Skip to Content
Security Program and Policies: Principles and Practices, Second Edition
book

Security Program and Policies: Principles and Practices, Second Edition

by Sari Greene
March 2014
Beginner
648 pages
17h 25m
English
Pearson IT Certification

Overview

Everything you need to know about information security programs and policies, in one book

  • Clearly explains all facets of InfoSec program and policy planning, development, deployment, and management

  • Thoroughly updated for today’s challenges, laws, regulations, and best practices

  • The perfect resource for anyone pursuing an information security management career

  • In today’s dangerous world, failures in information security can be catastrophic. Organizations must protect themselves. Protection begins with comprehensive, realistic policies. This up-to-date guide will help you create, deploy, and manage them.

    Complete and easy to understand, it explains key concepts and techniques through real-life examples. You’ll master modern information security regulations and frameworks, and learn specific best-practice policies for key industry sectors, including finance, healthcare, online commerce, and small business.

    If you understand basic information security, you’re ready to succeed with this book. You’ll find projects, questions, exercises, examples, links to valuable easy-to-adapt information security policies...everything you need to implement a successful information security program.

    Sari Stern Greene, CISSP, CRISC, CISM, NSA/IAM, is an information security practitioner, author, and entrepreneur. She is passionate about the importance of protecting information and critical infrastructure. Sari founded Sage Data Security in 2002 and has amassed thousands of hours in the field working with a spectrum of technical, operational, and management personnel, as  well as boards of directors, regulators, and service providers. Her first text was Tools and Techniques for Securing Microsoft Networks, commissioned by Microsoft to train its partner channel, which was soon followed by the first edition of Security Policies and Procedures: Principles and Practices. She is actively involved in the security community, and speaks regularly at security conferences and workshops. She has been quoted in The New York Times, Wall Street Journal, and on CNN, and CNBC. Since 2010, Sari has served as the chair of the annual Cybercrime Symposium.

    Learn how to

    ·         Establish program objectives, elements, domains, and governance

    ·         Understand policies, standards, procedures, guidelines, and plans—and the differences among them

    ·         Write policies in “plain language,” with the right level of detail

    ·         Apply the Confidentiality, Integrity & Availability (CIA) security model

    ·         Use NIST resources and ISO/IEC 27000-series standards

    ·         Align security with business strategy

    ·         Define, inventory, and classify your information and systems

    ·         Systematically identify, prioritize, and manage InfoSec risks

    ·         Reduce “people-related” risks with role-based Security Education, Awareness, and Training (SETA)

    ·         Implement effective physical, environmental, communications, and operational security

    ·         Effectively manage access control

    ·         Secure the entire system development lifecycle

    ·         Respond to incidents and ensure continuity of operations

    ·         Comply with laws and regulations, including GLBA, HIPAA/HITECH, FISMA, state data security and notification rules, and PCI DSS

    Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
    and much more.

    Read now

    Unlock full access

    More than 5,000 organizations count on O’Reilly

    AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

    QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
    Julian F.
    Head of Cybersecurity
    QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
    Addison B.
    Field Engineer
    QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
    Amir M.
    Data Platform Tech Lead
    QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
    Mark W.
    Embedded Software Engineer

    You might also like

    Information Security: Principles and Practices, Second Edition

    Information Security: Principles and Practices, Second Edition

    Mark S. Merkow, Jim Breithaupt
    Information Security Management Principles, 3rd Edition

    Information Security Management Principles, 3rd Edition

    Andy Taylor, David Alexander, Amanda Finch, David Sutton

    Publisher Resources

    ISBN: 9780133481181Purchase book