<?xml version="1.0" encoding="UTF-8"?><toc><section id="foreword.nat"><title>Nationales Vorwort</title><section id="sub-amendments"><title>Änderungen</title></section><section id="sub-previous.edition"><title>Frühere Ausgaben</title></section></section><section id="introduction.int"><label>0</label><title>Einleitung</title><section id="sub-0.1"><label>0.1</label><title>Allgemeines</title></section><section id="sub-0.2"><label>0.2</label><title>Kompatibilität mit anderen Normen für Managementsysteme</title></section></section><section id="sub-1"><label>1</label><title>Anwendungsbereich</title></section><section id="sub-2"><label>2</label><title>Normative Verweisungen</title></section><section id="sub-3"><label>3</label><title>Begriffe</title></section><section id="sub-4"><label>4</label><title>Kontext der Organisation</title><section id="sub-4.1"><label>4.1</label><title>Verstehen der Organisation und ihres Kontextes</title></section><section id="sub-4.2"><label>4.2</label><title>Verstehen der Erfordernisse und Erwartungen interessierter Parteien</title></section><section id="sub-4.3"><label>4.3</label><title>Festlegen des Anwendungsbereichs des Informationssicherheitsmanagementsystems</title></section><section id="sub-4.4"><label>4.4</label><title>Informationssicherheitsmanagementsystem</title></section></section><section id="sub-5"><label>5</label><title>Führung</title><section id="sub-5.1"><label>5.1</label><title>Führung und Verpflichtung</title></section><section id="sub-5.2"><label>5.2</label><title>Politik</title></section><section id="sub-5.3"><label>5.3</label><title>Rollen, Verantwortlichkeiten und Befugnisse in der Organisation</title></section></section><section id="sub-6"><label>6</label><title>Planung</title><section id="sub-6.1"><label>6.1</label><title>Maßnahmen zum Umgang mit Risiken und Chancen</title><section id="sub-6.1.1"><label>6.1.1</label><title>Allgemeines</title></section><section id="sub-6.1.2"><label>6.1.2</label><title>Informationssicherheitsrisikobeurteilung</title></section><section id="sub-6.1.3"><label>6.1.3</label><title>Informationssicherheitsrisikobehandlung</title></section></section><section id="sub-6.2"><label>6.2</label><title>Informationssicherheitsziele und Planung zu deren Erreichung</title></section></section><section id="sub-7"><label>7</label><title>Unterstützung</title><section id="sub-7.1"><label>7.1</label><title>Ressourcen</title></section><section id="sub-7.2"><label>7.2</label><title>Kompetenz</title></section><section id="sub-7.3"><label>7.3</label><title>Bewusstsein</title></section><section id="sub-7.4"><label>7.4</label><title>Kommunikation</title></section><section id="sub-7.5"><label>7.5</label><title>Dokumentierte Information</title><section id="sub-7.5.1"><label>7.5.1</label><title>Allgemeines</title></section><section id="sub-7.5.2"><label>7.5.2</label><title>Erstellen und Aktualisieren</title></section><section id="sub-7.5.3"><label>7.5.3</label><title>Lenkung dokumentierter Information</title></section></section></section><section id="sub-8"><label>8</label><title>Betrieb</title><section id="sub-8.1"><label>8.1</label><title>Betriebliche Planung und Steuerung</title></section><section id="sub-8.2"><label>8.2</label><title>Informationssicherheitsrisikobeurteilung</title></section><section id="sub-8.3"><label>8.3</label><title>Informationssicherheitsrisikobehandlung</title></section></section><section id="sub-9"><label>9</label><title>Bewertung der Leistung</title><section id="sub-9.1"><label>9.1</label><title>Überwachung, Messung, Analyse und Bewertung</title></section><section id="sub-9.2"><label>9.2</label><title>Internes Audit</title></section><section id="sub-9.3"><label>9.3</label><title>Managementbewertung</title></section></section><section id="sub-10"><label>10</label><title>Verbesserung</title><section id="sub-10.1"><label>10.1</label><title>Nichtkonformität und Korrekturmaßnahmen</title></section><section id="sub-10.2"><label>10.2</label><title>Fortlaufende Verbesserung</title></section></section><section id="sub-a"><label>Anhang A</label><title>Referenzmaßnahmenziele und -maßnahmen (normativ)</title></section><section id="sub-annex.bibliography.int"><title>Literaturhinweise (informativ)</title></section><section id="sub-na"><label>Nationaler Anhang NA</label><title>Literaturhinweise (informativ)</title></section></toc>