or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
More Buying Choices
Have one to sell? Sell yours here
Risk Management Solutions for Sarbanes-Oxley Section 404 IT Compliance
 
 
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Risk Management Solutions for Sarbanes-Oxley Section 404 IT Compliance [Paperback]

John S. Quarterman (Author)
5.0 out of 5 stars  See all reviews (1 customer review)

Price: $65.00 & this item ships for FREE with Super Saver Shipping. Details
  Special Offers Available
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 1 left in stock--order soon.
Want it delivered Monday, January 30? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for Students. Learn more


Book Description

0764598392 978-0764598395 January 11, 2006 1
  • Examines how risk management security technologies must prevent virus and computer attacks, as well as providing insurance and processes for natural disasters such as fire, floods, tsunamis, terrorist attacks
  • Addresses four main topics: the risk (severity, extent, origins, complications, etc.), current strategies, new strategies and their application to market verticals, and specifics for each vertical business (banks, financial institutions, large and small enterprises)
  • A companion book to Manager's Guide to the Sarbanes-Oxley Act (0-471-56975-5) and How to Comply with Sarbanes-Oxley Section 404 (0-471-65366-7)

Special Offers and Product Promotions

  • Buy $50 in qualifying physical textbooks, get $5 in Amazon MP3 Credit. Here's how (restrictions apply)

Frequently Bought Together

Customers buy this book with Management Strategies for the Cloud Revolution: How Cloud Computing Is Transforming Business and Why You Can't Afford to Be Left Behind $16.55

Risk Management Solutions for Sarbanes-Oxley Section 404 IT Compliance + Management Strategies for the Cloud Revolution: How Cloud Computing Is Transforming Business and Why You Can't Afford to Be Left Behind


Editorial Reviews

From the Back Cover

If your company does business on the Internet, your risks are growing exponentially. Worms, viruses, cracker attacks, mechanical failures, and natural disasters create a climate that compromises performance as well as security. Traditional solutions are too limited to address these risks. You need a strategy designed for today, and this book will help you build one.

  • Understand the risks faced by your particular business
  • Learn to assess the extent, origins, complications, growth, and potential severity of your risk factors
  • Examine and analyze strategies already in place
  • Explore new strategies and their application in various market contexts
  • Devise and implement a solution that is tailored to your enterprise and meets the requirements of Sarbanes-Oxley Section 404

About the Author

John S. Quarterman has previously coauthored The 4.2BSD Berkeley Unix Operating System1 and its successor edition, as well as The Matrix: Computer Networks and Conferencing Systems Worldwide2 and other books. Mr. Quarterman is CEO of InternetPerils, Inc., an Internet business risk management company that is extending risk management strategies available to business into new areas such as insurance, catastrophe bonds, and performance bonds.
He has 26 years of experience in internetworking, beginning with work on ARPANET software at BBN. In 1990, he incorporated MIDS, which published the first maps of the whole Internet and conducted the first Internet Demographic Survey. In 1993, he started the first series of performance data about the entire Internet, visible on the web since 1995 as the Internet Weather Report, which together with the Internet Average and ISP Ratings, were some of the most cited analyses available.

Product Details

  • Paperback: 312 pages
  • Publisher: Wiley; 1 edition (January 11, 2006)
  • Language: English
  • ISBN-10: 0764598392
  • ISBN-13: 978-0764598395
  • Product Dimensions: 9.2 x 7.4 x 0.7 inches
  • Shipping Weight: 1 pounds (View shipping rates and policies)
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (1 customer review)
  • Amazon Best Sellers Rank: #1,526,649 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

1 Review
5 star:
 (1)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
5.0 out of 5 stars (1 customer review)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

2 of 2 people found the following review helpful:
5.0 out of 5 stars All About Early 21st Century Risk, June 23, 2006
By 
This review is from: Risk Management Solutions for Sarbanes-Oxley Section 404 IT Compliance (Paperback)
This book is unique, as far as I know, as a very timely analysis on technical issues and their impact on risk management.

