The Virtual Bookcase for browsing and sharing reviews of books. New to this site? Read the welcome page first.

The Virtual Bookcase Home
Recent reviews
Collected book news
Welcome to this site
Add your own book

Book details of 'The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program'

Cover of The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program
TitleThe Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program
Author(s)Gerald L. Kovacich
ISBN0750698969
LanguageEnglish
PublisherButterworth-Heinemann
Web links for this book
Search at Bookcrossing.com
Wikipedia booksources
Shop for this book
At Amazon.com
At Amazon.co.uk

Back to shelf Computer security
Amazon.com info for The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program

Score:

Vote for this book

The Virtual Bookcase Reviews of 'The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program':

Reviewer Rob Slade wrote:
This book is not a list of those technical things that an information systems security (or InfoSec) officer (or ISSO) ought to know, but a guide to the process of acquiring and using that data. This is a guide to the ISSO career: what it is, how to train for it, how to do it, and how to tell if you are doing a good job. Chapter one repeats the adage that the world is changing. Unfortunately, this truism does not lead to much advise beyond the need to keep up with the technology. In the random assortment of waves and trends that are mentioned, some important points are missed. For example, along with the need to know something about your justice system (which is mentioned) and the rise of the Internet (which is mentioned), the fact that attacks over the Internet can come from anywhere, and that a knowledge of other justice systems may be needed for a prosecution that involves testimony from different countries and law enforcement agencies, is not mentioned. The position of the ISSO within a company is outlined in chapter two. Most of this material is more focussed than in chapter one, concentrating on corporate politics. One rather important aspect that does not get any space is the production and maintenance of a security policy, and the games that may have to be played around it. The company side is somewhat extended in chapter three by building a simulated corporation to use as a test case. However, few of the items addressed in the chapter have an awful lot of security involvement. One very definitely does, and is missed: the subcontractors of the simulated organization know and use a vital proprietary process, but no mention is made of ensuring that these contractors are sufficiently guarding *their* data. Chapter four outlines a career development plan, but it boils down to "have a degree, get experience, attend conferences, and read other stuff." The most useful information provided is on the Certified Information Systems Security Professional (CISSP) designation and contact data for some of the professional groups. As the book itself states, you probably have already attended a job interview or two in your time, so the advice in chapter five is likely redundant. It certainly isn't extensive. Chapter six's list of duties has two major problems. One is that there is no overall structure for the material, so it is hard to place into a context of priorities and tasks to be accomplished. The second is that the outline assumes one size fits all jobs. The text assumes the ISSO will be responsible for management of a team of InfoSec staff: only the largest of corporations have multiple security personnel, let alone a manager dedicated to them. The outline of business plans in chapter seven follows the usual style not only in format, but also in not providing any really solid information about what is to be done. Chapter eight's discussion of building an InfoSec organization basically repeats political advice from chapter two and job descriptions from chapter four. The look at InfoSec functions again repeats content from chapters two and six, although chapter nine does finally take a brief look at policies. Chapter ten introduces metrics in order to measure the performance of the InfoSec department. Most of the examples used deal with the administration of security, rather than measures of actual protection. There is a rehash of planning, with an emphasis on annual reviews, in chapter eleven. A brief review of current security concerns finishes off the book in chapter twelve. While this book is not intended to address the technical side of security, there is no reason that it couldn't be based on real and hard data. An overview of data security positions that do exist, the numbers of such positions, the courses actually available, and what the incumbents actually do would have added immensely to the value of the book. This volume does address a gap in the security literature, and it is important to know the business and managerial side of the security maven's job, but this work does not explain it very well. copyright Robert M. Slade, 1998
Add my review for The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program

Book description:

The information systems security (infosec) profession is one of the fastest growing professions today, which has caused an ever-increasing need and demand for training of security professionals. With the advent of email and the Internet and their wide uses as methods of conducting business, a growing amount of emphasis is being placed on infosec.This valuable guide presents a straight-forward business approach to the topics needed for the infosec professional. Covering a broad range of topics, beginning with defining the position of the information systems security officer (ISSO), to establishing and managing an infosec program, the author writes from over 14 years of research and experience. Each chapter ends with thought-provoking questions for use by the instructor.* Total systems approach* Straightforward, easy-to-read, non-technical writing

Search The Virtual Bookcase

Enter a title word, author name or ISBN.

The shelves in The Virtual Bookcase

Arts and architecture (25)
Biography (24)
Business and Management (119)
Cars and driving (53)
Cartoons (45)
Children's books (179)
Computer (475)
Computer history/fun (111)
Computer networks (382)
Computer programming (215)
Computer security (269)
Cook books (89)
Fantasy (154)
Fiction (446)
Health and body (70)
History (135)
Hobby (37)
Horror (65)
Humorous books (52)
Literature (57)
Operating systems (94)
Outdoor camping (162)
Outdoors (236)
Politics (83)
Privacy (61)
Psychology (55)
Religion (17)
Science (113)
Science Fiction (156)
Self-help books (55)
Technology (12)
Travel guides (307)
War and weapons (29)
World Wide Web (211)
Zen (5)
Other books (88)
Mailing list
Subscribe to booktalk, the discussion list about books at The Virtual Bookcase.
Enter your e-mail address to subscribe (you will receive an e-mail to confirm your subscription):


The Virtual Bookcase is created and maintained by Koos van den Hout. Contact e-mail webmaster@virtualbookcase.com.
Site credits
Copyright © 2000-2009 Koos van den Hout / The Virtual Bookcase Copyright and privacy statement