Share
Fr. 64.00
Evan Wheeler, Evan (Omgeo Wheeler
Security Risk Management - Building an Information Security Risk Management Program from Ground
English · Paperback / Softback
Shipping usually takes at least 4 weeks (title will be specially ordered)
Description
Informationen zum Autor Evan Wheeler currently is a Director of Information Security for Omgeo (A DTCC | Thomson Reuters Company), an instructor at both Clark and Northeastern Universities, and the author of the Information Security Risk Management course for the SANS Institute. Previously he spent six years as a Security Consultant for the U.S. Department of Defense. Klappentext Security Risk Management provides a roadmap for restructuring enterprise assurance management programs. Security professionals often fall into the trap of telling the business how they need to do something, but they can't explain why. This book will help the reader to justify the so-called "best practices" that security professionals typically impose on businesses. The book also provides organizations with a comprehensive, logical, and straightforward approach to managing information risk across the enterprise. It removes traditional obstacles to success by leveraging the core requirements that drive the business rather than focusing on technology solutions. The overall result is improved alignment of resources with the needs of the business while building in flexibility that will allow the business to absorb and recover from most attacks. Zusammenfassung Teaches you practical techniques that can be used on a daily basis! while also explaining the fundamentals so you understand the rationale behind these practices. This book helps you break free from the so-called "best practices" argument by articulating risk exposures in business terms. Inhaltsverzeichnis Part I - Introduction to Risk Management Chapter 1. The Security Evolution Chapter 2. Risky Business Chapter 3. The Risk Management Lifecycle Chapter 4. Risk Profiling Part II - Risk Assessment and Analysis Techniques Chapter 5. Formulating a Risk Chapter 6. Risk Exposure Factors Chapter 7. Security Controls and Services Chapter 8. Risk Evaluation and Mitigation Strategies Chapter 9. Reports and Consulting Chapter 10. Risk Assessment Techniques Part III - Building and Running a Risk Management Program Chapter 11. Threat and Vulnerability Management Chapter 12. Security Risk Reviews Chapter 13. A Blueprint for Security Chapter 14. Building a Program from Scratch Appendix A: Security Risk Profile Appendix B: Risk Models and Scales Appendix C: Architectural Risk Analysis Reference Tables ...
List of contents
Part I - Introduction to Risk Management Chapter 1. The Security Evolution Chapter 2. Risky Business Chapter 3. The Risk Management Lifecycle Chapter 4. Risk Profiling Part II - Risk Assessment and Analysis Techniques Chapter 5. Formulating a Risk Chapter 6. Risk Exposure Factors Chapter 7. Security Controls and Services Chapter 8. Risk Evaluation and Mitigation Strategies Chapter 9. Reports and Consulting Chapter 10. Risk Assessment Techniques Part III - Building and Running a Risk Management Program Chapter 11. Threat and Vulnerability Management Chapter 12. Security Risk Reviews Chapter 13. A Blueprint for Security Chapter 14. Building a Program from Scratch Appendix A: Security Risk Profile Appendix B: Risk Models and Scales Appendix C: Architectural Risk Analysis Reference Tables
Report
"Evan Wheeler has developed a much needed new approach to the field of security risk management. Readers familiar with this field of study will find that it does what he says he wants it to do: shake the old risk paradigms out of their roots and plant something fresh and useful today."--Dennis Treece, Colonel, US Army (Retired)/Chief Security Officer, Massachusetts Port Authority-Boston
"Wheeler's book is predominantly a practitioner's guide to security risk management but can also be used as a teaching text to help engineers, students of security, information assurance, or information systems more broadly. The key message that Wheeler is emphasizing is that risk is at the core of security, and at the heart of every business. Despite that the book lacks key referencing from academic literature, it can still be used as the basis for setting a large-scale team assignment on devising a risk management program from the ground up for a real organisation. Security professionals in banks will particularly find the book relevant."--Computers and Security
"This book is packed with practical?tips and the information contained throughout provides a good overview of the subject matter. The author explains the fundamentals of risk identification, assessment and management, exploring the differences between a vulnerability assessment and a risk assessment, and also providing rationales behind each of the subjects covered. This is not a technical book and the author generally avoids detailed technical analysis; rather it is an aide-memoir for Security Risk Management. .his book is recommended, in particular, for those beginning a career in Risk Management. It also provides a useful reference for current risk professionals who perhaps could benefit from a book that helps refine and further improve their current skillset."--Best Governance and ISMS Books in InfoSecReviews Book Awards
"Evan Wheeler's book, Security Risk Management, provides security and business continuity practitioners with the ability to thoroughly plan and build a solid security risk management program. The buzz words that are used throughout the corporate risk management industry today are often misused or overused. Wheeler breaks down such terms, translating them for the reader and articulating how they apply to a security risk management program. He believes risk managers should consider banning the term "best practices" from their vocabulary; he doesn't think one size fits all when creating a security risk management program. Building an information security risk management program from the ground up is a monumental task that requires various business units to react and adopt change to move a business forward. This book provides valuable information for security, IT, and business continuity professionals on creating such a program."--Security Management
Product details
Authors | Evan Wheeler, Evan (Omgeo Wheeler |
Publisher | ELSEVIER SCIENCE BV |
Languages | English |
Product format | Paperback / Softback |
Released | 31.12.2011 |
EAN | 9781597496155 |
ISBN | 978-1-59749-615-5 |
No. of pages | 384 |
Series |
Syngress Media Syngress Media |
Subject |
Natural sciences, medicine, IT, technology
> IT, data processing
> IT
|
Customer reviews
No reviews have been written for this item yet. Write the first review and be helpful to other users when they decide on a purchase.
Write a review
Thumbs up or thumbs down? Write your own review.