A.14.2.1Secure development policy
8.26Application security requirements
自行開發或採購系統前,先把驗證、加密、日誌等安全需求寫進規格,驗收時逐項對照。
技術合併A.14.1.2Securing application services on public networksA.14.1.3Protecting application services transactions
8.27Secure system architecture and engineering principles
用縱深防禦、最小權限、預設安全等共同原則設計系統,讓不同團隊做出的架構有一致底線。
技術沿用A.14.2.5Secure system engineering principles
8.28Secure coding
2022 新增。用安全寫法規範、程式碼審查與自動掃描,擋下注入、寫死密鑰、過時套件等常見漏洞。
技術新增2013 版沒有對應
8.29Security testing in development and acceptance
開發過程與上線前都要做安全測試,依安全需求逐項驗證,沒通過放行標準就不上線。
技術合併A.14.2.8System security testingA.14.2.9System acceptance testing
8.30Outsourced development
系統交給外部廠商開發時,從合約條款、過程監督到驗收測試都要把安全要求帶進去。
技術沿用A.14.2.7Outsourced development
8.31Separation of development, test and production environments
開發與測試不在正式環境裡進行,各環境的帳號、網路與資料分開,免得一個失誤波及正式業務。
技術合併A.12.1.4Separation of development, testing and operational environmentsA.14.2.6Secure development environment
8.32Change management
系統、網路與設定的任何異動都走申請、評估、測試、核准與紀錄,出問題時能回復原狀。
技術合併A.12.1.2Change managementA.14.2.2System change control proceduresA.14.2.3Technical review of applications after operating platform changesA.14.2.4Restrictions on changes to software packages
8.33Test information
測試優先使用合成或遮罩過的資料,真要用正式資料須經核准、受保護,用完立即刪除。
技術沿用A.14.3.1Protection of test data
8.34Protection of information systems during audit testing
要碰正式系統的稽核、掃描或滲透測試,先談好範圍、時段與權限,避免檢查本身造成中斷。
技術沿用A.12.7.1Information systems audit controls
2013 條號2013 控制名稱2013 領域→ 2022 對應類型
A.5.1.1Policies for information securityA.5 資訊安全政策5.1 合併
A.5.1.2Review of the policies for information securityA.5 資訊安全政策5.1 合併
A.6.1.1Information security roles and responsibilitiesA.6 資訊安全的組織5.2 沿用
A.6.1.2Segregation of dutiesA.6 資訊安全的組織5.3 沿用
A.6.1.3Contact with authoritiesA.6 資訊安全的組織5.5 沿用
A.6.1.4Contact with special interest groupsA.6 資訊安全的組織5.6 沿用
A.6.1.5Information security in project managementA.6 資訊安全的組織5.8 合併
A.6.2.1Mobile device policyA.6 資訊安全的組織8.1 合併
A.6.2.2TeleworkingA.6 資訊安全的組織6.7 沿用
A.7.1.1ScreeningA.7 人力資源安全6.1 沿用
A.7.1.2Terms and conditions of employmentA.7 人力資源安全6.2 沿用
A.7.2.1Management responsibilitiesA.7 人力資源安全5.4 沿用
A.7.2.2Information security awareness, education and trainingA.7 人力資源安全6.3 沿用
A.7.2.3Disciplinary processA.7 人力資源安全6.4 沿用
A.7.3.1Termination or change of employment responsibilitiesA.7 人力資源安全6.5 沿用
A.8.1.1Inventory of assetsA.8 資產管理5.9 合併
A.8.1.2Ownership of assetsA.8 資產管理5.9 合併
A.8.1.3Acceptable use of assetsA.8 資產管理5.10 合併
A.8.1.4Return of assetsA.8 資產管理5.11 沿用
A.8.2.1Classification of informationA.8 資產管理5.12 沿用
A.8.2.2Labelling of informationA.8 資產管理5.13 沿用
A.8.2.3Handling of assetsA.8 資產管理5.10 合併
A.8.3.1Management of removable mediaA.8 資產管理7.10 合併
A.8.3.2Disposal of mediaA.8 資產管理7.10 合併
A.8.3.3Physical media transferA.8 資產管理7.10 合併
