Zum Hauptinhalt springen Zur Suche springen Zur Hauptnavigation springen
Beschreibung

Building a Practical Information Security Program provides users with a strategic view on how to build an information security program that aligns with business objectives. The information provided enables both executive management and IT managers not only to validate existing security programs, but also to build new business-driven security programs. In addition, the subject matter supports aspiring security engineers to forge a career path to successfully manage a security program, thereby adding value and reducing risk to the business. Readers learn how to translate technical challenges into business requirements, understand when to "go big or go home," explore in-depth defense strategies, and review tactics on when to absorb risks. This book explains how to properly plan and implement an infosec program based on business strategy and results.

Building a Practical Information Security Program provides users with a strategic view on how to build an information security program that aligns with business objectives. The information provided enables both executive management and IT managers not only to validate existing security programs, but also to build new business-driven security programs. In addition, the subject matter supports aspiring security engineers to forge a career path to successfully manage a security program, thereby adding value and reducing risk to the business. Readers learn how to translate technical challenges into business requirements, understand when to "go big or go home," explore in-depth defense strategies, and review tactics on when to absorb risks. This book explains how to properly plan and implement an infosec program based on business strategy and results.

Über den Autor
Jason Andress (CISSP, ISSAP, CISM, GPEN) is a seasoned security professional with a depth of experience in both the academic and business worlds. Presently he carries out information security oversight duties, performing penetration testing, risk assessment, and compliance functions to ensure that critical assets are protected. Jason has taught undergraduate and graduate security courses since 2005 and holds a doctorate in computer science, researching in the area of data protection. He has authored several publications and books, writing on topics including data security, network security, penetration testing, and digital forensics.
Inhaltsverzeichnis

Why We Need Security Programs

Develop a Security Strategy

Integrate Security into the Organization

Establish a Security Organization

Develop a Security Policy

Manage the Risks

Protect the Data

Manage the Security of Third Parties and Vendors

Conduct Security Awareness and Training

Develop Metrics to Measure Program Effectiveness

Details
Erscheinungsjahr: 2016
Fachbereich: Datenkommunikation, Netze & Mailboxen
Genre: Importe, Informatik
Rubrik: Naturwissenschaften & Technik
Medium: Taschenbuch
Inhalt: Einband - fest (Hardcover)
ISBN-13: 9780128020425
ISBN-10: 0128020423
Sprache: Englisch
Einband: Kartoniert / Broschiert
Autor: Andress, Jason
Leary, Mark
Hersteller: Elsevier Inc
Verantwortliche Person für die EU: Libri GmbH, Europaallee 1, D-36244 Bad Hersfeld, gpsr@libri.de
Maße: 233 x 189 x 17 mm
Von/Mit: Jason Andress (u. a.)
Erscheinungsdatum: 04.11.2016
Gewicht: 0,442 kg
Artikel-ID: 131313367