IRM roadmap and Playbook
I am very new to the world of IRM as it relates to cyber security. I am literally learning on the job.
Part of job spec involves drafting policies, procedures, and standards related to the security stance of various companies. I have next to no knowledge of ISO, i do have a copy of the ISO/IEC 27000:2014(E) i would like some input and guided walk through examples as a lot of the content flies over my head.
Assign topic to the user
I'm assuming that by IRM you mean Integrated Risk Management.
Considering that, as a baseline for you to start I suggest the following material:
- What is ISO 27001 https://advisera.com/27001academy/what-is-iso-27001/
- Where to start from with ISO 27001 https://advisera.com/27001academy/knowledgebase/iso-27001-where-to-start-most-important-materials/
- ISO 27001/ISO 27005 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
These materials will also help you regarding ISO 27001:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Aug 24, 2020