A.9.1.1Access control policyA.9 存取控制5.15 合併
A.9.1.2Access to networks and network servicesA.9 存取控制5.15 合併
A.9.2.1User registration and de-registrationA.9 存取控制5.16 沿用
A.9.2.2User access provisioningA.9 存取控制5.18 合併
A.9.2.3Management of privileged access rightsA.9 存取控制8.2 沿用
A.9.2.4Management of secret authentication information of usersA.9 存取控制5.17 合併
A.9.2.5Review of user access rightsA.9 存取控制5.18 合併
A.9.2.6Removal or adjustment of access rightsA.9 存取控制5.18 合併
A.9.3.1Use of secret authentication informationA.9 存取控制5.17 合併
A.9.4.1Information access restrictionA.9 存取控制8.3 沿用
A.9.4.2Secure log-on proceduresA.9 存取控制8.5 沿用
A.9.4.3Password management systemA.9 存取控制5.17 合併
A.9.4.4Use of privileged utility programsA.9 存取控制8.18 沿用
A.9.4.5Access control to program source codeA.9 存取控制8.4 沿用
A.10.1.1Policy on the use of cryptographic controlsA.10 密碼學8.24 合併
A.10.1.2Key managementA.10 密碼學8.24 合併
A.11.1.1Physical security perimeterA.11 實體與環境安全7.1 沿用
A.11.1.2Physical entry controlsA.11 實體與環境安全7.2 合併
A.11.1.3Securing offices, rooms and facilitiesA.11 實體與環境安全7.3 沿用
A.11.1.4Protecting against external and environmental threatsA.11 實體與環境安全7.5 沿用
A.11.1.5Working in secure areasA.11 實體與環境安全7.6 沿用
A.11.1.6Delivery and loading areasA.11 實體與環境安全7.2 合併
A.11.2.1Equipment siting and protectionA.11 實體與環境安全7.8 沿用
A.11.2.2Supporting utilitiesA.11 實體與環境安全7.11 沿用
A.11.2.3Cabling securityA.11 實體與環境安全7.12 沿用
A.11.2.4Equipment maintenanceA.11 實體與環境安全7.13 沿用
A.11.2.5Removal of assetsA.11 實體與環境安全7.10 合併
A.11.2.6Security of equipment and assets off-premisesA.11 實體與環境安全7.9 沿用
A.11.2.7Secure disposal or re-use of equipmentA.11 實體與環境安全7.14 沿用
A.11.2.8Unattended user equipmentA.11 實體與環境安全8.1 合併
A.11.2.9Clear desk and clear screen policyA.11 實體與環境安全7.7 沿用
A.12.1.1Documented operating proceduresA.12 運作安全5.37 沿用
A.12.1.2Change managementA.12 運作安全8.32 合併
A.12.1.3Capacity managementA.12 運作安全8.6 沿用
A.12.1.4Separation of development, testing and operational environmentsA.12 運作安全8.31 合併
A.12.2.1Controls against malwareA.12 運作安全8.7 沿用
A.12.3.1Information backupA.12 運作安全8.13 沿用
A.12.4.1Event loggingA.12 運作安全8.15 合併
A.12.4.2Protection of log informationA.12 運作安全8.15 合併
A.12.4.3Administrator and operator logsA.12 運作安全8.15 合併
A.12.4.4Clock synchronisationA.12 運作安全8.17 沿用
A.12.5.1Installation of software on operational systemsA.12 運作安全8.19 合併
A.12.6.1Management of technical vulnerabilitiesA.12 運作安全8.8 合併
A.12.6.2Restrictions on software installationA.12 運作安全8.19 合併
A.12.7.1Information systems audit controlsA.12 運作安全8.34 沿用
A.13.1.1Network controlsA.13 通訊安全8.20 沿用
A.13.1.2Security of network servicesA.13 通訊安全8.21 沿用
A.13.1.3Segregation in networksA.13 通訊安全8.22 沿用
A.13.2.1Information transfer policies and proceduresA.13 通訊安全5.14 合併
