Brotby, W. Krag.

Information security governance : a practical development and implementation approach / Krag Brotby. - Hoboken, N.J. : John Wiley & Sons, �2009. - 1 online resource (xv, 189 pages) : illustrations - Wiley series in systems engineering and management . - Wiley series in systems engineering and management. .

Includes bibliographical references and index.

INFORMATION SECURITY GOVERNANCE; Contents; Acknowledgments; Introduction; 1. Governance Overview -- How Do We Do It? What Do We Get Out of It?; 2. Why Governance?; 3. Legal and Regulatory Requirements; 4. Roles and Responsibilities; 5. Strategic Metrics; 6. Information Security Outcomes; 7. Security Governance Objectives; 8. Risk Management Objectives; 9. Current State; 10. Developing a Security Strategy; 11. Sample Strategy Development; 12. Implementing Strategy; 13. Security Program Development Metrics; 14. Information Security Management Metrics; 15. Incident Management and Response Metrics.

This book provides an understanding of governance and its relevance to information security. It gives readers a clear, step-by-step approach to developing a sound security strategy aligned with their business objectives in order to ensure a predictable level of functionality and assurance. Next, it explores various approaches to implementing the strategy, guiding the reader toward practical, workable solutions. A broad range of business managers, IT security managers, and information security managers will value the guidance, action plans, and sample policies provided in this comprehensive boo.

9780470476000 0470476001 0470131187 9780470131183

10.1002/9780470476017 doi

10.1002/9780470476017 Wiley InterScience http://www3.interscience.wiley.com BC11C58E-029A-4F90-A144-3BDDA8E5C4B4 OverDrive, Inc. http://www.overdrive.com




Data protection.
Computer security--Management.
Information technology--Security measures.
Protection de l'information (Informatique)
S�ecurit�e informatique--Gestion.
Technologie de l'information--S�ecurit�e--Mesures.
BUSINESS & ECONOMICS--Workplace Culture.
BUSINESS & ECONOMICS--Corporate Governance.
BUSINESS & ECONOMICS--Leadership.
BUSINESS & ECONOMICS--Organizational Development.
Computer security--Management
Data protection
Information technology--Security measures

HF5548.37 / .B76 2009eb

658.4/78