Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
6 new from $495.00

Have one to sell? Sell yours here
 
   
Information Security Policies Made Easy, Version 10
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Information Security Policies Made Easy, Version 10 (Hardcover)

by Charles Cresson Wood (Author), Information Shield (Editor) "Information security policies are a special type of documented business rule..." (more)
Key Phrases: Four-Category Data Classification, Faxing Sensitive Information, Five-Category Application Criticality Classification Scheme (more...)
4.8 out of 5 stars See all reviews (4 customer reviews)

List Price: $795.00
Price: $795.00 & this item ships for FREE with Super Saver Shipping. Details
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Monday, July 20? Choose One-Day Shipping at checkout. Details
6 new from $495.00

Frequently Bought Together

Information Security Policies Made Easy, Version 10 + Information Security Roles & Responsibilities Made Easy, Version 2 + Security Metrics: Replacing Fear, Uncertainty, and Doubt
Price For All Three: $1,321.49

Show availability and shipping details


Customers Who Bought This Item Also Bought

Security Metrics: Replacing Fear, Uncertainty, and Doubt

Security Metrics: Replacing Fear, Uncertainty, and Doubt

by Andrew Jaquith
4.6 out of 5 stars (20)  $31.49
Writing Information Security Policies (Landmark)

Writing Information Security Policies (Landmark)

by Scott Barman
4.5 out of 5 stars (11)  $34.99
CISSP Certification All-in-One Exam Guide, Fourth Edition

CISSP Certification All-in-One Exam Guide, Fourth Edition

by Shon Harris
4.2 out of 5 stars (31)  $50.39
Managing an Information Security and Privacy Awareness and Training Program

Managing an Information Security and Privacy Awareness and Training Program

by Rebecca Herold
4.8 out of 5 stars (6)  $56.66
Computer Security: 20 Things Every Employee Should Know (McGraw-Hill Professional Education)

Computer Security: 20 Things Every Employee Should Know (McGraw-Hill Professional Education)

by Ben Rothke
4.7 out of 5 stars (21)  $7.87
Explore similar items

Editorial Reviews

Product Description
Information Security Policies Made Easy, Version 10 is the new and updated version of the best-selling policy resource by Charles Cresson Wood, CISSP, CISA, CISM. Based on the 20 year consulting and security experience of Mr. Wood, ISPME is the most complete policy resource available. ISPME Version 10 has everything you need to build a due-care security policy environment, including: 1. A complete policy library with over 1350 individual pre-written security policies including: Coverage of the latest technical, legal and regulatory issues. ISO 17799 outline format, allowing for easy gap-analysis against existing standards and security frameworks. Expert commentary discussing the risks mitigated by each policy. Target audience (management, technical, or user) and security environment (low, medium, high) for each policy. Policy coverage maps for Sarbanes-Oxley (COBIT) and HIPAA security 2. Eighteen complete pre-written security policy documents that every company should have, updated and ready to use as is or with easy customization, including: User-targeted policies such as: Electronic Mail Policy, Internet Security Policy for End Users and Web Privacy Policy. Organization-wide policies such as: High-Level Security Policy, Privacy policy, Information Ownership Policy. Technology-based policies such as: Firewall Policy, Data Classification Policy and Network Security Policy. Sample risk acceptance memo for the approval of out of compliance situations, a sample non-disclosure agreement, and a user policy acceptance agreement. 3. Expert advice on the policy development and review process, including: A step-by-step checklist of policy development tasks to quickly start a policy development project. Helpful tips and tricks for getting management buy-in for information security policies and education. Tips and techniques for raising security policy awareness. Real-world examples of problems caused by missing or poor security policies. Policy development resources such as Information Security Periodicals, professional associations and related security organizations. 4. All content available on an easy-to-use CD-ROM with an indexed and searchable HTML interface for easy location, featuring: Policies available in HTML, PDF, MS-Word format. Easy cut-and-paste into existing corporate documents. Extensive cross-references between policies that help the user quickly understand alternative solutions and complimentary controls. ISPME V10 policies cover these important security topics: Access Control, Data Classification and Control, Risk Assessments, Password and user ID management, Logging Controls, Encryption and Digital Signatures, Instant messaging, PDAs and smart,phones, Personnel Security including Security Awareness and Training, Data Privacy Management for employees and customers, Corporate governance, including Sarbanes-Oxley, Electronic mail, viruses, malicious code protection, and social engineering attacks, including phishing scams, Preventing and responding to identity theft, Network security including wireless and Voice Over Internet Protocol (VOIP), Security, configuration, and management firewalls, Communication Security including telephones and FAX machines, Web site and e-commerce security, Security in 3rd party contracts, including outsourcing and off-shoring of IT projects, Document destruction, as well as retention of documents that may be used in court cases, Incident Response and Contingency planning, Telecommuting and mobile computing, Honeypots and intrusion detection systems, Effective software patch management including Open Source software, And many others! Information Security Policies Made Easy, Version 10.0 policies are organized around the ISO/IEC 17799 Security Standard. An excellent resource purchase a copy and register your product to receive additional updates from Information Shield.

