2022 年版沒有改變 ISMS 的基本做法,條文 4–10 只有少數新增與調整;變動最大的是附錄 A:114 項控制重新整理成 93 項、分成四個主題,其中 11 項是全新控制。下面先看條文的差異,再用對照表逐項查附錄 A,可以切換「從 2022 查 2013」或「從 2013 查 2022」。點控制名稱會打開該節點的白話說明。
條文的要求內容大多不變,下表只列有變化的地方。「類型」中,新增是 2013 版沒有的要求,修改是要求內容有增減,結構是條號或排列改變而內容大致相同。
| 條號 | 2013 版 | 2022 版的變化 | 類型 | 實務上要做什麼 |
|---|---|---|---|---|
| 標題標準名稱 | Information security management systems — Requirements | 名稱前加上系列標題 Information security, cybersecurity and privacy protection | 名稱 | 只是系列命名調整,要求沒有因此改變;證書與文件上的標準名稱可順手更新。 |
| 4.2利害關係者 | 決定利害關係者及其與資安有關的要求 | 新增一項:要決定這些要求中,哪些會透過 ISMS 來處理 | 修改 | 利害關係者清單要多一欄「是否由 ISMS 處理、怎麼處理」,稽核常會追問這一欄。 |
| 4.4ISMS | 建立、實施、維持並持續改善 ISMS | 明確要求 ISMS 要包含所需的「過程及其交互作用」 | 修改 | 用流程圖或過程清單說清楚 ISMS 由哪些過程組成、彼此怎麼銜接(例如風險評鑑結果怎麼流到 SoA 與管審)。 |
| 6.1.3風險處理與 SoA | 附錄 A 包含控制目標與控制措施 | 附錄 A 不再列控制目標,改稱「資訊安全控制」清單,並說明它不是完整清單 | 修改 | SoA 要改成 93 項控制,重新寫每一項的納入或排除理由與實施狀態;也可以加入附錄 A 以外的自訂控制。 |
| 6.2資安目標 | 訂定可量測、與政策一致的目標 | 新增「目標要被監督」,並要求目標以文件化資訊形式可供取得 | 修改 | 每個目標要有追蹤紀錄(誰在什麼時候檢視過、進度如何),不能只在年初寫一次。 |
| 6.3變更的規劃 | (2013 版沒有這一條) | 新增條文:ISMS 需要變更時,要有規劃地進行 | 新增 | 建立 ISMS 變更的評估方式,例如組織調整、範圍擴大、系統汰換前先評估對 ISMS 的影響,並留下紀錄。 |
| 7.4溝通 | 分別決定由誰溝通、以及溝通的過程 | 兩項合併為「如何溝通」 | 修改 | 影響小;溝通計畫保留「溝通什麼、何時、對誰、怎麼溝通」即可。 |
| 8.1運作規劃與管制 | 規劃、實施與管制過程;管制委外過程 | 新增要為過程訂定準則並依準則管制;「委外過程」改為「外部提供的過程、產品或服務」 | 修改 | 供應商、雲端服務與外部取得的產品都要納入管制範圍,並說明各過程的運作準則。 |
| 9.2內部稽核 | 單一條文 | 拆成 9.2.1 一般要求與 9.2.2 內部稽核方案 | 結構 | 內容大致相同,主要是條號改變;內稽程序與報告引用的條號要更新。 |
| 9.3管理審查 | 單一條文 | 拆成 9.3.1~9.3.3;審查輸入新增「利害關係者需要與期望的變化」 | 修改 | 管理審查議程與會議紀錄要加上這一項輸入。 |
| 10改善 | 10.1 不符合與矯正措施、10.2 持續改善 | 順序對調:10.1 持續改善、10.2 不符合與矯正措施 | 結構 | 要求本身不變,程序書、矯正措施表單上引用的條號要改。 |
| 附錄 A控制清單 | 114 項控制、14 個領域,附控制目標 | 93 項控制、4 個主題,移除控制目標;新增 11 項 | 結構 | 重做 SoA 與風險處理計畫,並逐項確認 11 項新增控制是否適用、如何落地。 |
| Amd 1:2024氣候變遷修訂 | — | 4.1 要判斷氣候變遷是否為相關議題;4.2 加註利害關係者可能有氣候相關要求 | 修訂 | 沒有轉版期,也不換證;驗證機構會在之後的例行稽核中確認組織有做這項判斷。 |
類型說明:新增是 2013 版找不到對應的控制;合併是由兩項以上舊控制整併而成;沿用是一對一對應,名稱或內容可能改寫。A.18.2.3 技術遵循性審查同時拆到 5.36 與 8.8,所以在「從 2013 查 2022」裡會對到兩項。
| 2022 條號 | 控制名稱 | 主題 | 類型 | 2013 對應 |
|---|---|---|---|---|
| 5.1 | Policies for information security 訂出整體資安政策與各主題政策,經管理階層核准、公告給相關人員,並定期檢討。 | 組織 | 合併 | A.5.1.1Policies for information securityA.5.1.2Review of the policies for information security |
| 5.2 | Information security roles and responsibilities 依組織需要定義並分派資安相關的角色與責任,讓每項資安工作都有明確的負責人。 | 組織 | 沿用 | A.6.1.1Information security roles and responsibilities |
| 5.3 | Segregation of duties 把容易互相衝突的工作分給不同的人,降低一個人就能完成舞弊或嚴重錯誤的機會。 | 組織 | 沿用 | A.6.1.2Segregation of duties |
| 5.4 | Management responsibilities 各級主管要要求部屬依政策與程序落實資安,而不是把資安全丟給 IT 部門處理。 | 組織 | 沿用 | A.7.2.1Management responsibilities |
| 5.5 | Contact with authorities 預先建立與主管機關、執法與監管單位的聯絡管道,出事時知道要找誰、何時通報。 | 組織 | 沿用 | A.6.1.3Contact with authorities |
| 5.6 | Contact with special interest groups 參與資安社群、產業協會或專業論壇,持續取得新知、預警資訊與同業經驗。 | 組織 | 沿用 | A.6.1.4Contact with special interest groups |
| 5.7 | Threat intelligence 2022 新增:蒐集並分析與組織相關的威脅資訊,轉化成能調整防護的具體行動。 | 組織 | 新增 | 2013 版沒有對應 |
| 5.8 | Information security in project management 在各類專案的規劃與執行過程中納入資安考量,不等到上線前才發現問題。 | 組織 | 合併 | A.6.1.5Information security in project managementA.14.1.1Information security requirements analysis and specification |
