ImageVerifierCode 换一换
格式:DOCX , 页数:41 ,大小:96.01KB ,
资源ID:521456      下载积分:5 金币
已注册用户请登录:
账号:
密码:
验证码:   换一换
  忘记密码?
三方登录: 微信登录   QQ登录  
下载须知

1: 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。
2: 试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。
3: 文件的所有权益归上传用户所有。
4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
5. 本站仅提供交流平台,并不能对任何下载内容负责。
6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

版权提示 | 免责声明

本文(ISO 277892021.docx)为本站会员(飞猪)主动上传,三一文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三一文库(发送邮件至doc331@126.com或直接QQ联系客服),我们立即给予删除!

ISO 277892021.docx

1、INTERNATIONA1.STANDARDISO27789editionSecond2021-10Hea1.thinformatics-Audittrai1.sfore1.ectronichea1.threcordsInformatiquedeI1.istonque(TeXPertisedesdossiersdesantinfbrmatissCOPYRIGHTPROTECTEDDOCUMENTISO2021IUirhM*hedbdi1.iUedotherwiseupdhi.o啪InyM1.tta0DmkfifiU81.andonnet8CH-1214Vernier,GenevaPhone:M

2、1.22749O1.11觥曲ite:图洲跳触OQrgPub1.ishedinSwitzer1.andContentsForeword5.1.3Unambiguous.5.2.1ofGovernance7.2.2Event.一117.37.2.5identification7.3.3User7.4AccessNetworkidentification157.5.2OverviewParticipantOverview22187.6.5 Participantobjectdatatypecyc1.eiiiIntroductionviScope1Normativereferences1Termsan

3、ddefinitionsAbbrcviatedtcrms5Requirementsandusesofauditdata5.1Ethica1.andforma1.requirements511Genea1.7.6.6 Accesspo1.icyidentificationofinformationsystemusers7.6.7 Userro1.es67.6.8 Secureauditrecords6Usesauditdataandsupervision7.6.9 Subjectsofcareexercisingtheirrights.77.6.10 Evidenceandretentionre

4、quirements7Triggcrevents76.1 Genera1.6.2 Detai1.softheeventtypesandtheircontents8Access86.2.2ovntstothepeAuditrecorddetai1.s8Thegenera1.recordformat8Triggereventidentification106.2.1 IDactioncode7.2.3 EventdateandUme.117.2.4 Eventoutcomeindicator12UserEventtypecode7.3.1 User1.I)127.3.2 A1.ternativeu

5、serJD137.3.4 isnamerequestor1.1.2 Ro1.e1.D137.3.6 Pu)oseofuse147.4.1 pointaccesspointtypecode7.4.2 NetworkaccesspointII)167.5Auditsourceidentification167.5.1 AuditenterprisesiteID7.5.3 Auditsource1.D177.5.4 Auditsourcetypecode177.6.1 objectidentification7.6.2 Participantobjecttypecode197.6.3 Partidp

6、antobjecttypecodero1.e197.6.4 ID1.ifecodeandrecordentry1.ifecyc1.eevents7.6.6 ParticipantobjectPermissionPoIicySet237.6.8 ParticipantobjectIDsensitiviiy7.6.9 PartidnantObkJC1.name*.24.24.一238Auditrecordsforindividua1.events258.125n8.2Ouorvevontrmc8以始片隔布脸M躯W曲既麻外辎阁怅I1.hinformationfromthee1.ectronichea

7、1.threcord,otherthanidentifiers,theauditrecordon1.ycontaining1.inkstoEHRsegmentsasdefinedbythegoverningaccesspo1.icy.三ftf6MchspfffttwrftdOfUSePerfOIW崎1品豉哪PIiCatiOmW阳gf小闻tSuppJMystemareconstructionofdata,putersecuritystandardssuchasISO/IEC15408(a1.1.parts)9.scenarios.-AnneM-Bgivesanoverviewofaudit1.o

8、gservices.期刷福网的租用的t姓hisr(Ment.W%Mref融f热为W/a时用eedif1.bna1.1.*噂PIieS.由Wientundatedreferences,the1.atesteditionofthereferenceddocument(inc1.udinganyamendments)app1.ies.ISO27799:2016,Hea1.thinformaticsInformationsecuritymanagementinhea1.thusingIS0/1EC27002ISO8601-1,DateandtimeRepresentationsforinformati

9、oninterchange-Part1:Basicru1.es0TSTeWftiiriitiO11SfbrmtcsTrustedend-to-endinformationf1.owsfif1.JiWngfi1.susSah性曲HWWiQp1.y.thetermsanddefinitionsgiveninISO/TS21089:2018andtheISOandIECmaintaintermino1.ogydatabasesforuseinstandardizationatthefo1.1.owingaddresses:ISOOn1.inebrowsingp1.atform:avai1.ab1.e

10、avh11pswww5eeFgobpIECE1.ectropedia:avai1.ab1.eathttps:/www.e1.ectropedia.org/3.1accesscontro1.meanstoensurethataccesstoassetsisauthorizedandrestrictedbasedonbusinessandsecurityrequirementspgURCE:ISO1EC27000:2018,3.1accesspo1.icyyinitionoftheob1.igationsforauthorizingaccesstoaresourceaccountabi1.ityo

11、b1.igationofanindividua1.ororganizationtoaccountforitsactivities,forcomp1.etionofade1.iverab1.eortask,acceptresponsibi1.ityforthoseactivities,de1.iverab1.esortasks,andtodisc1.osetheresu1.tsinatransparentmanner期RCE:ISO/TS21089:2018,3.3.1agententitythattakesprogrammedactions,suchassoftwareoradeviceggU

