ISO 22340:2024
Security and resilience — Protective security — Guidelines for an enterprise protective security architecture and framework
Security and resilience — Protective security — Guidelines for an enterprise protective security architecture and framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 31
- Дата публикации:
- 1 ноября 2024 г.
- Издание:
- ISO IS 22340 edition 1 version 1
- ICS:
- 03.100.01
This document provides guidance on the enterprise protective security architecture and the framework of protective security policies, processes and types of controls necessary to mitigate and manage security risks across the protective security domains, including: a) security governance; b) personnel security; c) information security; d) cybersecurity; e) physical security. This document is applicable for any organization.
Abstract
Overview
ISO 22340:2024 - Security and resilience - Protective security - Guidelines for an enterprise protective security architecture and framework - provides high‑level guidance for designing an enterprise protective security architecture and an integrated protective security framework. The standard explains how organizations can align security governance, policies, processes and controls with business objectives using a risk‑based approach. It is applicable to any organization and focuses on coordination across five core protective security domains: security governance, personnel security, information security, cybersecurity, and physical security.
Key Topics
- Enterprise protective security architecture: structure and elements for documenting governance arrangements and the security framework that delivers protective security outcomes.
- Protective security domains: clear coverage of governance, personnel, information, cyber and physical security and how they integrate.
- Risk‑based principles: emphasis on understanding business impact, applying risk management and selecting controls proportionate to risk.
- Security governance: roles and responsibilities including the responsible security executive, security management structures and implementation oversight.
- Personnel security: eligibility, suitability checks, ongoing assessment, separation processes and HR–security cooperation.
- Information security: classification of information, business impact analysis and access control to organizational information.
- Cybersecurity: defining systems, selecting and evaluating cyber controls, system authorization and ongoing monitoring; considerations for rapid digital change.
- Physical security: protecting organizational assets and facilities through policy, procedures and controls.
- Security maturity & continuous improvement: guidance on developing organizational security capability and measuring progress.
- Scope & limitations: provides strategic guidance rather than detailed technical or operational procedures.
Applications
ISO 22340:2024 is intended for managers, security leaders, risk officers and consultants who need to:
- Build or revise an enterprise protective security framework that integrates multiple security disciplines.
- Align security controls with business objectives and risk appetite.
- Define governance structures and clear security roles and responsibilities.
- Guide procurement of security services and design of cross‑domain security programs.
- Improve organizational security maturity and foster a security‑aware culture.
Practical uses include strategic security planning, policy harmonization, vendor requirements for integrated security services, and as a reference when developing organization‑wide protective security roadmaps.
Related standards
- ISO 22300 (Security and resilience - Vocabulary) is referenced for terminology and complements ISO 22340:2024.
- ISO 22340:2024 is designed to complement national and sectoral security best practices and risk‑management frameworks.
Технические детали
- Технический комитет
- ISO/TC 292 - Security and resilience
- SKU
- ISO 22340:2024
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 22300:2021
ОтменёнSecurity and resilience — Vocabulary
Overview ISO 22300:2021 - Security and resilience - Vocabulary is the third edition (2021) of ISO’s core vocabulary for security and resilience standards. It defines generic and subject‑specific term…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…