Pragmatic Security Metrics : Applying Metametrics to Information Security
Langue : anglais
Edité par Auerbach Publications, 2013
- Livre relié
- Neuf

Vendeur : GreatBookPrices, Columbia, MD, Etats-UnisGreatBookPrices
Vendeur AbeBooks depuis 6 avril 2009
Etat: Neuf
EUR 181,77
Quantité disponible : 8 disponible(s)
Ajouter au panierN° de réf. du vendeur 18778848-n
- Titre
- Pragmatic Security Metrics : Applying Metametrics to Information Security
- Auteur
- Brotby, W. Krag; Kabay, M. E., Ph.D. (FRW)
- Éditeur
- Auerbach Publications
- Année de publication
- 2013
- État de l'article
- New
- Reliure
- Couverture rigide
- Langue
- anglais
- ISBN à 10 chiffres
- 1439881529
- ISBN à 13 chiffres
- 9781439881521
Other books on information security metrics discuss number theory and statistics in academic terms. Light on mathematics and heavy on utility, PRAGMATIC Security Metrics: Applying Metametrics to Information Security breaks the mold. This is the ultimate how-to-do-it guide for security metrics.
Packed with time-saving tips, the book offers easy-to-follow guidance for those struggling with security metrics. Step by step, it clearly explains how to specify, develop, use, and maintain an information security measurement system (a comprehensive suite of metrics) to help:
- Security professionals systematically improve information security, demonstrate the value they are adding, and gain management support for the things that need to be done
- Management address previously unsolvable problems rationally, making critical decisions such as resource allocation and prioritization of security relative to other business activities
- Stakeholders, both within and outside the organization, be assured that information security is being competently managed
The PRAGMATIC approach lets you hone in on your problem areas and identify the few metrics that will generate real business value. The book:
- Helps you figure out exactly what needs to be measured, how to measure it, and most importantly, why it needs to be measured
- Scores and ranks more than 150 candidate security metrics to demonstrate the value of the PRAGMATIC method
- Highlights security metrics that are widely used and recommended, yet turn out to be rather poor in practice
- Describes innovative and flexible measurement approaches such as capability maturity metrics with continuous scales
- Explains how to minimize both measurement and security risks using complementary metrics for greater assurance in critical areas such as governance and compliance
In addition to its obvious utility in the information security realm, the PRAGMATIC approach, introduced for the first time in this book, has broader application across diverse fields of management including finance, human resources, engineering, and productionin fact any area that suffers a surplus of data but a deficit of useful information.
Visit Security Metametrics. Security Metametrics supports the global community of professionals adopting the innovative techniques laid out in PRAGMATIC Security Metrics. If you, too, are struggling to make much sense of security metrics, or searching for better metrics to manage and improve information security, Security Metametrics is the place.http://securitymetametrics.com/
« Synopsis » peut appartenir à une autre édition de cet ouvrage.
À propos de l’auteur
Krag Brotby has 30 years of experience in the area of enterprise computer security architecture, governance, risk, and metrics and is a Certified Information Security Manager (CISM) and Certified in the Governance of Enterprise Information Technology qualifications. Krag is a CISM trainer and has developed a number of related courses in governance, metrics, governance-risk-compliance (GRC), and risk and trained thousands on five continents during the past decade.
Krags experience includes intensive involvement in current and emerging security architectures, IT and information security metrics, and governance. He holds a foundation patent for digital rights management and has published a variety of technical and IT security-related articles and books. Brotby has served as principal author and editor of the Certified Information Security Manager Review Manual (ISACA 2012) since 2005, and is the researcher and author of the widely circulated Information Security Governance: Guidance for Boards of Directors and Executive Management (ITGI 2006), and Information Security Governance: Guidance for Information Security Managers (ITGI 2008a) as well as a new approach to Information Security Management Metrics (Brotby 2009a) and Information Security Governance; A Practical Development and Implementation Approach (Brotby 2009b).
Krag has served on ISACAs Security Practice Development Committee. He was appointed to the Test Enhancement Committee, responsible for testing development, and to the committee developing a systems approach to information security called the Business Model for Information Security (BMIS). He received the 2009 ISACA John W. Lainhart IV Common Body of Knowledge Award for noteworthy contributions to the information security body of knowledge for the benefit of the global information security community.
