Information Security Evaluation: A Holistic Approach from a Business Perspective (Hardcover)
暫譯: 資訊安全評估:從商業角度的整體方法 (精裝版)
Igli Tashi, Solange Ghernaouti-Helie
- 出版商: EFPL Press
- 出版日期: 2021-04-15
- 售價: $3,150
- 貴賓價: 9.5 折 $2,993
- 語言: 英文
- 頁數: 300
- 裝訂: Hardcover
- ISBN: 143987915X
- ISBN-13: 9781439879153
-
相關分類:
資訊安全
立即出貨 (庫存=1)
相關主題
商品描述
Information systems have become a critical element of every organization’s structure. A malfunction of the information and communication technology (ICT) infrastructure can paralyze the whole organization and have disastrous consequences at many levels. On the other hand, modern businesses and organizations collaborate increasingly with companies, customers, and other stakeholders by technological means. This emphasizes the need for a reliable and secure ICT infrastructure for companies whose principal asset and added value is information.
Information Security Evaluation: A Holistic Approach from a Business Perspective proposes a global and systemic multidimensional integrated approach to the holistic evaluation of the information security posture of an organization. The Information Security Assurance Assessment Model (ISAAM) presented in this book is based on, and integrates, a number of information security best practices, standards, methodologies and sources of research expertise, in order to provide a generic model that can be implemented in organizations of all kinds as part of their efforts towards better governing their information security.
This approach will contribute to improving the identification of security requirements, measures and controls. At the same time, it provides a means of enhancing the recognition of evidence related to the assurance, quality and maturity levels of the organization’s security posture, thus driving improved security effectiveness and efficiency. The value added by this evaluation model is that it is easy to implement and operate and that through a coherent system of evaluation it addresses concrete needs in terms of reliance on an efficient and dynamic evaluation tool.
商品描述(中文翻譯)
資訊系統已成為每個組織結構中的關鍵元素。資訊與通信技術(ICT)基礎設施的故障可能會癱瘓整個組織,並在多個層面上造成災難性的後果。另一方面,現代企業和組織越來越多地通過技術手段與公司、客戶和其他利益相關者進行合作。這強調了對於以資訊為主要資產和附加價值的公司來說,可靠且安全的ICT基礎設施的需求。
《資訊安全評估:從商業角度的整體方法》提出了一種全球性和系統性的多維整合方法,用於全面評估組織的資訊安全狀態。本書中提出的資訊安全保證評估模型(ISAAM)基於多項資訊安全最佳實踐、標準、方法論和研究專業知識的整合,旨在提供一個通用模型,該模型可以在各類組織中實施,以促進其在資訊安全治理方面的努力。
這種方法將有助於改善安全需求、措施和控制的識別。同時,它提供了一種增強對與組織安全狀態的保證、質量和成熟度水平相關的證據識別的手段,從而推動安全效能和效率的提升。這個評估模型所增加的價值在於其易於實施和操作,並且通過一個連貫的評估系統,它滿足了對於依賴高效且動態評估工具的具體需求。