Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • Mastering Information Security Compliance Management
  • Toc
  • feedback
Mastering Information Security Compliance Management

Mastering Information Security Compliance Management

By : Adarsh Nair, Greeshma M. R.
4.7 (19)
close
Mastering Information Security Compliance Management

Mastering Information Security Compliance Management

4.7 (19)
By: Adarsh Nair, Greeshma M. R.

Overview of this book

ISO 27001 and ISO 27002 are globally recognized standards for information security management systems (ISMSs), providing a robust framework for information protection that can be adapted to all organization types and sizes. Organizations with significant exposure to information-security–related risks are increasingly choosing to implement an ISMS that complies with ISO 27001. This book will help you understand the process of getting your organization's information security management system certified by an accredited certification body. The book begins by introducing you to the standards, and then takes you through different principles and terminologies. Once you completely understand these standards, you’ll explore their execution, wherein you find out how to implement these standards in different sizes of organizations. The chapters also include case studies to enable you to understand how you can implement the standards in your organization. Finally, you’ll get to grips with the auditing process, planning, techniques, and reporting and learn to audit for ISO 27001. By the end of this book, you’ll have gained a clear understanding of ISO 27001/27002 and be ready to successfully implement and audit for these standards.
Table of Contents (19 chapters)
close
1
Part 1: Setting the Stage – Definitions, Concepts, Principles, Standards, and Certifications
4
Part 2: The Protection Strategy – ISO/IEC 27001/02 Design and Implementation
chevron up
10
Part 3: How to Sustain – Monitoring and Measurement
Appendix – Terms and Definitions

Part 2: The Protection Strategy – ISO/IEC 27001/02 Design and Implementation

Part 2, consisting of Chapters 3 to 7, delves into the heart of the ISO/IEC 27001/27002 standards, offering an in-depth understanding of controls, risk management, and the developmental stages of an ISMS. Chapter 3 navigates through the controls laid out in ISO 27001/27002, illustrating how they can be interpreted and applied based on business context. Chapter 4 dives into risk assessment and management and the crucial elements of the ISO 27001 framework, and introduces the role of a risk register. In Chapter 5, you’ll journey through the process of developing an ISMS, learning how to customize control implementation to a business’s specific context. Chapter 6 underscores the significance of a comprehensive incident management plan to maintain information security. Finally, Chapter 7 provides practical insights via real-world case studies concerning certification, a Statement of Applicability...

Unlock full access

Continue reading for free

A Packt free trial gives you instant online access to our library of over 7000 practical eBooks and videos, constantly updated with the latest in tech
bookmark search playlist font-size

Change the font size

margin-width

Change margin width

day-mode

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Delete Bookmark

Modal Close icon
Are you sure you want to delete it?
Cancel
Yes, Delete