My Account Log in

1 option

The complete guide to cybersecurity risks and controls / Anne Kohnke, Dan Shoemaker, Ken Sigler.

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Kohnke, Anne, author.
Shoemaker, Dan, author.
Sigler, Kenneth, author.
Series:
Internal audit and IT audit.
Internal Audit and IT Audit
Language:
English
Subjects (All):
Computer security.
Computer networks--Security measures.
Computer networks.
Information technology--Security measures.
Information technology.
Physical Description:
1 online resource (336 p.)
Edition:
1st edition
Place of Publication:
Boca Raton : CRC Press, [2016]
Language Note:
English
System Details:
text file
Summary:
The Complete Guide to Cybersecurity Risks and Controls presents the fundamental concepts of information and communication technology (ICT) governance and control. In this book, you will learn how to create a working, practical control structure that will ensure the ongoing, day-to-day trustworthiness of ICT systems and data. The book explains how to establish systematic control functions and timely reporting procedures within a standard organizational framework and how to build auditable trust into the routine assurance of ICT operations. The book is based on the belief that ICT operation is a strategic governance issue rather than a technical concern. With the exponential growth of security breaches and the increasing dependency on external business partners to achieve organizational success, the effective use of ICT governance and enterprise-wide frameworks to guide the implementation of integrated security controls are critical in order to mitigate data theft. Surprisingly, many organizations do not have formal processes or policies to protect their assets from internal or external threats. The ICT governance and control process establishes a complete and correct set of managerial and technical control behaviors that ensures reliable monitoring and control of ICT operations. The body of knowledge for doing that is explained in this text. This body of knowledge process applies to all operational aspects of ICT responsibilities ranging from upper management policy making and planning, all the way down to basic technology operation.
Contents:
Front Cover; Contents; Preface; Chapter 1: Why Cybersecurity Management Is Important; Chapter 2: Control-Based Information Governance, What It Is and How It Works; Chapter 3: A Survey of Control Frameworks, General Structure, and Application; Chapter 4: What Are Controls and Why Are They Important?; Chapter 5: Implementing a Multitiered Governance and Control Framework in a Business; Chapter 6: Risk Management and Prioritization Using a Control Perspective; Chapter 7: Control Formulation and Implementation Process; Chapter 8: Security Control Validation and Verification
Chapter 9: Control Framework Sustainment and Security of OperationsBack Cover
Notes:
An Auerbach book.
Includes bibliographical references and index.
Description based on print version record.
ISBN:
1-04-007756-0
0-429-18393-3
1-4987-4057-X
9780429183935
OCLC:
945735792

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account