Chapter 19. Is ISO 27001 for You?

Executive summary

Unless you’re a relatively small organization or, as an organization, you do not use information or information technology, ISO 27001 is an appropriate standard for you to deploy to safeguard your IT infrastructure investments, protect your competitive position and ensure you comply with current and future national and international laws and regulations.

Do you have information that you rely on or which needs to be kept confidential?

If you do, you need to have a structured approach to protecting it against multiple external and internal threats; such an approach requires a mix of technology and procedure, as well as informed and well-trained computer users. The standard contains best practice guidelines ...

Get The Case for ISO 27001 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.