Information Technology Management, Information Technology Consulting & Information Technology Jobs

Categories
Information Technology Management

Complete Guide to Security and Privacy Metrics: Measuring Regulatory Compliance, Operational Resilience, and ROI

Complete Guide to Security and Privacy Metrics: Measuring Regulatory Compliance, Operational Resilience, and ROI

enlarge enlarge 
Author: Debra S. Herrmann
Publisher: Auerbach Publications
Category: Book

List Price: $124.95
Buy New: $87.98
You Save: $36.97 (30%)



New (14) Used (13) from $75.59

Rating: 5.0 out of 5 stars 1 reviews

Media: Hardcover
Edition: 1
Pages: 848
Number Of Items: 1
Shipping Weight (lbs): 3.7
Dimensions (in): 10.1 x 7.1 x 1.9

ISBN: 0849354021
Dewey Decimal Number: 005.8
EAN: 9780849354021

Publication Date: January 22, 2007
Availability: Usually ships in 1-2 business days

Also Available In:

  • Kindle Edition - COMPLETE GUIDE TO SECURITY AND PRIVACY METRICS: Measuring Regulatory Compliance, Operational Resilience, and ROI

Accessories:

A Practical Guide to Security Assessments
A Practical Guide to Security Assessments
IT Security Governance Guidebook with Security Program Metrics on CD-ROM (The CISO Toolkit)
IT Security Governance Guidebook with Security Program Metrics on CD-ROM (The CISO Toolkit)
Assessing and Managing Security Risk in IT Systems: A Structured Methodology
Assessing and Managing Security Risk in IT Systems: A Structured Methodology

Similar Items:

Security Metrics: Replacing Fear, Uncertainty, and Doubt
Security Metrics: Replacing Fear, Uncertainty, and Doubt
The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments
The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments
Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement
Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement
Enterprise Security Architecture: A Business-Driven Approach
Enterprise Security Architecture: A Business-Driven Approach
Information Security Management Handbook, Sixth Edition (Isc2 Press)
Information Security Management Handbook, Sixth Edition (Isc2 Press)

Editorial Reviews:

Product Description
While it has become increasingly apparent that individuals and organizations need a security metrics program, it has been exceedingly difficult to define exactly what that means in a given situation. There are hundreds of metrics to choose from and an organization’s mission, industry, and size will affect the nature and scope of the task as well as the metrics and combinations of metrics appropriate to accomplish it. Finding the correct formula for a specific scenario calls for a clear concise guide with which to navigate this sea of information.

Complete Guide to Security and Privacy Metrics: Measuring Regulatory Compliance, Operational Resilience, and ROI defines more than 900 ready to use metrics that measure compliance, resiliency, and return on investment. The author explains what needs to be measured, why and how to measure it, and how to tie security and privacy metrics to business goals and objectives. The book addresses measuring compliance with current legislation, regulations, and standards in the US, EC, and Canada including Sarbanes-Oxley, HIPAA, and the Data Protection Act-UK. The metrics covered are scaled by information sensitivity, asset criticality, and risk, and aligned to correspond with different lateral and hierarchical functions within an organization. They are flexible in terms of measurement boundaries and can be implemented individually or in combination to assess a single security control, system, network, region, or the entire enterprise at any point in the security engineering lifecycle. The text includes numerous examples and sample reports to illustrate these concepts and stresses a complete assessment by evaluating the interaction and interdependence between physical, personnel, IT, and operational security controls.

Bringing a wealth of complex information into comprehensible focus, this book is ideal for corporate officers, security managers, internal and independent auditors, and system developers and integrators.


Customer Reviews:
5 out of 5 stars The Oracle of Metrics (and I am not talking about the company)   March 8, 2007
Nikk Gilbert (Paris, France)
12 out of 13 found this review helpful

***This is a big book full of a lot of facts and figures.*** (Yes a very big book, not a cover to cover book.) 824 pages, 5 chapters and by no means a read it from cover to cover book. The first two chapters, the "Introduction" and "the What's and Whys of Metrics" are the authors interesting and quite knowledgeable overview of the world of operational, personal, physical and IT security metrics. After, the remaining chapters get in-depth. Chapter 3 "Measuring Compliance" goes into great detail about relating the different acts, bills, regulations and directives with various Metrics. Chapter 4 "Measuring Resilience" provides numerous worksheets and questionnaires as well as an abundance of information regarding threats, asset protection, mission protection, audit trails and others. Finally Chapter 5 "Measuring ROI" covers cost, benefits, some case studies and comparative analysis as well again some great worksheets.
A very useful and well organized guide. (Although a bit on the expensive side)


metrics  risk assessment  roi  security