The Executive Guide to Information Security

The Executive Guide to Information Security pdf epub mobi txt 电子书 下载 2026

出版者:Addison-Wesley Professional
作者:Mark Egan
出品人:
页数:288
译者:
出版时间:2004-11-30
价格:USD 34.99
装帧:Paperback
isbn号码:9780321304513
丛书系列:
图书标签:
  • 信息安全
  • 执行管理
  • 网络安全
  • 风险管理
  • 合规性
  • 数据保护
  • 安全策略
  • IT管理
  • 领导力
  • 安全意识
想要找书就要到 本本书屋
立刻按 ctrl+D收藏本页
你会得到大惊喜!!

具体描述

Preface Preface Who Is This Book For This book is devoted to executives who could benefit from a crash course on information security. We know that you are quite busy, so you need practical recommendations that you can implement quickly. In this book, information security concepts are explained in nontechnical terms to enable executives from any discipline to quickly understand key principles and how to apply them to their business. This book provides a pragmatic approach to evaluating security at your company and putting together an information security program. Key elements of the program include staffing this function at your company, putting the necessary internal processes in place, and implementing the appropriate technology. Business executives will find this book a good primer for understanding the key existing and future security issues and for taking the necessary actions to ensure the protection of their enterprise s information assets. Information Security Background Information security is no longer an issue that is the responsibility of lower-level staff in the information technology (IT) department. Companies are now conducting a significant portion of their business electronically and need to be confident that their systems are safe and secure. This issue has now been escalated to the Board of Director level, and companies need to take information security seriously. The passage of the Sarbanes-Oxley Act has caused boards and especially audit committees to get much more involved in monitoring the performance and security of key information systems. This act requires companies to make new disclosures about internal controls and includes significant penalties and possible prison terms for executives of companies that are not in compliance. When I started with Symantec in 1999, information security was slowly becoming a major issue that executives had to address. More business was being conducted on the Internet, and system outages gained much more attention from the media. Many companies did not have formal information security programs, and security issues were addressed in an "ad hoc" fashion. Technology solutions at that time consisted mainly of firewalls and anti-virus software that operated independently. One of my challenges with my new position was to quickly gain an understanding of information security because Symantec had shifted its focus to address this market. Most of the literature that was available was very technical and did not provide a good overview for executives of how to put an effective information security program in place. Considering that I had spent the prior 25 years working in information technology, this would have been even more difficult for executives from other disciplines to understand. The industry has changed considerably over the past few years, and a simple virus that was a minor annoyance in the past has shifted to major threats such as Code Red that have caused major disruptions to businesses. Unfortunately, the future does not hold much promise for things to improve, and businesses will need to devote much more attention to this area. The objective of this book is to provide a shortcut for executives to learn more about information security and how it will affect their business in the future. An overview of information security concepts is provided so that executives can be better prepared to evaluate how their company is addressing information security. Pragmatic approaches are provided to assist companies in improving their information security programs. How This Book Is Organized This book focuses on three key themes: people, processes, and technology. These are the key elements of an effective information security program, and it is important to balance these components of the program. Considerable attention has been given to technology in the media and information security literature. However, this is just one element of an effective overall program. The best technology is not going to help if you do not have good staff and processes in place. This book is organized according to the steps you would follow to develop an information security program for your company. Chapter 1, "The Information Security Challenge," provides an overview of information security challenges and why executives should pay attention to the potential risks that these challenges pose to their business. A historical review of the Internet and information security incidents is also covered, and the chapter offers some insight into the power and vulnerability of conducting business electronically. Chapter 2, "Information Security Overview," provides an introduction to information security and the key elements of an effective program. The Security Evaluation Framework is introduced in Chapter 3, "Developing Your Information Security Program," and can be used to evaluate your information security program and develop a roadmap to improve your program. The overall methodology is reviewed, along with the critical areas to ensure success. The next three chapters are devoted to evaluating the people, process, and technology components of your information security program and developing an improvement plan. Chapter 7, "Information Security Roadmap," pulls all this analysis together and describes how to develop your roadmap to an improved information security program that is appropriate for your company. Future trends for information security are reviewed in Chapter 8, "View into the Future," which offers some insight into emerging threats and industry solutions to address these threats. This field is changing rapidly, and it is important to always keep up to date on the latest events. The final chapter lists the 10 essential components to an effective information security program and offers a good summary for anyone who wants to quickly identify areas for improvement. Additional sources of information and references are included in the appendixes. One final point is that this book is written from a vendor-neutral perspective; it does not contain references to commercially available security products and services. The focus is on industry best practices for information security. Due to the rapid changes in this industry, it is difficult to predict which companies will lead as the market evolves. The concepts outlined in this book can serve as a guide to choosing the appropriate products and services to support your program today and in the future. /> class="navigation"> Copyright Pearson Education. All rights reserved.

《The Executive Guide to Information Security》是一本专为专业从业者和管理层设计的权威参考书籍。该书以清晰而全面的结构,深入探讨了当前信息安全领域的重要概念、挑战与最佳实践。内容覆盖广泛,从基础的安全概念和风险管理,到具体的技术防护措施,再到高级策略的制定与实施,为读者提供系统性的知识框架。书中不仅详细描述了各类威胁及其应对方法,还强调了如何在不同业务环境中平衡安全性与运营效率。 其中一部分章节专注于信息保护的重要性,帮助读者理解信息安全不仅是技术问题,更涉及法律、伦理和管理的多方面考虑。这些内容通过实例分析和案例研究,增强了理论与实践的结合,使读者能够更全面地把握信息安全的实际应用场景。书中还详细介绍了常见的安全工具与方法,如加密技术、访问控制、身份验证及日志监控等,为用户提供实用且可操作的解决方案。 此外,该书不仅关注技术层面,还深入探讨了信息安全战略的制定与执行过程。通过系统性的指导,读者可以学会如何构建有效的安全政策,识别潜在风险,并设计出符合企业实际需求的安全措施。这一部分内容尤其适合管理层和负责任的IT决策者,帮助其在复杂多变的环境中做出明智的选择。书中还包含对未来信息安全趋势的预测,特别是人工智能、云计算和物联网等新兴技术带来的新挑战与机遇,使读者具备前瞻性的思考能力。 对于希望提升专业素养或希望深化自身在信息安全领域知识体系中的理解的人士,该书是一套非常完整的学习资源。它不仅强调理论知识的系统性,还注重实操操作,帮助读者掌握切实可行的安全实践。内容丰富、逻辑清晰,使得无论是初学者还是资深专家都能从中获得有价值的见解和指导。 总的来说,这本书以其详尽而专业的内容,旨在为信息安全管理人员提供一个权威且实用的参考工具,不仅帮助读者提升个人技能,还能推动整体组织信息安全水平的提升。这一系列深入浅出的内容使得读者能够从多个维度理解并应对当前复杂的信息安全环境。

作者简介

目录信息

读后感

评分

评分

评分

评分

评分

用户评价

评分

评分

评分

评分

评分

本站所有内容均为互联网搜索引擎提供的公开搜索信息,本站不存储任何数据与内容,任何内容与数据均与本站无关,如有需要请联系相关搜索引擎包括但不限于百度google,bing,sogou

© 2026 onlinetoolsland.com All Rights Reserved. 本本书屋 版权所有