相關主題
商品描述
With monotonous regularity, headlines announce ever more spectacular failures of information security and mounting losses. The succession of corporate debacles and dramatic control failures in recent years underscores the necessity for information security to be tightly integrated into the fabric of every organization. The protection of an organization's most valuable asset information can no longer be relegated to low-level technical personnel, but must be considered an essential element of corporate governance that is critical to organizational success and survival.
Written by an industry expert, Information Security Governance is the first book-length treatment of this important topic, providing readers with a step-by-step approach to developing and managing an effective information security program. Beginning with a general overview of governance, the book covers:
-
The business case for information security
-
Defining roles and responsibilities
-
Developing strategic metrics
-
Determining information security outcomes
-
Setting security governance objectives
-
Establishing risk management objectives
-
Developing a cost-effective security strategy
-
A sample strategy development
-
The steps for implementing an effective strategy
-
Developing meaningful security program development metrics
-
Designing relevant information security management metrics
-
Defining incident management and response metrics
Complemented with action plans and sample policies that demonstrate to readers how to put these ideas into practice, Information Security Governance is indispensable reading for any professional who is involved in information security and assurance.
商品描述(中文翻譯)
有效資訊安全治理的日益迫切需求
隨著單調的規律,新聞標題不斷報導資訊安全的驚人失敗和不斷增加的損失。近年來一連串的企業災難和戲劇性的控制失敗凸顯了資訊安全必須緊密融入每個組織的運作中。保護組織最有價值的資產——資訊,已不再能夠僅僅交給低層的技術人員,而必須被視為企業治理的基本要素,對於組織的成功和生存至關重要。
《資訊安全治理》是由行業專家撰寫的,這是對這一重要主題的首部書籍,為讀者提供了一個逐步的方法來開發和管理有效的資訊安全計劃。書中首先提供了治理的一般概述,然後涵蓋了以下內容:
- 資訊安全的商業案例
- 定義角色和責任
- 開發戰略指標
- 確定資訊安全結果
- 設定安全治理目標
- 建立風險管理目標
- 開發具成本效益的安全策略
- 策略開發範例
- 實施有效策略的步驟
- 開發有意義的安全計劃發展指標
- 設計相關的資訊安全管理指標
- 定義事件管理和響應指標
《資訊安全治理》附有行動計劃和範本政策,向讀者展示如何將這些理念付諸實踐,是任何從事資訊安全和保障的專業人士必讀的書籍。