Risk Management Framework: A Lab-Based Approach to Securing Information Systems (Paperback)
暫譯: 風險管理框架:基於實驗室的方法來保護資訊系統 (平裝本)

James Broad

  • 出版商: Syngress Media
  • 出版日期: 2013-07-22
  • 定價: $2,030
  • 售價: 8.5$1,726
  • 語言: 英文
  • 頁數: 316
  • 裝訂: Paperback
  • ISBN: 1597499951
  • ISBN-13: 9781597499958
  • 相關分類: 資訊安全Information-management
  • 立即出貨 (庫存 < 4)

商品描述

The RMF allows an organization to develop an organization-wide risk framework that reduces the resources required to authorize a systems operation. Use of the RMF will help organizations maintain compliance with not only FISMA and OMB requirements but can also be tailored to meet other compliance requirements such as Payment Card Industry (PCI) or Sarbanes Oxley (SOX). With the publishing of NIST SP 800-37 in 2010 and the move of the Intelligence Community and Department of Defense to modified versions of this process, clear implementation guidance is needed to help individuals correctly implement this process. No other publication covers this topic in the detail provided in this book or provides hands-on exercises that will enforce the topics. Examples in the book follow a fictitious organization through the RMF, allowing the reader to follow the development of proper compliance measures. Templates provided in the book allow readers to quickly implement the RMF in their organization. The need for this book continues to expand as government and non-governmental organizations build their security programs around the RMF. The companion website provides access to all of the documents, templates and examples needed to not only understand the RMF but also implement this process in the reader's own organization.

. A comprehensive case study from initiation to decommission and disposal

. Detailed explanations of the complete RMF process and its linkage to the SDLC

. Hands on exercises to reinforce topics

. Complete linkage of the RMF to all applicable laws, regulations and publications as never seen before

商品描述(中文翻譯)

RMF(風險管理框架)允許組織開發一個全組織的風險框架,從而減少授權系統運作所需的資源。使用RMF將幫助組織維持對FISMA(聯邦資訊安全管理法)和OMB(行政管理預算辦公室)要求的合規性,並且可以根據其他合規要求進行調整,例如支付卡產業(PCI)或薩班斯-奧克斯利法案(SOX)。隨著2010年NIST SP 800-37的發布,以及情報社群和國防部轉向此過程的修改版本,迫切需要清晰的實施指導,以幫助個人正確實施此過程。沒有其他出版物能像本書一樣詳細地涵蓋此主題,或提供能夠強化主題的實作練習。本書中的範例通過一個虛構的組織來展示RMF,讓讀者能夠跟隨合規措施的發展。本書提供的範本使讀者能夠快速在其組織中實施RMF。隨著政府和非政府組織圍繞RMF建立其安全計劃,對本書的需求持續擴大。配套網站提供所有文件、範本和範例的訪問,這些資料不僅有助於理解RMF,還能在讀者自己的組織中實施此過程。

- 從啟動到退役和處置的全面案例研究
- 完整RMF過程的詳細解釋及其與SDLC(系統開發生命週期)的聯繫
- 實作練習以強化主題
- RMF與所有適用法律、法規和出版物的完整聯繫,前所未見

最後瀏覽商品 (16)