000 02095cam a22003257i 4500
999 _c4695
_d4695
001 19253598
003 OSt
005 20250925114232.0
008 160830s2016 caua 001 0 eng d
010 _a 2016952621
020 _a9781484221396 (pbk.)
020 _a1484221397 (pbk.)
035 _a(OCoLC)ocn954429355
040 _aKYU
_beng
_cKYUL
_dKYUL
_dBDX
_dDLC
042 _alccopycat
050 0 0 _aQA76.9.A25
_bP656 2016
100 1 _aPompon, Raymond.
245 1 0 _aIT security risk control management :
_ban audit preparation plan /
_cRaymond Pompon.
246 3 _aI T security risk control management
260 _a[Berkeley, CA] :
_bApress
_cc2016.
300 _axxxi, 311 pages :
_billustrations ;
_c26 cm
500 _aIncludes index.
505 0 _aPart I: Getting a Handle on Things -- Chapter 1: Why Audit. Chapter 2: Assume Breach. Chapter 3: Risk Analysis: Assets and Impacts. Chapter 4: Risk Analysis: Natural Threats. Chapter 5: Risk Analysis: Adversarial Risk. Part II: Wrangling the Organization -- Chapter 6: Scope. Chapter 7: Governance. Chapter 8: Talking to the Suits. Chapter 9: Talking to the Techs. Chapter 10: Talking to the Users. Part III: Managing Risk with Controls -- Chapter 11: Policy. Chapter 12: Control Design. Chapter 13: Administrative Controls. Chapter 14: Vulnerability Management. Chapter 15: People Controls. Chapter 16: Logical Access Control. Chapter 17: Network Security Controls. Chapter 18: More Technical Controls. Chapter 19: Physical Security Controls. Part IV: Being Audited.-Chapter 20: Response Controls. Chapter 21: Starting the Audit. Chapter 22: Internal Audit. Chapter 23: Third Party Security. Chapter 24: Post Audit Improvement.
650 0 _aInformation technology
_xSchool of Pure and Applied Sciences
_xSchool of Pure and Applied Sciences
_2Computer Science
650 0 _aComputer security.
_2Computer Science
_xSchool of Pure and Applied Sciences
906 _a7
_bcbc
_ccopycat
_d2
_eepcn
_f20
_gy-gencatlg
942 _2lcc
_cLLB