IT Governance: A Manager's Guide to Data Security and BS 7799/ISO 17799

Alan Calder, Steve Watkins · CERN Document Server (European Organization for Nuclear Research) · 2005

Why is information security necessary? The Combined Code and the Turnbull Report. BS7799. Information security management. Information security policy and scope. The risk assessment and statement applicability. Security of third party access and outsourcing. Asset classification and control. Personnel security. Physical and environmental security. Equipment security. General security controls. Communications and operations management. Controls against malicious software. Housekeeping, network management and media handling. Exchanges of information and software. E-mail and Internet use. Access control. Network access control. Operating system access control. Application access control. Mobile computing and teleworking. Systems development and maintenance. Cryptographic controls. Security in development and support process. Business continuity management. Compliance. The BS7799 audit.

Read the paper · More papers on PaperTik