Principles of Information Security,. Fourth Edition. Michael E. Whitman and. Herbert J. Mattord.

Principles Of Information Security Whitman Pdf

Principles of Information Security, Fourth Edition provides comprehensive coverage of both the managerial and technical aspects of the field of information security.

Logical Design Creates and develops blueprints for information security Incident response actions planned: Continuity planning Incident response Disaster recovery.

Physical Design Needed security technology is evaluated, alternatives are generated, and final design is selected At end of phase, feasibility study determines readiness of organization for project. Implementation Security solutions are acquired, tested, implemented, and tested again Personnel issues evaluated; specific training and education programs conducted Entire tested package is presented to management for final approval.

Maintenance and Change Perhaps the most important phase, given the everchanging threat environment Often, repairing damage and restoring information is a constant duel with an unseen adversary Information security profile of an organization requires constant adaptation as new threats emerge and old threats evolve. Security Professionals and the Organization Wide range of professionals required to support a diverse information security program Senior management is key component Additional administrative support and technical expertise are required to implement details of IS program.

Information Security Project Team A number of individuals who are experienced in one or more facets of required technical and nontechnical areas: Champion Team leader Security policy developers Risk assessment specialists Security professionals Systems administrators End users Data Responsibilities Data owner: Information Security: Is it an Art or a Science?

Implementation of information security often described as combination of art and science Security artesan idea: Security as Art No hard and fast rules nor many universally accepted complete solutions No manual for implementing security through entire system.

Security as Science Dealing with technology designed to operate at high levels of performance Specific conditions cause virtually all actions that occur in computer systems Nearly every fault, security hole, and systems malfunction are a result of interaction of specific hardware and software If developers had sufficient time, they could resolve and eliminate faults.

Security as a Social Science Social science examines the behavior of individuals interacting with systems Security begins and ends with the people that interact with the system Security administrators can greatly reduce levels of risk caused by end users, and create more acceptable and supportable security profiles.

