Enterprise Architecture and Information Assurance: Developing a Secure Foundation (Hardcover)
暫譯: 企業架構與資訊保障:建立安全基礎 (精裝版)

James A. Scholz

  • 出版商: Auerbach Publication
  • 出版日期: 2013-07-29
  • 售價: $2,430
  • 貴賓價: 9.5$2,309
  • 語言: 英文
  • 頁數: 266
  • 裝訂: Hardcover
  • ISBN: 1439841594
  • ISBN-13: 9781439841594
  • 立即出貨 (庫存=1)

買這商品的人也買了...

商品描述

Securing against operational interruptions and the theft of your data is much too important to leave to chance. By planning for the worst, you can ensure your organization is prepared for the unexpected. Enterprise Architecture and Information Assurance: Developing a Secure Foundation explains how to design complex, highly available, and secure enterprise architectures that integrate the most critical aspects of your organization's business processes.

Filled with time-tested guidance, the book describes how to document and map the security policies and procedures needed to ensure cost-effective organizational and system security controls across your entire enterprise. It also demonstrates how to evaluate your network and business model to determine if they fit well together. The book’s comprehensive coverage includes:

  • Infrastructure security model components
  • Systems security categorization
  • Business impact analysis
  • Risk management and mitigation
  • Security configuration management
  • Contingency planning
  • Physical security
  • The certification and accreditation process

Facilitating the understanding you need to reduce and even mitigate security liabilities, the book provides sample rules of engagement, lists of NIST and FIPS references, and a sample certification statement. Coverage includes network and application vulnerability assessments, intrusion detection, penetration testing, incident response planning, risk mitigation audits/reviews, and business continuity and disaster recovery planning.

Reading this book will give you the reasoning behind why security is foremost. By following the procedures it outlines, you will gain an understanding of your infrastructure and what requires further attention.

商品描述(中文翻譯)

確保防範操作中斷和數據盜竊的重要性不容忽視。透過為最壞情況做準備,您可以確保您的組織能夠應對意外情況。《企業架構與資訊保障:建立安全基礎》解釋了如何設計複雜、高可用性且安全的企業架構,這些架構整合了您組織業務流程中最關鍵的方面。

本書充滿了經過時間考驗的指導,描述了如何記錄和繪製所需的安全政策和程序,以確保整個企業內的組織和系統安全控制具成本效益。它還展示了如何評估您的網絡和商業模型,以確定它們是否能夠良好契合。本書的全面內容包括:

- 基礎設施安全模型組件
- 系統安全分類
- 商業影響分析
- 風險管理與緩解
- 安全配置管理
- 應急計劃
- 實體安全
- 認證與認可過程

本書促進了您對減少甚至緩解安全責任所需理解的掌握,提供了參與規則範本、NIST 和 FIPS 參考列表,以及範本認證聲明。內容涵蓋網絡和應用程序漏洞評估、入侵檢測、滲透測試、事件響應計劃、風險緩解審計/評估,以及業務持續性和災難恢復計劃。

閱讀本書將使您了解為何安全是首要任務。遵循書中所列的程序,您將對您的基礎設施及其需要進一步關注的部分有更深入的理解。