Information security issues impact all organizations, however measures used to implement effective measures are often viewed as a businesses barrier costing a great deal of money. This practical title clearly explains the approaches that most organizations can consider and implement which helps turn Information Security management into an approachable, effective and well-understood tool. It covers •The quality requirements an organization may have for information •The risks associated with these quality requirements •The countermeasures that are necessary to mitigate these risks •Ensuring business continuity in the event of a disaster •When and whether to report incidents outside the organization
This textbook represents the only study guide currently available for the ISO 27001/27002 individual certification exams. I read the entire book, wrote copious notes, took the only practice exam available (found on the EXIN website), and passed the Foundation exam with a score of 95%.
The book was a good, quick read, but I found many errors, likely from its rushed translation from Dutch to English.