Aligning IT, Security and Risk Management Programs

Information Security Policies (ISO 27002:2013 Section 5) and Organization of Information Security (ISO 27002:2013 Section 6) are closely related, so we address both domains in this chapter. The Information Security Policies domain focuses on information security policy requirements and the need to align policy with organizational objectives. The Organization of Information Security domain focuses on the governance structure necessary to implement and manage information security policy operations, across and outside of the organization. Included in this chapter is a discussion of risk management because it is a fundamental aspect of governance, decision making, and policy. Risk management is important enough that it warrants two sets of standards: ISO/IEC 27005 and ISO/IEC 31000.

Spotlight

Foresight

Foresight is a specialist cyber security consultancy focused on providing governance, risk, compliance and technical assurance services to enterprises and government agencies. Our aim is to provide high quality, pragmatic security consulting services to our customers. Our customers include national and international companies from both the private and public sectors. Our capabilities and expertise align with our four main service lines: Strategic Advisory. Governance, Risk and Compliance. Security Engineering.

OTHER VIDEOS

Find All Your APIs with API Discovery

video | August 3, 2023

APIs operating without any security controls are just waiting to be exploited. Misconfigurations, suspicious behavior, and cyber attacks may already be occurring without your knowledge. Hackers are on the lookout for APIs that will allow them to access data covertly, providing time to not only extract data, but to explore additional attack vectors....

Watch Now

How VMware Uses MetaAccess to Validate and Remediate Endpoints at Scale

video | July 28, 2023

VMware, a global leader in cloud computing and virtualization technology uses MetaAccess from OPSWAT to ensure tens of thousands of remote users can access VMware's Horizon cloud software with devices that meet strict security standards. MetaAccess provides a zero trust access solution Kristina de Nike, Director of Product Management, Horizon, discusses how OPSWAT's MetaAccess is able to detect and remediate endpoints at scale....

Watch Now

Cloud Pak for Security: Introduction to Cloud Pak for Security

video | July 27, 2023

This is an introductory video for Cloud Pak for Security. Cloud Pak for Security is based on Open Shift technology. This means that it can be installed on-prem as well as on any of the cloud solutions like IBM Cloud, AWS, Microsoft Azure, Google Cloud etc. QRadar XDR is SIEM of SIEM. Typically in huge environments, there are multiple SIEMs being used. To get a birds eye view of the complete environment, the data needs to be copied from one SIEM to another. Rather than this, CP4S can be leveraged in such a scenario. The data does not need to move from SIEM to CP4S and still CP4S is capable to understand the security posture of an organisation, understand risk valuation, create and manage inci...

Watch Now

Simplifying Hybrid Cloud Protection with HPE GreenLake for Backup and Recovery

video | July 31, 2023

HPE GreenLake for Backup and Recovery is backup as a service designed for hybrid cloud. It simplifies how you protect your on-premises and cloud-native workloads bringing with it the cloud experience and flexibility of software delivered as a service....

Watch Now

Spotlight

Foresight

Foresight is a specialist cyber security consultancy focused on providing governance, risk, compliance and technical assurance services to enterprises and government agencies. Our aim is to provide high quality, pragmatic security consulting services to our customers. Our customers include national and international companies from both the private and public sectors. Our capabilities and expertise align with our four main service lines: Strategic Advisory. Governance, Risk and Compliance. Security Engineering.

Events