Information Security: Design, Implementation, Measurement, and Compliance
Autor Timothy P. Laytonen Limba Engleză Hardback – 20 iul 2006
Fortunately, Information Security: Design, Implementation, Measurement, and Compliance outlines a complete roadmap to successful adaptation and implementation of a security program based on the ISO/IEC 17799:2005 (27002) Code of Practice for Information Security Management. The book first describes a risk assessment model, a detailed risk assessment methodology, and an information security evaluation process. Upon this foundation, the author presents a proposed security baseline for all organizations, an executive summary of the ISO/IEC 17799 standard, and a gap analysis exposing the differences between the recently rescinded version and the newly released version of the standard. Finally, he devotes individual chapters to each of the 11 control areas defined in the standard, covering systematically the 133 controls within the 39 control objectives.
Tim Layton's Information Security is a practical tool to help you understand the ISO/IEC 17799 standard and apply its principles within your organization's unique context.
Preț: 863.80 lei
Preț vechi: 1079.76 lei
-20% Nou
Puncte Express: 1296
Preț estimativ în valută:
165.31€ • 171.72$ • 137.32£
165.31€ • 171.72$ • 137.32£
Carte tipărită la comandă
Livrare economică 03-17 februarie 25
Preluare comenzi: 021 569.72.76
Specificații
ISBN-13: 9780849370878
ISBN-10: 0849370876
Pagini: 260
Ilustrații: 16 Tables, black and white; 3 Illustrations, black and white
Dimensiuni: 156 x 234 x 20 mm
Greutate: 0.65 kg
Ediția:1
Editura: CRC Press
Colecția Auerbach Publications
ISBN-10: 0849370876
Pagini: 260
Ilustrații: 16 Tables, black and white; 3 Illustrations, black and white
Dimensiuni: 156 x 234 x 20 mm
Greutate: 0.65 kg
Ediția:1
Editura: CRC Press
Colecția Auerbach Publications
Public țintă
Academic, Professional, and Professional Practice & DevelopmentCuprins
EVALUATING AND MEASURING AN INFORMATION SECURITY PROGRAM. Information Security Risk Assessment Model (ISRAM™). Global Information Security Assessment Methodology (GISAM™). Developing an Information Security Evaluation (ISE™) Process. A Security Baseline. Background of the ISO/IEC 17799 Standard. ISO/IEC 17799:2005 Gap Analysis. ANALYSIS OF ISO/IEC 17799:2005 (27002) CONTROLS. Security Policy. Organization of Information Security. Asset Management. Human Resources Security. Physical and Environmental Security. Communications and Operations Management. Access Control. Information Systems Acquisition, Development, and Maintenance. Information Security Incident Management. Business Continuity Management. Compliance. Appendix A: ISO Standards Cited in ISO/IEC 17799:2005. Appendix B: General References. Index.
Recenzii
"I have had the pleasure of working with Tim on several large risk assessment projects and I have tremendous respect for his knowledge and experience as an information security practitioner. … Risk assessment is the cornerstone of an effective information security program. … striving to achieve compliance in the absence of a risk-based security strategy can only lead to failure. … Implement an effective risk assessment program and take control of the compliance monster. … This book will help you do just that. I know you will benefit from Tim's guidance on how to get the most from your risk assessment efforts. For today's information security leaders, there is not a topic more important."
-From the Foreword by Gary Geddes, CISSP, Strategic Security Advisor, Microsoft Corporation
-From the Foreword by Gary Geddes, CISSP, Strategic Security Advisor, Microsoft Corporation
Descriere
Presenting an in-depth perspective of the ISO/IEC 17799 Information Security Standard, this book provides a detailed analysis of how to effectively measure an information security program using this standard. It includes a qualitative-based risk assessment methodology and describes a quantitative measurement framework that organizations can adopt and implement within the risk assessment process, allowing firms to customize practices to their own needs. This text also includes a comprehensive gap analysis of the recently rescinded standard against the newly released version, making the transition to the new standard much easier for organizations and practitioners.