Buy New

or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Kindle Edition
Read instantly on your iPad, PC or Mac, no Kindle required
Buy Price: $34.29
Rent From: $14.66
 
 
   
Buy Used
Used - Very Good See details
$19.56 & eligible for FREE Super Saver Shipping on orders over $25. Details

or
Sign in to turn on 1-Click ordering.
 
   
More Buying Choices
Have one to sell? Sell yours here
Risk Management for Computer Security: Protecting Your Network & Information Assets
 
 

Risk Management for Computer Security: Protecting Your Network & Information Assets [Paperback]

Andy Jones (Author), Debi Ashenden (Author)
5.0 out of 5 stars  See all reviews (1 customer review)

Price: $50.95 & this item ships for FREE with Super Saver Shipping. Details
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Want it delivered Wednesday, February 1? Choose One-Day Shipping at checkout. Details

Formats

Amazon Price New from Used from
Kindle Edition
Rent from
$34.29
$14.66
 
Paperback $50.95  

Book Description

March 29, 2005
The information systems security (InfoSec) profession remains one of the fastest growing professions in the world today. With the advent of the Internet and its use as a method of conducting business, even more emphasis is being placed on InfoSec. However, there is an expanded field of threats that must be addressed by today's InfoSec and information assurance (IA) professionals.
Operating within a global business environment with elements of a virtual workforce can create problems not experienced in the past. How do you assess the risk to the organization when information can be accessed, remotely, by employees in the field or while they are traveling internationally? How do you assess the risk to employees who are not working on company premises and are often thousands of miles from the office? How do you assess the risk to your organization and its assets when you have offices or facilities in a nation whose government may be supporting the theft of the corporate "crown jewels" in order to assist their own nationally owned or supported corporations? If your risk assessment and management program is to be effective, then these issues must be assessed.
Personnel involved in the risk assessment and management process face a much more complex environment today than they have ever encountered before.
This book covers more than just the fundamental elements that make up a good risk program. It provides an integrated "how to" approach to implementing a corporate program, complete with tested methods and processes; flowcharts; and checklists that can be used by the reader and immediately implemented into a computer and overall corporate security program. The challenges are many and this book will help professionals in meeting their challenges as we progress through the 21st Century.

*Presents material in an engaging, easy-to-follow manner that will appeal to both advanced INFOSEC career professionals and network administrators entering the information security profession
*Addresses the needs of both the individuals who are new to the subject as well as of experienced professionals
*Provides insight into the factors that need to be considered & fully explains the numerous methods, processes & procedures of risk management

Frequently Bought Together

Customers buy this book with The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments, Second Edition $64.92

Risk Management for Computer Security: Protecting Your Network & Information Assets + The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments, Second Edition
Price For Both: $115.87

Show availability and shipping details



Editorial Reviews

Book Description

Provides IT professionals with an integrated plan to establish and implement a corporate risk assessment and management program

About the Author

Andy Jones is an experienced Military Intelligence Analyst and Information Technology Security specialist. He has had considerable experience in the analysis of Intelligence material in Strategic, Tactical and Counter-Insurgency operations and a wide range of Information systems management experience. In addition, he has considerable experience in the security of Information Technology systems, having been responsible for the implementation of Information Technology security within all areas of the British Army and in some joint service organizations. He has directed both Intelligence and Security operations and briefed the results at the highest level. He was awarded the MBE for his work during his service in Northern Ireland and has gained an Open University Bachelor of Science degree in mathematics and technology and a Masters degree in Information Security and Computer Crime from the University of Glamorgan. After completing 25 years service with the British Army's Intelligence Corps, he moved into the area of defense research and was employed as the manager of a group of 80 research scientists and as a researcher and analyst in the area of Information Security. He has also had experience as a project manager within defense research for the security aspects of a number of large projects and has gained considerable expertise on the criminal and terrorist aspects of Information Security. He has undertaken a range of research into a number of aspects of Information warfare and the threats to information systems. 1n 2002 he co-authored a book on information warfare and is currently researching to write a book on the risks to information systems. In addition to his main work as a senior lecturer on Information Security and Computer Crime at the University of Glamorgan, he is currently also an associate lecturer for the Open University on Internet communications. His primary area of research for the last two years has been into methods for the measurement of t

