Information security

Information security protects information held by organizations from a wide range of threats to ensure business continuity, minimize business damage and maximise return on investment and business opportunities. BSI’s range of publications and standards will help you implement an effective Information Security Management System.

Read more about Information Security on the Information and Communication Technology (ICT) microsite.

Key publications button cover

BS 7799-3:2006
Information security management systems. Guidelines for information security risk management


Identifying, evaluating, treating and managing information security risks are key processes if businesses want to keep their information safe and secure. Whilst these processes are specified in the information security standard BS ISO/IEC 27001:2005, further guidance is required on how to manage these risks as well as to put them into context with other business risks.

BS 7799-3:2006 provides this guidance and covers:

  • risk assessment
  • risk treatment
  • management decision making
  • risk re-assessment
  • monitoring and reviewing of risk profile
  • information security risk in the context of corporate governance compliance with other risk based standards and regulations.

  

standard coverSecuring Email and Electronic Messages coverBS ISO/IEC 27005:2008
Information technology. Security techniques. Information security risk management

standard coverKIT 20
Information security standards kit

coverBS ISO/IEC 20000 ITSM Online
The new self-assessment tool giving you confidence in IT service management systems (ITSM) and ISO/IEC 20000.

 

Coming soon BS 25777 Code of practice for ICT continuity

Register for updates

Print this page
See more information security titles

ISEB Courses available

Coming soon - BS 25777 Code of practice for ICT continuity