02127cam a22003137i 4500999001500000001000900015003000400024005001700028008004100045010001700086020002500103020002200128035002400150040003500174042001400209050002600223100002100249245008800270246004100358260003700399300004600436500002000482505093300502650011901435650007801554906004501632942001301677952012301690 c4695d469519253598OSt20250925114232.0160830s2016 caua 001 0 eng d a 2016952621 a9781484221396 (pbk.) a1484221397 (pbk.) a(OCoLC)ocn954429355 aKYUbengcKYULdKYULdBDXdDLC alccopycat00aQA76.9.A25bP656 20161 aPompon, Raymond.10aIT security risk control management :ban audit preparation plan /cRaymond Pompon.3 aI T security risk control management a[Berkeley, CA] :bApresscc2016. axxxi, 311 pages :billustrations ;c26 cm aIncludes index.0 aPart I: Getting a Handle on Things -- Chapter 1: Why Audit. Chapter 2: Assume Breach. Chapter 3: Risk Analysis: Assets and Impacts. Chapter 4: Risk Analysis: Natural Threats. Chapter 5: Risk Analysis: Adversarial Risk. Part II: Wrangling the Organization -- Chapter 6: Scope. Chapter 7: Governance. Chapter 8: Talking to the Suits. Chapter 9: Talking to the Techs. Chapter 10: Talking to the Users. Part III: Managing Risk with Controls -- Chapter 11: Policy. Chapter 12: Control Design. Chapter 13: Administrative Controls. Chapter 14: Vulnerability Management. Chapter 15: People Controls. Chapter 16: Logical Access Control. Chapter 17: Network Security Controls. Chapter 18: More Technical Controls. Chapter 19: Physical Security Controls. Part IV: Being Audited.-Chapter 20: Response Controls. Chapter 21: Starting the Audit. Chapter 22: Internal Audit. Chapter 23: Third Party Security. Chapter 24: Post Audit Improvement. 0aInformation technologyxSchool of Pure and Applied SciencesxSchool of Pure and Applied Sciences2Computer Science 0aComputer security.2Computer SciencexSchool of Pure and Applied Sciences a7bcbcccopycatd2eepcnf20gy-gencatlg 2lcccLLB 00102lcc4070aKyUCLbKyUCLd2021-05-10l1oQA76.9 .P66 2016pKYU/2021/8576r2026-03-31s2023-01-07w2021-05-10yLLB