Debi has a well-developed set of "soft" consultancy skills and experience developed by her formal education in the Arts and subsequent experience as a lecturer and advisor to students in colleges of further education. She has built on this so as to develop a set of IT skills through additional training with Birmingham University. Moreover she has deployed these skills to good effect in both civil and military consulting assignments. In this latter phase Debi's M.Sc. work was directed at investigating issues of system lifecycle security under DERA (now QinetiQ) sponsorship. Debi has also led the development and application of security risk analysis techniques within the Trusted Information Management Department at QinetiQ. She was previously the Head of Professional Services in the Trusted Information Management department at QinetiQ, the privatised element of what was previously the Defence Evaluation and Research Agency and is currently a Senior Research Fellow in Information Assurance at the Royal Military College of Science, Cranfield University.


Product Details

  • Paperback: 296 pages
  • Publisher: Butterworth-Heinemann; 1 edition (March 29, 2005)
  • Language: English
  • ISBN-10: 0750677953
  • ISBN-13: 978-0750677950
  • Product Dimensions: 8.9 x 6.1 x 0.7 inches
  • Shipping Weight: 1.1 pounds (View shipping rates and policies)
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (1 customer review)
  • Amazon Best Sellers Rank: #1,401,997 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

1 Review
5 star:
 (1)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
5.0 out of 5 stars (1 customer review)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

9 of 9 people found the following review helpful:
5.0 out of 5 stars Best Risk Management book on the market today!, April 28, 2005
By 
ShockwaveWriter (Whidbey Island, Washington, USA) - See all my reviews
This review is from: Risk Management for Computer Security: Protecting Your Network & Information Assets (Paperback)
There are many books on the market dealing with risk management as part of InfoSec. So, I wasn't sure that this one would be better, or provide any new information. I was first surprised to find it written in a non-techie way. That means the information is easy to read and more importantly, easy to understand. Also, because it is written by two authors from the UK, it offers a slightly different look than what has been written on the topic by numerous U.S. authors.

What I especially liked about this book is that it not only dealt with all of today's relative risk management issues but the section on "The Threat Assessment Process" was really well done. Often this is not given the importance it deserves as other authors concentrated on the risks. However, one must know the enemies to defend again them. This part was a nice surprise.

So for today's professional whose experience is vast or limited, this book offers all you need to know about risk manaagement as it relates to InfoSec - or "Computer Security" as the authors call it.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Inside This Book (learn more)
First Sentence:
Here we introduce a brief history of risk management through the changing scope of information security risk, the evolving methods for carrying out a risk assessment, and the changing configurations of drivers for undertaking risk assessment. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
information security risk manager, threat amplifiers, potential threat capability, threat amplification, security risk managers, threat agent catalysts, metrics for the catalysts, threat inhibitor, information security risk assessment, terrorist threat agent, malicious threat agents, total maximum value, threat inhibition, information security environment, information security risk management, information warfare capability, security risk assessments, information security risks, critical national infrastructure, value weighting, threat profiles, open source material, risk mitigation strategies, potential maximum, risk assessment process
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Total Value of Influences, United Kingdom, United States, Weighting Value Factor, Aerospaciale France, Limited Adequate High, None Very, Department of Defense, None Extremely, Outlook Express, Catalysts Table, Coordination Center, Far East, Information Security Forum, International International, Motivation Motivation, National National, None Limited Low Medium High Very, Scott Morton, Threat Inhibitors Table, Turnbull Report, Basel Committee, British Standard, Computer Related Risks, Hong Kong
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Surprise Me!
Search Inside This Book:

Citations (learn more)
This book cites 3 books:



What Other Items Do Customers Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

Search Customer Discussions
Search all Amazon discussions
   


Listmania!


Create a Listmania! list

So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject