Chapter 1. Information Security Auditing and Strategy


‘We should base our decisions on awareness rather than on mechanical habit. That is, we act on a keen appreciation for the essential factors that make each situation unique instead of from conditioned response.s’

 --MCDP 1 Warfighting

Rephrasing Clausewitz, to produce a workable scheme for information security assessments, is one of the tasks that are inherently simple, yet the simplest thing is difficult to implement. It is simple because the underlining logic is clear. It can be formulated in a minute. Here it comes from the (independent) auditor’s viewpoint:

  • Find out about goals and conditions of the assessment.

  • Plan the appropriate actions.

  • Select the corresponding methodologies and tools. ...

Get Assessing Information Security: Strategies, tactics, logic and framework now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.