Portada

INFORMATION SECURITY RISK MANAGEMENT FOR ISO 27001 / ISO 270 IBD

EDITORIAL DESCONOCIDA
09 / 2019
9781787781368
Inglés

Sinopsis

Protect your information assets with effective risk managementIn today&rsquo,s information economy, the development, exploitation and protection of informationáand associatedáassets are key to the long-term competitiveness and survival of corporations and entire economies. The protection of informationáand associatedáassets &ndash, information security &ndash, is therefore overtaking physical asset protection as a fundamental corporate governance responsibility.áInformation security management system requirementsISO 27000, which provides an overview for the family of international standards for information security, states that &ldquo,An organisation needs to undertake the following steps in establishing, monitoring, maintaining and improving its ISMS [&hellip,] assess information security risks and treat information security risks&rdquo,. The requirements for an ISMS are specified in ISO 27001. Under this standard, a risk assessment must be carried out to inform the selection of security controls, making risk assessment the core competence of information security management and a critical corporate discipline.Plan and carry out a risk assessment to protect your informationInformation Security Risk Management for ISO 27001 / ISO 27002: Provides information security and risk management teams with detailed, practical guidance on how to develop and implement a risk assessment in line with the requirements of ISO 27001. Draws on national and international best practice around risk assessment, including BS 7799-3:2017 (BS 7799-3). Covers key topics such as risk assessment methodologies, risk management objectives, information security policy and scoping, threats and vulnerabilities, risk treatment and selection of controls. Includes advice on choosing risk assessment software. Ideal for risk managers, information security managers, lead implementers, compliance managers and consultants, as well as providing useful background material for auditors, this book will enable readers to develop an ISO 27001-compliant risk assessment framework for their organisation and deliver real, bottom-line business benefits. Buy your copy today! About the authors Alan Calderáis the Group CEO of GRCáInternational Groupáplc, the AIM-listed company that owns IT GovernanceáLtd.áAlan is an acknowledged international cyber security guru and a leadingáauthor on information security and IT governance issues. He has beenáinvolved in the development of a wide range of information security managementátraining courses that have beenáaccredited by IBITGQ (International Boardáfor IT Governance Qualifications). Alan has consulted for clientsáin the UK andáabroad, andáis a regular media commentator and speaker.á Steve G Watkinsáis an executive director at GRC International Group plc. He is a contracted technical assessor for UKAS &ndash, advising on its assessments of certification bodies offering ISMS/ISO 27001 and ITSMS/ISO 20000-1 accredited certification. He is a member of

PVP
46,13