Executive's Cybersecurity Program Handbook: A comprehensive guide to building and operationalizing a complete cybersecurity program
暫譯: 高層網路安全計畫手冊:全面指南以建立和運營完整的網路安全計畫

Brown, Jason

  • 出版商: Packt Publishing
  • 出版日期: 2023-02-24
  • 售價: $1,860
  • 貴賓價: 9.5$1,767
  • 語言: 英文
  • 頁數: 232
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 180461923X
  • ISBN-13: 9781804619230
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Develop strategic plans for building cybersecurity programs and prepare your organization for compliance investigations and audits

Key Features

- Get started as a cybersecurity executive and design an infallible security program
- Perform assessments and build a strong risk management framework
- Promote the importance of security within the organization through awareness and training sessions

Book Description

Ransomware, phishing, and data breaches are major concerns affecting all organizations as a new cyber threat seems to emerge every day. making it paramount to protect the security of your organization and be prepared for potential cyberattacks. This book will ensure that you can build a reliable cybersecurity framework to keep your organization safe from cyberattacks.

This Executive’s Cybersecurity Program Handbook explains the importance of executive buy-in, mission, and vision statement of the main pillars of security program (governance, defence, people and innovation). You’ll explore the different types of cybersecurity frameworks, how they differ from one another, and how to pick the right framework to minimize cyber risk. As you advance, you’ll perform an assessment against the NIST Cybersecurity Framework, which will help you evaluate threats to your organization by identifying both internal and external vulnerabilities. Toward the end, you’ll learn the importance of standard cybersecurity policies, along with concepts of governance, risk, and compliance, and become well-equipped to build an effective incident response team.

By the end of this book, you’ll have gained a thorough understanding of how to build your security program from scratch as well as the importance of implementing administrative and technical security controls.

What you will learn

- Explore various cybersecurity frameworks such as NIST and ISO
- implement industry-standard cybersecurity policies and procedures effectively to minimize the risk of cyberattacks
- Find out how to hire the right talent for building a sound cybersecurity team structure
- Understand the difference between security awareness and training
- Explore the zero-trust concept and various firewalls to secure your environment
- Harden your operating system and server to enhance the security
- Perform scans to detect vulnerabilities in software

Who This Book Is For

This book is for you if you are a newly appointed security team manager, director, or C-suite executive who is in the transition stage or new to the information security field and willing to empower yourself with the required knowledge. As a Cybersecurity professional, you can use this book to deepen your knowledge and understand your organization's overall security posture. Basic knowledge of information security or governance, risk, and compliance is required.

商品描述(中文翻譯)

制定建立網路安全計畫的策略,並為您的組織準備合規調查和審計

主要特點

- 作為網路安全高管開始您的旅程,設計一個無懈可擊的安全計畫

- 進行評估並建立強大的風險管理框架

- 透過意識提升和訓練課程促進組織內部對安全的重要性

書籍描述

勒索病毒、釣魚攻擊和數據洩露是影響所有組織的主要問題,因為新的網路威脅似乎每天都在出現,因此保護組織的安全並為潛在的網路攻擊做好準備至關重要。本書將確保您能夠建立一個可靠的網路安全框架,以保護您的組織免受網路攻擊。

《高管網路安全計畫手冊》解釋了高管支持、使命和願景聲明在安全計畫主要支柱(治理、防禦、人員和創新)中的重要性。您將探索不同類型的網路安全框架,它們之間的差異,以及如何選擇合適的框架以最小化網路風險。隨著進展,您將根據NIST網路安全框架進行評估,這將幫助您通過識別內部和外部的脆弱性來評估對組織的威脅。在最後,您將了解標準網路安全政策的重要性,以及治理、風險和合規的概念,並為建立有效的事件響應團隊做好充分準備。

在本書結束時,您將全面了解如何從零開始建立您的安全計畫,以及實施行政和技術安全控制的重要性。

您將學到什麼

- 探索各種網路安全框架,如NIST和ISO

- 有效實施行業標準的網路安全政策和程序,以最小化網路攻擊的風險

- 瞭解如何招聘合適的人才以建立健全的網路安全團隊結構

- 理解安全意識與訓練之間的區別

- 探索零信任概念和各種防火牆以保護您的環境

- 加固您的操作系統和伺服器以增強安全性

- 執行掃描以檢測軟體中的脆弱性

本書適合誰

如果您是新任命的安全團隊經理、主任或C-suite高管,正處於過渡階段或對資訊安全領域不熟悉並希望增強所需知識,那麼本書適合您。作為一名網路安全專業人士,您可以利用本書深化您的知識,了解您組織的整體安全狀況。需要具備基本的資訊安全或治理、風險和合規知識。

目錄大綱

1. First 90 Days
2. Choosing the Right Cybersecurity Framework
3. Cybersecurity Strategic Planning Through the Assessment Process
4. Establishing Governance Through Policy
5. The Security Team
6. Risk Management
7. Incident Response
8. Security Awareness and Training
9. Network Security
10. Computer and Server Security
11. Securing Software Development Through DevSecOps
12. Testing Your Security and Building Metrics

目錄大綱(中文翻譯)

1. First 90 Days

2. Choosing the Right Cybersecurity Framework

3. Cybersecurity Strategic Planning Through the Assessment Process

4. Establishing Governance Through Policy

5. The Security Team

6. Risk Management

7. Incident Response

8. Security Awareness and Training

9. Network Security

10. Computer and Server Security

11. Securing Software Development Through DevSecOps

12. Testing Your Security and Building Metrics