Chapter 3. Security Management and Practices

OBJECTIVES

Understand the principles of security management.

  • In understanding information security management, there are a number of principles you need to know to create a managed security program. These principles go beyond firewalls, encryptions, and access control. They are concerned with the various aspects of managing the organization's information assets in areas such as privacy, confidentiality, integrity, accountability, and the basics of the mechanisms used in their management.

Know what management's responsibility is in the information security environment.

  • Management cannot just decree that the systems and networks will be secure. They must take an active role in setting and supporting ...

Get CISSP Training Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.