Buy New

or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Kindle Edition
Read instantly on your iPad, PC or Mac, no Kindle required
Buy Price: $47.96
Rent From: $14.45
 
 
 
Buy Used
Used - Like New See details
$49.21 & this item ships for FREE with Super Saver Shipping. Details

or
Sign in to turn on 1-Click ordering.
 
   
Sell Back Your Copy
For a $19.43 Gift Card
Trade in
More Buying Choices
Have one to sell? Sell yours here
Assessing and Managing Security Risk in IT Systems: A Structured Methodology
 
 

Assessing and Managing Security Risk in IT Systems: A Structured Methodology [Hardcover]

John McCumber (Author)
4.0 out of 5 stars  See all reviews (2 customer reviews)

List Price: $67.95
Price: $61.19 & this item ships for FREE with Super Saver Shipping. Details
You Save: $6.76 (10%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 3 left in stock--order soon (more on the way).
Want it delivered Tuesday, February 14? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for students on millions of items. Learn more

Formats

Amazon Price New from Used from
 
Kindle Edition
Rent from
$47.96
$14.45
 
Hardcover $61.19  
Sell Back Your Copy for $19.43
Whether you buy it used on Amazon for $41.64 or somewhere else, you can sell it back through our Book Trade-In Program at the current price of $19.43.
Used Price$41.64
Trade-in Price$19.43
Price after
Trade-in
$22.21

Book Description

June 15, 2004 0849322324 978-0849322327 1
Assessing and Managing Security Risk in IT Systems: A Structured Methodology builds upon the original McCumber Cube model to offer proven processes that do not change, even as technology evolves. This book enables you to assess the security attributes of any information system and implement vastly improved security environments.

Part I delivers an overview of information systems security, providing historical perspectives and explaining how to determine the value of information. This section offers the basic underpinnings of information security and concludes with an overview of the risk management process.

Part II describes the McCumber Cube, providing the original paper from 1991 and detailing ways to accurately map information flow in computer and telecom systems. It also explains how to apply the methodology to individual system components and subsystems.

Part III serves as a resource for analysts and security practitioners who want access to more detailed information on technical vulnerabilities and risk assessment analytics. McCumber details how information extracted from this resource can be applied to his assessment processes.

Frequently Bought Together

Customers buy this book with Enterprise Risk Management: A Methodology for Achieving Strategic Objectives (Wiley and SAS Business Series) $45.50

Assessing and Managing Security Risk in IT Systems: A Structured Methodology + Enterprise Risk Management: A Methodology for Achieving Strategic Objectives (Wiley and SAS Business Series)
Price For Both: $106.69

Show availability and shipping details



Product Details

  • Hardcover: 288 pages
  • Publisher: Auerbach Publications; 1 edition (June 15, 2004)
  • Language: English
  • ISBN-10: 0849322324
  • ISBN-13: 978-0849322327
  • Product Dimensions: 9.3 x 6.3 x 0.8 inches
  • Shipping Weight: 1 pounds (View shipping rates and policies)
  • Average Customer Review: 4.0 out of 5 stars  See all reviews (2 customer reviews)
  • Amazon Best Sellers Rank: #689,093 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

2 Reviews
5 star:
 (1)
4 star:    (0)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.0 out of 5 stars (2 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

4 of 5 people found the following review helpful:
3.0 out of 5 stars Interesting but repetitive, September 21, 2008
This review is from: Assessing and Managing Security Risk in IT Systems: A Structured Methodology (Hardcover)
The book essentially describes the McCumber Cube information security methodology.
And the McCumber Cube methodology is indeed interesting and worth the read.

Unfortunately, the author wrote around it a whole book!
In the first part the author describes the bases on the information security and relates it to the McCumber Cube (without really describing what the Cube is! Luckily, the hardcover has a picture of it.)
In the second part he dwelves in a little more detail of the McCumber Cube methodology, repeating again and again the same concepts, just with slight viewpoint variations.

Obviously his methodology is described as superior to any other methodology! While he makes a few good points, often he just states this without really comparing it to the other technologies.

Worth the read if you have time to spare... it indeed has a few interesting ideas and viewpoints.
If only they were expressed in a tenth of the space!

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


2 of 4 people found the following review helpful:
5.0 out of 5 stars Fabulous!, April 26, 2007
This review is from: Assessing and Managing Security Risk in IT Systems: A Structured Methodology (Hardcover)
I had John as my Info Sec professor for two classes. His insight in class has given me such a passion for InfoSec! I undoubtedly believe his book will do the same! If you can hear him lecture it will only drive your passion even more for the need for and drive towards info security! Anyone who is truly in need of the 'ah-ha' effect should buy this book!
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Inside This Book (learn more)
First Sentence:
In the late 17th century, as the story goes, Sir Isaac Newton observed an apple fall from a tree. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
information systems security program, information state map, information state changes, network topology map, threat measurement, technology safeguards, information security program, security practitioner, technical vulnerabilities, security policy requirements, security life cycle, electronic exposure, remote attackers, layered security, occurrence measurement, transmission state, storage state, technical safeguards, security attributes, information valuation, security safeguards, threat profile, confidentiality controls, security researchers, processing state
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Common Criteria, Orange Book, Pearl Harbor, United States, World War, Rainbow Series, German Enigma, Trusted Computer System Evaluation Criteria
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:





Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(64)
(7)

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject