International Organization for Standardization (ISO) in2013Year10Month1day was released.ISO/IEC 27001:2013Information Technology Security Technology information security management system requirements, which replacesISO/IEC 27001:2005.2013Year10International Accreditation Forum (IAF) The General Assembly of Members adopted the relevantISO/IEC 27001:2013Transformed Resolution (No:IAF Resolution 2013-13). National Accreditation Committee (CNAS) BasisIAFThe relevant resolutions2014Year6Month20The certification body basis was issued on the day.ISO/IEC 27001:2013Implementation of information security management system certification recognition conversion instructions (CNAS-EC-039:2014) and2014Year9Month30On the implementation ofCNAS-EC-039:2014notice of additional instructions.
In order to ensure the effective development of our companys information security management system certification, the successful completion of the certification standardsISO/IEC 27001:2013The conversion work, accordingCNASThe spirit of the document and the new editionGB/T22080The progress of the equivalent transformation work is hereby notified of the conversion of information security management system certification standards as follows:
(I) all basisGB/T 22080:2008The system certification certificate issued by the version is from the new version.GB/T 22080From the date of implementation, the conversion of the new version of the standard should be completed within one year.
(II), our company encourages customers to pay attention to the changes in the requirements of the new version and start the standard version change as soon as possible. Due to equivalent adoptionISO/IEC 27001:2013The new version of the national standardGB/T 22080Not yet published, since2015Year5Month1From the date, on the basisGB/T 22080-2008The certification organization that issues the certification certificate, our company can be based on.ISO/IEC 27001:2013Combined with re-certification, annual supervision or special review work for conversion. After passing the audit, it can be issued according to the standardISO/IEC 27001:2013The certificate of certification.
(III)2015Year5Month1From now on, our company will no longer accept the basis.GB/T 22080-2008application for certification.
(IV) to meet customer needs from2015Year5Month1From now on, our company began to accept the standard.ISO/IEC 27001:2013The establishment of information security management system certification business,
After passing the audit, it can be issued according to the standard.ISO/IEC 27001:2013The certificate of certification. To be the new version of national standardsGB/T 22080After enactment, for obtainingISO/IEC 27001:2013The customer of the certificate reissue the certificate.
(V) from new versionGB/T 22080From the date of implementation, our company accepts the new version based onGB/T 22080The certification application, according to the requirements of the implementation of certification audit.
The specific matters of this version change can be contacted with the system certification department of our company.
Zhou Zhao:010-56313448
Notice is hereby given.
April 22, 2015