Practical Risk Management for the CIO (Hardcover)
暫譯: CIO的實用風險管理 (精裝版)
Mark Scherling
- 出版商: Auerbach Publication
- 出版日期: 2011-04-25
- 售價: $2,680
- 貴賓價: 9.5 折 $2,546
- 語言: 英文
- 頁數: 399
- 裝訂: Hardcover
- ISBN: 1439856532
- ISBN-13: 9781439856536
-
相關分類:
管理與領導 Management-leadership、資訊安全、Information-management
立即出貨 (庫存=1)
商品描述
The growing complexity of today’s interconnected systems has not only increased the need for improved information security, but also helped to move information from the IT backroom to the executive boardroom as a strategic asset. And, just like the tip of an iceberg is all you see until you run into it, the risks to your information are mostly invisible until disaster strikes.
Detailing procedures to help your team perform better risk assessments and aggregate results into more meaningful metrics, Practical Risk Management for the CIO approaches information risk management through improvements to information management and information security. It provides easy-to-follow guidance on how to effectively manage the flow of information and incorporate both service delivery and reliability.
- Explains why every CIO should be managing his or her information differently
- Provides time-tested risk ranking strategies
- Considers information security strategy standards such as NIST, FISMA, PCI, SP 800, & ISO 17799
- Supplies steps for managing: information flow, classification, controlled vocabularies, life cycle, and data leakage
- Describes how to put it all together into a complete information risk management framework
Information is one of your most valuable assets. If you aren’t on the constant lookout for better ways to manage it, your organization will inevitably suffer. Clarifying common misunderstandings about the risks in cyberspace, this book provides the foundation required to make more informed decisions and effectively manage, protect, and deliver information to your organization and its constituents.
商品描述(中文翻譯)
隨著當今互聯系統的日益複雜,不僅增加了對改善資訊安全的需求,也促使資訊從IT後台轉移到高層決策會議,成為一項戰略資產。而且,就像冰山的尖端在你撞上它之前你什麼都看不見一樣,對你資訊的風險在災難發生之前大多是隱形的。
《CIO的實用風險管理》詳細說明了幫助你的團隊進行更好風險評估的程序,並將結果匯總成更有意義的指標,通過改善資訊管理和資訊安全來處理資訊風險管理。它提供了易於遵循的指導,說明如何有效管理資訊流並結合服務交付和可靠性。
- 解釋為什麼每位CIO應該以不同的方式管理其資訊
- 提供經過時間考驗的風險排名策略
- 考慮資訊安全策略標準,如NIST、FISMA、PCI、SP 800和ISO 17799
- 提供管理資訊流、分類、受控詞彙、生命週期和數據洩漏的步驟
- 描述如何將所有內容整合成一個完整的資訊風險管理框架
資訊是你最有價值的資產之一。如果你不持續尋找更好的管理方式,你的組織將不可避免地受到影響。本書澄清了有關網路空間風險的常見誤解,提供了做出更明智決策所需的基礎,並有效管理、保護和交付資訊給你的組織及其相關方。