About the Author
Charles Cresson Wood, CISA, CISSP, is an author and independent information security consultant based in Sausalito California. In the information security field on a full-time basis since 1979, he has worked as an information security management consultant at SRI International (formerly Stanford Research Institute) as well as lead network security consultant at Bank of America. He has done information security work with over 120 organizations many of them Fortune 500 companies including a large number of financial institutions and high-tech companies. His consulting work has taken him to over twenty different countries around the world. He is noted for his ability to integrate competing objectives (like ease-of-use, speed, flexibility and security) in customized and practical compromises that are acceptable to all parties involved. Acknowledging that information security is multi-disciplinary, multi-departmental, and often multi-organizational, he is additionally noted for his ability to synthesize a large number of complex considerations and then to document these in security architectures, system security requirements, risk assessments, project plans, policy statements, and other clear and action-oriented documents. He has published over 225 technical articles and five books in the information security field. In addition to TV and radio appearances, he has been quoted as an expert in publications such as Business Week, Christian Science Monitor, Computerworld, IEEE Spectrum, Infoworld, LA Times, Network Computing, Network World, PC Week, The Wall Street Journal, and Time. He has also presented cutting-edge information security ideas at over 100 technical and professional conferences around the globe. Mr. Wood is Senior North American Editor for the journals "Computers & Security" and "Computer Fraud & Security Bulletin", as well as a monthly columnist for "Computer Security Alert". He holds an MBA in financial information systems, an MSE in computer science, and a BSE in accounting from the Wharton School of Business at the University of Pennsylvania. He has passed the Certified Public Accountant (CPA) examination and is both a Certified Information Systems Auditor (CISA) and a Certified Information Systems Security Professional (CISSP). In November 1996 he received the Lifetime Achievement Award from the Computer Security Institute for "sincere dedication to the computer security profession."

Product Details

  • Hardcover: 739 pages
  • Publisher: Information Shield (February 1, 2008)
  • Language: English
  • ISBN-10: 1881585131
  • ISBN-13: 978-1881585138
  • Product Dimensions: 11.1 x 8.5 x 1.8 inches
  • Shipping Weight: 4.6 pounds (View shipping rates and policies)
  • Average Customer Review: 4.8 out of 5 stars See all reviews (4 customer reviews)
  • Amazon.com Sales Rank: #760,722 in Books (See Bestsellers in Books)

Inside This Book (learn more)


Books on Related Topics (learn more)
 
 

What Do Customers Ultimately Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

4 Reviews
5 star:
 (3)
4 star:
 (1)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.8 out of 5 stars (4 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
14 of 14 people found the following review helpful:
5.0 out of 5 stars New version of a vital information security reference, August 16, 2005
In technology, books are often obsolete shortly after publication. Given the dynamic nature of technology, very few technology books can stand the test of time and remain relevant for a few years, let alone a decade after their original printing. Some of those rare titles that seem timeless include Applied Cryptography by Bruce Schneier, Security Engineering: A Guide to Building Dependable Distributed Systems by Ross Anderson, and the book I'll review here, Information Security Policies Made Easy, Version 10. Information Security Policies Made Easy (ISPME) is one of the most important information security books available for those who are serious about creating a comprehensive set of information systems security policies.

The importance of effective information security policies cannot be overemphasized, as they are the foundation toward implementing information security and ensuring the security of the people, systems, and networks within an organization. If an organization lacks security policies, they cannot inform employees and users of their specific security responsibilities. Policies define acceptable system use and user behavior, and those policies must be in place before they can be enforced.

Version 10 of ISPME contains more than 1350 pre-written security policies that can be used as a framework for the creation of a comprehensive set of information security policies. The book comes with a CD-ROM that includes every policy. The beauty of ISPME is that it removes the huge burden and time required to create a global set of security policies. With ISPME, you can immediately begin exploring the myriad policies required for information security.

One of the biggest mistakes you could make, however, when using ISPME, is to implement a policy too quickly, without deciding specifically how those policies with be selected, developed, deployed, maintained, and enforced. With that, Chapter 2 provides an orientation to the information security policy writing and development process. The books states that while it may be tempting to immediately start cutting and pasting policies together, it is crucial to understand both what the policies do and what you want to accomplish with them before you begin. If that is done, the subsequent policy writing tasks will be much more efficient and focused.

