Update Details: A new Business Health and Compliance update has been issued on Keeping Your Information Secure. The full article has been emailed to subscribers with the Business Health and Compliance preference and is available as a PDF in the Update Service folder.
Why Keeping Your Information Secure Matters
Most information security incidents don't start with a sophisticated attack. They start with a convincing email, a lost laptop, or an account that stayed live long after the person using it left. Information security covers the confidentiality, integrity and availability of everything a business holds, wherever that information happens to sit.
What the Information Security Update Covers
The update starts with a risk assessment: what information you hold, where it lives, who can reach it, and what would happen if it was lost, leaked or locked up. The answer depends on how a business operates, and a small office, a virtual company and a larger organisation each face a different picture.
It then sets out where the exposure usually sits, in people, access and devices, and the recovery question behind all three, followed by a proportionate set of controls. A closing section covers where ISO 27001 fits, and why significant risks belong on a risks register alongside everything else.
Getting the Full Information Security Update
The full update, along with the supporting documents and example risk assessments for managing information security, is provided to subscribers as part of the update service.
Business Health and Compliance updates are issued as part of the ISO and legal update service and the content is also saved to the Update Service folder (this is in the alphaZ subscribers section) where they can be downloaded in pdf format and used for providing topic-specific training or for sending out as an update to workers.