| 5.9 | Inventory of information and other associated assets 建立並維護資訊及相關資產的清冊,每一項都指定擁有者,作為風險評鑑與保護的基礎。 | 組織 | 合併 | A.8.1.1Inventory of assetsA.8.1.2Ownership of assets |
| 5.10 | Acceptable use of information and other associated assets 訂出資訊與資產可以怎麼用、不可以怎麼用的規則,並讓使用者知道且遵守。 | 組織 | 合併 | A.8.1.3Acceptable use of assetsA.8.2.3Handling of assets |
| 5.11 | Return of assets 人員離職、調職或合約結束時,收回其持有的組織資產,包括設備、門禁卡與資訊。 | 組織 | 沿用 | A.8.1.4Return of assets |
| 5.12 | Classification of information 依資訊的機密性、完整性、可用性需求與利害關係者期望,把資訊分成不同等級。 | 組織 | 沿用 | A.8.2.1Classification of information |
| 5.13 | Labelling of information 依分級制度在文件、檔案、媒體或系統上標示級別,讓人和系統都能辨識該如何處理。 | 組織 | 沿用 | A.8.2.2Labelling of information |
| 5.14 | Information transfer 對組織內外的資訊傳遞訂出規則、程序或協議,涵蓋電子、實體媒體與口頭等各種方式。 | 組織 | 合併 | A.13.2.1Information transfer policies and proceduresA.13.2.2Agreements on information transferA.13.2.3Electronic messaging |
| 5.15 | Access control 依業務與資安需求訂出存取控制規則,決定誰在什麼條件下可以存取哪些資訊與資產。 | 組織 | 合併 | A.9.1.1Access control policyA.9.1.2Access to networks and network services |
| 5.16 | Identity management 管理使用者與系統身分從建立、異動到刪除的完整生命週期,確保每個身分都能對應到負責人。 | 組織 | 沿用 | A.9.2.1User registration and de-registration |
| 5.17 | Authentication information 管理密碼、權杖、憑證等鑑別資訊的發放、保管與使用規則,避免被猜到、外洩或共用。 | 組織 | 合併 | A.9.2.4Management of secret authentication information of usersA.9.3.1Use of secret authentication informationA.9.4.3Password management system |
| 5.18 | Access rights 依存取控制規則辦理權限的申請、核准、變更、定期審查與移除,讓權限隨職務變化而調整。 | 組織 | 合併 | A.9.2.2User access provisioningA.9.2.5Review of user access rightsA.9.2.6Removal or adjustment of access rights |
| 5.19 | Information security in supplier relationships 建立管理供應商資安風險的流程,從選商、評估到關係結束,都考慮供應商能接觸到的資訊與系統。 | 組織 | 沿用 | A.15.1.1Information security policy for supplier relationships |
| 5.20 | Addressing information security within supplier agreements 依供應商類型與風險,在合約中寫明資安要求、雙方責任、通報義務與稽核權等條款。 | 組織 | 沿用 | A.15.1.2Addressing security within supplier agreements |
| 5.21 | Managing information security in the ICT supply chain 管理資訊與通訊技術產品和服務的供應鏈風險,延伸到供應商的供應商、元件來源與軟體組成。 | 組織 | 沿用 | A.15.1.3Information and communication technology supply chain |
| 5.22 | Monitoring, review and change management of supplier services 定期監督與審查供應商的資安表現與服務品質,並管理供應商服務的變更。 | 組織 | 合併 | A.15.2.1Monitoring and review of supplier servicesA.15.2.2Managing changes to supplier services |
| 5.23 | Information security for use of cloud services 2022 新增:對雲端服務的取得、使用、管理到退出建立流程,並釐清與雲端服務商的責任分工。 | 組織 | 新增 | 2013 版沒有對應 |
| 5.24 | Information security incident management planning and preparation 事先規劃事件管理的流程、角色、溝通與工具,讓組織在事故發生時能快速且一致地處理。 | 組織 | 沿用 | A.16.1.1Responsibilities and procedures |
| 5.25 | Assessment and decision on information security events 評估通報上來的資安事件,判斷是否構成資安事故,並依分級決定後續處理方式。 | 組織 | 沿用 | A.16.1.4Assessment of and decision on information security events |
| 5.26 | Response to information security incidents 依文件化的程序處理資安事故,包括遏止、根除、復原、溝通與紀錄。 | 組織 | 沿用 | A.16.1.5Response to information security incidents |
| 5.27 | Learning from information security incidents 分析處理過的資安事故,找出根本原因與改善機會,用來強化控制並降低再發生的機率。 | 組織 | 沿用 | A.16.1.6Learning from information security incidents |
| 5.28 | Collection of evidence 訂定程序來識別、收集、取得並保存與資安事件有關的證據,確保證據可信且可用於法律程序。 | 組織 | 沿用 | A.16.1.7Collection of evidence |
