99此处对应原文为:Top management may also assign responsibilities and authorities for reporting performance of theinforma -tion security management system within the organization。在这里如果用Effectiveness of the information security management system,effectiveness词义非常明确,就是有效性,汇报范围太小,不够全面,用performance词义则比较宽泛,所有的与信息安全相关的都可包括在内。
100原文为:“the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to:”,用to后面加“:”表示目的。
预期目标为:intended outcome(s),已经是第三次出现了。
102这句话可操作性不强,比较空洞,因为风险是不可能消除殆尽的。当然,有些空洞的话也不是没有作用,可能是为了表达某种情绪,或者决心。举几个比较通俗的例子,例如:“改天一起吃个饭”、“有空一起坐坐”,没有具体的时间,变动范围很大,不具备实际的可操作性,但是表达了一种愿望或者态度,至少说明不讨厌对方。