<?xml version="1.0" encoding="UTF-8"?>
<mods xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.1" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-1.xsd">
  <titleInfo>
    <title>IT security risk control management</title>
    <subTitle>an audit preparation plan</subTitle>
  </titleInfo>
  <titleInfo type="alternative">
    <title>I T security risk control management</title>
  </titleInfo>
  <name type="personal">
    <namePart>Pompon, Raymond.</namePart>
    <role>
      <roleTerm authority="marcrelator" type="text">creator</roleTerm>
    </role>
  </name>
  <typeOfResource>text</typeOfResource>
  <originInfo>
    <place>
      <placeTerm type="code" authority="marccountry">cau</placeTerm>
    </place>
    <place>
      <placeTerm type="text">Berkeley, CA]</placeTerm>
    </place>
    <publisher>Apress</publisher>
    <dateIssued>c2016</dateIssued>
    <dateIssued encoding="marc">2016</dateIssued>
    <issuance>monographic</issuance>
  </originInfo>
  <language>
    <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
  </language>
  <physicalDescription>
    <form authority="marcform">print</form>
    <extent>xxxi, 311 pages : illustrations ; 26 cm</extent>
  </physicalDescription>
  <tableOfContents>Part I: Getting a Handle on Things -- Chapter 1: Why Audit. Chapter 2: Assume Breach. Chapter 3: Risk Analysis: Assets and Impacts. Chapter 4: Risk Analysis: Natural Threats. Chapter 5: Risk Analysis: Adversarial Risk. Part II: Wrangling the Organization -- Chapter 6: Scope. Chapter 7: Governance. Chapter 8: Talking to the Suits. Chapter 9: Talking to the Techs. Chapter 10: Talking to the Users. Part III: Managing Risk with Controls -- Chapter 11: Policy. Chapter 12: Control Design. Chapter 13: Administrative Controls. Chapter 14: Vulnerability Management. Chapter 15: People Controls. Chapter 16: Logical Access Control. Chapter 17: Network Security Controls. Chapter 18: More Technical Controls. Chapter 19: Physical Security Controls. Part IV: Being Audited.-Chapter 20: Response Controls. Chapter 21: Starting the Audit. Chapter 22: Internal Audit. Chapter 23: Third Party Security. Chapter 24: Post Audit Improvement.</tableOfContents>
  <note type="statement of responsibility">Raymond Pompon.</note>
  <note>Includes index.</note>
  <subject authority="lcsh">
    <topic>Information technology</topic>
    <topic>School of Pure and Applied Sciences</topic>
    <topic>School of Pure and Applied Sciences</topic>
  </subject>
  <subject authority="lcsh">
    <topic>Computer security</topic>
    <topic>School of Pure and Applied Sciences</topic>
  </subject>
  <classification authority="lcc">QA76.9.A25 P656 2016</classification>
  <identifier type="isbn">9781484221396 (pbk.)</identifier>
  <identifier type="isbn">1484221397 (pbk.)</identifier>
  <identifier type="lccn">2016952621</identifier>
  <recordInfo>
    <recordContentSource authority="marcorg">KYU</recordContentSource>
    <recordCreationDate encoding="marc">160830</recordCreationDate>
    <recordChangeDate encoding="iso8601">20250925114232.0</recordChangeDate>
    <recordIdentifier source="OSt">19253598</recordIdentifier>
    <languageOfCataloging>
      <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
    </languageOfCataloging>
  </recordInfo>
</mods>
