Cyber Security Institute
§ Current Worries
Top 3 Worries
- Regulations
- Old Firewall Configurations
- Security Awareness
§ Listening
For the best information
- The underground
- Audible
- Executive Excellence
- Music (to keep me sane)
§ Watching
For early warnings
- 150 Security Websites
- AP Newsfeeds
- Vendors
Wednesday, February 18, 2009
Clear Guide on How to Benefit from ISO27001 in a Windows® Environment Now Available
Independent compliance expert IT Governance has today announced the publication of Implementing ISO27001 in a Windows® Environment’ (http://www.itgovernance.co.uk/products/2207), a step-by-step guide on implementing this major security standard, written with the aim of helping project managers, IT and security staff develop a shared understanding of what controls are appropriate to mitigate identified risks - and how, within the Windows® environment, to apply them.
Information security management standard (ISMS) ISO/IEC 27001 encourages organisations to bring technical decision making about information security controls into a business-driven risk-based framework. This challenges all parties involved in information security management to communicate effectively, especially between technical and non-technical staff about effective security control implementation.
The guide’s author, Brian Honan, is widely recognised as an industry expert on information security and, in particular, on the ISO27001 information security standard.
A member of the Information Systems Security Association, the Irish Information Security Forum, and the Information Systems Audit and Control Association, Brian established Ireland’s first ever national Computer Security Incident Response Team.
“Written in non-technical language and in a style that makes its content accessible to non-technical ISO27001 project managers, Brian’s invaluable study will give IT security practitioners the information and knowledge they need,” says Alan Calder, Chief Executive of the book’s publishers, IT Governance.
IT Governance is ‘non-geek’, approaching IT issues from a non-technology background and talking to management in its own language.