Security Risk Management - The Driving Force for Operational Resilience: The Firefighting Paradox
Seaman, Jim, Gioia, Michael
相關主題
商品描述
The importance of businesses being Operationally Resilient is becoming increasingly more important and a driving force behind whether an organization can ensure that their valuable business operations can 'Bounce Back' from, or manage to evade, impactful occurrences is the Security Risk Management Capabilities.
In this book, we change the perspective on an organization's operational resilience capabilities so that it changes from being a reactive (tick box) approach to being proactive. The perspectives of every chapter in this book are with a focus on risk profiles and how your business can reduce these profiles using effective mitigation measures.
The book is divided into two sections:
1. Security Risk Management.
All the components of Security Risk Management contribute to your organization's Operational Resilience capabilities, to help reduce your risks.
Reduce the Probability/Likelihood.
2. Survive to Operate.
In the event that your SRM capabilities fail your organization, these are the components that are needed to allow you to quickly 'Bounce Back'.
Reduce the Severity/Impact.
Rather than looking at this from an Operational Resilience compliance capabilities aspect, we have written these to be agnostic of any specific Operational Resilience Framework (e.g., CERT RMM, ISO 22316, SP 800-160 Vol. 2 Rev. 1, etc.), with the idea of looking at Operational Resilience through a Risk Management lens instead.
This book is not intended to replace these numerous Operational Resilience standards/frameworks but, rather, has been designed to complement them by getting you to appreciate their value in helping to identify and mitigate your Operational Resilience risks.
Unlike the Cyber Security or Information Security domains, Operational Resilience looks at the risks from a business-orientated view, so that anything that might disrupt your essential business operations are risk assessed and appropriate countermeasures identified and applied.
Consequently, this book is not limited to cyber-attacks or the loss of sensitive data but, instead, looks at things from a business holistic viewpoint.
商品描述(中文翻譯)
企業具備運營韌性的重要性日益增加,而組織能否確保其有價值的業務運營能夠從具有影響力的事件中「彈回」或避免受到影響,取決於安全風險管理能力。
在本書中,我們改變了對組織運營韌性能力的觀點,使其從一種被動(勾選方塊)的方法轉變為主動的方法。本書的每一章都以風險概況為重點,介紹了如何使用有效的緩解措施來降低業務的風險概況。
本書分為兩個部分:
1. 安全風險管理。
安全風險管理的所有組成部分都有助於您組織的運營韌性能力,以幫助降低風險。
降低概率/可能性。
2. 生存運營。
如果您的安全風險管理能力無法應對組織的需求,這些組成部分將使您能夠快速「彈回」。
降低嚴重性/影響。
我們撰寫這些章節時,並不是從運營韌性合規能力的角度出發,而是從風險管理的角度來看待運營韌性,不受任何特定的運營韌性框架(例如CERT RMM、ISO 22316、SP 800-160 Vol. 2 Rev. 1等)的影響。
本書並不意圖取代這些眾多的運營韌性標準/框架,而是通過讓您欣賞它們在幫助識別和緩解運營韌性風險方面的價值,來補充它們。
與網絡安全或信息安全領域不同,運營韌性從業務的角度來看待風險,因此對可能干擾您的基本業務運營的任何事物進行風險評估,並確定並應用適當的對策。
因此,本書不僅局限於網絡攻擊或敏感數據的損失,而是從業務整體的角度來看待問題。
作者簡介
Jim Seaman honed his skills and craft during a 22-year career in the Royal Air Force Police, with the final decade being employed on Counter Intelligence, Computer Security, Counter Terrorism and Risk Management duties. On completion of his 22-years of military service, he sought the new challenge of transferring his specialist skills and knowledge across to the corporate sector. In the decade since transitioning across to the corporate environment, he has fulfilled roles within Payment Card Industry Data Security Standard (PCI D)SS compliance, data protection, information security, industrial systems security and risk management. In the past few years, he has sought to further develop his knowledge and to rise to the challenge of authoring two books, one on the subject of PCI DSS (published May 2020) and the other on Protective Security (published Apr 2021).
Michael Gioia is an information security leader with over 18 years of experience delivering security solutions across several industries. He has served as an officer in the United States Air Force and worked in higher education, the Department of Defense, retail food services, and security consulting. He has performed most of his information security work within higher education, currently, as the Chief Information Security Officer (CISO) for Babson College and formerly as the Information Security Officer (ISO) at Eastern Illinois University, Rose-Hulman Institute of Technology, and Bentley University. He retains various professional certifications that include a Certified Information Security Manager (CISM) and Certified Data Privacy Solutions Engineer (CDPSE) from ISACA, Certified Information System Security Professional (CISSP) from ISC2, GIAC Security Leadership Certification (GSLC) from SANS, and Payment Card Industry Professional (PCIP) from the PCI Security Standards Council.
作者簡介(中文翻譯)
Jim Seaman在皇家空軍警察部隊的22年職業生涯中磨練了他的技能和專業知識,其中最後十年從事反情報、電腦安全、反恐和風險管理工作。在完成22年的軍事服務後,他尋求將他的專業技能和知識轉移到企業界的新挑戰。在轉向企業環境的十年中,他在支付卡行業數據安全標準(PCI DSS)合規、數據保護、信息安全、工業系統安全和風險管理方面擔任過多個職位。在過去幾年中,他努力進一步發展自己的知識,並迎接撰寫兩本書的挑戰,一本關於PCI DSS的(於2020年5月出版),另一本關於保護安全的(於2021年4月出版)。
Michael Gioia是一位資訊安全領導者,擁有超過18年的經驗,在多個行業提供安全解決方案。他曾在美國空軍擔任軍官,並在高等教育、國防部、零售食品服務和安全咨詢等領域工作。他在高等教育領域進行了大部分的資訊安全工作,目前擔任巴布森學院的首席資訊安全官(CISO),曾在Eastern Illinois University、Rose-Hulman Institute of Technology和Bentley University擔任資訊安全官(ISO)。他擁有多種專業認證,包括來自ISACA的認證資訊安全經理(CISM)和認證數據隱私解決方案工程師(CDPSE),來自ISC2的認證資訊系統安全專業人員(CISSP),來自SANS的GIAC安全領導認證(GSLC),以及來自PCI安全標準委員會的支付卡行業專業人員(PCIP)。