Security Park, the leading online news site for security professionals
Home | About us | Contact us | Submit an article | Advertise | Sales leads | Newsletter | RSS Newsfeed | SEARCH




Develop an ISO 27001-compliant Information Security Management System
This useful guide clarifies the steps you have to follow to develop an ISO 27001-compliant ISMS. Each step is integral in how secure your information security system is.

Need a
reference book?
Find it on Amazon:
Security books and magazines in association with Amazon.co.uk

SecurityPark Research Library

Help | Advanced Search
What's New?
What's Popular?
Layer8: Fad or For Real?
sponsored by Information Security Magazine
Posted:  05 Feb 2007
Published:  01 Feb 2007
Format:  HTML
Length:  2   Page(s)
Type:  Journal Article
Language:  English


ABSTRACT:
Risk management involves understanding how likely it is that something bad will happen, and making decisions about risk and control activities such that some sort of economic optimization is reached. Couldn't it also be the case that the risk management banner is the most effective way to try to create some alignment and common structure to related processes like personnel and IT security and disaster recovery? If the business is asking us to help it make good decisions, shouldn't we want to accommodate it? Why wouldn't an information security professional want to sing from the same score as everyone else?

Concerns that we will do a trivial job of it, or that rote bureaucratic process will overcome security substance, are valid. And the expectation that risk management requires a belief in the precise quantifiability of business is often a stumbling block, but a needless one. The one thing that formal risk management does not imply is that there is any such thing as certainty in business--quite the opposite. Mature and effective risk management is about using the most appropriate tool for the job, not about using the one that provides answers in the most politically correct form.


Author

Jay G. Heiser
VP and Research Director ,  Gartner Research



BROWSE RELATED RESOURCES
Information Security | Risk Management

View All Resources sponsored by Information Security Magazine

Library Home | Advertise with Us | Product Library
A Service of Bitpipe