| 5.29 | Information security during disruption 規劃在營運中斷或危機期間,仍能把資安維持在適當水準,不因為趕著恢復而開大門。 | 組織 | 合併 | A.17.1.1Planning information security continuityA.17.1.2Implementing information security continuityA.17.1.3Verify, review and evaluate information security continuity |
| 5.30 | ICT readiness for business continuity 2022 新增:依營運持續目標規劃、實作、維護並測試 ICT 的備妥程度,確保中斷後能及時恢復。 | 組織 | 新增 | 2013 版沒有對應 |
| 5.31 | Legal, statutory, regulatory and contractual requirements 鑑別並記錄與資安相關的法律、法規與合約要求,說明組織如何滿足,並保持更新。 | 組織 | 合併 | A.18.1.1Identification of applicable legislation and contractual requirementsA.18.1.5Regulation of cryptographic controls |
| 5.32 | Intellectual property rights 建立適當程序保護智慧財產權,包括合法使用軟體授權與他人著作,以及保護組織自己的智財。 | 組織 | 沿用 | A.18.1.2Intellectual property rights |
| 5.33 | Protection of records 保護紀錄不被遺失、毀損、偽造、未經授權的存取或提前銷毀,並依要求保存足夠期間。 | 組織 | 沿用 | A.18.1.3Protection of records |
| 5.34 | Privacy and protection of PII 依適用的法規與合約要求,識別並滿足保護個人資料與隱私的要求。 | 組織 | 沿用 | A.18.1.4Privacy and protection of personally identifiable information |
| 5.35 | Independent review of information security 定期或在重大變更時,由獨立的人員對資安管理方式與實作進行審查。 | 組織 | 沿用 | A.18.2.1Independent review of information security |
| 5.36 | Compliance with policies, rules and standards for information security 定期檢查組織是否遵守自己的資安政策、主題政策、規則與標準,發現不符時採取改善行動。 | 組織 | 合併 | A.18.2.2Compliance with security policies and standardsA.18.2.3Technical compliance review |
| 5.37 | Documented operating procedures 把資訊處理設施的重要作業程序寫成文件,並讓需要的人員能夠取得與遵循。 | 組織 | 沿用 | A.12.1.1Documented operating procedures |
| 6.1 | Screening 錄用前依職務敏感度與法規限制,查證候選人的身分、學經歷等資料,查核深度要與風險相稱。 | 人員 | 沿用 | A.7.1.1Screening |
| 6.2 | Terms and conditions of employment 在勞動契約、聘書或到職承諾書中寫明人員的資安責任,讓責任從到職第一天就有依據。 | 人員 | 沿用 | A.7.1.2Terms and conditions of employment |
| 6.3 | Information security awareness, education and training 依角色規劃資安認知、教育與訓練,隨威脅與政策更新內容,並確認人員真的理解。 | 人員 | 沿用 | A.7.2.2Information security awareness, education and training |
| 6.4 | Disciplinary process 違反資安政策時,有事先公告、查明事實並依情節一致處理的流程,兼具嚇阻與究責作用。 | 人員 | 沿用 | A.7.2.3Disciplinary process |
| 6.5 | Responsibilities after termination or change of employment 人員離職或調動時,告知哪些資安義務仍持續有效,並把原本負責的資安職責交接出去。 | 人員 | 沿用 | A.7.3.1Termination or change of employment responsibilities |
| 6.6 | Confidentiality or non-disclosure agreements 依組織保護資訊的需要訂定保密或不揭露協議,讓員工與外部對象清楚哪些資訊不能外流。 | 人員 | 沿用 | A.13.2.4Confidentiality or non-disclosure agreements |
| 6.7 | Remote working 人員在辦公室以外的地點工作時,透過規則與技術措施,維持與辦公室相當的資訊保護。 | 人員 | 沿用 | A.6.2.2Teleworking |
| 6.8 | Information security event reporting 提供簡單、人人都知道的管道,讓人員能及時回報觀察到或懷疑的資訊安全事件。 | 人員 | 合併 | A.16.1.2Reporting information security eventsA.16.1.3Reporting information security weaknesses |
| 7.1 | Physical security perimeters 依資訊與資產的重要性劃出實體區域的邊界,邊界上的牆、門窗與出入口要真的擋得住人。 | 實體 | 沿用 | A.11.1.1Physical security perimeter |
| 7.2 | Physical entry 用門禁、訪客管理與收發貨區規劃,確保只有獲得授權的人能進入受保護的區域。 | 實體 | 合併 | A.11.1.2Physical entry controlsA.11.1.6Delivery and loading areas |
| 7.3 | Securing offices, rooms and facilities 規劃辦公室、會議室與機房時就把資安納入考量,避免機密被看見、聽見或被輕易找到。 | 實體 | 沿用 | A.11.1.3Securing offices, rooms and facilities |
| 7.4 | Physical security monitoring 2022 新增。用監視器、入侵警報等持續監看場所,及早發現並嚇阻未經授權的實體進入。 | 實體 | 新增 | 2013 版沒有對應 |
