Herrmann | Complete Guide to Security and Privacy Metrics | E-Book | www2.sack.de
E-Book

E-Book, Englisch, 848 Seiten

Herrmann Complete Guide to Security and Privacy Metrics

Measuring Regulatory Compliance, Operational Resilience, and ROI
Erscheinungsjahr 2007
ISBN: 978-1-4200-1328-3
Verlag: Taylor & Francis
Format: PDF
Kopierschutz: Adobe DRM (»Systemvoraussetzungen)

Measuring Regulatory Compliance, Operational Resilience, and ROI

E-Book, Englisch, 848 Seiten

ISBN: 978-1-4200-1328-3
Verlag: Taylor & Francis
Format: PDF
Kopierschutz: Adobe DRM (»Systemvoraussetzungen)



While it has become increasingly apparent that individuals and organizations need a security metrics program, it has been exceedingly difficult to define exactly what that means in a given situation. There are hundreds of metrics to choose from and an organization’s mission, industry, and size will affect the nature and scope of the task as well as the metrics and combinations of metrics appropriate to accomplish it. Finding the correct formula for a specific scenario calls for a clear concise guide with which to navigate this sea of information. Complete Guide to Security and Privacy Metrics: Measuring Regulatory Compliance, Operational Resilience, and ROI defines more than 900 ready to use metrics that measure compliance, resiliency, and return on investment. The author explains what needs to be measured, why and how to measure it, and how to tie security and privacy metrics to business goals and objectives. The book addresses measuring compliance with current legislation, regulations, and standards in the US, EC, and Canada including Sarbanes-Oxley, HIPAA, and the Data Protection Act-UK. The metrics covered are scaled by information sensitivity, asset criticality, and risk, and aligned to correspond with different lateral and hierarchical functions within an organization. They are flexible in terms of measurement boundaries and can be implemented individually or in combination to assess a single security control, system, network, region, or the entire enterprise at any point in the security engineering lifecycle. The text includes numerous examples and sample reports to illustrate these concepts and stresses a complete assessment by evaluating the interaction and interdependence between physical, personnel, IT, and operational security controls. Bringing a wealth of complex information into comprehensible focus, this book is ideal for corporate officers, security managers, internal and independent auditors, and system developers and integrators.

Herrmann Complete Guide to Security and Privacy Metrics jetzt bestellen!

Zielgruppe


Corporate officers, security managers, internal and independent auditors, system developers and integrators, and systems and network management staff.


Autoren/Hrsg.


Weitere Infos & Material


Introduction

Background

Purpose

Scope

How to Get the Most Out of This Book

Acknowledgments

The “Whats” and “Whys” of Metrics

Measurement Basics

Data Collection and Validation

Defining Measurement Boundaries

Whose Metrics?

Uses and Limits of Metrics

Avoiding the Temptation to Bury Your Organization in Metrics

Relation to Risk Management

Examples from Reliability Engineering

Examples from Safety Engineering

Examples from Software Engineering

The Universe of Security and Privacy Metrics

Measuring Compliance with Security and Privacy Regulations and Standards

Financial Industry

Gramm-Leach-Bliley (GLB) Act — United States

Sarbanes-Oxley Act — United States

Healthcare

Health Insurance Portability And Accountability Act (HIPAA) — United States

Personal Health Information Act (PHIA) — Canada

Personal Privacy

Organization for Economic Cooperation and Development (OECD) Privacy, Cryptography, and Security Guidelines

Data Protection Directive — E.C.

Data Protection Act — United Kingdom

Personal Information Protection And Electronic Documents Act (PIPEDA) — Canada

Privacy Act — United States

Homeland Security

Federal Information Security Management Act (FISMA) — United States

Homeland Security Presidential Directives (HSPDs) — United States

North American Electrical Reliability Council (NERC) Cyber Security Standards

The Patriot Act — United States

Measuring Resilience of Physical, Personnel, IT, and Operational Security Controls

Physical Security

Personnel Security

IT Security

Operational Security

Measuring Return on Investment (ROI) in Physical, Personnel, IT, and Operational Security Controls

Security ROI Model

Security ROI Primitives, Metrics, and Reports

Appendices

A Glossary of Terms, Acronyms, and Abbreviations

B Additional Resources:

Standards

Policies

Publications

Index



Ihre Fragen, Wünsche oder Anmerkungen
Vorname*
Nachname*
Ihre E-Mail-Adresse*
Kundennr.
Ihre Nachricht*
Lediglich mit * gekennzeichnete Felder sind Pflichtfelder.
Wenn Sie die im Kontaktformular eingegebenen Daten durch Klick auf den nachfolgenden Button übersenden, erklären Sie sich damit einverstanden, dass wir Ihr Angaben für die Beantwortung Ihrer Anfrage verwenden. Selbstverständlich werden Ihre Daten vertraulich behandelt und nicht an Dritte weitergegeben. Sie können der Verwendung Ihrer Daten jederzeit widersprechen. Das Datenhandling bei Sack Fachmedien erklären wir Ihnen in unserer Datenschutzerklärung.