A Practical Guide to Security Assessments

Hardcover
from $0.00

Author: Sudhanshu Kairab

ISBN-10: 0849317061

ISBN-13: 9780849317064

Category: Databases Security

Search in google:

The modern dependence upon information technology and the corresponding information security regulations and requirements force companies to evaluate the security of their core business processes, mission critical data, and supporting IT environment. Combine this with a slowdown in IT spending resulting in justifications of every purchase, and security professionals are forced to scramble to find comprehensive and effective ways to assess their environment in order to discover and prioritize vulnerabilities, and to develop cost-effective solutions that show benefit to the business.A Practical Guide to Security Assessments is a process-focused approach that presents a structured methodology for conducting assessments. The key element of the methodology is an understanding of business goals and processes, and how security measures are aligned with business risks. The guide also emphasizes that resulting security recommendations should be cost-effective and commensurate with the security risk. The methodology described serves as a foundation for building and maintaining an information security program.In addition to the methodology, the book includes an Appendix that contains questionnaires that can be modified and used to conduct security assessments. This guide is for security professionals who can immediately apply the methodology on the job, and also benefits management who can use the methodology to better understand information security and identify areas for improvement.

Ch. 1Introduction1Ch. 2Evolution of information security5Ch. 3The information security program and how a security assessment fits in45Ch. 4Planning67Ch. 5Initial information gathering103Ch. 6Business process evaluation139Ch. 7Technology evaluation165Ch. 8Risk analysis and final presentation193Ch. 9Information security standards229Ch. 10Information security legislation245App. APreliminary checklist to gather information259App. BGeneric questionnaire for meetings with business process owners271App. CGeneric questionnaire for meetings with technology owners277App. DData classification283App. EData retention291App. FBackup and recovery297App. GExternally hosted services309App. HPhysical security325App. IEmployee termination343App. JIncident handling351App. KBusiness to business (B2B)361App. LBusiness to consumer (B2C)371App. MChange management385App. NUser ID administration391App. OManaged security403App. PMedia handling415App. QHIPAA security423