
Information Security Risk Analysis
Thomas R. Peltier - Collection Information Security
Résumé
The risk management process supports executive decision-making, allowing managers and owners to perform their fiduciary responsibility of protecting the assets of their enterprises. This crucial process should not be a long, drawn-out affair. To be effective, it must be done quickly and efficiently.
Information Security Risk Analysis, Second Edition enables CIOs, CSOs, and MIS managers to understand when, why, and how risk assessments and analyses can be conducted effectively. This book discusses the principle of risk management and its three key elements: risk analysis, risk assessment, and vulnerability assessment. It examines the differences between quantitative and qualitative risk assessment, and details how various types of qualitative risk assessment can be applied to the assessment process. The text offers a thorough discussion of recent changes to the Facilitated Risk Analysis and Assessment Process (FRAAP) and the need to develop a pre-screening method for risk assessment and business impact analysis.
Features:
- Analyzes risk analysis, risk assessment, and vulnerability assessments
- Introduces System Development Life Cycle (SDLC) and Business Process Life Cycle (BPLC), and integrates risk analysis and assessment into these processes
- Discusses the need to develop a standard set of controls, and details how to apply regulations such as GLBA, HIPPA, SOX, ISO 17799, and others
- Explains how to use qualitative risk assessment concepts and FRAAP to conduct business impact analyses and determine information classification requirements
- Contains samples of forms, controls, policies, letters, and spreadsheets needed to complete the risk analysis and assessment processes
L'auteur - Thomas R. Peltier
Peltier & Associates, Wyandotte, Michigan, USA
Sommaire
- Introduction
- Risk Management
- Risk Assessment Process
- Quantitative versus Qualitative Risk Assessment
- Other Forms of Qualitative Risk Assessment
- Facilitated Risk Analysis and Assessment Process (FRAAP)
- Variations on the FRAAP
- Mapping Controls
- Business Impact Analysis (BIA)
- Conclusion
- Appendix A: Sample Risk Assessment Management Summary Report
- Appendix B: Terms and Definitions
- Appendix C: Bibliography
- Index
Caractéristiques techniques
PAPIER | |
Éditeur(s) | Auerbach |
Auteur(s) | Thomas R. Peltier |
Collection | Information Security |
Parution | 03/06/2005 |
Édition | 2eme édition |
Nb. de pages | 344 |
Format | 16 x 24 |
Couverture | Relié |
Poids | 637g |
Intérieur | Noir et Blanc |
EAN13 | 9780849333460 |
ISBN13 | 978-0-8493-3346-0 |
Avantages Eyrolles.com
Nos clients ont également acheté
Consultez aussi
- Les meilleures ventes en Graphisme & Photo
- Les meilleures ventes en Informatique
- Les meilleures ventes en Construction
- Les meilleures ventes en Entreprise & Droit
- Les meilleures ventes en Sciences
- Les meilleures ventes en Littérature
- Les meilleures ventes en Arts & Loisirs
- Les meilleures ventes en Vie pratique
- Les meilleures ventes en Voyage et Tourisme
- Les meilleures ventes en BD et Jeunesse