Drawing on international best practice, including ISO/IEC 27005, NIST SP800-30 and BS7799-3, the book explains in practical detail how to carry out an information security risk assessment. It covers key topics, such as risk scales, threats and vulnerabilities, selection of controls, and roles and responsibilities, and includes advice on choosing risk assessment software.
Rezensionen / Stimmen
'... a timely and expert resource for any information and knowledge professional seeking to improve information security management... Additional chapters on policy development and the range of threats that could face an organisation make this an essential resource for any information professional. The authors have managed to balance technical expertise with the realities of delivering services in a recession ...' -- Robin Smith, Head of Information Governance, Northampton General Hospital
Sprache
Verlagsort
Zielgruppe
Maße
Höhe: 216 mm
Breite: 140 mm
Dicke: 11 mm
Gewicht
ISBN-13
978-1-84928-043-3 (9781849280433)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Klassifikation
Alan Calder is an acknowledged international cyber security guru and a leading author on information security and IT governance issues.
Alan co-wrote (with Steve Watkins) the definitive compliance guide, IT Governance: An International Guide to Data Security and ISO27001/ISO27002 (now in its sixth edition), which is the basis for the UK Open University's postgraduate course on information security. This work draws on his experience leading the world's first successful implementation of BS 7799 (now ISO 27001).
Steve is an authority on information security management and ISO 27001 implementation.
He is Chair of the ISO/IEC 27001 User Group - the UK Chapter of the ISMS International User Group - and is an ISMS Technical Assessor for UKAS, advising on its assessments of certification bodies offering accredited certification. Steve sits on the IST/33 committee responsible for the UK's contributions to the revisions of the ISO 27000 series of standards and on RM/1, the committee responsible for BS 31100 - the British standard for risk management - and for the UK's contributions to ISO 31000.
1: Risk Management
2: Risk Assessment Methodologies
3: Risk Management Objectives
4: Roles and Responsibilities
5: Risk Assessment Software
6: Information Security Policy and Scoping
7: The ISO27001 Risk Assessment
8: Information Assets
9: Threats and Vulnerabilities
10: Impact and Asset Valuation
11: Likelihood
12: Risk Level
13: Risk Treatment and the Selection of Controls
14: The Statement of Applicability
15: The Gap Analysis and Risk Treatment Plan
16: Repeating and Reviewing the Risk Assessment
Appendix 1: Carrying Out an ISO272001 Risk Assessment using VSRisk
Appendix 2: ISO27001 Implementation Resources