Operational Procedures and Responsibilities (4.1) 8 Documented Operating Procedures (4.1.1) 8 Change Management (4.1.2) 8 Change Control Procedures (4.1.2.1) 8 Capacity Management (4.1.3) 8 Separation of Development, Testing and Operational Environments (4.1.4) 8 Protection from Malware (4.2) 9 Malicious Software Control (4.2.1) 9 Backup (4.3) 9 Data Backup (4.3.1) 9 Logging and Monitoring (4.4) 9 Event Logging (4.4.1) 9 Availability and Performance Monitoring (4.4.2) 10 Protection of Log Information (4.4.3) 10 Administrator and Logs (4.4.4) 10 Clock Synchronization (4.4.5) 10 Control of Operational Software (4.5) 10 Installation of Software on Operational Systems (4.5.1) 10 Patch Management (4.5.1.1) 10 Software Maintenance (4.5.1.2) 11 Software Development Code (4.5.1.3) 11 Review of Application和操作系统的更改(4.5.1.4)11技术和漏洞管理(4.6)11技术漏洞的管理(4.6.1)11对软件安装的限制(4.6.2)11信息系统审核注意事项(4.7)11信息系统审核控制(4.7.1.1)11
主要关键词