Picture of Information Security: Design, Implementation, Measurement, and Compliance

Information Security: Design, Implementation, Measurement, and Compliance

Timothy P. Layton

Auerbach Publications

July 2006

Hardcover, 264 pages

ISBN: 0849370876

Business Analyst Training IIBA endorsed
On-Site and On-Line Training Courses for Business Analysts

  • Contains a programmatic approach that applies to a business regardless of its size or type
  • Presents a process that allows firms to shape customized information security practices for their own requirements
  • Demonstrates how to conduct a risk assessment covering all controls and control objectives
  • Illustrates how to use data both qualitatively and quantitatively to meet the ISO/IEC 17799 standard
  • Provides a gap analysis between the first and second editions of the standard to simplify transition to the new one


Description
Organizations rely on digital information today more than ever before. Unfortunately, that information is equally sought after by criminals. New security standards and regulations are being implemented to deal with these threats, but they are very broad and organizations require focused guidance to adapt the guidelines to their specific needs.

Fortunately, Information Security: Design, Implementation, Measurement, and Compliance outlines a complete roadmap to successful adaptation and implementation of a security program based on the ISO/IEC 17799:2005 (27002) Code of Practice for Information Security Management. The book first describes a risk assessment model, a detailed risk assessment methodology, and an information security evaluation process. Upon this foundation, the author presents a proposed security baseline for all organizations, an executive summary of the ISO/IEC 17799 standard, and a gap analysis exposing the differences between the recently rescinded version and the newly released version of the standard. Finally, he devotes individual chapters to each of the 11 control areas defined in the standard, covering systematically the 133 controls within the 39 control objectives.

Tim Layton‘s Information Security is a practical tool to help you understand the ISO/IEC 17799 standard and apply its principles within your organization‘s unique context.

 

Share

Free Business Analyst Skills Test for CBAP

Business Analysis for Information Technology deals

Picture of Facilitation Skills: DVD

Facilitation Skills: DVD

Picture of Effective Presentation Skills: Preview Vhs

Effective Presentation Skills: Preview Vhs

 

 

Share

Business Analysis for Information Technology products