Information Security Roles and Responsibilities Made Easy
Save money while building a leading security organization. Information Security Roles and Responsibilities Made Easy, Version 2 by Charles Cresson Wood, CISSP, CISA provides practical, step-by-step instructions on how to develop and document specific information security responsibilities for over 40 different key organizational roles. This valuable reference will save you time and money by providing pre-written job descriptions, mission statements, and organization charts that you can use and customize for your own organization.
Learn More
- Request free sample job descriptions!
- Data Sheet
- What's new in Version 2
- Read the Review
- Table of Contents
Get It Now
Information Security Roles & Responsibilities Made Easy provides:
1. Over 70 pre-written, time-saving information security documents including:- 29 information-security-related committee, board, and department mission statements, with information security responsibilities reflecting the latest technical and legal requirements.
- Over 40 information-security-related job descriptions.
- 12 separate information security organization structures with discussions of pros and cons of each.
- Specification and discussion of 29 critical information security documents that every organization should have.
- Standard practices that have been shown to be effective at over 125 organizations around the world.
- How to persuade management to properly document information security roles and responsibilities, including an easily-customized sample management memorandum.
- Reducing the total cost of information security services by properly documented roles and responsibilities.
- Discussion of responsibility and liability as it relates to documented information security roles, including citations supporting the legal notion of the standard of due care.
- Information security staffing data and analysis to help gain management support for additional resources.
- Common mistakes many organizations make and how to avoid them.
- Information on how to properly review and update information security roles and responsibilities, including department interview techniques.
- How to schedule project resources and time lines for documenting roles and responsibilities.
- Detailed discussion of the Data Owner, Custodian and User roles.
- Actions you should take to reduce your organization's exposure to workers in information security related positions of trust.
- The synergy between role based access control (RBAC) and clarification of information security roles and responsibilities.
- Pros and cons of outsourcing security functions, including validation and security when outsourcing.
- The security roles and responsibilities of software and hardware vendors.
- Decision-making criteria for releasing or withholding roles and responsibilities documentation to/from various external parties
- Characteristics of effective information security professionals, including discussion about the pros and cons of hiring hackers and others who have been on the wrong side of the law.
- Specific performance criteria for individuals and teams.
- An expanded list of new information professional certifications with web sites, phone numbers, and addresses for each.
Information Security Roles and Responsibilities is written by security policy consultant and expert Charles Cresson Wood CISSP, CISA, CISM who has over 20 years of experience writing and implementing information security roles and responsibility statements for companies worldwide. This book can be used effectively by anyone that needs to develop, refine, or otherwise specify information security organizational design documents, no matter what their prior experience in the information security field. Providing never before available "best practices," this book will help you develop, refine, and gain management approval of the information security function in an organization.
Information
Security Roles & Responsibilities Made Easy, Version 2 -
Hardcover, 278 pages. Includes CD ROM and organization-wide license
to reproduce the materials. Also available as electronic
download. Published by Information Shield.