By definition, information security exists to protect your organization's valuable information resources. But too often information security efforts are viewed as thwarting business objectives. An effective information secur...

Buy Now From Amazon

Product Review

By definition, information security exists to protect your organization's valuable information resources. But too often information security efforts are viewed as thwarting business objectives. An effective information security program preserves your information assets and helps you meet business objectives. Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management provides the tools you need to select, develop, and apply a security program that will be seen not as a nuisance but as a means to meeting your organization's goals.

Divided into three major sections, the book covers: writing policies, writing procedures, and writing standards. Each section begins with a definition of terminology and concepts and a presentation of document structures. You can apply each section separately as needed, or you can use the entire text as a whole to form a comprehensive set of documents. The book contains checklists, sample policies, procedures, standards, guidelines, and a synopsis of British Standard 7799 and ISO 17799.

Peltier provides you with the tools you need to develop policies, procedures, and standards. He demonstrates the importance of a clear, concise, and well-written security program. His examination of recommended industry best practices illustrates how they can be customized to fit any organization's needs. Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management helps you create and implement information security procedures that will improve every aspect of your enterprise's activities.

Similar Products

Assessing and Managing Security Risk in IT Systems: A Structured MethodologyIncident Response & Computer Forensics, Third EditionEthics and Technology: Controversies, Questions, and Strategies for Ethical Computing, 4th EditionCase Studies in Information Technology Ethics (2nd Edition)Writing Information Security PoliciesThe Hacker Playbook 2: Practical Guide To Penetration TestingThe Practice of Network Security Monitoring: Understanding Incident Detection and ResponseCISSP (ISC)2 Certified Information Systems Security Professional Official Study GuideInformation Security Policy Development for Compliance: ISO/IEC 27001, NIST SP 800-53, HIPAA Standard, PCI DSS V2.0, and AUP V5.0Blue Team Handbook: Incident Response Edition: A condensed field guide for the Cyber Security Incident Responder.