July 2024
Intermediate to advanced
486 pages
11h 19m
English
An earlier version of ISO 27001 identified three sources for establishing the organization’s information security requirements: the risks that the organization faces (business, risks, discussed further below); the risks arising from the compliance and contractual requirements imposed on the organization in each of the jurisdictions in which it operates (compliance requirements in particular are discussed in Chapter 26); and the “particular set of principles, objectives and business requirements for information processing that an organization has developed to support its operations,” which are the consequence of the IT architecture the organization ...
Read now
Unlock full access