Information Security Risk Management for ISO 27001/ISO 27002
Idioma: inglés
Editorial: IT Governance Publishing, GB, 2019
- Tapa blanda
- Nuevo

Librería: Rarewaves.com UK, London, Reino UnidoRarewaves.com UK
Vendedor de AbeBooks desde 11 de junio de 2025
Condición: Nuevo
EUR 46,56
Cantidad disponible: Más de 20 disponibles
Añadir al carritoDescripción del artículo del vendedor
Protect your information assets with effective risk managementIn today's information economy, the development, exploitation and protection of information and associated assets are key to the long-term competitiveness and survival of corporations and entire economies. The protection of information and associated assets - information security - is therefore overtaking physical asset protection as a fundamental corporate governance responsibility. Information security management system requirementsISO 27000, which provides an overview for the family of international standards for information security, states that "An organisation needs to undertake the following steps in establishing, monitoring, maintaining and improving its ISMS [.] assess information security risks and treat information security risks". The requirements for an ISMS are specified in ISO 27001. Under this standard, a risk assessment must be carried out to inform the selection of security controls, making risk assessment the core competence of information security management and a critical corporate discipline.Plan and carry out a risk assessment to protect your informationInformation Security Risk Management for ISO 27001 / ISO 27002:Provides information security and risk management teams with detailed, practical guidance on how to develop and implement a risk assessment in line with the requirements of ISO 27001.Draws on national and international best practice around risk assessment, including BS 7799-3:2017 (BS 7799-3).Covers key topics such as risk assessment methodologies, risk management objectives, information security policy and scoping, threats and vulnerabilities, risk treatment and selection of controls.Includes advice on choosing risk assessment software.Ideal for risk managers, information security managers, lead implementers, compliance managers and consultants, as well as providing useful background material for auditors, this book will enable readers to develop an ISO 27001-compliant risk assessment framework for their organisation and deliver real, bottom-line business benefits.Buy your copy today!About the authorsAlan Calder is the Group CEO of GRC International Group plc, the AIM-listed company that owns IT Governance Ltd. Alan is an acknowledged international cyber security guru and a leading author on information security and IT governance issues. He has been involved in the development of a wide range of information security management training courses that have been accredited by IBITGQ (International Board for IT Governance Qualifications). Alan has consulted for clients in the UK and abroad, and is a regular media commentator and speaker. Steve Watkins is an executive director at GRC International Group plc. He is a contracted technical assessor for UKAS - advising on its assessments of certification bodies offering ISMS/ISO 27001 and ITSMS/ISO 20000-1 accredited certification. He is a member of ISO/IEC JTC 1/SC 27, the international technical committee res.…
N° de ref. del artículo LU-9781787781368
- Título
- Information Security Risk Management for ISO 27001/ISO 27002
- Autor
- Alan Calder, Steve Watkins
- Editorial
- IT Governance Publishing, GB
- Año de publicación
- 2019
- Estado
- New
- Encuadernación
- Paperback
- Idioma
- inglés
- ISBN 10
- 1787781364
- ISBN 13
- 9781787781368
- Edición
- Third edition.
- Peso del artículo
- 231 gramos
Protect your information assets with effective risk management
In today’s information economy, the development, exploitation and protection of information and associated assets are key to the long-term competitiveness and survival of corporations and entire economies. The protection of information and associated assets – information security – is therefore overtaking physical asset protection as a fundamental corporate governance responsibility.
Information security management system requirements
ISO 27000, which provides an overview for the family of international standards for information security, states that “An organisation needs to undertake the following steps in establishing, monitoring, maintaining and improving its ISMS […] assess information security risks and treat information security risks”. The requirements for an ISMS are specified in ISO 27001. Under this standard, a risk assessment must be carried out to inform the selection of security controls, making risk assessment the core competence of information security management and a critical corporate discipline.
Plan and carry out a risk assessment to protect your information
Information Security Risk Management for ISO 27001 / ISO 27002:
- Provides information security and risk management teams with detailed, practical guidance on how to develop and implement a risk assessment in line with the requirements of ISO 27001.
- Draws on national and international best practice around risk assessment, including BS 7799-3:2017 (BS 7799-3).
- Covers key topics such as risk assessment methodologies, risk management objectives, information security policy and scoping, threats and vulnerabilities, risk treatment and selection of controls.
- Includes advice on choosing risk assessment software.
Ideal for risk managers, information security managers, lead implementers, compliance managers and consultants, as well as providing useful background material for auditors, this book will enable readers to develop an ISO 27001-compliant risk assessment framework for their organisation and deliver real, bottom-line business benefits.
Buy your copy today!
