Information Security Based on ISO 27001/ISO 17799: A Management Guide
Alan Calder · Medical Entomology and Zoology · 2006
Introduction Information security Background to the standards Use of the standards Certification process Overview of ISO 27001 Summary of changes from BS 7799-2:2002 ISO 27000 series in future Integration with other management systems Record contraol Management responsibility The PDCA cycle Scope definition Risk assessment Risk treatment plan The statement of applicability Monitor & review the ISMS Maintain the ISMS Annex A control areas ISO 27001 & CobiT ISO 27001, ITIL & ISO 20000