Skip to Content
IT Security Risk Control Management: An Audit Preparation Plan
book

IT Security Risk Control Management: An Audit Preparation Plan

by Raymond Pompon
September 2016
Intermediate to advanced
311 pages
12h 30m
English
Apress

Overview

Follow step-by-step guidance to craft a successful security program. You will identify with the paradoxes of information security and discover handy tools that hook security controls into business processes.

Information security is more than configuring firewalls, removing viruses, hacking machines, or setting passwords. Creating and promoting a successful security program requires skills in organizational consulting, diplomacy, change management, risk analysis, and out-of-the-box thinking.

What You'll Learn

  • Build a security program that will fit neatly into an organization and change dynamically to suit both the needs of the organization and survive constantly changing threats

  • Prepare for and pass such common audits as PCI-DSS, SSAE-16, and ISO 27001

  • Calibrate the scope, and customize security controls to fit into an organization's culture

  • Implement the most challenging processes, pointing out common pitfalls and distractions

  • Frame security and risk issues to be clear and actionable so that decision makers, technical personnel, and users will listen and value your advice

Who This Book Is For

IT professionals moving into the security field; new security managers, directors, project heads, and would-be CISOs; and security specialists from other disciplines moving into information security (e.g., former military security professionals, law enforcement professionals, and physical security professionals)

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Rational Cybersecurity for Business: The Security Leaders' Guide to Business Alignment

Rational Cybersecurity for Business: The Security Leaders' Guide to Business Alignment

Dan Blum

Publisher Resources

ISBN: 9781484221402Purchase book