About the authors
Alan Calder is the Group CEO of GRC International Group plc, the AIM-listed company that owns IT Governance Ltd. Alan is an acknowledged international cyber security guru and a leading author on information security and IT governance issues. He has been involved in the development of a wide range of information security management training courses that have been accredited by IBITGQ (International Board for IT Governance Qualifications). Alan has consulted for clients in the UK and abroad, and is a regular media commentator and speaker.
Steve G Watkins is an executive director at GRC International Group plc. He is a contracted technical assessor for UKAS – advising on its assessments of certification bodies offering ISMS/ISO 27001 and ITSMS/ISO 20000-1 accredited certification. He is a member of ISO/IEC JTC 1/SC 27, the international technical committee responsible for information security, cyber security and privacy standards, and chairs the UK National Standards Body’s technical committee IST/33 (information security, cyber security and privacy protection) that mirrors it. Steve was an active member of IST/33/-/6, which developed BS 7799-3.
“Sinopsis” puede pertenecer a otra edición de este título.
Acerca del autor
“Acerca de” puede pertenecer a otra edición de este título.
Rarewaves.com UK
London, Reino Unido
Vendedor de AbeBooks desde 11 de junio de 2025
Tarifas de envío de Reino Unido a Estados Unidos de America
| Artículo | De 60 a 60 días hábiles | De 60 a 60 días hábiles |
|---|---|---|
| Primer artículo | EUR 75,58 | EUR 116,28 |
Métodos de pago
Información empresarial del vendedor
RAREWAVES.COM LIMITED
Elsley Court, 20-22 Great Titchfield Street
London, Reino Unido W1W 8BE
Derecho al desistimiento
Si es un consumidor, puede rescindir el contrato de acuerdo con lo siguiente. Por consumidor se entiende cualquier persona física que actúe con fines ajenos a su actividad comercial, empresarial, oficio o profesión.
Información sobre el derecho de desistimiento
Derecho legal de desistimiento
Tiene derecho a rescindir este contrato en un plazo de 14 días sin dar ningún motivo.
El periodo de desistimiento vencerá a los 14 días desde que usted, o un tercero que no sea el transportista e indicado por usted, adquiera la posesión física del último bien o del último lote o pieza.
Para ejercer el derecho de desistimiento, complete de forma electrónica y envíe una declaración clara en nuestro sitio web, desde "Mis compras" en "Mi cuenta". Le enviaremos sin demora un acuse de recibo de dicho desistimiento a través de un soporte duradero (por ejemplo, por correo electrónico).
Para cumplir con el plazo de desistimiento, basta con que envíe su comunicación relativa al ejercicio del derecho de desistimiento antes de que venza el periodo de desistimiento.
Efectos del desistimiento
Si rescinde este contrato, le reembolsaremos todos los pagos que hayamos recibido de usted, incluidos los gastos de envío (excepto los gastos adicionales que surjan si elige un tipo de envío que no sea el tipo de envío estándar más económico que ofrecemos).
Podemos hacer una deducción del reembolso por la pérdida de valor de cualquier bien suministrado, si la pérdida es el resultado de una manipulación innecesaria por su parte.
Efectuaremos el reembolso sin demoras indebidas y, a más tardar, 14 días después de que se nos informe de su decisión de rescindir este contrato.
Efectuaremos el reembolso utilizando el mismo medio de pago que utilizó para la transacción inicial, a menos que haya acordado expresamente lo contrario; en cualquier caso, no incurrirá en ningún cargo como resultado de dicho reembolso.
Podremos retener el reembolso hasta que hayamos recibido los bienes o hasta que nos haya presentado una prueba de que los ha devuelto, lo que ocurra primero.
Deberá devolver los bienes o entregarlos a Rarewaves.com UK, Unit 144 The Lightbox, 111 Power Road, W4 5PY, London, London, United Kingdom, sin demoras indebidas y, en cualquier caso, en un plazo máximo de 14 días a partir del día en que nos comunique su desistimiento del presente contrato. El plazo se cumple si devuelve la mercancía antes de que venza el periodo de 14 días. Tendrá que asumir los gastos directos de devolución de los bienes. Usted solo es responsable de la disminución del valor de los bienes como resultado de una manipulación distinta a la necesaria para establecer la naturaleza, las características y el funcionamiento de los bienes.
Excepciones al derecho de desistimiento
El derecho de desistimiento no se aplica a lo siguiente:
- La entrega de periódicos, diarios o revistas, con la excepción de los contratos de suscripción; y
- El suministro de contenido digital que no se proporcione en un soporte tangible (por ejemplo, en un CD o DVD) si, al hacer el pedido, aceptó que podíamos empezar a entregarlo y que no podría desistir una vez iniciada la entrega.
Condiciones de envío
Please note that we do not offer Priority shipping to any country.
We currently do not ship to the below countries:
Russia
Belarus
Ukraine
Please do not attempt to place orders with any of these countries as a ship to address - they will be cancelled.