What is a Wise Risk Decision Worth? or ISO 27001 KPIs Follow Up
...risk - and similarly Shrdlu wrote
I really have no idea. I personally wouldnt try to justify an ISO implementation by itself. If I could show traceability on how it affected our overall security risk, then thats what Id do
And thats a delightful answer. That traceability (geeze-louise Shrdlu - what a word!) is absolutely what Im after here....
