GB/T 25067-2010 Information technology—Security techniques—Requirements for bodies providing audit and certification of information security management systems
GB/T 25067-2010 Information technology—Security techniques—Requirements for bodies providing audit and certification of information security management systems
Basic Information
Scope
This standard sets forth requirements and provides guidance for organizations implementing information security management systems (hereinafter referred to as "ISMS") audits and certifications, serving as a supplement to the requirements of GB/T 27021-2007 and GB/T 22080-2008. The primary purpose of establishing this standard is to provide support for the accreditation of certification bodies implementing ISMS certifications.
Any organization offering ISMS certifications must demonstrate that it meets the requirements of this standard in terms of competence and reliability. The guidance provisions of this standard provide further explanations of these requirements.
Note: This standard can be used as a normative document for accreditation, peer review, or other audit processes.