Information Assurance Handbook: Effective Computer Security and Risk Management Strategies

Information Assurance Handbook: Effective Computer Security and Risk Management Strategies

Information Assurance Handbook: Effective Computer Security and Risk Management Strategies

Information Assurance Handbook: Effective Computer Security and Risk Management Strategies

eBook

$49.49  $65.70 Save 25% Current price is $49.49, Original price is $65.7. You Save 25%.

Available on Compatible NOOK devices, the free NOOK App and in My Digital Library.
WANT A NOOK?  Explore Now

Related collections and offers


Overview

Best practices for protecting critical data and systems

Information Assurance Handbook: Effective Computer Security and Risk Management Strategies discusses the tools and techniques required to prevent, detect, contain, correct, and recover from security breaches and other information assurance failures. This practical resource explains how to integrate information assurance into your enterprise planning in a non-technical manner. It leads you through building an IT strategy and offers an organizational approach to identifying, implementing, and controlling information assurance initiatives for small businesses and global enterprises alike.

Common threats and vulnerabilities are described and applicable controls based on risk profiles are provided. Practical information assurance application examples are presented for select industries, including healthcare, retail, and industrial control systems. Chapter-ending critical thinking exercises reinforce the material covered. An extensive list of scholarly works and international government standards is also provided in this detailed guide.

Comprehensive coverage includes:

  • Basic information assurance principles and concepts
  • Information assurance management system
  • Current practices, regulations, and plans
  • Impact of organizational structure
  • Asset management
  • Risk management and mitigation
  • Human resource assurance
  • Advantages of certification, accreditation, and assurance
  • Information assurance in system development and acquisition
  • Physical and environmental security controls
  • Information assurance awareness, training, and education
  • Access control
  • Information security monitoring tools and methods
  • Information assurance measurements and metrics
  • Incident handling and computer forensics
  • Business continuity management
  • Backup and restoration
  • Cloud computing and outsourcing strategies
  • Information assurance big data concerns

Product Details

ISBN-13: 9780071826310
Publisher: McGraw Hill LLC
Publication date: 09/12/2014
Sold by: Barnes & Noble
Format: eBook
Pages: 480
File size: 16 MB
Note: This product may take a few minutes to download.

About the Author

Corey D. Schou, Ph.D., is the University Professor of Informatics and the Associate Dean of the College of Business at Idaho State University. He has been involved in establishing computer security and information assurance training and standards for 25 years. His research interests include information assurance, ethics, privacy, and collaborative decision making. He was responsible for compiling and editing computer security standards and training materials for the Committee on National Security Systems (CNSS). Throughout his career, Dr. Schou has remained an active classroom teacher despite his research and service commitments. He is the founding director of the Informatics Research Institute and the National Information Assurance Training and Education Center (NIATEC) that was designated the National Center of Excellence in Information Assurance Education. In 1996, his research center was cited by the Information Systems Security Association (ISSA) for Outstanding Contributions to the Security Profession and he was selected as the Educator of the Year by the Federal Information Systems Security Educators Association (FISSEA). In 1997, the Masie Institute and TechLearn Consortium recognized his contributions to distance education. In 2001, Dr. Schou was honored by the International Information Systems Security Certification Consortium [(ISC)2] with the Tipton award for his work in professionalization of computer security and his development of the generally accepted common body of knowledge (CBK) used in the certification of information assurance professionals. Dr. Schou serves as the chair of the Colloquium for Information Systems Security Education (CISSE). Under his leadership, the Colloquium creates an environment for exchange and dialogue among leaders in government, industry, and academia concerning information security and information assurance education. In addition, he is the editor of Information Systems Security and serves on the board of several professional organizations.

Table of Contents

TABLE OF CONTENTSPart I: Information Security Infrastructure1.The Need for Information Security2.Concepts in Information Security3.Assets, Threats, Vulnerabilities, Risks and Controls4.Security Professionals and Organizations Providing Resources for Professionals5.Information Security Management System6.Implementing Information Security Strategy into Current Practices, Regulations and PlansPart II: Information Security Planning Process7.Approaches to Implementing Information Security8.Organizational Structure for Managing Information Security9.Asset Management10.Information Security Risk Management11.Information Security Policy12.Human Resource Security13.Certification, Accreditation and AssurancePart III: Information Security Prevention Process 14.Information Security in System Development15.Physical and Environmental Security Controls16.Information Security Awareness, Training and Education17.Preventive Tools and Techniques18.Access ControlPart IV: Information Security Detection Process19. Information Security Monitoring Tools and Methods20.Information Security Measurements and MetricsPart V: Information Security Recovery Process21.Information Security Incident Handling 22.Computer Forensics23.Business Continuity24.Backup & RestorationAppendices
From the B&N Reads Blog

Customer Reviews