ENGLISH

Official (ISC)2® Guide to the CAP® CBK®, Second Edition ((ISC)2 Press

Book information

Publisher
Auerbach Publications
Year
2012
ISBN
978-1-4398-2075-9, 978-1-4398-0483-4, 978-1-4398-0093-5, 978-1-4200-9443-5, 978-1-4398-2076-6, 1439820767, 1439820759
Language
english
Format
PDF
Filesize
5 MB (5305457 bytes)
Series
(ISC)2 Press series
Edition
2
Pages
462\452
Time added
2016-01-24 03:00:00
C

Description

"Providing an overview of certification and accreditation, the second edition of this officially sanctioned guide demonstrates the practicality and effectiveness of C & A as a risk management methodology for IT systems in public and private organizations. It enables readers to document the status of their security controls and learn how to secure IT systems via standard, repeatable processes. The text describes what it takes to build a certification and accreditation program at the organization level and then analyzes various C & A processes and how they interrelate. A case study illustrates the successful implementation of certification and accreditation in a major U.S. government department. The appendices offer a collection of helpful samples"-- "There are many elements that make system authorization complex. This book focuses on the processes that must be employed by an organization to establish a system authorization program based on current federal government criteria. Although the roots of this book address various federal requirements, the process developed and presented can be used by nongovernment organizations to address compliance and the myriad laws, regulations, and standards currently driving information technology security. The key to reaching system authorization nirvana is understanding what is required and then implementing a methodology that will achieve those requirements. The top-down methodology presented in this book provides the reader with a practical approach for completion of such an undertaking. By demystifying government requirements, this book presents a simplified, practical approach to system authorization"-- �Read more... Abstract: Demonstrates the effectiveness of certification and accreditation as a risk management methodology for IT systems in public and private organizations. This work provides security professionals with an overview of C&A components, showing them how to document the status of IT security controls and secure systems via standard, repeatable processes. �Read more...

Similar books