Chapter 1 looks at three power laws for scaling networks - Sarnoff, Metcalfe and Reed. Valuing assets is a precursor to any risk management activity. Chapter 2 looks at the differences between traditional risk and Internet-style risks. There is an important distinction in perils and anomalies. Perils are defined as bugs and vulnerabilities. Anomalies are defined as the problems that arise once a vulnerability is exercised. There is also a section on monoculture which compares computing monoculture to bollweevils and other physical world monoculture risks.

Chapter 3 describes high level strategies like redundancy and backups for dealing with risks. These are high level not detailed operational planning, but they are useful for directors to plan what actions manage what risks. Federation is mentioned as having a positive impact on higher assurance integration between service providers and consumers. Another theme is the positive and negative aspects of decentralization, Quarterman concludes it is largely a positive development, and a decade and half into the web, that looks like a safe assumption.

For a book with Sarbanes in its title, there is not a ton of information on compliance. This is not a big a problem for me, since I, like this book, view compliance as a subset of risk management. Chapters 4-8 look at the implications of risk in various business sizes and verticals.

Chapter 6 examines some physical world controls that work fine in the real world but are insufficient in the digital world such as 4 digit PINs for ATMs. This chapter also covers various types of insurance schemes such as Cat Bonds.

Chapter 7 compares Frederick Winslow Taylor (command and control) to John Boyd (smart nodes) and concludes - Taylor Wrong. Boyd Right. Speed and autonomy are more valuable in a networked world. It is often said the important stuff is not exciting, risk management may not be a thrill a minute for everyone, but this book shows why risk management is important to businesses.

Chapter 8 contains an history of technologies, but does not address SOA, Web Services, Web 2.0 et. al in the context of the 5th Wave. Chapter 9 deals with a recurring theme on differentiating between risk inside the perimeter and outside the perimeter and the disparate strategies available. Chapter 10 describes some key differences between SOX (looking for black list items) and Basel II (culture change). Boyd's OODA loop is revisited in the context of self-healing networks. There is a section on the modern military's reliance on the web, which reminded me of a story by Thomas Barnett about how soldiers in Iraq were going into chat rooms to teach other about counterinsurgency. The officers instructed them to stop because Al Qaeda would listen in, the soldier's response:"Al Qaeda already knows this. We are the ones with the knowledge gap." Now the training manuals are being updated.

My favorite part of the book is Cliff Forts versus Coordinated Mesas which detailes the ancient Anasazis Protect-Detect-Respond strategy.

Chapter 11 discerns between first party loss and third party loss. Chapter 12 contains a set of actionable items for companies wanting to improve their risk management.

Overall, a useful window into the current risks and risk management opportunities in the early 21st century.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Inside This Book (learn more)
First Sentence:
Internet risks beyond the firewall have grown rapidly since 2000 into cyber-hurricanes that are force majeure risks that threaten every enterprise that uses the Internet, yet they are beyond the control of any enterprise. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
internet perils, risk transfer instruments, business continuity insurance, peril detection, capital withholding, disaster accounting, catastrophe bonds, cat bonds, software diversity, liability programs, reputation systems, mance bonds, majeure events, risk management solutions, aggregate damage, business risk management, fifth wave, electronic crime, operational risk, risk management plan
Key Phrases - Capitalized Phrases (CAPs): (learn more)
United States, New York, Indian Ocean, Metcalfe's Law, Ingram Micro, Sound Practices, University of California, Bruce Schneier, Department of Homeland Security, Bob Metcalfe, Bruce Sterling, Cumbre Vieja, Michael Lynn, National Strategy, Secure Cyberspace, Social Security, Howard Rheingold, Hurricane Ivan, Lord Levene, Robert Lemos, Scott Bradner, Standardized Approach, University of Minnesota, World Wide Web, Cisco Tries
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:




Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums


Listmania!


Create a Listmania! list

So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject