FURTHER READING

An Introduction to Information System Risk Management, SANS Institute, InfoSec Reading Room, www.sans.org/reading_room/whitepapers/auditing/an_introduction_to_information_system_risk_management_1204.

A Practical Approach to Managing Information System Risk, Tom Olzak, http://it.toolbox.com/blogs/adventuresinsecurity/a-practical-approach-to-managing-information-systemrisk-22212.

BS31100:2008 Risk Management. Code of Practice, www.bsigroup.com /, ISBN: 978 0 580 64908 0.

Guidance on the Department Information Risk Policy, the UK Cabinet Office, www.cabinetoffice.gov.uk/media/207099/guide_on_irp.pdf .

Internal Control: Revised Guidance for Directors on the Combined Code (Oct 2005) (the ‘Turnbull Guidance’), www.frc.org.uk/documents/pagemanager/frc/Revised%20Turnbull%20Guidance%20October%202005.pdf ...

Get Managing Information Risk: A Director's Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.