At 501 pages, Chapter 3 comprises the bulk of the book and contains the all of the specific policies. These policies are divided into 10 separate domains that are mapped to the ISO-17799 standard. This organization scheme makes it makes it easy to create a gap-analysis of your current policies against the ISO-17799 standard. This is helpful since many organizations are now embracing ISO-17799.

Each of the policies contain the individual policy itself and a detailed commentary on why the policy is specifically needed. Each policy also has a cross-reference to related policies and an indication of the audience (management, technical, end-user) and the security environment (low, medium, high) for which it is written.

Chapters 4 - 20 contain various high-level policies in areas such as mobile computing, data classification, email, Web security, and more. These 18 chapters are complete security policy documents that can be implemented with little customization.

The book contains 15 appendixes, which include secondary information such as awareness-raising methods, checklists, memos, and next steps to take.

The CD-ROM that is included contains the entire set of polices in HTML, Word, and PDF formats. It also includes two documents that map the policies in the book against HIPAA and Sarbanes-Oxley.

Organizations that take information security seriously will likely have used ISPME in its previous versions. But for those that have not yet taken the plunge, ISPME is a valuable tool that can be utilized to create a comprehensive set of information security policies in a cost- and time-effective manner. For those building corporate or organizational security policies, ISPME is clearly the definitive reference.


Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
15 of 16 people found the following review helpful:
4.0 out of 5 stars Notes on ISPME version 10, January 24, 2006
Book is a very good resource on information security policies; however, I was disappointed that this book did not match ISO 17799 version 2005 it only matched the 2000 version. I would wait for the next version of the book for updated material matches for ISO 17799 v2005. The authors should have provided updates via CD ROM or download to support this necessary update to this version they have not. You would seem to think at $795.00 a pop for the book and CDROM you would get better support on the material in the book. Also pay close attention to the license uses of the security policies..
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
10 of 10 people found the following review helpful:
5.0 out of 5 stars Even Better, August 9, 2006
By Stephen Northcutt (Kauai, HI USA) - See all my reviews
(REAL NAME)   
I keep books in two places, a small shelf near my computer that I can reach and a large bookshelf across the room. This book deserves a place on the small shelf within arm's reach.

Version 10 builds on the previous work and includes ISO 17799 outline format, policy coverage maps for Sarbanes-Oxley and coverage of the latest issues (technical, legal and regulatory.) I particularly appreciate the section on policy awareness. This is one of the biggest problems you run into.


If you are a manager, before you ever make a decision, or approve a policy, look the topic up, there is a good chance you will see something you didn't think of.

Let me give you an example, our company used to have a fairly long Non-Diclosure Agreement (NDA) prepared by our attorney for a specific purpose. However, we decided to create a simpler, general purpose NDA for all 1099 contractors. The lawyer created it and before I approved it I checked it against the book. I found three items that really should have been in our NDA that we would have missed, thank you Mr. Wood!

If you are a techie, do you need this book? Sure, because everything we do as a techie or engineer has liability implications for the company. Each topic is very clear, concise, and well thought out. It takes a few seconds to look it up, about two minutes to read the section and that investment is well worth your time.

Yes, this is an expensive book; however, it is worth the investment, every organization should have at least one copy. S.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
Ad
 
Most Recent Customer Reviews

5.0 out of 5 stars Make it a policy to have this book in your library
I once consulted for an organization that wanted to develop and publish from the ground up, their official "rules of behavior" policy document. Read more
Published 17 months ago by Kenny McNees, CPA, CISSP, CISA...

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Product Information from the Amapedia Community

Beta (What's this?)

Information Security Policies Made Easy, Version 10

The CD-ROM that is included contains the entire set of polices in HTML, Word, and PDF formats. It also includes two documents that map the policies in the book against HIPAA and Sarbanes-Oxley.

(Report this)
Created on Mar 22, 2006, last edited on Mar 22, 2006.

 Explore and Edit at Amapedia.com opens new browser window



Look for Similar Items by Category


NARS: Free Shipping

NARS blush orgasm
Get free shipping on all NARS Cosmetics orders of $60 or more. Shop NARS' blush, eyeshadows, lips, palletes and more NARS favorites now.

Shop NARS now

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Make a Good Turn

Shop for lathes
When you need to shape and smooth your workpiece, a lathe is the perfect power tool.

Shop for lathes

 
Shop for Welding Torches and Oxyacetylene Torch Kits
Welding Torch and Oxyacetylene Torch KitsSelect a welding torch and oxyacetylene torch kit for tough construction, fabrication, repair, and other torch jobs.
 
Ad

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Free
Free by Chris Anderson
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Darkfever
Darkfever by Karen Marie Moning

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates