Nicht aus der Schweiz? Besuchen Sie lehmanns.de
IT Governance - Alan Calder, Steve Watkins

IT Governance

An International Guide to Data Security and ISO 27001/ISO 27002
Buch | Hardcover
408 Seiten
2019 | 7th Revised edition
Kogan Page Ltd (Verlag)
978-1-78966-030-2 (ISBN)
CHF 289,95 inkl. MwSt
  • Versand in 15-20 Tagen
  • Versandkostenfrei
  • Auch auf Rechnung
  • Artikel merken
Implement an effective and compliant information security management system using IT governance best practice.
Faced with the compliance requirements of increasingly punitive information and privacy-related regulation, as well as the proliferation of complex threats to information security, there is an urgent need for organizations to adopt IT governance best practice.

IT Governance is a key international resource for managers in organizations of all sizes and across industries, and deals with the strategic and operational aspects of information security.

Now in its seventh edition, the bestselling IT Governance provides guidance for companies looking to protect and enhance their information security management systems (ISMS) and protect themselves against cyber threats. The new edition covers changes in global regulation, particularly GDPR, and updates to standards in the ISO/IEC 27000 family, BS 7799-3:2017 (information security risk management) plus the latest standards on auditing. It also includes advice on the development and implementation of an ISMS that will meet the ISO 27001 specification and how sector-specific standards can and should be factored in. With information on risk assessments, compliance, equipment and operations security, controls against malware and asset management, IT Governance is the definitive guide to implementing an effective information security management and governance system.

Alan Calder is Group CEO of GRC International Group plc, the AIM-listed company that owns IT Governance Ltd.. He led the world's first successful implementation of BS 7799 (now ISO 27001) and was involved in developing a wide range of information security management training courses, accredited by the International Board for IT Governance Qualifications (IBITGQ). Steve Watkins is Executive Director at GRC International Group plc, chair of the UK ISO/IEC 27001 User Group and contracted technical assessor for UKAS. He is a member of the international technical committee responsible for the ISO 27000 family of standards, and chairs the UK National Standards Body's technical committee IST/33 (information security, cyber security and privacy protection) that mirrors it.

Chapter - 01: Why is information security necessary?;
Chapter - 02: The UK combined code, the FRC risk guidance and Sarbanes–Oxley;
Chapter - 03: ISO27001;
Chapter - 04: Organizing information security;
Chapter - 05: Information security policy and scope;
Chapter - 06: The risk assessment and Statement of Applicability;
Chapter - 07: Mobile devices;
Chapter - 08: Human resources security;
Chapter - 09: Asset management;
Chapter - 10: Media handling;
Chapter - 11: Access control;
Chapter - 12: User access management;
Chapter - 13: System and application access control;
Chapter - 14: Cryptography;
Chapter - 15: Physical and environmental security;
Chapter - 16: Equipment security;
Chapter - 17: Operations security;
Chapter - 18: Controls against malicious software (malware);
Chapter - 19: Communications management;
Chapter - 20: Exchanges of information;
Chapter - 21: System acquisition, development and maintenance;
Chapter - 22: Development and support processes;
Chapter - 23: Supplier relationships;
Chapter - 24: Monitoring and information security incident management;
Chapter - 25: Business and information security continuity management;
Chapter - 26: Compliance;
Chapter - 27: The ISO27001 audit

"This book is to ISO27002 what ISO27002 is to ISO27001 - it is the guidance to the standard's guidance. As such, it is the most impressively comprehensive guide to implementing ISO27001-level InfoSec in your organisation. It gives detailed understanding and insight about the motivation and purpose of the different controls that will help build a fit-for-purpose ISMS. Because of this, I chose it as the set book for the very popular Open University Introduction to InfoSec module."

"A well-structured and informative book that deserves a place on the bookshelf of any ISMS lead implementer and an invaluable reference for organisations seeking accredited third-party certification."

Erscheinungsdatum
Verlagsort London
Sprache englisch
Maße 165 x 241 mm
Gewicht 935 g
Themenwelt Informatik Netzwerke Sicherheit / Firewall
Wirtschaft Betriebswirtschaft / Management Allgemeines / Lexika
Wirtschaft Betriebswirtschaft / Management Unternehmensführung / Management
ISBN-10 1-78966-030-0 / 1789660300
ISBN-13 978-1-78966-030-2 / 9781789660302
Zustand Neuware
Haben Sie eine Frage zum Produkt?
Mehr entdecken
aus dem Bereich
Das Lehrbuch für Konzepte, Prinzipien, Mechanismen, Architekturen und …

von Norbert Pohlmann

Buch | Softcover (2022)
Springer Vieweg (Verlag)
CHF 48,95
Management der Informationssicherheit und Vorbereitung auf die …

von Michael Brenner; Nils gentschen Felde; Wolfgang Hommel

Buch (2024)
Carl Hanser (Verlag)
CHF 97,95

von Chaos Computer Club

Buch | Softcover (2024)
KATAPULT Verlag
CHF 39,20