INFORMATION SECURITY POLICIES AND PROCEDURES: A PRACTITIONER’S REFERENCE, SECOND EDITION

Product Description
This book illustrates how to rise a associated standards, procedures, as good as discipline for implementing policy. Each section provides recommendation upon a constructional mechanics of a assorted papers as good as an e.g. of any form. This brand new book updates element upon a judgment of responsibilities which reflects a ubiquitous inlet of a people responsible. Standards as good as procedures have been additionally updated to simulate a work finished in a margin during 2002 with additiona… More >>

Information Security Policies as good as Procedures: A Practitioner’s Reference, Second Edition

, , , , , , ,

5 Comments

  • Eric Kent says:

    If you are doing infosec policy dev., this book is aweseome!

    It saved me 10 hours this week alone.
    Rating: 5 / 5

  • Frank Cusack says:

    I must agree with the previous reviewer, this book is lacking.
    I bought a copy new and had the same problem where the
    holes punched in the paper does not match the binder spacing.
    What terrible quality. I had to force myself to even read
    through the book after that.

    And I found it lacking. The first part has some good info
    about how to write a policy. Good but not great.

    The second part was a sample policy/standard/procedure rolled
    into one. I found it too thin and missing too much to be
    really useful.

    I haven’t looked at the text the previous reviewer recommends,
    but I have to say, given another book with similar content,
    definitely stay away from this one.

    My personal recommendation is Information Security Policies
    Made Easy, by Charles Cresson Wood. It’s pricey but oh so
    worth it.
    Rating: 2 / 5

  • It explains how why and how to integrate security policies and procedures across all tiers of software engineering organization. I had limited understanding f and this book helped me to get deep in to details and understand at an organization level.

    I recommend this for all engineers and managers in sofware organization.
    Rating: 5 / 5

  • This is one of the best books available for information systems security polices. The book covers tier 1 and tier 2 policies. This book looks at policies as a business enabler where policies support management’s organizational goals. Great samples!
    Rating: 5 / 5

  • This is a useful book for me to reference, especially when I deal with challenges in security policy framework review. The most impressive pages include the tier 1-2-3 framework, proper wordings in policy, policy sample studies and analysis, complete checklist and questionnaire.

    After reading this book or on-and-off reference, I always remember four major elements in a policy:

    1. Topic

    2. Scope

    3. Responsibility

    4. Compliance

    In addition, I have shared this book with an IT supervisor, he always go for this book for the team reference. I do feel happy to recommend it. Moreover, it readily happens to me I could apply the hints and tips from this book to the revised policy. Meanwhile, compared with the company’s policy, it is undoubted organized and logical.

    Be honest, in reality, many people still always mix up policy, standard and procedures as well as guidelines and produce a “Spaghetti-like” document to deal with auditor and compliance once a year only, you could say, many companies treat it as a last-minute homework.

    Rating: 5 / 5

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Security Code:

Powered by Yahoo! Answers