The modern dependence upon information technology and the corresponding information security regulations and requirements force companies to evaluate the security of their core business processes, mission critical data, and supporting IT environment. Combine this with a slowdown in IT spending resulting in justifications of every purchase, and security professionals are forced to scramble to find comprehensive and effective ways to assess their environment in order to discover and prioritize vulnerabilities, and to develop cost-effective solutions that show benefit to the business. A Practical Guide to Security Assessments is a process-focused approach that presents a structured methodology for conducting assessments. The key element of the methodology is an understanding of business goals and processes, and how security measures are aligned with business risks. The guide also emphasizes that resulting security recommendations should be cost-effective and commensurate with the security risk. The methodology described serves as a foundation for building and maintaining an information security program. In addition to the methodology, the book includes an Appendix that contains questionnaires that can be modified and used to conduct security assessments. This guide is for security professionals who can immediately apply the methodology on the job, and also benefits management who can use the methodology to better understand information security and identify areas for improvement.
Used the book for a college class. Great information and very useful. I decided to keep the book for future reference instead of trying to resell when the class was over.
Excellent Resource
Published by Thriftbooks.com User , 21 years ago
Excellent. This book is a practical approach to security assessment from planning to the final report. Being in this field for over ten years, this is the first book that truly provides the appropriate level of guidance from not just the security assessment but also from the business standpoint where it looks at involved risks. The appendix is excellent and extremely useful, particularly the questionnaires, which can be modified, based on the type of assessment/client. The book is well structured and very clear, and provides a logical approach to addressing and assessing information security issues. Highly recommended reading.
ThriftBooks sells millions of used books at the lowest
everyday prices. We personally assess every book's quality and offer rare, out-of-print treasures. We
deliver the joy of reading in recyclable packaging with free standard shipping on US orders over $15.
ThriftBooks.com. Read more. Spend less.