Book Summary:
This handbook provides practical guidance into designing and implementing an information security program that delivers true value to the stakeholders of a company.The authors present essential high-level concepts before building a robust framework that you can use to map the concepts to your company's environment. The book presents chapters in a consistent methodology - Assess, Plan, Design, Execute, and Report. Each chapter begins with an Overview, followed by Foundation Concepts that are critical success factors to understanding the material presented. The chapters also contain a Methodology section that explains the steps necessary to achieve the goals of the chapter. |