Does your organisation have an effective Incident Management Plan?
Given the increasing risks from cyber attack from external and internal sources, your organisation will inevitably experience a security breach at some time in the future. The ability to respond to an event, mitigate its impact and prevent it happening in the future is an essential requirement of effective information security management. This is also recognised as mandatory requirement of the ISO27001 (Control A.13.2.1) and the PCI DSS (Req. 11 &12) standards.
ISO27035 (ISO 27035) Information Security Incident Management
ISO/IEC 27035:2011 is now available from IT Governance as a PDF. Do you know how to cope should an information security incident occur? If not, this standard will provide you with the solution!
ISO/IEC 27035:2011 details a best practice approach to information security incident management. The stages in this standard cover how to:
- Detect, report and assess information security incidents
- Respond to and manage information security incidents
- Detect, assess and manage information security vulnerabilities; and
- Continuously improve information security and incident management as a result of managing information security incidents and vulnerabilities.
The guidance is ISO/IEC 27035 is as applicable as to small organisations as it is to large organisations. Specific guidance within this standard is also provided to organisations providing information security incident management services.
Key Features and Benefits:
- Details an approach to information security incident management that can be employed to respond should the worst happen. Using this approach to manage incidents will allow you to ensure you are prepared and know how to react to minimise risks.
- The approach detailed in this standard is applicable no matter the size of your organisation, it can be employed by organisations small, medium or large. It can also be employed in the public, private and not-for-profit sectors. Making it widely applicable.
We also offer a hardcopy version of this standard - ISO/IEC 27035:2011 (Hardcopy).
Publisher: BSI
Format:Electronic Download .PDF
Published Date: 17 August 2011
Licensing: Licensing Terms: Governed by BSI's Copyright Terms and Conditions.
Availability: Immediate Download
Now there is an International Standard for information security incident management - buy your PDF copy today for immediate download!
To write review for this product Click here
RELATED PRODUCTS