Description:
This book provides practical guidance to the principles and development of a strategic approach to an IRM programme, to allow readers to be able to identify, assess, prioritise and treat risks to keep information secure and available.
Brief description: David Sutton's career in IT spans more than 50 years and includes voice and data networking, information security and critical information infrastructure protection. He has been a member of the BCS Professional Certification Information Security Panel since 2005 and has delivered lectures on information risk management and business continuity at the Royal Holloway University of London. He is the author of BCS book 'Cyber Security' and co-author of 'Information Security Management Principles' and 'Data Governance.'
Review Quotes: Information risk management is an integral part of every business and the author presents its lifecycle in an easy-to-follow and well-organised format with real-life examples, tools and templates. I highly recommend the book also as a valuable reference for legislation, standards, methodologies and frameworks for risk professionals to follow.