Information Security Risk Management For ISO 27001/Iso27002 / Edition 2

Information Security Risk Management For ISO 27001/Iso27002 / Edition 2

by IT Governance Publishing
ISBN-10:
1849280436
ISBN-13:
9781849280433
Pub. Date:
04/27/2010
Publisher:
It Governance Publishing
ISBN-10:
1849280436
ISBN-13:
9781849280433
Pub. Date:
04/27/2010
Publisher:
It Governance Publishing
Information Security Risk Management For ISO 27001/Iso27002 / Edition 2

Information Security Risk Management For ISO 27001/Iso27002 / Edition 2

by IT Governance Publishing
$45.95 Current price is , Original price is $45.95. You
$45.95 
  • SHIP THIS ITEM
    Qualifies for Free Shipping
  • PICK UP IN STORE
    Check Availability at Nearby Stores

Overview

The changing global economy, together with recent corporate and IT governance developments, all provide the context within which organisations have to assess risks to the information assets on which their organisations, and the delivery of their business plan objectives, depend. Information security management decisions are entirely driven by specific decisions made as an outcome of a risk assessment process in relation to identified risks and specific information assets. Risk assessment is, therefore, the core competence of information security management.


Product Details

ISBN-13: 9781849280433
Publisher: It Governance Publishing
Publication date: 04/27/2010
Edition description: Second Edition
Pages: 198
Product dimensions: 5.50(w) x 8.40(h) x 0.40(d)

About the Author

Steve G Watkins leads the consultancy and training services of IT Governance Ltd. In his various roles in both the public and private sectors he has been responsible for most support disciplines. He has over 20 years' experience of managing integrated management systems, and is a lead auditor for ISO27001 and ISO9000. He is now an ISMS Technical Expert for UKAS, and provides them with advice for their assessments of certification bodies offering certification to ISO27001. || Alan Calder is a leading author on IT governance and information security issues. He is the CEO of GRC International Group plc, the AIM-listed company that owns IT Governance Ltd. Alan is an acknowledged international cyber security guru. He has been involved in the development of a wide range of information security management training courses that have been accredited by the International Board for IT Governance Qualifications (IBITGQ). He is a frequent media commentator on information security and IT governance issues, and has contributed articles and expert comment to a wide range of trade, national and online news outlets.

Table of Contents

1. Risk Management; 2. Risk Assessment Methodologies; 3. Risk Management Objectives; 4. Roles and Responsibilities; 5. Risk Assessment Software; 6. Information Security Policy and Scoping; 7. The ISO27001 Risk Assesment; 8. Information Assets; 9. Threats and Vunerabilities; 10. Impact and Asset Valuation; 11. Likelihood; 12. Risk Level; 13. Risk Treatment and the Selection of Controls; 14. The Statement of Applicability; 15. The Gap Analysis and Risk Treatment Plan; 16. Repeating and Reviewing the Risk Assessment; Appendix 1: Carrying Out an ISO272001 Risk Assessment using VSRisk; Appendix 2: ISO27001 Implementation Resources

From the B&N Reads Blog

Customer Reviews