000 02867nam a2200253Ia 4500
003 NULRC
005 20250520103023.0
008 250520s9999 xx 000 0 und d
020 _a9780749496951
040 _cNULRC
050 _aQA 76.9.A25 .C35 2020
100 _aCalder, Alan
_eauthor
245 0 _aIT governance :
_ban international guide to data security and ISO27001/ISO27002 /
_cAlan Calder and Steve Watkins
250 _a7th Edition.
260 _aLondon, United Kingdom :
_bKogan Page Limited,
_cc2020
300 _a395 pages ;
_c24 cm.
365 _bUSD53
504 _aIncludes bibliographical references.
505 _aChapter 01: Why is information security necessary -- Chapter 02: The UK combined code, the FRC risk guidance and Sarbanes-Oxley -- Chapter 03: ISO27001 -- Chapter 04: Organizing information security -- Chapter 05: Information security policy and scope -- Chapter 06: The risk assessment and Statement of Applicability -- Chapter 07: Mobile devices -- Chapter 08: Human resources security -- Chapter 09: Asset management -- Chapter 10: Media handling -- Chapter 11: Access control -- Chapter 12: User access management -- Chapter 13: System and application access control -- Chapter 14: Cryptography -- Chapter 15: Physical and environmental security -- Chapter 16: Equipment security -- Chapter 17: Operations security -- Chapter 18: Controls against malicious software (malware) -- Chapter 19: Communications management -- Chapter 20: Exchanges of information -- Chapter 21: System acquisition, development and maintenance -- Chapter 22: Development and support processes -- Chapter 23: Supplier relationships -- Chapter 24: Monitoring and information security incident management -- Chapter 25: Business and information security continuity management -- Chapter 26: Compliance -- Chapter 27: The ISO27001 audit.
520 _aNow in its seventh edition, the bestselling IT Governance provides guidance for companies looking to protect and enhance their information security management systems (ISMS) and protect themselves against cyber threats. The new edition covers changes in global regulation, particularly GDPR, and updates to standards in the ISO/IEC 27000 family, BS 7799-3:2017 (information security risk management) plus the latest standards on auditing. It also includes advice on the development and implementation of an ISMS that will meet the ISO 27001 specification and how sector-specific standards can and should be factored in. With information on risk assessments, compliance, equipment and operations security, controls against malware and asset management, IT Governance is the definitive guide to implementing an effective information security management and governance system.
650 _aCOMPUTER SECURITY
700 _aWatkins, Steve
_eco-author
942 _2lcc
_cBK
999 _c21542
_d21542