
As an Amazon Associate and affiliate partner, Menrva Books earns from qualifying purchases. Learn more
Effective security rules and procedures do not exist for their own sake-they are put in place to protect critical assets, thereby supporting overall business objectives. Recognizing security as a business enabler is the first step in building a successful program. Information Security Fundamentals allows future security professionals to gain a solid understanding of the foundations of the field and the entire range of issues that practitioners must address. This book enables students to understand the key elements that comprise a successful information security program and eventually apply these concepts into their own efforts. The book examines the elements of computer security, employee roles and responsibilities, and common threats. It examines the need for management controls, policies and procedures, and risk analysis, and also presents a comprehensive list of tasks and objectives that make up a typical information protection program. The volume discusses organization wide policies and their documentation, and legal and business requirements. It explains policy format, focusing on global, topic-specific, and application-specific policies.; Following a review of asset classification, the book explores access control, the components of physical security, and the foundations and processes of risk analysis and risk management. Information Security Fundamentals concludes by describing business continuity planning, including preventive controls, recovery strategies, and ways to conduct a business impact analysis.
This book investigates the foundational principles required to integrate information security as a strategic business enabler rather than a purely technical constraint. Authors John A. Blackley and Peltier R. leverage their professional expertise to outline a comprehensive framework for security programs. They argue that effective security is rooted in the alignment of organizational policies, risk management, and asset protection with broader business objectives. The text serves as a structured guide for practitioners to understand the intersection of management controls, legal requirements, and operational security tasks.
What You Will Find
Experts identify this volume as a foundational text for students and entry-level professionals seeking a holistic view of information security management. Readers frequently note the practical utility of the book's structured approach to policy development and risk assessment in corporate environments.
Page Count:
280
Publication Date:
2004-10-28
Publisher:
Auerbach Publishers Inc.
ISBN-10:
0203488652
ISBN-13:
9780203488652
No comments yet. Be the first to share your thoughts!