The IT Regulatory and Standards Compliance Handbook provides comprehensive methodology, enabling the staff charged with an IT security audit to create a sound framework, allowing them to meet the challenges of compliance in a way that aligns with both business and technical needs. This "roadmap" provides a way of interpreting complex, often confusing, compliance requirements within the larger scope of an organization's overall needs.
- The ulitmate guide to making an effective security policy and controls that enable monitoring and testing against them
- The most comprehensive IT compliance template available, giving detailed information on testing all your IT security, policy and governance requirements
- A guide to meeting the minimum standard, whether you are planning to meet ISO 27001, PCI-DSS, HIPPA, FISCAM, COBIT or any other IT compliance requirement
- Both technical staff responsible for securing and auditing information systems and auditors who desire to demonstrate their technical expertise will gain the knowledge, skills and abilities to apply basic risk analysis techniques and to conduct a technical audit of essential information systems from this book
- This technically based, practical guide to information systems audit and assessment will show how the process can be used to meet myriad compliance issues
Sprache
Verlagsort
ISBN-13
978-0-08-056017-5 (9780080560175)
Schweitzer Klassifikation
Chapter 1 - IntroductionChapter 2 - Evolution of Information SystemsChapter 3 - The Information Systems Audit ProgramChapter 4 - PlanningChapter 5 - Information Gathering Chapter 6 - Security Policy OverviewChapter 7 - Policy Issues and fundamentalsChapter 8 - Assessing SecurityChapter 9 - An Introduction to Network AuditChapter 10 - Audting Cisco Router and SwitchesChapter 11 - Testing the FirewallChapter 12 - Auditing and Security with Wireless TechnologiesChapter 13 - Analyzing the ResultsChapter 14 - An Introduction to Systems AuditingChapter 15 - Database AuditingChapter 16 - Microsoft Windows Security and AuditsChapter 17 - Auditing UNIX and LinuxChapter 18 - Auditing Web-Based ApplicationsChapter 19 - Other SystemsChapter 20 - Risk Management, Security Compliance, and Audit ControlsChapter 21 - Information Systems LegislationChapter 22 - Operations Secuirty