Skip to article sections

This volume is a practical guide to information security that complements the information security standard ISO 27001. ISO 27001 is one of the most successful international standards, implemented to a certified level in a wide range of organisations across the world. It has been embedded as a desirable requirement within the context of regulatory frameworks (e.g. the UK Information Commissioner's Office advise organisations to comply with ISO 27001 to ensure the protection of personal data in accordance with the requirements of European Union data protection legislation) and contractual guarantees (e.g. some organisations make one of the conditions of the award of a contract proof of certification against ISO 27001). As a standard, ISO 27001 contains the high level requirements for implementing an information security management system but it does lack detailed guidance on what to do in practice. This text fills that gap and provides guidance on routes to implementing an information security management system. The author, Ted Humphreys, is a leading international expert within the field of information security who was involved in the development of the ISO 27000 family of standards. As a consultant, he has provided practical expertise on implementing information security management systems within a wide range of public and private sector organisations around the world.

The text starts with a concise but informative introduction to the risk landscape. Humphreys sets out the range of risks that face an organisation; establishing the differences between pure risk and speculative risk as well as static versus dynamic risks. He breaks down risk factors (human resources, legislation, competition and business markets, operations, finance and investments, security and safety) and discusses how each of these factors can impact upon an organisation's business. Having understood the risk environment in which one is working, it is possible to establish an information security management system; this is the process that occupies the body of the text.

The main text details the process of establishing an information security management system following the structure of the ISO 27001, which includes strategies for scoping the framework, risk assessment, risk treatment, risk controls, risk monitoring and reviews, risk improvements, documentation systems, audits and reviews. The text contains standard textbook risk framework tools and some additional approaches. For example, the discussions on business impact include systems to measure information security risks in regard to business effect and business criticality to deliver an overall business impact rating. Humphreys also discusses the return on investment (ROI) for the security system and individual security measures. This is particularly helpful in the current economic climate where ROI does need to be articulated, particularly as the costs are often not a one‐off investment. Humphreys stresses that information security management systems are living systems that need monitoring, review, audit and evolution. He tackles how to remap information security management systems to cope with business change and also the complexities of organisational acquisitions and mergers. The framework and tools presented are intended to be equally applicable to large‐scale organisations and SMEs. Diagrams and case studies help to deliver a very clear understanding of the practicalities and complexities of delivering an information security management system. However, the text does have some weaknesses, which are, in part, due to the fact that a volume of this length can only be an introduction to the subject.

The book does focus too heavily on IT security. The link between paper and electronic environments is not discussed. The presumption is that all information is online and yet some of the biggest data losses have been through the mismanagement of hardcopies. It would have been helpful to include case studies which covered the wider range of risks mapped out in the section on the risk landscape. Despite this comprehensive introduction, the text also focuses on pure/negative risk rather than speculative/opportunistic risks. The volume does not provide practical examples of the ways in which risk assessment can harness competitive business advantages, e.g. engaging with Web 2.0, Cloud software or other forms of outsourcing. Humphreys correctly identifies staff as the greatest potential security risk for an organisation but fails to also expand and discuss that these same staff are often the biggest information asset. For records and information management/security/risk professionals to realise their full value, within an organisational context, there is an important role to play in developing records and information management frameworks that provide security assurances and organisational opportunities/evolution. In making this text relevant to SMEs some of the additional discussion of the balancing of risks would have been an important addition as the scales can tip in a different direction within the SME context. However, in fairness to Humphreys, ISO 27001 is a standard against which an organisation's information security management systems are certified, and thus this does prejudice a system's evolution towards close alignment with risk avoidance. In this context, it would be helpful to spell out why information security management cannot be easily outsourced, i.e. information storage can be outsourced but the actual information ownership assigns risks that cannot be transferred.

Despite these criticisms this is an excellent read which delivers its purpose given its length. As a British Standard publication it has been written to link to and underpin the ISO standard and therefore it does not link out to other key texts and risk information freely available online, which would supplement the work. However, it is a practical and useful presentation of how to develop an information security management system with lots of information that is not readily available elsewhere. I will read and refer to it again; if it is republished then I hope an index is added! In conclusion I would strongly recommend this text to records and information managers. The systems discussed are those which can be embedded into and aligned to records and information management frameworks. Information governance and security should be a critical part of records and information management programmes. At £38.95 this volume is a valuable reference text.

Data & Figures

Contents

Supplements

References

Languages

or Create an Account

Close Modal
Close Modal