The Growing Imperative Need for Effective Information Security Governance<p>With monotonous regularity, headlines announce ever more spectacular failures of information security and mounting losses. The succession of corporate debacles and dramatic control failures in recent years underscores the ne
Information security governance: a practical development and implementation approach
โ Scribed by Krag Brotby
- Publisher
- Wiley
- Year
- 2009
- Tongue
- English
- Leaves
- 193
- Series
- Wiley series in systems engineering and management
- Category
- Library
No coin nor oath required. For personal study only.
โฆ Synopsis
The Growing Imperative Need for Effective Information Security Governance
With monotonous regularity, headlines announce ever more spectacular failures of information security and mounting losses. The succession of corporate debacles and dramatic control failures in recent years underscores the necessity for information security to be tightly integrated into the fabric of every organization. The protection of an organization's most valuable asset information can no longer be relegated to low-level technical personnel, but must be considered an essential element of corporate governance that is critical to organizational success and survival.
Written by an industry expert, Information Security Governance is the first book-length treatment of this important topic, providing readers with a step-by-step approach to developing and managing an effective information security program. Beginning with a general overview of governance, the book covers:
โข The business case for information security
โข Defining roles and responsibilities
โข Developing strategic metrics
โข Determining information security outcomes
โข Setting security governance objectives
โข Establishing risk management objectives
โข Developing a cost-effective security strategy
โข A sample strategy development
โข The steps for implementing an effective strategy
โข Developing meaningful security program development metrics
โข Designing relevant information security management metrics
โข Defining incident management and response metrics
Complemented with action plans and sample policies that demonstrate to readers how to put these ideas into practice, Information Security Governance is indispensable reading for any professional who is involved in information security and assurance.
๐ SIMILAR VOLUMES
<p><span>This book demonstrates how information security requires a deep understanding of an organization's assets, threats and processes, combined with the technology that can best protect organizational security. It provides step-by-step guidance on how to analyze business processes from a securit
A comprehensive entity security program deploys information asset protection through stratified technological and non-technological controls. Controls are necessary for counteracting threats, opportunities, and vulnerabilities risks in a manner that reduces potential adverse effects to defined, acce
In many organizations, information technology (IT) has become crucial in the support, sustainability, and growth of the business. This pervasive use of technology has created a critical dependency on IT that calls for a specific focus on IT governance. <b>Implementing Information Technology Governa
In many organizations, information technology (IT) has become crucial in the support, sustainability, and growth of the business. This pervasive use of technology has created a critical dependency on IT that calls for a specific focus on IT governance. Implementing Information Technology Governance