相關主題
商品描述
Create appropriate, security-focused business propositions that consider the balance between cost, risk, and usability, while starting your journey to become an information security manager. Covering a wealth of information that explains exactly how the industry works today, this book focuses on how you can set up an effective information security practice, hire the right people, and strike the best balance between security controls, costs, and risks.
Practical Information Security Management provides a wealth of practical advice for anyone responsible for information security management in the workplace, focusing on the ‘how’ rather than the ‘what’. Together we’ll cut through the policies, regulations, and standards to expose the real inner workings of what makes a security management program effective, covering the full gamut of subject matter pertaining to security management: organizational structures, security architectures, technical controls, governance frameworks, and operational security.
This book was not written to help you pass your CISSP, CISM, or CISMP or become a PCI-DSS auditor. It won’t help you build an ISO 27001 or COBIT-compliant security management system, and it won’t help you become an ethical hacker or digital forensics investigator – there are many excellent books on the market that cover these subjects in detail. Instead, this is a practical book that offers years of real-world experience in helping you focus on the getting the job done.
What You Will Learn
Learn the practical aspects of being an effective information security manager
- Strike the right balance between cost and risk
Take security policies and standards and make them work in reality
- Leverage complex security functions, such as Digital Forensics, Incident Response and Security Architecture
Who This Book Is For
商品描述(中文翻譯)
創建適當的以安全為重點的商業提案,考慮成本、風險和可用性之間的平衡,開始您成為資訊安全經理的旅程。本書涵蓋了大量資訊,詳細解釋了當今行業的運作方式,重點在於如何建立有效的資訊安全實踐、聘用合適的人才,以及在安全控制、成本和風險之間達成最佳平衡。
實用資訊安全管理為任何負責工作場所資訊安全管理的人提供了豐富的實用建議,重點在於「如何」而非「什麼」。我們將一起穿透政策、法規和標準,揭示使安全管理計劃有效的真正內部運作,涵蓋與安全管理相關的所有主題:組織結構、安全架構、技術控制、治理框架和操作安全。
本書並不是為了幫助您通過CISSP、CISM或CISMP考試,或成為PCI-DSS審核員。它不會幫助您建立符合ISO 27001或COBIT的安全管理系統,也不會幫助您成為道德駭客或數位取證調查員——市場上有許多優秀的書籍詳細涵蓋這些主題。相反,這是一本實用的書,提供多年現實世界的經驗,幫助您專注於完成工作。
您將學到什麼
學習成為有效資訊安全經理的實用方面
- 在成本和風險之間達成正確的平衡
將安全政策和標準付諸實踐
利用複雜的安全功能,如數位取證、事件響應和安全架構
本書適合誰