How to Achieve 27001 Certification: An Example of Applied Compliance Management

  • 4h 40m
  • Keith D. Willett, Sigurjon Thor Arnason
  • CRC Press
  • 2008

The security criteria of the International Standards Organization (ISO) provides an excellent foundation for identifying and addressing business risks through a disciplined security management process. Using security standards ISO 17799 and ISO 27001 as a basis, How to Achieve 27001 Certification: An Example of Applied Compliance Management helps an organization align its security and organizational goals so it can generate effective security, compliance, and management programs. The authors offer insight from their own experiences, providing questions and answers to determine an organization's information security strengths and weaknesses with respect to the standard. They also present step-by-step information to help an organization plan an implementation, as well as prepare for certification and audit. Security is no longer a luxury for an organization, it is a legislative mandate. A formal methodology that helps an organization define and execute an ISMS is essential in order to perform and prove due diligence in upholding stakeholder interests and legislative compliance. Providing a good starting point for novices, as well as finely tuned nuances for seasoned security professionals, this book is an invaluable resource for anyone involved with meeting an organization's security, certification, and compliance needs.

In this Book

  • Introduction to International Standards Organization Security Standards
  • Information Security Management System
  • Foundational Concepts and Tools for an Information Security Management System
  • Implementing an Information Security Management System—Plan-Do Check-Act
  • Audit and Certification
  • Compliance Management
  • Useful Bits of Knowledge
  • Glossary


Rating 4.6 of 30 users Rating 4.6 of 30 users (30)
Rating 4.7 of 27 users Rating 4.7 of 27 users (27)