CHAPTER 6: RISK MANAGEMENT
Risk management is at the heart of the ISMS. Understanding its significance to the overall process is one of the keys to project success. The board adopts an information security policy because there are several significant risks to the confidentiality, integrity and availability of the organisation’s information, and ISO 27001 mandates the design and deployment of an ISMS to ensure that the policy is implemented systematically and comprehensively.
The policy must therefore reflect the board’s assessment of information security risks and opportunities. This doesn’t mean the board needs to carry out a detailed risk assessment itself, but it does need to set out a clear, overall approach to risk that can be used to take ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access