Security Program and Policies: Principles and Practices, 2/e (Paperback)
暫譯: 安全計畫與政策:原則與實務,第2版 (平裝本)

Sari Greene

買這商品的人也買了...

相關主題

商品描述

Everything you need to know about information security programs and policies, in one book

  • Clearly explains all facets of InfoSec program and policy planning, development, deployment, and management
  • Thoroughly updated for today’s challenges, laws, regulations, and best practices
  • The perfect resource for anyone pursuing an information security management career

 

In today’s dangerous world, failures in information security can be catastrophic. Organizations must protect themselves. Protection begins with comprehensive, realistic policies. This up-to-date guide will help you create, deploy, and manage them.

Complete and easy to understand, it explains key concepts and techniques through real-life examples. You’ll master modern information security regulations and frameworks, and learn specific best-practice policies for key industry sectors, including finance, healthcare, online commerce, and small business.

 

If you understand basic information security, you’re ready to succeed with this book. You’ll find projects, questions, exercises, examples, links to valuable easy-to-adapt information security policies...everything you need to implement a successful information security program.

 

Sari Stern Greene, CISSP, CRISC, CISM, NSA/IAM, is an information security practitioner, author, and entrepreneur. She is passionate about the importance of protecting information and critical infrastructure. Sari founded Sage Data Security in 2002 and has amassed thousands of hours in the field working with a spectrum of technical, operational, and management personnel, as  well as boards of directors, regulators, and service providers. Her first text was Tools and Techniques for Securing Microsoft Networks, commissioned by Microsoft to train its partner channel, which was soon followed by the first edition of Security Policies and Procedures: Principles and Practices. She is actively involved in the security community, and speaks regularly at security conferences and workshops. She has been quoted in The New York Times, Wall Street Journal, and on CNN, and CNBC. Since 2010, Sari has served as the chair of the annual Cybercrime Symposium.

 

Learn how to

·         Establish program objectives, elements, domains, and governance

·         Understand policies, standards, procedures, guidelines, and plans—and the differences among them

·         Write policies in “plain language,” with the right level of detail

·         Apply the Confidentiality, Integrity & Availability (CIA) security model

·         Use NIST resources and ISO/IEC 27000-series standards

·         Align security with business strategy

·         Define, inventory, and classify your information and systems

·         Systematically identify, prioritize, and manage InfoSec risks

·         Reduce “people-related” risks with role-based Security Education, Awareness, and Training (SETA)

·         Implement effective physical, environmental, communications, and operational security

·         Effectively manage access control

·         Secure the entire system development lifecycle

·         Respond to incidents and ensure continuity of operations

·         Comply with laws and regulations, including GLBA, HIPAA/HITECH, FISMA, state data security and notification rules, and PCI DSS

 

商品描述(中文翻譯)

您需要了解的有關資訊安全計畫和政策的所有內容,盡在一本書中


  • 清楚解釋資訊安全計畫和政策的規劃、開發、部署和管理的各個方面

  • 針對當前的挑戰、法律、法規和最佳實踐進行全面更新

  • 對於任何追求資訊安全管理職業的人來說,這是完美的資源

 

在當今危險的世界中,資訊安全的失敗可能是災難性的。組織必須保護自己。保護始於全面且現實的政策。本指南將幫助您創建、部署和管理這些政策。

內容完整且易於理解,通過實際案例解釋關鍵概念和技術。您將掌握現代資訊安全法規和框架,並學習針對金融、醫療保健、在線商務和小型企業等關鍵行業的具體最佳實踐政策。

 

如果您了解基本的資訊安全,您就已經準備好成功使用這本書。您將找到項目、問題、練習、範例、可輕鬆調整的資訊安全政策的有價值鏈接……一切您需要的都在這裡,以實施成功的資訊安全計畫。

 

Sari Stern Greene,CISSP、CRISC、CISM、NSA/IAM,是一位資訊安全從業者、作者和企業家。她對保護資訊和關鍵基礎設施的重要性充滿熱情。Sari於2002年創立了Sage Data Security,並在該領域積累了數千小時的工作經驗,與各種技術、運營和管理人員,以及董事會、監管機構和服務提供商合作。她的第一本書是Tools and Techniques for Securing Microsoft Networks,由微軟委託用於培訓其合作夥伴渠道,隨後不久便出版了Security Policies and Procedures: Principles and Practices的第一版。她積極參與安全社區,並定期在安全會議和研討會上發言。她曾在The New York TimesWall Street Journal、CNN和CNBC上被引用。自2010年以來,Sari擔任年度網路犯罪研討會的主席。

 

學習如何

·         建立計畫目標、要素、領域和治理

·         理解政策、標準、程序、指導方針和計畫——以及它們之間的差異

·         用「簡單語言」撰寫政策,並具備適當的細節程度

·         應用機密性、完整性和可用性(CIA)安全模型

·         使用NIST資源和ISO/IEC 27000系列標準

·         將安全與商業策略對齊

·         定義、清點和分類您的資訊和系統

·         系統性地識別、優先排序和管理資訊安全風險

·         通過基於角色的安全教育、意識和培訓(SETA)減少「人員相關」風險

·         實施有效的物理、環境、通信和操作安全

·         有效管理存取控制

·         確保整個系統開發生命週期的安全

·         對事件做出反應並確保業務持續性

·         遵守法律和法規,包括GLBA、HIPAA/HITECH、FISMA、州數據安全和通知規則,以及PCI DSS