Information technology. Security techniques. Information security management. Organizational economics

Information technology. Security techniques. Information security management. Organizational economics

Regular price
£272.00
Sale price
£272.00
Regular price
£136.00
Sold out
Unit price
per 

What is ISO/IEC TR 27016 about?  

ISO/IEC TR 27016 provides guidelines on how an organization can make decisions to protect information and understand the economic consequences of these decisions in the context of competing requirements for resources. 

Who is ISO/IEC TR 27016 for? 

ISO/IEC TR 27016 on information security management is useful for the organization: 

  • Chief Executive Officers  
  • Heads of Government Organizations  
  • Chief Financial Officers 
  • Chief Operating Officers 
  • Chief Information Officers 
  • Chief Operating Officers 
  • Chief Information Officers 
  • Chief Information Security Officers 

Why should you use ISO/IEC TR 27016 

Information security management is often seen as an information technology only approach using technical controls (e.g. encryption, access and privilege management, firewalls, and intrusion and malicious code eradication). However, any application of information security is not effective without considering a broad range of other controls (e.g. physical controls, human resource controls, policies, rules, etc.). A decision has to be made to allocate sufficient resources to support a broad range of controls as part of information security management. ISO/IEC TR 27016 supports the broad objectives of information security as provided in the ISO/IEC 27000 family of standards by introducing economics as a key component of the decision-making process. 

ISO/IEC TR 27016 provides guidelines on information security economics as a decision-making process concerning the production, distribution, and consumption of limited goods and services. Actions for the protection of an organization’s information assets require resources, which otherwise could be allocated to alternative non-information security-related uses.