A.13.2.2Agreements on information transferA.13 通訊安全5.14 合併
A.13.2.3Electronic messagingA.13 通訊安全5.14 合併
A.13.2.4Confidentiality or non-disclosure agreementsA.13 通訊安全6.6 沿用
A.14.1.1Information security requirements analysis and specificationA.14 系統獲取、開發及維護5.8 合併
A.14.1.2Securing application services on public networksA.14 系統獲取、開發及維護8.26 合併
A.14.1.3Protecting application services transactionsA.14 系統獲取、開發及維護8.26 合併
A.14.2.1Secure development policyA.14 系統獲取、開發及維護8.25 沿用
A.14.2.2System change control proceduresA.14 系統獲取、開發及維護8.32 合併
A.14.2.3Technical review of applications after operating platform changesA.14 系統獲取、開發及維護8.32 合併
A.14.2.4Restrictions on changes to software packagesA.14 系統獲取、開發及維護8.32 合併
A.14.2.5Secure system engineering principlesA.14 系統獲取、開發及維護8.27 沿用
A.14.2.6Secure development environmentA.14 系統獲取、開發及維護8.31 合併
A.14.2.7Outsourced developmentA.14 系統獲取、開發及維護8.30 沿用
A.14.2.8System security testingA.14 系統獲取、開發及維護8.29 合併
A.14.2.9System acceptance testingA.14 系統獲取、開發及維護8.29 合併
A.14.3.1Protection of test dataA.14 系統獲取、開發及維護8.33 沿用
A.15.1.1Information security policy for supplier relationshipsA.15 供應商關係5.19 沿用
A.15.1.2Addressing security within supplier agreementsA.15 供應商關係5.20 沿用
A.15.1.3Information and communication technology supply chainA.15 供應商關係5.21 沿用
A.15.2.1Monitoring and review of supplier servicesA.15 供應商關係5.22 合併
A.15.2.2Managing changes to supplier servicesA.15 供應商關係5.22 合併
A.16.1.1Responsibilities and proceduresA.16 資訊安全事故管理5.24 沿用
A.16.1.2Reporting information security eventsA.16 資訊安全事故管理6.8 合併
A.16.1.3Reporting information security weaknessesA.16 資訊安全事故管理6.8 合併
A.16.1.4Assessment of and decision on information security eventsA.16 資訊安全事故管理5.25 沿用
A.16.1.5Response to information security incidentsA.16 資訊安全事故管理5.26 沿用
A.16.1.6Learning from information security incidentsA.16 資訊安全事故管理5.27 沿用
A.16.1.7Collection of evidenceA.16 資訊安全事故管理5.28 沿用
A.17.1.1Planning information security continuityA.17 營運持續管理之資訊安全層面5.29 合併
A.17.1.2Implementing information security continuityA.17 營運持續管理之資訊安全層面5.29 合併
A.17.1.3Verify, review and evaluate information security continuityA.17 營運持續管理之資訊安全層面5.29 合併
A.17.2.1Availability of information processing facilitiesA.17 營運持續管理之資訊安全層面8.14 沿用
A.18.1.1Identification of applicable legislation and contractual requirementsA.18 遵循性5.31 合併
A.18.1.2Intellectual property rightsA.18 遵循性5.32 沿用
A.18.1.3Protection of recordsA.18 遵循性5.33 沿用
A.18.1.4Privacy and protection of personally identifiable informationA.18 遵循性5.34 沿用
A.18.1.5Regulation of cryptographic controlsA.18 遵循性5.31 合併
A.18.2.1Independent review of information securityA.18 遵循性5.35 沿用
A.18.2.2Compliance with security policies and standardsA.18 遵循性5.36 合併
A.18.2.3Technical compliance reviewA.18 遵循性5.36 8.8 合併