| 7.5 | Protecting against physical and environmental threats 針對火災、淹水、地震、停電與蓄意破壞等威脅,在選址、設計與維運上預先做好防護。 | 實體 | 沿用 | A.11.1.4Protecting against external and environmental threats |
| 7.6 | Working in secure areas 為機房、實驗室等安全區域訂定專屬的作業規則,管住已經獲准進入的人在裡面做什麼。 | 實體 | 沿用 | A.11.1.5Working in secure areas |
| 7.7 | Clear desk and clear screen 離開座位時收好機密文件與儲存媒體、鎖定螢幕,避免資訊被他人看見或順手取走。 | 實體 | 沿用 | A.11.2.9Clear desk and clear screen policy |
| 7.8 | Equipment siting and protection 把設備放在能降低環境風險與未授權接觸的位置,並依設備重要性加上適當的防護。 | 實體 | 沿用 | A.11.2.1Equipment siting and protection |
| 7.9 | Security of assets off-premises 筆電、手機與帶出公司的設備,在辦公室以外也要有防遺失、防竊與防窺看的保護措施。 | 實體 | 沿用 | A.11.2.6Security of equipment and assets off-premises |
| 7.10 | Storage media 隨身碟、外接硬碟、光碟等儲存媒體,從取得、使用、運送到銷毀,都依資訊分類來管理。 | 實體 | 合併 | A.8.3.1Management of removable mediaA.8.3.2Disposal of mediaA.8.3.3Physical media transferA.11.2.5Removal of assets |
| 7.11 | Supporting utilities 電力、空調、通訊與供水等支援設施要穩定可靠,避免它們故障而拖垮資訊處理設備。 | 實體 | 沿用 | A.11.2.2Supporting utilities |
| 7.12 | Cabling security 保護電源線與網路線不被截聽、干擾或破壞,並清楚標示,方便維護與查核。 | 實體 | 沿用 | A.11.2.3Cabling security |
| 7.13 | Equipment maintenance 依廠商建議定期維護設備,並管控維修人員、送修過程與維修完成後的檢查。 | 實體 | 沿用 | A.11.2.4Equipment maintenance |
| 7.14 | Secure disposal or re-use of equipment 設備報廢、轉售或轉給他人使用前,確認其中的敏感資料與授權軟體都已被安全清除。 | 實體 | 沿用 | A.11.2.7Secure disposal or re-use of equipment |
| 8.1 | User endpoint devices 員工使用的筆電、手機、平板要有一致的安全設定與管理方式,遺失或被入侵時資料仍受保護。 | 技術 | 合併 | A.6.2.1Mobile device policyA.11.2.8Unattended user equipment |
| 8.2 | Privileged access rights 系統管理員、資料庫管理者等高權限帳號要另外核准、限制範圍、留下紀錄並定期覆核。 | 技術 | 沿用 | A.9.2.3Management of privileged access rights |
| 8.3 | Information access restriction 在 ERP、檔案伺服器等系統裡依角色設定權限,讓每個人只碰得到工作需要的資料與功能。 | 技術 | 沿用 | A.9.4.1Information access restriction |
| 8.4 | Access to source code 誰能讀、誰能改原始碼要管清楚,搭配分支保護與程式碼審查,防止竄改、外流或被植入後門。 | 技術 | 沿用 | A.9.4.5Access control to program source code |
| 8.5 | Secure authentication 登入機制要依資訊敏感度與風險設計,例如啟用多因子驗證、限制錯誤嘗試、保護登入過程。 | 技術 | 沿用 | A.9.4.2Secure log-on procedures |
| 8.6 | Capacity management 監看並預估運算、儲存、網路與人力資源的使用量,避免資源不足造成服務中斷或效能惡化。 | 技術 | 沿用 | A.12.1.3Capacity management |
| 8.7 | Protection against malware 結合偵測工具、使用者認知與系統管控,防止病毒、勒索軟體等惡意程式進入並擴散。 | 技術 | 沿用 | A.12.2.1Controls against malware |
| 8.8 | Management of technical vulnerabilities 掌握手上系統有哪些已知漏洞,依嚴重與暴露程度排定修補或暫時緩解,縮短被攻擊的空窗。 | 技術 | 合併 | A.12.6.1Management of technical vulnerabilitiesA.18.2.3Technical compliance review |
| 8.9 | Configuration management 2022 新增。替各類系統訂出安全設定基準,定期比對實際設定有沒有偏離,改設定要走變更流程。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.10 | Information deletion 2022 新增。替資料訂保存期限,到期就用合適方法確實刪除或銷毀;留得越少,外洩時損失越小。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.11 | Data masking 2022 新增。用部分遮蔽、假名化、匿名化等手法,讓客服、測試等角色只看到工作需要的那部分資料。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.12 | Data leakage prevention 2022 新增。盯住郵件、網頁上傳、USB 等外流通道,偵測並攔下敏感資訊被不當帶出組織。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.13 | Information backup 重要資料與系統要有可用的副本,並定期實際還原驗證,確保誤刪、故障或勒索時救得回來。 | 技術 | 沿用 | A.12.3.1Information backup |
