Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement (Hardcover)
暫譯: 資訊安全管理指標:有效安全監控與測量的權威指南 (精裝版)

W. Krag Brotby CISM

  • 出版商: Auerbach Publication
  • 出版日期: 2009-03-01
  • 定價: $3,600
  • 售價: 5.0$1,800
  • 語言: 英文
  • 頁數: 200
  • 裝訂: Hardcover
  • ISBN: 1420052853
  • ISBN-13: 9781420052855
  • 相關分類: 資訊安全
  • 立即出貨(限量) (庫存=3)

買這商品的人也買了...

相關主題

商品描述

Spectacular security failures continue to dominate the headlines despite huge increases in security budgets and ever-more draconian regulations. The 20/20 hindsight of audits is no longer an effective solution to security weaknesses, and the necessity for real-time strategic metrics has never been more critical.

Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement offers a radical new approach for developing and implementing security metrics essential for supporting business activities and managing information risk. This work provides anyone with security and risk management responsibilities insight into these critical security questions:

  • How secure is my organization?
  • How much security is enough?
  • What are the most cost-effective security solutions?
  • How secure is my organization?
  • Solid metrics are the key to cost-effective information security – you can’t manage what you can’t measure

    This volume shows readers how to develop metrics that can be used across an organization to assure its information systems are functioning, secure, and supportive of the organization’s business objectives. It provides a comprehensive overview of security metrics, discusses the current state of metrics in use today, and looks at promising new developments. Later chapters explore ways to develop effective strategic and management metrics for information security governance, risk management, program implementation and management, and incident management and response.  

    The book ensures that every facet of security required by an organization is linked to business objectives, and provides metrics to measure it. Case studies effectively demonstrate specific ways that metrics can be implemented across an enterprise to maximize business benefit.

    With three decades of enterprise information security experience, author Krag Brotby presents a workable approach to developing and managing cost-effective enterprise information security.

    商品描述(中文翻譯)

    儘管安全預算大幅增加且規範日益嚴格,驚人的安全失敗事件仍然主導著新聞頭條。對於安全弱點的審計回顧已不再是有效的解決方案,實時戰略指標的必要性從未如此關鍵。

    《資訊安全管理指標:有效安全監控與測量的權威指南》提供了一種激進的新方法,用於開發和實施支持商業活動和管理資訊風險所必需的安全指標。本書為任何負責安全和風險管理的人提供了對這些關鍵安全問題的深入見解:

    - 我的組織有多安全?
    - 多少安全才算足夠?
    - 最具成本效益的安全解決方案是什麼?
    - 我的組織有多安全?

    穩健的指標是成本效益高的資訊安全的關鍵——你無法管理你無法測量的東西。

    本書向讀者展示如何開發可以在整個組織中使用的指標,以確保其資訊系統正常運作、安全且支持組織的商業目標。它提供了安全指標的全面概述,討論了當前使用的指標狀態,並探討了有前景的新發展。後面的章節探討了如何為資訊安全治理、風險管理、計畫實施與管理以及事件管理與響應開發有效的戰略和管理指標。

    本書確保組織所需的每一個安全面向都與商業目標相連結,並提供測量這些面向的指標。案例研究有效地展示了指標如何在企業中實施,以最大化商業利益。

    擁有三十年企業資訊安全經驗的作者Krag Brotby提出了一種可行的方法來開發和管理成本效益高的企業資訊安全。