Books — the smart way to learn about management system standards |
||||||||
Books by Dr David Brewer An introduction to ISO/IEC 27001:2022/
|
Edition 5 (published May 2024). First published 2014 181 pages. Available on Amazon as a paperback, ISBN 9798326462220: price £42.25 This new edition gives advice on the new requirements concerning climate change, futher advice on tranisitioning from ISO/IEC 27001:2013 to ISO/IEC 27001:2022, and insights into Annex A and the SOA. |
Edition 2 (published November 2022). 95 pages. Available on Amazon as a paperback, ISBN 9798361626724, price £27.99. |
This book is a “must-have” for organizations and individuals keen on ensuring a smooth transition and obtaining maximum benefit from their investment in having a management system.
No prior knowledge of management systems is assumed.
In April 2012, ISO updated its directives. There was a new annex – Annex SL – which defines the High Level Structure and Identical Core Text for all new and revised management system standards. The concept is that some requirements, e.g. management review, are common to all management system standards and therefore ought to be identically worded.
The book explains these requirements and how they are related to those in management system standards published prior to the advent of the new ISO directives. It shows how familiar concepts have metamorphosed into new ones. It provides fresh insights into understanding management system standards and thereby gives guidance on how to develop a management system for the first time.
Edition 2 (published 6 November 2019). First published in 2014. 102 pages. Available on Amazon as a paperback, ISBN-10 1706087543. ISBN-13 978-1706087540, price £27.16, or Kindle, price £23.38 |
Dr David Brewer has over thirty-five years’ worldwide experience working with management systems as a standards maker, consultant, auditor, tutor, and integrated management system administrator. He was one of the first consultants to advise the British Government on information security matters, helping to establish the first ever computer security evaluation facilities and evaluation criteria. He was a founder member of the Department of Trade and Industry’s Commercial Computer Security Centre (1987-1992) and became co-author of the European IT Security Evaluation Criteria (the forerunner of ISO/IEC 15408) and its associated evaluation manual. He was co-author of the original ISMS standard, BS 7799 Part 2 and Head of the UK delegation to ISO/IEC JTC1 SC27 WG1, which is responsible for the ISO 27000 family of standards. He is the editor for the revision of ISO/IEC 27000 (ISMS Overview) and ISO/IEC 27004 (Monitoring, measurement, analysis and evaluation).
David has conducted a wide variety of consultancy assignments in information security spanning 42 years in over 23 countries. He is known for his work in rolling out ISO/IEC 27001 to the Civil Service in Mauritius (an exemplar of his ISMS implementation methodology), and for his ability to train people to train others. His seminal research papers include: The Chinese Wall Security Policy, published in 1989; and Measuring the Effectiveness of an Internal Control System, published in 2004.