| 8.14 | Redundancy of information processing facilities 找出關鍵系統的單點故障,依業務能承受的停機程度準備雙電源、雙線路、叢集或異地備援。 | 技術 | 沿用 | A.17.2.1Availability of information processing facilities |
| 8.15 | Logging 登入、權限變更、錯誤與告警都要留下紀錄,集中保存、防止竄改,出事時才查得到經過。 | 技術 | 合併 | A.12.4.1Event loggingA.12.4.2Protection of log informationA.12.4.3Administrator and operator logs |
| 8.16 | Monitoring activities 2022 新增。先掌握系統與使用者的正常樣態,持續找出偏離的異常行為,並及時判斷是否為資安事件。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.17 | Clock synchronization 讓伺服器、網路與安全設備都向同一個可信時間來源對時,事件調查時日誌才拼得出正確時間線。 | 技術 | 沿用 | A.12.4.4Clock synchronisation |
| 8.18 | Use of privileged utility programs 磁碟編輯、密碼重設這類能越過系統控制的工具,只給少數人在受控條件下使用並留下紀錄。 | 技術 | 沿用 | A.9.4.4Use of privileged utility programs |
| 8.19 | Installation of software on operational systems 在正式運作的系統上安裝或更新軟體要走管控程序,限制誰能裝、裝什麼,並保留回復能力。 | 技術 | 合併 | A.12.5.1Installation of software on operational systemsA.12.6.2Restrictions on software installation |
| 8.20 | Networks security 網路設備的設定、管理介面、防火牆規則與架構圖都要受控,別讓內部網路成為攻擊者的通行道。 | 技術 | 沿用 | A.13.1.1Network controls |
| 8.21 | Security of network services 向電信或雲端業者取得的網路服務,要把安全功能與服務水準寫進合約,並定期確認有做到。 | 技術 | 沿用 | A.13.1.2Security of network services |
| 8.22 | Segregation of networks 依信任程度、用途與敏感度把網路切成不同區段,限制區段之間的流量,降低攻擊擴散。 | 技術 | 沿用 | A.13.1.3Segregation in networks |
| 8.23 | Web filtering 2022 新增。依網站分類與威脅情資擋掉惡意、釣魚等高風險網站,降低員工上網誤觸的機會。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.24 | Use of cryptography 什麼資料要加密、用哪種演算法、金鑰怎麼產生保管與更換,都要有明確規則並確實執行。 | 技術 | 合併 | A.10.1.1Policy on the use of cryptographic controlsA.10.1.2Key management |
| 8.25 | Secure development life cycle 把需求、設計、撰寫、測試、上線各階段該做的安全活動固定下來,不靠個人習慣決定。 | 技術 | 沿用 | A.14.2.1Secure development policy |
| 8.26 | Application security requirements 自行開發或採購系統前,先把驗證、加密、日誌等安全需求寫進規格,驗收時逐項對照。 | 技術 | 合併 | A.14.1.2Securing application services on public networksA.14.1.3Protecting application services transactions |
| 8.27 | Secure system architecture and engineering principles 用縱深防禦、最小權限、預設安全等共同原則設計系統,讓不同團隊做出的架構有一致底線。 | 技術 | 沿用 | A.14.2.5Secure system engineering principles |
| 8.28 | Secure coding 2022 新增。用安全寫法規範、程式碼審查與自動掃描,擋下注入、寫死密鑰、過時套件等常見漏洞。 | 技術 | 新增 | 2013 版沒有對應 |
| 8.29 | Security testing in development and acceptance 開發過程與上線前都要做安全測試,依安全需求逐項驗證,沒通過放行標準就不上線。 | 技術 | 合併 | A.14.2.8System security testingA.14.2.9System acceptance testing |
| 8.30 | Outsourced development 系統交給外部廠商開發時,從合約條款、過程監督到驗收測試都要把安全要求帶進去。 | 技術 | 沿用 | A.14.2.7Outsourced development |
| 8.31 | Separation of development, test and production environments 開發與測試不在正式環境裡進行,各環境的帳號、網路與資料分開,免得一個失誤波及正式業務。 | 技術 | 合併 | A.12.1.4Separation of development, testing and operational environmentsA.14.2.6Secure development environment |
| 8.32 | Change management 系統、網路與設定的任何異動都走申請、評估、測試、核准與紀錄,出問題時能回復原狀。 | 技術 | 合併 | A.12.1.2Change managementA.14.2.2System change control proceduresA.14.2.3Technical review of applications after operating platform changesA.14.2.4Restrictions on changes to software packages |
| 8.33 | Test information 測試優先使用合成或遮罩過的資料,真要用正式資料須經核准、受保護,用完立即刪除。 | 技術 | 沿用 | A.14.3.1Protection of test data |
| 8.34 | Protection of information systems during audit testing 要碰正式系統的稽核、掃描或滲透測試,先談好範圍、時段與權限,避免檢查本身造成中斷。 | 技術 | 沿用 | A.12.7.1Information systems audit controls |
