Buch, Englisch, 320 Seiten, Format (B × H): 242 mm x 162 mm, Gewicht: 664 g
Reihe: Internal Audit and IT Audit
Life Lessons and Concepts to Accelerate Your Professional Development
Buch, Englisch, 320 Seiten, Format (B × H): 242 mm x 162 mm, Gewicht: 664 g
Reihe: Internal Audit and IT Audit
ISBN: 978-1-138-19739-8
Verlag: Taylor & Francis Ltd
The book takes readers though a series of security and risk discussions based on real-life experiences. While the experience story may not be technical, it will relate specifically to a value or skill critical to being a successful CISO. The core content is organized into ten major chapters, each relating to a "Rule of Information Security" developed through a career of real life experiences. The elements are selected to accelerate the development of CISO skills critical to success. Each segments clearly calls out lessons learned and skills to be developed. The last segment of the book addresses presenting security to senior execs and board members, and provides sample content and materials.
Zielgruppe
Professional Practice & Development
Autoren/Hrsg.
Fachgebiete
Weitere Infos & Material
List of Figures
List of Tables
Prologue
Foreword
Acknowledgments
Author
Section I INTRODUCTION AND HISTORY
1 Introduction: The Journey
2 Learning from History?
3 My First CISO Lesson: The Squirrel
Section II THE RULES AND INDUSTRY DISCUSSION
4 A Weak Foundation Amplifies Risk
5 If a Bad Guy Tricks You into Running His Code on Your Computer, It’s Not Your Computer Anymore
6 There’s Always a Bad Guy Out There Who’s Smarter, More Knowledgeable, or Better-Equipped Than You
7 Know the Enemy, Think Like the Enemy
8 Know the Business, Not Just the Technology
9 Technology Is Only One-Third of Any Solution
10 Every Organization Must Assume Some Risk
11 When Preparation Meets Opportunity, Excellence Happens
12 There Are Only Two Kinds of Organizations: Those That Know They’ve Been Compromised and Those That Don’t Know Yet
13 In Information Security, Just Like in Life, Evolution Is Always Preferable to Extinction
14 A Security Culture Is In Place When Talk Is Replaced with Action
15 NEVER Trust and ALWAYS Verify
Section III SUMMARY
16 My Best Advice for New CISOs
Appendix A: The Written Information Security Plan
Appendix B: Talking to the Board
Appendix C: Establishing an Incident Response Program
Appendix D: Sample High-Level Risk Assessment Methodology