...that they take information security seriously I'm certainly not unfamiliar with the standard, having documented a gapanalysis for my organisation a couple of years ago. What I wasn't able to do is build a convincing business case for proceeding...
http://www.computerweekly.com/blogs/stuart_king/2007/10/iso-27001.html
...and a good look sideways at what everyone else is doing. Compliance is not an overnight activity. It requires a gapanalysis, impact assessment, business case and a rectification programme. You can’t conjure new budgets and the necessary...
http://www.computerweekly.com/blogs/david_lacey/governance-issues/