三、2013 的 14 個領域去了哪裡

2022 版不再按領域分章,而是依控制的性質分成組織、人員、實體、技術四個主題。下表統計每個舊領域的控制,分別被整理到哪個新主題(一項舊控制拆到兩項新控制時兩邊都算)。

2013 領域舊控制數組織人員實體技術
A.5 資訊安全政策22–––
A.6 資訊安全的組織751–1
A.7 人力資源安全615––
A.8 資產管理107–3–
A.9 存取控制149––5
A.10 密碼學2–––2
A.11 實體與環境安全15––141
A.12 運作安全141––13
A.13 通訊安全731–3
A.14 系統獲取、開發及維護131––12
A.15 供應商關係55–––
A.16 資訊安全事故管理752––
A.17 營運持續管理之資訊安全層面43––1
A.18 遵循性88––1
2022 主題控制數114 → 933781434

四、轉版要做的事

  1. 更新風險處理計畫與 SoA:依 93 項控制重新對照,逐項寫納入或排除理由與實施狀態。
  2. 逐項評估 11 項新增控制:威脅情資、雲端服務、ICT 營運持續、實體監視、組態管理、資訊刪除、資料遮罩、資料外洩防護、監控活動、網頁過濾、安全程式設計。
  3. 補上條文的新要求:4.2 由 ISMS 處理哪些要求、4.4 過程與交互作用、6.2 目標的監督、6.3 變更的規劃、8.1 過程準則與外部提供的服務、9.3 新的審查輸入。
  4. 更新文件引用的條號:政策、程序、內稽檢查表與矯正措施表單上引用的舊條號(例如 A.12.3.1、10.1)都要改成新版。
  5. 確認證書狀態:2013 版證書在 2025-10-31 轉版期結束後已失效;2024 年的 Amd 1 沒有轉版期,但要在 4.1、4.2 判斷氣候變遷議題。

想動手練習對照與轉版時程,可以看互動教學頁:

▶互動教學2013 到 2022:控制對照與轉版

對照依 ISO/IEC 27002:2022 公開的新舊控制對照整理,控制名稱只列英文短標題,說明為本站自行撰寫;標準原文請參閱 ISO 正式出版品。

我是 AKIRA

學習電腦技術 30 年、歷經 IT 工程師、網路工程師、DQA、FAE、PM 到 iOS App 開發、前端/後端/全端開發、白帽駭客、DevOps、AI 開發,逐步累積了完整的技術與跨領域經驗。

這讓我變成 AI 時代的六邊形戰士。AI時代必須成為T型人才。

📧 EMAIL:tomokuri8@gmail.com

🎯 擅長

  • Prompt Engineering
  • Agent 開發
  • RAG 開發
  • Vibe / SPEC Coding
  • DevOps
  • AI-Chatbot Design
  • Public Cloud / Private Cloud Architect
  • Network Design and Maintenance Engineer
  • UI/UX Designer
  • iOS APP Development
  • Front-end / Back-end Full Stack Developer
  • WordPress

📜 證照

iPAS
  • iPAS 中級 AI 應用規劃師(機器學習)
  • iPAS 初級 AI 應用規劃師
Microsoft
  • Microsoft 認證:Azure AI(AI-900)
  • Microsoft® Certified Solutions Expert: Private Cloud
  • Microsoft Certified Professional
  • Microsoft® Certified Solutions Associate: Windows Server 2008
  • Microsoft® Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
  • Microsoft® Certified Technology Specialist: Windows Server 2008 R2, Server Virtualization
  • Microsoft® Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
  • Microsoft® Certified IT Professional: Server Administrator on Windows Server 2008
AWS
  • AWS Certified AI Practitioner
Cisco
  • CCNP Enterprise CCNP-Enterprise · Professional
  • Cisco Certified Specialist - Enterprise Core CCS-ECore · Specialist
  • Cisco Certified Specialist - Enterprise Advanced Infrastructure CCS-EAI · Specialist
  • CCNA Associate
  • CCNP Routing and Switching CCNP
  • CCNA Routing and Switching CCNA-RS
資安
  • CEH(Certified Ethical Hacker)
Google
  • Google Analytics
  • Google Ads

💻 專業技能

  • AI:Agent 開發 / RAG 開發 / Prompt Engineering / Vibe / SPEC Coding
  • Front-end:JavaScript / jQuery / Vue.js / Bootstrap / React
  • Back-end:Python / PHP / Node.js
  • Mobile APP:Objective-C / Swift
  • Database:MySQL / Oracle / PostgreSQL / RAG
  • Programming:Python
  • Server:Windows Server / Linux
  • Virtualization:Hyper-V / VMware
  • Cloud:Azure / Google Cloud / AWS
  • Design:Adobe Photoshop / Illustrator / AE / Sketch / UI/UX Design