7

Case Studies – Certification, SoA, and Incident Management

This chapter delves into a series of case studies centered around the implementation of an Information Security Management System (ISMS), the ISO 27001 certification process, the creation of a Statement of Applicability (SoA), and the management of information security incidents. These case studies revolve around a hypothetical organization named Titan Consulting Inc., a rapidly growing technology consulting firm operating in the IT industry.

Each case study will provide a comprehensive analysis of Titan Consulting Inc.’s journey toward securing its information assets. We will examine its initial motivations for pursuing ISO 27001 certification, the steps taken to implement the ISMS, ...

Get Mastering Information Security Compliance Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.