𝔖 Scriptorium
✦   LIBER   ✦

πŸ“

Securing an IT Organization through Governance, Risk Management, and Audit

✍ Scribed by Ken E. Sigler, James L. Rainey III


Publisher
Auerbach Publications
Year
2016
Tongue
English
Leaves
364
Series
Internal Audit and IT Audit
Edition
1
Category
Library

⬇  Acquire This Volume

No coin nor oath required. For personal study only.

✦ Synopsis


Past events have shed light on the vulnerability of mission-critical computer systems at highly sensitive levels. It has been demonstrated that common hackers can use tools and techniques downloaded from the Internet to attack government and commercial information systems. Although threats may come from mischief makers and pranksters, they are more likely to result from hackers working in concert for profit, hackers working under the protection of nation states, or malicious insiders.


Securing an IT Organization through Governance, Risk Management, and Audit introduces two internationally recognized bodies of knowledge: Control Objectives for Information and Related Technology (COBIT 5) from a cybersecurity perspective and the NIST Framework for Improving Critical Infrastructure Cybersecurity (CSF). Emphasizing the processes directly related to governance, risk management, and audit, the book provides details of a cybersecurity framework (CSF), mapping each of the CSF steps and activities to the methods defined in COBIT 5. This method leverages operational risk understanding in a business context, allowing the information and communications technology (ICT) organization to convert high-level enterprise goals into manageable, specific goals rather than unintegrated checklist models.

The real value of this methodology is to reduce the knowledge fog that frequently engulfs senior business management, and results in the false conclusion that overseeing security controls for information systems is not a leadership role or responsibility but a technical management task. By carefully reading, implementing, and practicing the techniques and methodologies outlined in this book, you can successfully implement a plan that increases security and lowers risk for you and your organization.

✦ Subjects


Information Management;Management & Leadership;Business & Money;Leadership;Management & Leadership;Business & Money;Network Security;Networking & Cloud Computing;Computers & Technology;Security & Encryption;Cryptography;Encryption;Hacking;Network Security;Privacy & Online Safety;Security Certifications;Viruses;Computers & Technology;Business & Finance;Accounting;Banking;Business Communication;Business Development;Business Ethics;Business Law;Economics;Entrepreneurship;Finance;Human Resources;Int


πŸ“œ SIMILAR VOLUMES


IT Security Risk Control Management: an
✍ Pompon, Raymond πŸ“‚ Library πŸ“… 2016 πŸ› Apress 🌐 English

Information security is more than configuring firewalls, removing viruses, hacking machines, or setting passwords. Creating and promoting a successful security program requires skills in organizational consulting, diplomacy, change management, risk analysis, and out-of-the-box thinking. IT Security

IT Security Risk Control Management: An
✍ Raymond Pompon πŸ“‚ Library πŸ“… 2016 πŸ› Apress 🌐 English

<p>This book explains how to construct an information security program, from inception to audit, with enduring, practical, hands-on advice and actionable behavior for IT professionals. Β Information security is more than configuring firewalls, removingΒ viruses, hacking machines, or setting passwords.

IT Security Risk Control Management: An
✍ Raymond Pompon (auth.) πŸ“‚ Library πŸ“… 2016 πŸ› Apress 🌐 English

<p><p>This book explains how to construct an information security program, from inception to audit, with enduring, practical, hands-on advice and actionable behavior for IT professionals. Information security is more than configuring firewalls, removing viruses, hacking machines, or setting password

Next-Generation Enterprise Security and
✍ Mohiuddin Ahmed (editor), Nour Moustafa (editor), Abu Barkat (editor), Paul Hask πŸ“‚ Library πŸ“… 2022 πŸ› CRC Press 🌐 English

<p><span>The Internet is making our daily lives as digital as possible, and this new era is called the Internet of Everything (IoE). The key force behind the rapid growth of the Internet is the technological advancement of enterprises. The digital world we live in is facilitated by these enterprises