May 2017
Intermediate to advanced
1280 pages
94h 8m
English
In this chapter, the selection and specification of security controls for an information system are accomplished as part of an organization-wide information security program that involves the management of organizational risk: that is, the risk to the organization or to individuals associated with the operation of an information system. The management of organizational risk is a key element in the organization's information security program and provides an effective framework for selecting the appropriate security controls for an information system: the security controls necessary to protect individuals and the operations and assets of the organization. ...
Read now
Unlock full access