Search Images Maps Play YouTube News Gmail Drive More »
My library | Help | Advanced Book Search | Web History | Sign in

Books

Information Security Governance:

A Practical Development and Implementation Approach
Front Cover
2 Reviews
John Wiley & Sons, Apr 22, 2009 - Computers - 220 pages
The Growing Imperative Need for Effective Information Security Governance

With monotonous regularity, headlines announce ever more spectacular failures of information security and mounting losses. The succession of corporate debacles and dramatic control failures in recent years underscores the necessity for information security to be tightly integrated into the fabric of every organization. The protection of an organization's most valuable asset information can no longer be relegated to low-level technical personnel, but must be considered an essential element of corporate governance that is critical to organizational success and survival.

Written by an industry expert, Information Security Governance is the first book-length treatment of this important topic, providing readers with a step-by-step approach to developing and managing an effective information security program. Beginning with a general overview of governance, the book covers:

  • The business case for information security

  • Defining roles and responsibilities

  • Developing strategic metrics

  • Determining information security outcomes

  • Setting security governance objectives

  • Establishing risk management objectives

  • Developing a cost-effective security strategy

  • A sample strategy development

  • The steps for implementing an effective strategy

  • Developing meaningful security program development metrics

  • Designing relevant information security management metrics

  • Defining incident management and response metrics

Complemented with action plans and sample policies that demonstrate to readers how to put these ideas into practice, Information Security Governance is indispensable reading for any professional who is involved in information security and assurance.

  

What people are saying - Write a review

Review: Information Security Governance: A Practical Development and Implementation Approach

User Review  - John Johnson - Goodreads

This is a good, short text on infosec governance. Using it for the Walden graduate course, Information Assurance and Risk Management course I am just finishing. Read full review

Related books

Contents

1 Governance OverviewHow Do We Do It? What Do We Get Out of It?
1
2 Why Governance?
9
3 Legal and Regulatory Requirements
17
4 Roles and Responsibilities
21
5 Strategic Metrics
27
6 Information Security Outcomes
33
7 Security Governance Objectives
47
8 Risk Management Objectives
75
11 Sample Strategy Development
99
12 Implementing Strategy
109
13 Security Program Development Metrics
127
14 Information Security Management Metrics
131
15 Incident Management and Response Metrics
155
16 Conclusion
161
APPENDIX A SABSA Business Attributes and Metrics
163
APPENDIX B Cultural Worldviews
181

9 Current State
81
10 Developing a Security Strategy
87

Common terms and phrases

About the author (2009)

Krag Brotby, cism, has more than twenty-five years of experience in the computer security field with a focus on governance, metrics, and architecture. A frequent presenter at security conferences, he has authored a variety of publications on information security risk management, governance, and metrics. A principal author and editor of the ISACA CISM review manual and related presentation materials, he has served on the CISM Practice Analysis Task Force defining the information security practice area for the coming years.

Bibliographic information