Krag is a member of the California High Tech Task Force Steering Committee, an advisory board for law enforcement. He is a frequent workshop presenter and speaker at conferences globally and lectures on information security governance; metrics; information security management; and GRC and CISM preparation throughout Oceania, Asia, Europe, the Middle East, and North America. As a practitioner in the security industry for three decades, Krag was the principal Xerox BASIA enterprise security architect and managed the proof-of-concept project, pilot, and global PKI implementation plan. He was a principal architect of the SWIFT Next Gen PKI security architecture; served as technical director at RAND Corporation for the cyber assurance initiative; as chief security strategist, was the PKI architect for TransactPlus, a J.P. Morgan spinoff; and developed policies and standards for a number of organizations, including the Australian Post Office and several U.S. banks.
Recent consulting engagements include security governance projects for the Australia Post, New Zealand Inland Revenue, and Singapore Infocom Development Agency. Clients have included Microsoft, Unisys, AT&T, BP Alyeska, Countrywide Financial, Informix, Visa, VeriSign, Digital Signature Trust, Zantaz, Bank Al-Bilad, J.P. Morgan Chase, KeyBank, Certicom, and Paycom, among others. He has served on the board of advisors for Signet Assurance and has been involved in significant trade secret theft cases in the Silicon Valley.
Gary Hinson
Despite his largely technical background, Dr. Gary Hinson, PhD, MBA, CISSP, has an abiding interest in human factorsthe people side as opposed to the purely technical aspects of information security and governance. Garys professional career stretches back to the mid-1980s as both a practitioner and manager in the fields of IT system and network administration, information security, and IT auditing. He has worked for some well-known multinationals in the pharmaceuticals/life sciences, utilities, IT, engineering, defense, and financial services industries, mostly in the United Kingdom and Europe. He emigrated to New Zealand in 2005 and now lives on a "lifestyle block" surrounded by more sheep than people.
In the course of his work, Gary has developed or picked up and used a variety of information security metrics. Admittedly, they didnt all work out, but such is the nature of this developing field (Hinson 2006). In relation to programs to implement information security management systems, for example, Gary had some success using conventional project management metrics to guide the implementation activities and discuss progress with senior managers. However, management seemed curiously disinterested in measuring the business benefits achieved by their security investments despite Gary having laid out the basis for measurement in the original business cases. And so started his search for a better way.
Since 2000, Gary has been consulting in information security, originally for a specialist security consultancy in London and then for IsecT Ltd., his own firm. Gary designed, developed, and, in 2003, launched NoticeBored (www.NoticeBored.com), an innovative information security awareness subscription service. NoticeBored has kept him busy ever since, researching and writing awareness materials for subscribers covering a different information security topic each month. One of the regular monthly awareness deliverables from NoticeBored is a management-level awareness briefing proposing and discussing potential metrics associated with each months information security topicfor example, a suite of metrics concerning the management of incidents was delivered with a host of other awareness materials about incident management.
Gary has been a passionate fan of the ISO/IEC 27000-series "ISO27k" information security management standards since shortly before BS 7799 was first released nearly two decades ago. He contributes to the continued development of ISO27k through New Zealands membership of SC27, the ISO/IEC committee responsible for them, although he arrived in NZ too late to influence ISO/IEC 27004:2009 on information security measurements, unfortunately (we have more to say on 27004 below!). To find out what ISO27k can do for your organization, visit www.ISO27001security.com to explore the standards, find out about new developments, and join ISO27k Forum, the email reflector for a global user group.
Before all that, Gary was a scientist researching bacterial genetics at the universities of York and Leicester in the United Kingdom. He has long since lost touch with the cut and thrust of gene cloning, DNA fingerprinting, and all that, but despite recently discovering his creative streak through NoticeBored, the rational scientist and metrician still lurks deep within him. So seven years of university study was not a total waste after all.
« A propos de ce titre » peut appartenir à une autre édition de cet ouvrage.
