January 2020
Intermediate to advanced
268 pages
9h 22m
English
In this and subsequent chapters, ways of addressing the risks to information security are covered based on the three main categories of operational risk controls. This chapter discusses the controls involving procedures and people and how to manage them by use of the appropriate measures.
There are three main types of operational control:
At the time of writing, the latest version of the ISO/IEC 27001 Annex A (Reference control objectives and controls) contains 114 controls within 13 functional groups, and this does ...
Read now
Unlock full access