An Introduction to Information Security and ISO27001
Steve G. Watkins(Author)
IT Governance Publishing
Published on 23. October 2008
Book
Paperback/Softback
44 pages
978-1-905356-68-3 (ISBN)
Description
This new pocket guide will suit both individuals who need an introduction to a topic that they know little about, and also organizations implementing, or considering implementing, some sort of information security management regime, particularly if using ISO/IEC 27001. The guide furnishes readers with an understanding of the basics of information security, including: * A definition of what information security means. * How managing information security can be achieved using an approach recognised world-wide. * The sorts of factors that need to be considered in an information security regime, including how the perimeters of such a scheme can be properly defined. * How an information security management system can ensure it is maximising the effect of any budget it has. * What sort of things resources might be invested in to deliver a consistent level of assurance. * How organizations can demonstrate the degree of assurance they offer with regards to information security, how to interpret claims of adherence to the ISO 27001 standard and exactly what it means.
Corporate bodies will find this book useful at a number of stages in any information security project, including: * At the decision-making stage; to ensure that those committing to an information security project do so from a truly informed position. * At project initiation stage, as an introduction to information security for the project board, project team members and those on the periphery of the project. * As part of an on-going awareness campaign, being made available to all staff and to new starters as part of their introduction to the company. The guide is designed to be read without having to frequently break from the text, there is also a list of abbreviations along with terms and definitions in chapter 7 for easy reference.
Corporate bodies will find this book useful at a number of stages in any information security project, including: * At the decision-making stage; to ensure that those committing to an information security project do so from a truly informed position. * At project initiation stage, as an introduction to information security for the project board, project team members and those on the periphery of the project. * As part of an on-going awareness campaign, being made available to all staff and to new starters as part of their introduction to the company. The guide is designed to be read without having to frequently break from the text, there is also a list of abbreviations along with terms and definitions in chapter 7 for easy reference.
More details
Language
English
Place of publication
Ely
United Kingdom
Illustrations
Illustrations
Dimensions
Height: 165 mm
Width: 95 mm
Thickness: 4 mm
Weight
48 gr
ISBN-13
978-1-905356-68-3 (9781905356683)
Copyright in bibliographic data is held by Nielsen Book Services Limited or its licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

Steve G. Watkins
Introduction to Information Security and ISO27001
E-Book
10/2008
IT Governance Publishing
€10.49
Available for download
Person
ABOUT THE AUTHORSteve G Watkins: Director, Training and Consultancy, IT Governance Ltd.Steve managed the world's first successful BS7799 implementation project. He has over 18 years' experience of managing integrated manage-ment systems, including maintenance of Information Security, Quality, Environmental and Investor in People certifications.Steve's experience includes senior management positions in both the public and private sectors, having responsibility for nearly all corporate support functions.As well as being a trained ISO27001 and ISO9001 auditor, Steve is a trained EFQM assessor and holds diplomas in safety and financial management. He is Chair of the UK ISO/IEC 27001 Users Group (which is the UK chapter of the International ISMS User Group) and also sits on the Management Committee of the British Standards Society, where he chairs the Corporate Governance Special Interest Group.Steve can be contacted at:swatkins@itgovernance.co.uk.
Content
IntroductionChapter 1: Information Security - What's That? Chapter 2: It's Not IT Chapter 3: ISO27001 and the Management System Requirements Chapter 4: Information Assets and the Information Security Risk Assessment Chapter 5: Information Security Controls Chapter 6: Certification Chapter 7: Signposting ITG Resources