Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
3 used & new from $305.00

Have one to sell? Sell yours here
 
   
Information Security Roles & Responsibilities Made Easy, Version 2
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Information Security Roles & Responsibilities Made Easy, Version 2 (Hardcover)

by Charles Cresson Wood (Author) "The total cost of ownership (TCO) models developed by a variety of industry analysts such as the Gartner Group indicate that labor represents anywhere from..." (more)
Key Phrases: Responsibilities Made Easy, Information Technology Department, Human Resources Department (more...)
4.7 out of 5 stars See all reviews (3 customer reviews)

List Price: $495.00
Price: $495.00 & this item ships for FREE with Super Saver Shipping. Details
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Monday, July 20? Choose One-Day Shipping at checkout. Details
2 new from $305.00 1 used from $326.00

Frequently Bought Together

Information Security Roles & Responsibilities Made Easy, Version 2 + Information Security Policies Made Easy, Version 10 + Security Metrics: Replacing Fear, Uncertainty, and Doubt
Price For All Three: $1,321.49

Show availability and shipping details


Customers Who Bought This Item Also Bought

Security Metrics: Replacing Fear, Uncertainty, and Doubt

Security Metrics: Replacing Fear, Uncertainty, and Doubt

by Andrew Jaquith
4.6 out of 5 stars (20)  $31.49
Managing an Information Security and Privacy Awareness and Training Program

Managing an Information Security and Privacy Awareness and Training Program

by Rebecca Herold
4.8 out of 5 stars (6)  $56.66
Computer Security: 20 Things Every Employee Should Know (McGraw-Hill Professional Education)

Computer Security: 20 Things Every Employee Should Know (McGraw-Hill Professional Education)

by Ben Rothke
4.7 out of 5 stars (21)  $7.87
The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments

The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments

by Douglas J. Landoll
5.0 out of 5 stars (4)  $67.16
Kindle DX: Amazon's 9.7" Wireless Reading Device (Latest Generation)

Kindle DX: Amazon's 9.7" Wireless Reading Device (Latest Generation)

4.1 out of 5 stars (363)  $489.00
Explore similar items

Editorial Reviews

Product Description
Information Security Roles and Responsibilities Made Easy, Version 2 is the new and updated version of the best-selling security resource by Charles Cresson Wood, CISSP, CISA, CISM. ISR&R V2 is based on the 20 year consulting and security experience of Mr. Wood and contains these features to help you save money while establishing a due-care information security organization: 1. Over 70 pre-written, time-saving information security documents including: • 29 information-security-related committee, board, and department mission statements, with information security responsibilities reflecting the latest technical and legal requirements. • Over 40 information-security-related job descriptions • 12 separate information security organization structures with discussions of pros and cons of each. • Specification and discussion of 29 critical information security documents that every organization should have. 2. Justification to help increase managements awareness and funding of information security, including: • How to persuade management to properly document information security roles and responsibilities, including an easily-customized sample management memorandum. • Reducing the total cost of information security services by properly documented roles and responsibilities. • Discussion of responsibility and liability as it relates to documented information security roles, including citations supporting the legal notion of the standard of due care. • Information security staffing data and analysis to help gain management support for additional resources. • Common mistakes many organizations make and how to avoid them. 3. Specific advice on how to plan, document and execute an information security infrastructure project including: • Information on how to properly review and update information security roles and responsibilities, including department interview techniques. • How to schedule project resources and time lines for documenting roles and responsibilities. • Detailed discussion of the Data Owner, Custodian and User roles. • Actions you should take to reduce your organization's exposure to workers in information security related positions of trust. • The synergy between role based access control (RBAC) and clarification of information security roles and responsibilities. 4. Practical advice on how to maintain security when dealing with third parties, including: • Pros and cons of outsourcing security functions, including validation and security when outsourcing. • The security roles and responsibilities of software and hardware vendors. • Decision-making criteria for releasing or withholding roles and responsibilities documentation to/from various external parties. 5. Valuable staffing advice and descriptions for information security professionals including: • Characteristics of effective information security professionals, including discussion about the pros and cons of hiring hackers and others who have been on the wrong side of the law. • Specific performance criteria for individuals and teams. • An expanded list of new information professional certifications with web sites, phone numbers, and addresses for each. Information Security Roles and Responsibilities Made Easy, Version 2.0 contains easily customized documents in MS-Word format. All contents come on a fully indexed and searchable CD-ROM with linked cross-references. All contents © 2005, Information Shield, Inc. – All Rights Reserved