| 2013 條號 | 2013 控制名稱 | 2013 領域 | → 2022 對應 | 類型 |
|---|---|---|---|---|
| A.5.1.1 | Policies for information security | A.5 資訊安全政策 | 5.1 | 合併 |
| A.5.1.2 | Review of the policies for information security | A.5 資訊安全政策 | 5.1 | 合併 |
| A.6.1.1 | Information security roles and responsibilities | A.6 資訊安全的組織 | 5.2 | 沿用 |
| A.6.1.2 | Segregation of duties | A.6 資訊安全的組織 | 5.3 | 沿用 |
| A.6.1.3 | Contact with authorities | A.6 資訊安全的組織 | 5.5 | 沿用 |
| A.6.1.4 | Contact with special interest groups | A.6 資訊安全的組織 | 5.6 | 沿用 |
| A.6.1.5 | Information security in project management | A.6 資訊安全的組織 | 5.8 | 合併 |
| A.6.2.1 | Mobile device policy | A.6 資訊安全的組織 | 8.1 | 合併 |
| A.6.2.2 | Teleworking | A.6 資訊安全的組織 | 6.7 | 沿用 |
| A.7.1.1 | Screening | A.7 人力資源安全 | 6.1 | 沿用 |
| A.7.1.2 | Terms and conditions of employment | A.7 人力資源安全 | 6.2 | 沿用 |
| A.7.2.1 | Management responsibilities | A.7 人力資源安全 | 5.4 | 沿用 |
| A.7.2.2 | Information security awareness, education and training | A.7 人力資源安全 | 6.3 | 沿用 |
| A.7.2.3 | Disciplinary process | A.7 人力資源安全 | 6.4 | 沿用 |
| A.7.3.1 | Termination or change of employment responsibilities | A.7 人力資源安全 | 6.5 | 沿用 |
| A.8.1.1 | Inventory of assets | A.8 資產管理 | 5.9 | 合併 |
| A.8.1.2 | Ownership of assets | A.8 資產管理 | 5.9 | 合併 |
| A.8.1.3 | Acceptable use of assets | A.8 資產管理 | 5.10 | 合併 |
| A.8.1.4 | Return of assets | A.8 資產管理 | 5.11 | 沿用 |
| A.8.2.1 | Classification of information | A.8 資產管理 | 5.12 | 沿用 |
| A.8.2.2 | Labelling of information | A.8 資產管理 | 5.13 | 沿用 |
| A.8.2.3 | Handling of assets | A.8 資產管理 | 5.10 | 合併 |
| A.8.3.1 | Management of removable media | A.8 資產管理 | 7.10 | 合併 |
| A.8.3.2 | Disposal of media | A.8 資產管理 | 7.10 | 合併 |
| A.8.3.3 | Physical media transfer | A.8 資產管理 | 7.10 | 合併 |
| A.9.1.1 | Access control policy | A.9 存取控制 | 5.15 | 合併 |
| A.9.1.2 | Access to networks and network services | A.9 存取控制 | 5.15 | 合併 |
| A.9.2.1 | User registration and de-registration | A.9 存取控制 | 5.16 | 沿用 |
| A.9.2.2 | User access provisioning | A.9 存取控制 | 5.18 | 合併 |
| A.9.2.3 | Management of privileged access rights | A.9 存取控制 | 8.2 | 沿用 |
| A.9.2.4 | Management of secret authentication information of users | A.9 存取控制 | 5.17 | 合併 |
| A.9.2.5 | Review of user access rights | A.9 存取控制 | 5.18 | 合併 |
| A.9.2.6 | Removal or adjustment of access rights | A.9 存取控制 | 5.18 | 合併 |
| A.9.3.1 | Use of secret authentication information | A.9 存取控制 | 5.17 | 合併 |
| A.9.4.1 | Information access restriction | A.9 存取控制 | 8.3 | 沿用 |
| A.9.4.2 | Secure log-on procedures | A.9 存取控制 | 8.5 | 沿用 |
| A.9.4.3 | Password management system | A.9 存取控制 | 5.17 | 合併 |
| A.9.4.4 | Use of privileged utility programs | A.9 存取控制 | 8.18 | 沿用 |
| A.9.4.5 | Access control to program source code | A.9 存取控制 | 8.4 | 沿用 |
| A.10.1.1 | Policy on the use of cryptographic controls | A.10 密碼學 | 8.24 | 合併 |
| A.10.1.2 | Key management | A.10 密碼學 | 8.24 | 合併 |
| A.11.1.1 | Physical security perimeter | A.11 實體與環境安全 | 7.1 | 沿用 |
| A.11.1.2 | Physical entry controls | A.11 實體與環境安全 | 7.2 | 合併 |
| A.11.1.3 | Securing offices, rooms and facilities | A.11 實體與環境安全 | 7.3 | 沿用 |
| A.11.1.4 | Protecting against external and environmental threats | A.11 實體與環境安全 | 7.5 | 沿用 |
