Supply Chain Risk Management: Applying Secure Acquisition Principles to Ensure a Trusted Technology Product (Internal Audit and IT Audit)
暫譯: 供應鏈風險管理:應用安全採購原則以確保可信的技術產品(內部審計與IT審計)

Ken Sigler, Dan Shoemaker, Anne Kohnke

  • 出版商: CRC
  • 出版日期: 2017-11-07
  • 售價: $6,720
  • 貴賓價: 9.5$6,384
  • 語言: 英文
  • 頁數: 302
  • 裝訂: Hardcover
  • ISBN: 1138197351
  • ISBN-13: 9781138197350
  • 海外代購書籍(需單獨結帳)

商品描述

The book presents the concepts of ICT supply chain risk management from the perspective of NIST IR 800-161. It covers how to create a verifiable audit-based control structure to ensure comprehensive security for acquired products. It explains how to establish systematic control over the supply chain and how to build auditable trust into the products and services acquired by the organization. It details a capability maturity development process that will install an increasingly competent process and an attendant set of activities and tasks within the technology acquisition process. It defines a complete and correct set of processes, activities, tasks and monitoring and reporting systems.

商品描述(中文翻譯)

本書從 NIST IR 800-161 的角度介紹了資訊與通信技術(ICT)供應鏈風險管理的概念。內容涵蓋如何建立可驗證的基於審計的控制結構,以確保所獲得產品的全面安全。它解釋了如何對供應鏈建立系統化的控制,以及如何在組織所獲得的產品和服務中建立可審計的信任。書中詳細說明了一個能力成熟度發展過程,該過程將在技術獲取過程中安裝一個日益成熟的流程及相關的活動和任務。它定義了一套完整且正確的流程、活動、任務以及監控和報告系統。