IT Asset Management: Financial Services NIST SP 1800-5: Practice Guide (Draft Jan 2016)
暫譯: IT資產管理:金融服務 NIST SP 1800-5:實務指南(草稿 2016年1月)

National Instituteof Standards

  • 出版商: CreateSpace Independ
  • 出版日期: 2017-06-01
  • 售價: $1,470
  • 貴賓價: 9.5$1,397
  • 語言: 英文
  • 頁數: 60
  • 裝訂: Paperback
  • ISBN: 1547103469
  • ISBN-13: 9781547103461
  • 無法訂購

商品描述

Draft - Jan 2016 Large financial services organizations employ tens or hundreds of thousands of individuals. At this scale, the technology base required to ensure smooth business operations (including computers, mobile devices, operating systems, applications, data, and network resources) is massive. To effectively manage, use, and secure each of those assets, you need to know their locations and functions. While physical assets can be labeled with bar codes and tracked in a database, this approach does not answer questions such as “What operating systems are our laptops running?” and “Which devices are vulnerable to the latest threat?” Computer security professionals in the financial services sector are challenged by the vast diversity of hardware and software they attempt to track, and by a lack of centralized control: A large financial services organization can include subsidiaries, branches, third-party partners, contractors, as well as temporary workers and guests. This complexity makes it difficult to assess vulnerabilities or to respond quickly to threats, and accurately assess risk in the first place (by pinpointing the most valuable assets).

This public domain material was printed by 4th Watch Cyber Books. 4th Watch is not affiliated with the National Institute of Standards. 4th Watch books use high-quality 8 ½ by 11 inch paper, and are tightly bound. Most are printed in full color, that’s why they cost so much.

For more NIST titles, visit: cybah.webplus.net/index.html Partial list below:


NIST SP 800-12 Rev 1 An Introduction to Information Security

NIST SP 800-18 Developing Security Plans for Federal Information Systems

NIST SP 800-30 Guide for Conducting Risk Assessments

NIST SP 800-32 Public Key Technology and the Federal PKI Infrastructure

NIST SP 800-34 Contingency Planning Guide for Federal Information Systems

NIST SP 800-37 Applying Risk Management Framework to Federal Information

NIST SP 800-39 Managing Information Security Risk

NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations

NIST SP 800-53A R4 Assessing Security and Privacy Controls

NIST SP 800-57 Recommendation for Key Management

NIST SP 800-61 Computer Security Incident Handling Guide

NIST SP 800-82r2 Guide to Industrial Control Systems (ICS) Security

NIST SP 800-95 Guide to Secure Web Services

NIST SP 800-121 Guide to Bluetooth Security

NIST SP 800-137 Information Security Continuous Monitoring (ISCM)

NIST SP 800-160 Systems Security Engineering

NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems

NIST SP 800-177 Trustworthy Email

NIST SP 800-184 Guide for Cybersecurity Event Recovery

NIST SP 800-190 Application Container Security Guide

NIST SP 800-193 Platform Firmware Resiliency Guidelines

NIST SP 1800-1 Securing Electronic Health Records on Mobile Devices

NIST SP 1800-2 Identity and Access Management for Electric Utilities

NIST SP 1800-5 IT Asset Management: Financial Services

NIST SP 1800-6 Domain Name Systems-Based Electronic Mail Security

NIST SP 1800-7 Situational Awareness for Electric Utilities

NIST SP 1800-8: Securing Wireless Infusion Pumps

NISTIR 8011 Automation Support for Security Control Assessments

NISTIR 8170 The Cybersecurity Framework Cybersecurity Framework Manufacturing Profile

NIST Framework for Improving Critical Infrastructure Cybersecurity

NISTIR 8062 Introduction to Privacy Engineering and Risk Management in Federal Systems

商品描述(中文翻譯)

草稿 - 2016年1月 大型金融服務組織雇用數萬或數十萬名員工。在這樣的規模下,確保業務運營順利所需的技術基礎(包括計算機、移動設備、操作系統、應用程序、數據和網絡資源)是龐大的。要有效管理、使用和保護這些資產,您需要了解它們的位置和功能。雖然實體資產可以用條形碼標記並在數據庫中跟蹤,但這種方法無法回答“我們的筆記本電腦運行的是什麼操作系統?”和“哪些設備容易受到最新威脅?”等問題。金融服務行業的計算機安全專業人員面臨著他們試圖跟蹤的硬體和軟體的巨大多樣性,以及缺乏集中控制的挑戰:一家大型金融服務組織可能包括子公司、分支機構、第三方合作夥伴、承包商,以及臨時工和訪客。這種複雜性使得評估漏洞或快速應對威脅變得困難,並且在第一時間準確評估風險(通過確定最有價值的資產)也變得困難。

這份公共領域材料由4th Watch Cyber Books印刷。4th Watch與國家標準協會無關。4th Watch的書籍使用高品質的8½ x 11英寸紙張,並且裝訂緊密。大多數書籍以全彩印刷,因此價格較高。

欲了解更多NIST書籍,請訪問:cybah.webplus.net/index.html 部分書籍列表如下:

NIST SP 800-12 Rev 1 信息安全簡介

NIST SP 800-18 為聯邦信息系統制定安全計劃

NIST SP 800-30 風險評估指南

NIST SP 800-32 公鑰技術與聯邦PKI基礎設施

NIST SP 800-34 聯邦信息系統應急計劃指南

NIST SP 800-37 將風險管理框架應用於聯邦信息

NIST SP 800-39 管理信息安全風險

NIST SP 800-53 Rev 4 聯邦信息系統和組織的安全與隱私控制

NIST SP 800-53A R4 評估安全與隱私控制

NIST SP 800-57 密鑰管理建議

NIST SP 800-61 計算機安全事件處理指南

NIST SP 800-82r2 工業控制系統(ICS)安全指南

NIST SP 800-95 安全網絡服務指南

NIST SP 800-121 藍牙安全指南

NIST SP 800-137 信息安全持續監控(ISCM)

NIST SP 800-160 系統安全工程

NIST SP 800-171 在非聯邦系統中保護受控未分類信息

NIST SP 800-177 可信電子郵件

NIST SP 800-184 網絡安全事件恢復指南

NIST SP 800-190 應用容器安全指南

NIST SP 800-193 平台固件韌性指南

NIST SP 1800-1 在移動設備上保護電子健康記錄

NIST SP 1800-2 電力公用事業的身份和訪問管理

NIST SP 1800-5 IT資產管理:金融服務

NIST SP 1800-6 基於域名系統的電子郵件安全

NIST SP 1800-7 電力公用事業的情境意識

NIST SP 1800-8:保護無線輸液泵

NISTIR 8011 安全控制評估的自動化支持

NISTIR 8170 網絡安全框架 網絡安全框架製造業概況

NIST改善關鍵基礎設施網絡安全的框架

NISTIR 8062 聯邦系統中的隱私工程和風險管理簡介