Information Security Policy Development for Compliance: ISO/IEC 27001, NIST SP 800-53, HIPAA Standard, PCI DSS V2.0, and AUP V5.0 (Hardcover)
暫譯: 資訊安全政策開發與合規:ISO/IEC 27001、NIST SP 800-53、HIPAA 標準、PCI DSS V2.0 及 AUP V5.0 (精裝版)

Barry L. Williams

  • 出版商: Auerbach Publication
  • 出版日期: 2013-03-22
  • 售價: $2,980
  • 貴賓價: 9.5$2,831
  • 語言: 英文
  • 頁數: 152
  • 裝訂: Hardcover
  • ISBN: 1466580585
  • ISBN-13: 9781466580589
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

買這商品的人也買了...

商品描述

Although compliance standards can be helpful guides to writing comprehensive security policies, many of the standards state the same requirements in slightly different ways. Information Security Policy Development for Compliance: ISO/IEC 27001, NIST SP 800-53, HIPAA Standard, PCI DSS V2.0, and AUP V5.0 provides a simplified way to write policies that meet the major regulatory requirements, without having to manually look up each and every control.

Explaining how to write policy statements that address multiple compliance standards and regulatory requirements, the book will help readers elicit management opinions on information security and document the formal and informal procedures currently in place. Topics covered include:

  • Entity-level policies and procedures
  • Access-control policies and procedures
  • Change control and change management
  • System information integrity and monitoring
  • System services acquisition and protection
  • Informational asset management
  • Continuity of operations

The book supplies you with the tools to use the full range of compliance standards as guides for writing policies that meet the security needs of your organization. Detailing a methodology to facilitate the elicitation process, it asks pointed questions to help you obtain the information needed to write relevant policies. More importantly, this methodology can help you identify the weaknesses and vulnerabilities that exist in your organization.

A valuable resource for policy writers who must meet multiple compliance standards, this guidebook is also available in eBook format. The eBook version includes hyperlinks beside each statement that explain what the various standards say about each topic and provide time-saving guidance in determining what your policy should include.

商品描述(中文翻譯)

雖然合規標準可以作為撰寫全面安全政策的有用指導,但許多標準以略有不同的方式陳述相同的要求。《合規性的信息安全政策開發:ISO/IEC 27001、NIST SP 800-53、HIPAA標準、PCI DSS V2.0和AUP V5.0》提供了一種簡化的方法來撰寫符合主要法規要求的政策,而無需手動查找每一項控制措施。

本書解釋了如何撰寫針對多個合規標準和法規要求的政策聲明,幫助讀者引導管理層對信息安全的意見,並記錄當前的正式和非正式程序。涵蓋的主題包括:

- 實體層級的政策和程序
- 存取控制政策和程序
- 變更控制和變更管理
- 系統信息完整性和監控
- 系統服務的獲取和保護
- 信息資產管理
- 營運持續性

本書為您提供了使用全範圍合規標準作為撰寫符合您組織安全需求的政策指導的工具。詳細說明了一種促進引導過程的方法,並提出尖銳問題以幫助您獲取撰寫相關政策所需的信息。更重要的是,這種方法可以幫助您識別組織中存在的弱點和漏洞。

這本對於必須滿足多個合規標準的政策撰寫者來說是寶貴的資源,該指南也提供電子書格式。電子書版本在每個聲明旁邊包含超連結,解釋各種標準對每個主題的說明,並提供節省時間的指導,以確定您的政策應該包含什麼。