01883cam a22002657i 450000100090000000300040000900500170001300800410003001000170007102000250008802000220011303500240013504000350015904200140019405000260020810000210023424500880025524600410034326000370038430000460042150000200046750509330048765001190142065000780153919253598OSt20250925114232.0160830s2016 caua 001 0 eng d a 2016952621 a9781484221396 (pbk.) a1484221397 (pbk.) a(OCoLC)ocn954429355 aKYUbengcKYULdKYULdBDXdDLC alccopycat00aQA76.9.A25bP656 20161 aPompon, Raymond.10aIT security risk control management :ban audit preparation plan /cRaymond Pompon.3 aI T security risk control management a[Berkeley, CA] :bApresscc2016. axxxi, 311 pages :billustrations ;c26 cm aIncludes index.0 aPart I: Getting a Handle on Things -- Chapter 1: Why Audit. Chapter 2: Assume Breach. Chapter 3: Risk Analysis: Assets and Impacts. Chapter 4: Risk Analysis: Natural Threats. Chapter 5: Risk Analysis: Adversarial Risk. Part II: Wrangling the Organization -- Chapter 6: Scope. Chapter 7: Governance. Chapter 8: Talking to the Suits. Chapter 9: Talking to the Techs. Chapter 10: Talking to the Users. Part III: Managing Risk with Controls -- Chapter 11: Policy. Chapter 12: Control Design. Chapter 13: Administrative Controls. Chapter 14: Vulnerability Management. Chapter 15: People Controls. Chapter 16: Logical Access Control. Chapter 17: Network Security Controls. Chapter 18: More Technical Controls. Chapter 19: Physical Security Controls. Part IV: Being Audited.-Chapter 20: Response Controls. Chapter 21: Starting the Audit. Chapter 22: Internal Audit. Chapter 23: Third Party Security. Chapter 24: Post Audit Improvement. 0aInformation technologyxSchool of Pure and Applied SciencesxSchool of Pure and Applied Sciences2Computer Science 0aComputer security.2Computer SciencexSchool of Pure and Applied Sciences