Skip to Content
Governance, Risk, and Compliance Handbook: Technology, Finance, Environmental, and International Guidance and Best Practices
book

Governance, Risk, and Compliance Handbook: Technology, Finance, Environmental, and International Guidance and Best Practices

by Anthony Tarantino
March 2008
Intermediate to advanced
1127 pages
33h 30m
English
Wiley
Content preview from Governance, Risk, and Compliance Handbook: Technology, Finance, Environmental, and International Guidance and Best Practices

CHAPTER 12

ISO 27001 AND ISO 17799

Alan Calder

12.1 ISO 27001 AND ISO 17799—THE INFORMATION SECURITY STANDARDS

(a) Background to ISO 27001

(b) Information Security Standards Originating Body

(c) ISO/IEC 27001:2005 (ISO 27001)

(d) ISO/IEC 17799:2005 (ISO 17799)

12.2 ISO 17799 VERSUS ISO 27001

(a) Correspondence between the Two Standards

(b) Integration of Management Systems

(c) IT Governance and Information Security Management

(d) Risks to Information Assets

(e) Information Security

(f) Information Security Management System

(g) ISO 27001 as a Model for the ISMS

(h) Legal and Regulatory Framework

(i) Process Approach and the PDCA Cycle

(j) Establishing the ISMS

(k) Policy and Business Objectives

(l) Risk Assessment

(m) Risk Treatment Plan

12.3 CONCLUSION

12.4 ESSENTIAL FURTHER READING

NOTES

12.1 ISO 27001 AND ISO 17799—THE INFORMATION SECURITY STANDARDS

The replacement, in late 2005, of BS 77799-2:2002 by the international information security management system (ISMS) standard ISO/IEC 27001:2005 marks the coming of age of information security management. ISO 27001 is the international standard for information security management systems, and it provides organizations with best practice guidance for identifying, assessing, and controlling information risks in strategic business plans and everyday operational environments. It's the essential standard for the information age organization. It has an important and symbiotic relationship with another international standard, ISO/IEC 17799:2005, ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Information Governance, 2nd Edition

Information Governance, 2nd Edition

Robert F. Smallwood
Enterprise Risk Management, 2nd Edition

Enterprise Risk Management, 2nd Edition

John R. S. Fraser, Rob Quail, Betty Simkins

Publisher Resources

ISBN: 9780470095898