
vsRisk™ – the Definitive ISO 27001: 2005-Compliant Information Security Risk Assessment Tool
Risk assessment is one of the core competences of ISO 27001 information security management. With this toolkit, project managers can access both a national standard that describes how to carry out a risk assessment to meet the requirements of ISO 27001 and also obtain a tool & book that will make it possible.
All materials, guides and tools provided in this toolkit are aligned with best practices
Doing a risk assessment for any organization that has more than three employees is virtually impossible without using a risk assessment tool such as vsRisk.
vsRisk is the most cost-effective tool for meeting the requirements of ISO 27001.
1. Single User License/ CD-ROM of vsRisk™
• Automates and delivers an ISO/IEC 27001-compliant risk assessment;
• Uniquely, vsRisk™ can assess confidentiality, integrity & availability for each of the business, legal and contractual aspects of information assets – as required by ISO 27001
• Comprehensive best-practice alignment:
• Supports ISO/IEC 27002 and ISO/IEC27001:2005
• Wizard-based approach simplifies and accelerates the risk assessment process;
• Integrated, regularly updated, BS7799-3 compliant threat and vulnerability databases;
• Customisable assessment scales and risk acceptance criteria;
• Contains all ISO 27001/ISO 27002 controls with additional control databases available;
• Produces an audit-ready Statement of Applicability;
• Backup and restore capability;
• Clear, clean user interface with integrated help, making the tool easy-to-use
It also integrates with the ITG ISMS Documentation Toolkit (integration templates supplied separately to all Documentation Toolkit purchasers).
Other key features include:
vsRisk™ has been designed with the user in mind and for the first time empowers the user to comply with the requirements of ISO 27001:2005 and effectively assess and align their total assets with their objectives.
2. The new British Standard – BS 7799-3:2006 – provides this guidance and covers:
BS 7799-3:2006 gives guidance to support the requirements given in BS ISO/IEC 27001:2005 regarding all aspects of an information security management system (ISMS) risk management cycle. This includes assessing and evaluating the risks, implementing controls to treat the risks, monitoring and reviewing the risks, and maintaining and improving the system of risk controls.
The focus of this standard is effective information security through an ongoing programme of risk management activities. This focus is targeted at information security in the context of an organization’s business risks.
The guidance set out in this British Standard is intended to be applicable to all organizations, regardless of their type, size and nature of business. It is intended for those business managers and their staff involved in ISMS risk management activities.
3. Information Security Risk Management for ISO 27001/ISO 27002 (Soft Cover)
This book provides clear, practical and comprehensive guidance on developing a risk management methodology that meets the requirements of ISO27001, the the information security management standard, and how to carry out a risk assessment that will help achieve corporate risk management objectives.
While this book's detailed guidance will enable anyone to carry out an ISO27001-compliant risk assessment, it also draws on the complementary guidance of ISO 27002 (17799), BS7799-3, ISO 13335-3, NIST SP 800-30 and the UK's Risk Assessment Standard to provide the most comprehensive information security risk assessment, analysis and management manual available.
| < Prev | Next > |
|---|
stick something nice in here
stick something nice in here here is some footer stuffasdfasdsadf sdaf sadf sadsad fdsa fsadf sadfadsf
stick something nice in here