LIMITED OFFER
Save 50% on book bundles
Immediately download your ebook while waiting for your print delivery. No promo code needed.
In order to protect company’s information assets such as sensitive customer records, health care records, etc., the security practitioner first needs to find out: what needs pr… Read more
LIMITED OFFER
Immediately download your ebook while waiting for your print delivery. No promo code needed.
In order to protect company’s information assets such as sensitive customer records, health care records, etc., the security practitioner first needs to find out: what needs protected, what risks those assets are exposed to, what controls are in place to offset those risks, and where to focus attention for risk treatment. This is the true value and purpose of information security risk assessments. Effective risk assessments are meant to provide a defendable analysis of residual risk associated with your key assets so that risk treatment options can be explored. Information Security Risk Assessment Toolkit gives you the tools and skills to get a quick, reliable, and thorough risk assessment for key stakeholders.
Information Security Officers, IT Auditors, IT Professionals, Chief Information Officers, Privacy Officers, Risk Officers, IT Enterprise Architects
Dedication
Acknowledgements
About the Technical Editor
About the Authors
Introduction
Chapter 1. Information Security Risk Assessments
Introduction
What is Risk?
What is an Information Security Risk Assessment?
Drivers, Laws, and Regulations
Summary
References
Chapter 2. Information Security Risk Assessment: A Practical Approach
Introduction
A Primer on Information Security Risk Assessment Frameworks
Summary
Chapter 3. Information Security Risk Assessment: Data Collection
Introduction
The Sponsor
The Project Team
Data Collection Mechanisms
Executive Interviews
Document Requests
IT Asset Inventories
Asset Scoping
The Asset Profile Survey
The Control Survey
Survey Support Activities and Wrap-Up
Consolidation
Chapter 4. Information Security Risk Assessment: Data Analysis
Introduction
Compiling Observations from Organizational Risk Documents
Preparation of Threat and Vulnerability Catalogs
Overview of the System Risk Computation
Designing the Impact Analysis Scheme
Designing the Control Analysis Scheme
Designing the Likelihood Analysis Scheme
Putting it Together and the Final Risk Score
Chapter 5. Information Security Risk Assessment: Risk Assessment
Introduction
System Risk Analysis
Chapter 6. Information Security Risk Assessment: Risk Prioritization and Treatment
Introduction
Organizational Risk Prioritization and Treatment
System Specific Risk Prioritization and Treatment
Issues Register
Chapter 7. Information Security Risk Assessment: Reporting
Introduction
Outline
Risk Analysis Executive Summary
Methodology
Results
Risk Register
Conclusion
Appendices
Chapter 8. Information Security Risk Assessment: Maintenance and Wrap Up
Introduction
Process Summary
Key Deliverables
Post Mortem
Index
MT
He is co-author of the book "Information Security Risk Assessment Toolkit: Practical Assessments through Data Collection and Data Analysis" from Syngress. He has presented in various security and academic conferences and organizations around the world including Blackhat, Defcon, Shakacon, INFORMS, INFRAGARD, ISSA, and ISACA. He has a number of published papers to his name in various peer-reviewed journals and is also an alumni member of the Honeynet Project.
He has a Master of Liberal Arts Degree (ALM) in Information Technology from Harvard University and a Master of Science (MS) degree in Information Technology from Ateneo de Manila University. He holds several certifications including a Certified Information Systems Security Professional (CISSP); Certified Information Systems Auditor (CISA); and Certified in Risk and Information Systems Control (CRISC).
JM