| A.11.1.5 | Working in secure areas | A.11 實體與環境安全 | 7.6 | 沿用 |
| A.11.1.6 | Delivery and loading areas | A.11 實體與環境安全 | 7.2 | 合併 |
| A.11.2.1 | Equipment siting and protection | A.11 實體與環境安全 | 7.8 | 沿用 |
| A.11.2.2 | Supporting utilities | A.11 實體與環境安全 | 7.11 | 沿用 |
| A.11.2.3 | Cabling security | A.11 實體與環境安全 | 7.12 | 沿用 |
| A.11.2.4 | Equipment maintenance | A.11 實體與環境安全 | 7.13 | 沿用 |
| A.11.2.5 | Removal of assets | A.11 實體與環境安全 | 7.10 | 合併 |
| A.11.2.6 | Security of equipment and assets off-premises | A.11 實體與環境安全 | 7.9 | 沿用 |
| A.11.2.7 | Secure disposal or re-use of equipment | A.11 實體與環境安全 | 7.14 | 沿用 |
| A.11.2.8 | Unattended user equipment | A.11 實體與環境安全 | 8.1 | 合併 |
| A.11.2.9 | Clear desk and clear screen policy | A.11 實體與環境安全 | 7.7 | 沿用 |
| A.12.1.1 | Documented operating procedures | A.12 運作安全 | 5.37 | 沿用 |
| A.12.1.2 | Change management | A.12 運作安全 | 8.32 | 合併 |
| A.12.1.3 | Capacity management | A.12 運作安全 | 8.6 | 沿用 |
| A.12.1.4 | Separation of development, testing and operational environments | A.12 運作安全 | 8.31 | 合併 |
| A.12.2.1 | Controls against malware | A.12 運作安全 | 8.7 | 沿用 |
| A.12.3.1 | Information backup | A.12 運作安全 | 8.13 | 沿用 |
| A.12.4.1 | Event logging | A.12 運作安全 | 8.15 | 合併 |
| A.12.4.2 | Protection of log information | A.12 運作安全 | 8.15 | 合併 |
| A.12.4.3 | Administrator and operator logs | A.12 運作安全 | 8.15 | 合併 |
| A.12.4.4 | Clock synchronisation | A.12 運作安全 | 8.17 | 沿用 |
| A.12.5.1 | Installation of software on operational systems | A.12 運作安全 | 8.19 | 合併 |
| A.12.6.1 | Management of technical vulnerabilities | A.12 運作安全 | 8.8 | 合併 |
| A.12.6.2 | Restrictions on software installation | A.12 運作安全 | 8.19 | 合併 |
| A.12.7.1 | Information systems audit controls | A.12 運作安全 | 8.34 | 沿用 |
| A.13.1.1 | Network controls | A.13 通訊安全 | 8.20 | 沿用 |
| A.13.1.2 | Security of network services | A.13 通訊安全 | 8.21 | 沿用 |
| A.13.1.3 | Segregation in networks | A.13 通訊安全 | 8.22 | 沿用 |
| A.13.2.1 | Information transfer policies and procedures | A.13 通訊安全 | 5.14 | 合併 |
| A.13.2.2 | Agreements on information transfer | A.13 通訊安全 | 5.14 | 合併 |
| A.13.2.3 | Electronic messaging | A.13 通訊安全 | 5.14 | 合併 |
| A.13.2.4 | Confidentiality or non-disclosure agreements | A.13 通訊安全 | 6.6 | 沿用 |
| A.14.1.1 | Information security requirements analysis and specification | A.14 系統獲取、開發及維護 | 5.8 | 合併 |
| A.14.1.2 | Securing application services on public networks | A.14 系統獲取、開發及維護 | 8.26 | 合併 |
| A.14.1.3 | Protecting application services transactions | A.14 系統獲取、開發及維護 | 8.26 | 合併 |
| A.14.2.1 | Secure development policy | A.14 系統獲取、開發及維護 | 8.25 | 沿用 |
| A.14.2.2 | System change control procedures | A.14 系統獲取、開發及維護 | 8.32 | 合併 |
| A.14.2.3 | Technical review of applications after operating platform changes | A.14 系統獲取、開發及維護 | 8.32 | 合併 |
| A.14.2.4 | Restrictions on changes to software packages | A.14 系統獲取、開發及維護 | 8.32 | 合併 |
| A.14.2.5 | Secure system engineering principles | A.14 系統獲取、開發及維護 | 8.27 | 沿用 |
| A.14.2.6 | Secure development environment | A.14 系統獲取、開發及維護 | 8.31 | 合併 |
| A.14.2.7 | Outsourced development | A.14 系統獲取、開發及維護 | 8.30 | 沿用 |
| A.14.2.8 | System security testing | A.14 系統獲取、開發及維護 | 8.29 | 合併 |
