Management Of Information Security
Michael E. Whitman, Herbert J. Mattord · 2004
1. Introduction to the Management of Information Security 2. Planning for Security 3. Planning for Contingencies 4. Information Security Policy 5. Developing the Security Program 6. Security Management Models and Practices 7. Risk Management: Identifying and Assessing Risk 8. Risk Management: Controlling Risk 9. Protection Mechanisms 10. Personnel and Security 11. Law and Ethics 12. Information Security Project Management Appendix A: NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems, and ISO 17799:2005 Overview