Management system requirements in ISO 27001 for information security : security
Christel Fouché · Risk management · 2008
Most organisations believe that information security management does not apply to them, or that their information is secure, or cannot be secured. Whichever they believe, these organisations are merely ignorant of an aspect that could and should be managed.