Considers
Trade Review
This is an exceptionally well-written primer for anyone responsible for corporate information risk management. … It's obvious that the author has regularly encountered and solved the problems he describes in the course of his three decades in Canadian government and justice IT, and he has an appealing no-nonsense approach. …the true greatest strength of this book is its holistic viewpoint - all too rare and much appreciated - that demonstrates how all the disparate aspects of information management actually fit together to create a robust business asset base. I can unhesitatingly recommend it, not only to CIOs but also to anyone tasked with protecting corporate information assets, whatever the level of their role. It imparts understanding, which is vastly more useful than mere facts. An excellent holistic primer on corporate information management. The author's credentials are fully justified by the clear, concise and informative text. A must-have for CIOs and anyone else managing business information assets.—Michael Barwise, BSc, CEng, CITP, MBCS, in InfoSec Reviews, September 2011
This is an exceptionally well-written primer for anyone responsible for corporate information risk management. … It's obvious that the author has regularly encountered and solved the problems he describes in the course of his three decades in Canadian government and justice IT, and he has an appealing no-nonsense approach. …the true greatest strength of this book is its holistic viewpoint - all too rare and much appreciated - that demonstrates how all the disparate aspects of information management actually fit together to create a robust business asset base. I can unhesitatingly recommend it, not only to CIOs but also to anyone tasked with protecting corporate information assets, whatever the level of their role. It imparts understanding, which is vastly more useful than mere facts. An excellent holistic primer on corporate information management. The author's credentials are fully justified by the clear, concise and informative text. A must-have for CIOs and anyone else managing business information assets.
—Michael Barwise, BSc, CEng, CITP, MBCS, in InfoSec Reviews, September 2011
Table of Contents
Introduction: Why Risk Management? Liability. Service Delivery. PRINCIPLES AND CONCEPTS. Overview. Basic Concepts, Principles, and Practices. Risk Assessment, Analysis, and Procedures. Metrics. Best Practices. SERVICE DELIVERY. Product Management. Process Management. Project Management. IT Service Management. Reporting on Service Delivery. LIABILITIES MANAGEMENT. Information Management. Information Protection. E-Discovery. Privacy. Policies and Procedures. Planning for Big Failures or Business Continuity. PUTTING IT ALL TOGETHER. Designing a Risk Management Strategy. Forward-Looking Risk Management. Preparing for a "Black Swan". APPENDICES: OECD Privacy Principles. Project Profiling Risk Assessment. Risk Impact Scales. Classification Schema.