E-book details

ISO 27001/ISO 27002. A guide to information security management systems

ISO 27001/ISO 27002. A guide to information security management systems

IT Governance Publishing, Alan Calder

Ebook
This comprehensive guide demystifies the ISO 27001 and ISO 27002 standards, offering a clear roadmap to understanding, implementing, and managing an Information Security Management System (ISMS). It begins with foundational concepts, a history of ISO 27001, and introduces the ISO 27000 family. The book proceeds to cover the PDCA cycle, Annex SL structure, and the significance of shall vs. should in compliance language.
Core chapters walk through ISO 27001’s clauses and requirements, from organizational context and leadership to performance evaluation and continual improvement. Annex A's security controls are explored in detail, linking theory with practical application. ISO 27002 is also thoroughly reviewed to offer guidance on selecting and implementing appropriate controls.
By the end of the book, readers gain a strong understanding of ISMS design, certification processes, and control mapping. This resource supports IT managers, compliance officers, and auditors seeking to align with international security standards.
  • 1. Accredited Certification
  • 2. Terms and Definitions
  • 3. ISO 27001 Requirements
  • 4. ISO 27002
  • Title: ISO 27001/ISO 27002. A guide to information security management systems
  • Author: IT Governance Publishing, Alan Calder
  • Original title: ISO 27001/ISO 27002. A guide to information security management systems
  • ISBN: 9781806382385, 9781806382385
  • Date of issue: 2025-07-21
  • Format: Ebook
  • Item ID: e_4j28
  • Publisher: IT Governance Publishing