Table of Contents
Preface
Section 1: Information Security Risk Management and Governance
Chapter 1: InfoSec and Risk Management
Basic InfoSec terminology
Understanding why risk management is important
Understanding assets7
Understanding vulnerabilities9
Performing a basic risk assessment
Defining and calculating impact11
Defining and calculating likelihood12
Calculating risk13
Risk appetite, risk treatment, and risk acceptance 16
Considering legal regulations, investigations, and compliance structures
Compliance structures18
Understanding legal and regulatory requirements19
Responding to and undertaking investigations21
Further compliance optimization22
Proven methodologies in creating a strategy
Creating InfoSec policies, procedures, and playbooks 23 ...
Get Infosec Strategies and Best Practices now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.