| A.14.2.9 | System acceptance testing | A.14 系統獲取、開發及維護 | 8.29 | 合併 |
| A.14.3.1 | Protection of test data | A.14 系統獲取、開發及維護 | 8.33 | 沿用 |
| A.15.1.1 | Information security policy for supplier relationships | A.15 供應商關係 | 5.19 | 沿用 |
| A.15.1.2 | Addressing security within supplier agreements | A.15 供應商關係 | 5.20 | 沿用 |
| A.15.1.3 | Information and communication technology supply chain | A.15 供應商關係 | 5.21 | 沿用 |
| A.15.2.1 | Monitoring and review of supplier services | A.15 供應商關係 | 5.22 | 合併 |
| A.15.2.2 | Managing changes to supplier services | A.15 供應商關係 | 5.22 | 合併 |
| A.16.1.1 | Responsibilities and procedures | A.16 資訊安全事故管理 | 5.24 | 沿用 |
| A.16.1.2 | Reporting information security events | A.16 資訊安全事故管理 | 6.8 | 合併 |
| A.16.1.3 | Reporting information security weaknesses | A.16 資訊安全事故管理 | 6.8 | 合併 |
| A.16.1.4 | Assessment of and decision on information security events | A.16 資訊安全事故管理 | 5.25 | 沿用 |
| A.16.1.5 | Response to information security incidents | A.16 資訊安全事故管理 | 5.26 | 沿用 |
| A.16.1.6 | Learning from information security incidents | A.16 資訊安全事故管理 | 5.27 | 沿用 |
| A.16.1.7 | Collection of evidence | A.16 資訊安全事故管理 | 5.28 | 沿用 |
| A.17.1.1 | Planning information security continuity | A.17 營運持續管理之資訊安全層面 | 5.29 | 合併 |
| A.17.1.2 | Implementing information security continuity | A.17 營運持續管理之資訊安全層面 | 5.29 | 合併 |
| A.17.1.3 | Verify, review and evaluate information security continuity | A.17 營運持續管理之資訊安全層面 | 5.29 | 合併 |
| A.17.2.1 | Availability of information processing facilities | A.17 營運持續管理之資訊安全層面 | 8.14 | 沿用 |
| A.18.1.1 | Identification of applicable legislation and contractual requirements | A.18 遵循性 | 5.31 | 合併 |
| A.18.1.2 | Intellectual property rights | A.18 遵循性 | 5.32 | 沿用 |
| A.18.1.3 | Protection of records | A.18 遵循性 | 5.33 | 沿用 |
| A.18.1.4 | Privacy and protection of personally identifiable information | A.18 遵循性 | 5.34 | 沿用 |
| A.18.1.5 | Regulation of cryptographic controls | A.18 遵循性 | 5.31 | 合併 |
| A.18.2.1 | Independent review of information security | A.18 遵循性 | 5.35 | 沿用 |
| A.18.2.2 | Compliance with security policies and standards | A.18 遵循性 | 5.36 | 合併 |
| A.18.2.3 | Technical compliance review | A.18 遵循性 | 5.36 8.8 | 合併 |
2022 版不再按領域分章,而是依控制的性質分成組織、人員、實體、技術四個主題。下表統計每個舊領域的控制,分別被整理到哪個新主題(一項舊控制拆到兩項新控制時兩邊都算)。
| 2013 領域 | 舊控制數 | 組織 | 人員 | 實體 | 技術 |
|---|---|---|---|---|---|
| A.5 資訊安全政策 | 2 | 2 | – | – | – |
| A.6 資訊安全的組織 | 7 | 5 | 1 | – | 1 |
| A.7 人力資源安全 | 6 | 1 | 5 | – | – |
| A.8 資產管理 | 10 | 7 | – | 3 | – |
| A.9 存取控制 | 14 | 9 | – | – | 5 |
| A.10 密碼學 | 2 | – | – | – | 2 |
| A.11 實體與環境安全 | 15 | – | – | 14 | 1 |
| A.12 運作安全 | 14 | 1 | – | – | 13 |
| A.13 通訊安全 | 7 | 3 | 1 | – | 3 |
| A.14 系統獲取、開發及維護 | 13 | 1 | – | – | 12 |
| A.15 供應商關係 | 5 | 5 | – | – | – |
| A.16 資訊安全事故管理 | 7 | 5 | 2 | – | – |
| A.17 營運持續管理之資訊安全層面 | 4 | 3 | – | – | 1 |
| A.18 遵循性 | 8 | 8 | – | – | 1 |
| 2022 主題控制數 | 114 → 93 | 37 | 8 | 14 | 34 |
想動手練習對照與轉版時程,可以看互動教學頁:
▶互動教學2013 到 2022:控制對照與轉版對照依 ISO/IEC 27002:2022 公開的新舊控制對照整理,控制名稱只列英文短標題,說明為本站自行撰寫;標準原文請參閱 ISO 正式出版品。
學習電腦技術 30 年、歷經 IT 工程師、網路工程師、DQA、FAE、PM 到 iOS App 開發、前端/後端/全端開發、白帽駭客、DevOps、AI 開發,逐步累積了完整的技術與跨領域經驗。
這讓我變成 AI 時代的六邊形戰士。AI時代必須成為T型人才。
📧 EMAIL:tomokuri8@gmail.com