Information Security Risk Management for ISO27001/ISO17799 - Softcover

Alan Calder; Steve Watkins

 
9781905356232: Information Security Risk Management for ISO27001/ISO17799

Synopsis

All organizations today have to respond to a rapidly changing and increasingly threatening range of information security risks - risks which can, if unmitigated, lead to severe financial, regulatory and reputation damage for organizations. Information security investment and control decisions should be specifically driven by the outcome of a risk assessment process that identifies risks to specific information assets. Risk assessment is, in fact, the core competence of information security management. International standards, including ISO/IEC 27001:2005, ISO17799, BS7799-3 and NIST SP 800-30, provide overlapping guidance on risk assessment. This book provides clear, practical and comprehensive guidance on developing a risk management methodology that meets the requirements of ISO27001, the information security management standard, and on carrying out a risk assessment that will help achieve corporate risk management objectives. It is essential reading for anyone involved generally in enterprise risk management and in information security specifically.

"synopsis" may belong to another edition of this title.

About the Author

Alan Calder is the founder director of IT Governance Ltd , an information, advice and consultancy firm that helps companies tackle governance, risk management, compliance and information security issues. He has many years of senior management and board-level experience in the private and public sectors. The company's website is a 'one-stop-shop' for information, books, tools, training and consultancy on governance, risk management, compliance and information security. Steve Watkins leads the consultancy and training services of IT Governance Ltd. In his various roles in both the public and private sectors he has been responsible for most support disciplines. He has over 17 years' experience of managing integrated management systems, including maintenance of Information Security, Quality, Environmental and Investor in People certifications. As well as being a trained ISO27001 and ISO9000 auditor Steve is a trained EFQM Assessor and holds diplomas in safety and financial management. He is Deputy Chair of the Steering Committee of the DTi ISO/IEC17799 Users Group and also sits on the Management Committee of the British Standards Society where he chairs the Management Systems Special Interest Group.

"About this title" may belong to another edition of this title.