5

ISMS – Phases of Implementation

An information security management system (ISMS) comprises the various policies, standards, procedures, practices, behaviors, and scheduled activities that a corporation implements to protect the (important) information assets it possesses. Both the organization and its external constituents are provided with clear objectives and context regarding information security.

The design and implementation of the ISMS are dependent on the organization’s requirements and goals. The organization’s size and structure, the market or service region, and the sensitivity of the information it possesses or controls on behalf of others should also be considered. It is the goal of an ISMS to identify, assess (if necessary), and ...

Get Mastering Information Security Compliance Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.