12、RCE:ISO/TS21089:2018,3.6.4a1.ert笠掷issentwhenthemonitorservicenoticesthataseriesofeventsmatchesapatternauditindependentreviewandexaminationofrecordsandactivitiestoassesstheadequacyofsystemcontro1.s,toensurecomp1.iancewithestab1.ishedpo1.iciesandoperationa1.procedures,andtorecommendnecessarychangesinc

13、ontro1.s,po1.iciesorprocedures史9URCE:ISO/TS21089:2018,3.20auditarchivegrghiva1.co1.1.ectionofoneormoreaudit1.ogsauditdata妒obtainedfromoneormoreauditrecordsaudit1.oghjgno1.ogica1.sequenceofauditrecords,eachofwhichcontainsdataaboutaspecificeventauditrecord型Hrdofasing1.especificeventinthe1.ifecyc1.eofa

14、ne1.ectronichea1.threcordauditsysteminformationprocessingsystemthatmaintainsoneormoreaudit1.ogs3.12audittrai1.chrono1.ogica1.recordofsystemactivitiesthatissufficienttoenab1.ethereconstruction,reviewingandexaminationofthesequenceofenvironmentsandactivitiessurroundingor1.eadingtoanoperation,aprocedure

15、oraneventinatransactionfromitsinceptiontofina1.resu1.ts更WRCE:GCSTauthenticationprovisionofassurancethatac1.aimedcharacteristicofanentityiscorrectRCE:ISO/IEC27000:2018,3.5authorizationgrantingofrights,whichinc1.udesthegrantingofaccessbasedonaccessrightsRCE:ISO/IEC2382:2015,2126256rmodifiedNotestoent

16、ryde1.eted.)avai1.abi1.itypropertyofbeingaccessib1.eanduseab1.eupondemandbyanauthorizedentityRCE:ISO/iEC27000:2018,3.7Jconfidentia1.itypropertythatinformationisnotmadeavai1.ab1.eordisc1.osedtounauthorizedindividua1.s,entities,orprocessesgOURCE:ISO/IEC27000:2018,3.10coordinateduniversa1.timeUTCtimesc

17、a1.ewhichformsthebasisofacoordinatedradiodisseminationOfstandardfrequenciesandtimesigna1.sNote1entry:UTCnumbertoofseconds,correspondsexact1.yinratewithinternationa1.atomictime,butdiffersfromitbyanintegra1.更9那CE:IEC60050-713:1998.05-20)dataintegritypropertyofdatawhoseaccuracyandconsistencyarepreserve

18、dregard1.essofchangesmade史,JRCE:ISO2382:2015,2126247.modifiedNotestoentryde1.eted.e1.ectronichea1.threcordEHRrepositoryof(organizedsetsof)informationregardingthehea1.thstatusofasubjectofcare,incomputerprocessab1.eformSOURCE:ISO/TR20514:2005,2.11imodifiedTextinparenthesisadded.)e1.ectronichea1.threco

19、rdsegmentEHRsegmentpartofane1.ectronichea1.threcordthatconstitutesadistinctresourcefortheaccesspo1.icy3.21identificationprocessofrecognizingtheattributesthatidentifytheobject融RCE:ISO16678:2014,2.1.7Jidentieroneormorecharactersusedtoidentifyornameadatae1.ementandpossib1.ytoindicatecertainpropertiesof

20、thatdatae1.ement0URCE:ISO!EC2382:2015,2121623informationsecuritypreservationofconfidentia1.ity,integrityandavai1.abi1.ityofinformation炒9RRCE:ISO!EC27000:2018,3.28Jintegritypropertyofaccuracyandcomp1.etenessgggRCE:ISO/IEC27000:2018,3.36objectidentierOIDg1.oba1.1.yuniqueidentifierforaninformationobjec

21、tNerteQdnaenttvndhcdn蟒ntif1.ersU诃imxhHactoutmEtfeobe(i(ttetf)fterws0rifieda(tengSSfcten1.XAbbtractngxNotationOne(ASN.1)definedinISO/IEC8824-1andISO/IEC8824-2.po1.icysetofru1.esre1.atedtoaparticu1.arpurposeNote1toentry:ru1.ecanbeexpressedasanob1.igation,anauthorization,apermissionoraprohibition.f2aRC

22、E:ISO19101-2:2018,modifiedNote1toentryadded)privi1.egeapgcityassignedtoanentitybyanauthorityrecordsmanagementfie1.dofmanagementresponsib1.eforcontro1.ofcreation,receipt,maintenance,useanddispositionofrecords,inc1.udingprocessesforcapturingandmaintainingevidenceofandinformationaboutbusinessactivities

23、andtransactionsintheformofrecords叵2gRCE:ISO15489-1:2016,3.15,modifiedro1.ecompetencesand/orperformancesassociatedwithataskSeciiritypo1.icyp1.anorcourseofactionadoptedforprovidingcomputersecurityPOURCE:ISO/IEC2382:2015,2126246,modifiedNotestoentryde1.eted.3.31sensitivity3.32subjectofcareNote1toentrr:

24、Forexamp1.e,apaiient,c1.ient,customer,orhea1.thp1.anmember.3.33userfunctionsentry:systcmhumanhis/hcrbcha1.f.thcsystemtoissuerequeststoobjectsinordertogetthemtoperform4AbbreviatedtermsEVRequirementsVa1.ueusesofauditdata5.1 Ethica1.andforma1.requirements5.1.1 Genera1.hea1.threcordssubjcctsensuringtheirdocumentingusefindingsessentia1.rcquircmentsRestrictingaccesstoSecureorganizationa1.po1.iciesto1.egis

宁ICP备18001539号-1