GreatBookPrices
Columbia, MD, Etats-Unis
Vendeur AbeBooks depuis 6 avril 2009
Frais d'expédition à l'intérieur de ce pays : Etats-Unis
| Article | 5 à 14 jours ouvrés | 8 à 14 jours ouvrés |
|---|---|---|
| Premier article | EUR 2,32 | EUR 2,32 |
Modes de paiement
Description de la boutique
SuperBookDeals.com is your top source for finding new books at the absolute lowest prices, guaranteed ! We offer big discounts - everyday - on millions of titles in virtually any category, from Architecture to Zoology -- and everything in between. Discover great deals and super-savings, on professional books, text book titles, the newest computer guides, or your favorite fiction authors. You'll find it all - at HUGE SAVINGS - at SuperBookDeals. Browse through our complete online product catalog today. Serving customers around the world for years, we help thousands find just the books they're looking for -- at incredibly low, bargain prices.…
Profil professionnel du vendeur
Expert Trading Limited
9220 Rumsey Road, Suite 101
Columbia, MD Etats-Unis 21045
Conditions de vente
Company Name: GreatBookPrices
Legal Entity: Expert Trading, LLC
Address: 6310 Stevens Forest, suite 200, Columbia MD 21046
Email address: CustomerService@SuperBookDeals.com
Phone number: 410-964-0026
consumer complaints can be addressed to address above
Registration #: 52-1713923
Authorized representative: Danielle Hainsey
Droit de rétractation
Si vous êtes un consommateur, vous pouvez exercer votre droit de rétractation sur le contrat conformément à ce qui suit. Le mot « consommateur » désigne toute personne physique agissant à des fins qui n'entrent pas dans le cadre de son activité commerciale, artisanale ou professionnelle.
Informations concernant le droit de rétractation
Droit statutaire de rétractation
Vous avez le droit d'exercer votre droit de rétractation sur ce contrat dans les 14 jours sans donner de raison.
Le délai de rétractation expirera au bout de 14 jours à compter du jour où vous-même, ou un tiers autre que le transporteur et désigné par vous, prendrez physiquement possession de la dernière marchandise, du dernier lot ou de la dernière pièce.
Pour exercer votre droit de rétractation, remplissez électroniquement et envoyez une déclaration claire sur notre site Web, sous « Vos achats » dans « Votre compte ». Nous vous communiquerons sans délai un accusé de réception de cette rétractation sur un support durable (par exemple, par e-mail).
Pour respecter le délai de rétractation, il vous suffit d'envoyer votre message concernant l'exercice de votre droit de rétractation avant l'expiration du délai de rétractation.
Effets de la rétractation
Si vous exercez votre droit de rétractation sur ce contrat, nous vous rembourserons tous les paiements que vous avez effectués, y compris les frais de livraison (à l'exception des frais supplémentaires résultant du choix d'un mode de livraison autre que le type de livraison standard le moins cher que nous proposons).
Nous pouvons déduire du remboursement la perte de valeur de toute marchandise livrée, si la perte est le résultat d'une manipulation inutile de votre part.
Nous effectuerons le remboursement dans les meilleurs délais, et au plus tard 14 jours après le jour où nous aurons été informés de votre décision d'exercer votre droit de rétractation sur ce contrat.
Nous effectuerons le remboursement en utilisant le même moyen de paiement que celui que vous avez utilisé pour la transaction initiale, sauf si vous en avez expressément convenu autrement ; en tout état de cause, aucuns frais ne vous seront facturés à la suite d'un tel remboursement.
Nous pouvons suspendre le remboursement jusqu'à ce que nous ayons reçu les marchandises ou que vous ayez fourni la preuve que vous avez renvoyé les marchandises, en fonction de la première éventualité.
Vous devez renvoyer les marchandises ou les remettre à GreatBookPrices, Bensenville, Illinois, U.S.A., sans retard injustifié et, en tout état de cause, au plus tard 14 jours à compter du jour où vous nous avez communiqué votre décision de rétractation du présent contrat. Le délai est respecté si vous renvoyez les marchandises avant l'expiration du délai de 14 jours. Vous devrez prendre en charge les frais directs du renvoi des marchandises. Vous n'êtes responsable que de toute diminution de valeur des marchandises résultant d'une manipulation autre que celle nécessaire pour établir la nature, les caractéristiques et le fonctionnement des marchandises.
Exceptions au droit de rétractation
Le droit de rétractation ne s'applique pas à ce qui suit :
- Distribution de journaux, de revues ou de magazines, à l'exception des contrats d'abonnement ; et
- Fourniture d'un contenu numérique qui n'est pas fourni sur un support matériel (par exemple, sur un CD ou un DVD) si vous avez accepté, lors de votre commande, que nous puissions commencer à le livrer et que vous ne puissiez pas exercer votre droit de rétractation une fois la livraison commencée.
Conditions d'expédition
Our warehouses across the globe are fully operational without substantial delays. We are working hard and continue to overcome the daily challenges presented by COVID-19. We appreciate your understanding.
Internal processing of your order will take about 1-2 business days. Please allow an additional 4-14 business days for Media Mail delivery. We have multiple ship-from locations - MD,IL,NJ,UK,IN,NV,TN & GA