Information Security : Design, Implementation, Measurement, and Compliance

個数:

Information Security : Design, Implementation, Measurement, and Compliance

  • 提携先の海外書籍取次会社に在庫がございます。通常3週間で発送いたします。
    重要ご説明事項
    1. 納期遅延や、ご入手不能となる場合が若干ございます。
    2. 複数冊ご注文の場合、分割発送となる場合がございます。
    3. 美品のご指定は承りかねます。
  • 【入荷遅延について】
    世界情勢の影響により、海外からお取り寄せとなる洋書・洋古書の入荷が、表示している標準的な納期よりも遅延する場合がございます。
    おそれいりますが、あらかじめご了承くださいますようお願い申し上げます。
  • ◆画像の表紙や帯等は実物とは異なる場合があります。
  • ◆ウェブストアでの洋書販売価格は、弊社店舗等での販売価格とは異なります。
    また、洋書販売価格は、ご注文確定時点での日本円価格となります。
    ご注文確定後に、同じ洋書の販売価格が変動しても、それは反映されません。
  • 製本 Hardcover:ハードカバー版/ページ数 260 p.
  • 言語 ENG
  • 商品コード 9780849370878
  • DDC分類 658.478

Full Description

Organizations rely on digital information today more than ever before. Unfortunately, that information is equally sought after by criminals. New security standards and regulations are being implemented to deal with these threats, but they are very broad and organizations require focused guidance to adapt the guidelines to their specific needs.

Fortunately, Information Security: Design, Implementation, Measurement, and Compliance outlines a complete roadmap to successful adaptation and implementation of a security program based on the ISO/IEC 17799:2005 (27002) Code of Practice for Information Security Management. The book first describes a risk assessment model, a detailed risk assessment methodology, and an information security evaluation process. Upon this foundation, the author presents a proposed security baseline for all organizations, an executive summary of the ISO/IEC 17799 standard, and a gap analysis exposing the differences between the recently rescinded version and the newly released version of the standard. Finally, he devotes individual chapters to each of the 11 control areas defined in the standard, covering systematically the 133 controls within the 39 control objectives.

Tim Layton's Information Security is a practical tool to help you understand the ISO/IEC 17799 standard and apply its principles within your organization's unique context.

Contents

EVALUATING AND MEASURING AN INFORMATION SECURITY PROGRAM. Information Security Risk Assessment Model (ISRAM™). Global Information Security Assessment Methodology (GISAM™). Developing an Information Security Evaluation (ISE™) Process. A Security Baseline. Background of the ISO/IEC 17799 Standard. ISO/IEC 17799:2005 Gap Analysis. ANALYSIS OF ISO/IEC 17799:2005 (27002) CONTROLS. Security Policy. Organization of Information Security. Asset Management. Human Resources Security. Physical and Environmental Security. Communications and Operations Management. Access Control. Information Systems Acquisition, Development, and Maintenance. Information Security Incident Management. Business Continuity Management. Compliance. Appendix A: ISO Standards Cited in ISO/IEC 17799:2005. Appendix B: General References. Index.