IT Governance: An International Guide to Data Security and ISO 27001/ISO 27002
Faced with the compliance requirements of increasingly punitive information and privacy-related regulation, as well as the proliferation of complex threats to information security, there is an urgent need for organizations to adopt IT governance best practice. Alan Calder is responsible for security development lifecycle threat modeling at Microsoft and is one of a handful of threat modeling experts in the world. Now, he is sharing his considerable expertise into this unique book. With pages of specific actionable advice, he details how to build better security into the design of systems, software, or services from the outset. You'll explore various threat modeling approaches, find out how to test your designs against threats, and learn effective ways to address threats that have been validated at Microsoft and other top companies. Systems security managers, you'll find tools and a framework for structured thinking about what can go wrong. Software developers, you'll appreciate the jargon-free and accessible introduction to this essential skill. Security professionals, you'll learn to discern changing threats and discover the easiest ways to adopt a structured approach to threat modeling.
Book contents:
-
Why is Information Security Necessary?
-
The Corporate Governance Code, the FRC Risk Guidance and Sarbanes-Oxley
-
ISO 27001
-
Organizing Information Security
-
Information Security Policy and Scope
-
The Risk Assessment and Statement of Applicability
-
Mobile Devices
-
Human Resources Security
-
Asset Management
-
Media Handling
-
Access Control
-
Use Access Management
-
System and Application Access Control
-
Communications Management
-
Exchanges of Information
-
System Acquisition, Development and maintenance
-
Development and Support Processes
-
Supplier Relationships
-
Monitoring and Information Security Incident Management
-
Business and Information Security Continuity Management
-
Compliance
-
The ISO 27001 Audit