Organizations rely on digital information today more than ever before. Unfortunately, that information is equally sought after by criminals. New security standards and regulations are being implemented to deal with these threats, but they are very broad and organizations require focused guidance to adapt the guidelines to their specific needs.

Section I: Evaluating and Measuring an Information Security Program

The Culmination of ISRAM and GISAM

KRI Security Baseline Controls

History of the Standard

Section II: Analysis of ISO/IEC 17799:2005 (27002) Controls

Security Policy

Organization of Information Security

Asset Management

Human Resources Security

Physical and Environmental Security

Communications and Operations Management

Access Control

Information Security Incident Management

Compliance with Legal Requirements