July 2024
Intermediate to advanced
486 pages
11h 19m
English
It is both practical and sensible to consider the organization’s information security management structure at an early stage in the implementation process. This needs to be thought through at the same time as the information security policy is being drawn up, as set out in Chapter 5. An effective information security management structure also enables the risk assessment (to be discussed in Chapter 6) to be carried out effectively.
The first control category in Annex A of the Standard is Organizational. Controls are selected to meet business, regulatory, or contractual requirements (the baseline security criteria), or in response to the risk analysis (see Chapter 6); there is a business requirement to ...
Read now
Unlock full access