About the Author
Charles Cresson Wood, CISA, CISSP is an author and independent information security consultant based in Sausalito California. In the information security field on a full-time basis since 1979, he has worked as an information security management consultant at SRI International (formerly Stanford Research Institute) as well as lead network security consultant at Bank of America. He has done information security work with over 120 organizations, many of them Fortune 500 companies, including a large number of financial institutions and high-tech companies. His consulting work has taken him to over twenty different countries around the world. He is noted for his ability to integrate competing objectives (like ease-of-use, speed, flexibility and security) in customized and practical compromises that are acceptable to all parties involved. Acknowledging that information security is multi-disciplinary, multi-departmental, and often multi-organizational, he is additionally noted for his ability to synthesize a large number of complex considerations and then to document these in security architectures, system security requirements, risk assessments, project plans, policy statements, and other clear and action-oriented documents. He has published over 225 technical articles and five books in the information security field. In addition to TV and radio appearances, he has been quoted as an expert in publications such as Business Week, Christian Science Monitor, Computerworld, IEEE Spectrum, Infoworld, LA Times, Network Computing, Network World, PC Week, The Wall Street Journal, and Time. He has also presented cutting-edge information security ideas at over 100 technical and professional conferences around the globe. Mr. Wood is Senior North American Editor for the journals "Computers & Security" and "Computer Fraud & Security Bulletin", as well as a monthly columnist for "Computer Security Alert". He holds an MBA in financial information systems, an MSE in computer science, and a BSE in accounting from the Wharton School of Business at the University of Pennsylvania. He has passed the Certified Public Accountant (CPA) examination and is both a Certified Information Systems Auditor (CISA) and a Certified Information Systems Security Professional (CISSP). In November 1996 he received the Lifetime Achievement Award from the Computer Security Institute for "sincere dedication to the computer security profession."

Product Details

  • Hardcover: 288 pages
  • Publisher: Information Shield (June 1, 2005)
  • ISBN-10: 1881585123
  • ISBN-13: 978-1881585121
  • Product Dimensions: 11.3 x 8.5 x 0.8 inches
  • Shipping Weight: 2.1 pounds (View shipping rates and policies)
  • Average Customer Review: 4.7 out of 5 stars See all reviews (3 customer reviews)
  • Amazon.com Sales Rank: #1,220,201 in Books (See Bestsellers in Books)

Inside This Book (learn more)



Books on Related Topics (learn more)
 
 

What Do Customers Ultimately Buy After Viewing This Item?

Information Security Roles & Responsibilities Made Easy, Version 2
58% buy the item featured on this page:
Information Security Roles & Responsibilities Made Easy, Version 2 4.7 out of 5 stars (3)
$495.00
Information Security Policies Made Easy, Version 10
42% buy
Information Security Policies Made Easy, Version 10 4.8 out of 5 stars (4)
$795.00

Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
Check a corresponding box or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

3 Reviews
5 star:
 (2)
4 star:
 (1)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.7 out of 5 stars (3 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
2 of 2 people found the following review helpful:
4.0 out of 5 stars Every IT/IT Security Shop should have one, October 3, 2005
By Stephen Northcutt (Kauai, HI USA) - See all my reviews
(REAL NAME)   
This is a difficult book to review because it is meant to be a resource, not something you read on an airplane. I have passed this around to some of students and fellow SANS instructors and tried to get some of their feedback as well.

The greatest contribution this book makes is a discussion of organization structure, who should report to who and why. This is something that has been desparately needed in the industry and if this book is successful in the marketplace, I would like to see some additional research and have this already excellent resource expanded.

The job descriptions are also wonderful, we have many names for the same position and I would hope that over time, this book can help us develop a common terminology.

Who needs this book? It is designed to be licensed to organizations and as a rough rule of thumb, any organization with an IT department of 25 people or more could benefit from this book.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
5.0 out of 5 stars Great reference book, August 21, 2006
We had to create a security organization for a financial institution and as a part of the job, we had to define the roles and responsbilities. This book was extremely useful for me.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
5.0 out of 5 stars Excellent book ; completely Hands-On, March 17, 2006
By Cesar Bravo V "CISO" (Central America) - See all my reviews
(REAL NAME)   
I am the CISO of a regional Latin American Bank, and I used this book almost inmediately to define a project of defining information security roles in my organization. Even though some of the roles have to be changed due to the nature of the organization, and the internal politics that are at stake, I consider this book almost a "best practice" for information security. It helps you implement Information security infraestructure, and to show the importance of it to top management. Now, my organization is paying more attention to InfoSec, and the roles of the people are clearer in respecto to InfoSec.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
Ad
 
Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Product Information from the Amapedia Community

Beta (What's this?)



Shop in a Box with Power-Tool Combo Packs

Shop for combo packs
Expand your tool collection with a versatile combo pack. Our extensive line of combo packs includes air tools and convenient cordless power tools.

Shop combo packs

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Buy Three Books, Get a Fourth Free

4-for-3 Books
Order any four eligible books under $10 and get the lowest-price book free in our 4-for-3 Books Store. See more details.
 

Great Gifts from LUSH

LUSH
Find bath bombs, bubble bars, shower gels, and more from LUSH Fresh Handmade Cosmetics.

Shop LUSH

 
Ad

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Free
Free by Chris Anderson
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Darkfever
Darkfever by Karen Marie Moning

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates