0%

Book Description

The IT Regulatory and Standards Compliance Handbook provides comprehensive methodology, enabling the staff charged with an IT security audit to create a sound framework, allowing them to meet the challenges of compliance in a way that aligns with both business and technical needs. This "roadmap" provides a way of interpreting complex, often confusing, compliance requirements within the larger scope of an organization's overall needs.
  • The ulitmate guide to making an effective security policy and controls that enable monitoring and testing against them
  • The most comprehensive IT compliance template available, giving detailed information on testing all your IT security, policy and governance requirements
  • A guide to meeting the minimum standard, whether you are planning to meet ISO 27001, PCI-DSS, HIPPA, FISCAM, COBIT or any other IT compliance requirement
  • Both technical staff responsible for securing and auditing information systems and auditors who desire to demonstrate their technical expertise will gain the knowledge, skills and abilities to apply basic risk analysis techniques and to conduct a technical audit of essential information systems from this book
  • This technically based, practical guide to information systems audit and assessment will show how the process can be used to meet myriad compliance issues

Book Description

The IT Regulatory and Standards Compliance Handbook provides comprehensive methodology, enabling the staff charged with an IT security audit to create a sound framework, allowing them to meet the challenges of compliance in a way that aligns with both business and technical needs. This "roadmap" provides a way of interpreting complex, often confusing, compliance requirements within the larger scope of an organization's overall needs.
  • The ulitmate guide to making an effective security policy and controls that enable monitoring and testing against them
  • The most comprehensive IT compliance template available, giving detailed information on testing all your IT security, policy and governance requirements
  • A guide to meeting the minimum standard, whether you are planning to meet ISO 27001, PCI-DSS, HIPPA, FISCAM, COBIT or any other IT compliance requirement
  • Both technical staff responsible for securing and auditing information systems and auditors who desire to demonstrate their technical expertise will gain the knowledge, skills and abilities to apply basic risk analysis techniques and to conduct a technical audit of essential information systems from this book
  • This technically based, practical guide to information systems audit and assessment will show how the process can be used to meet myriad compliance issues

Table of Contents

  1. Cover image
  2. Table of Contents
  3. Lead Author
  4. Technical Editors
  5. Chapter 1. Introduction to IT Compliance
  6. Chapter 2. Evolution of Information Systems
  7. Chapter 3. The Information Systems Audit Program
  8. Chapter 4. Planning
  9. Chapter 5. Information Gathering
  10. Chapter 6. Security Policy Overview
  11. Chapter 7. Policy Issues and Fundamentals
  12. Chapter 8. Assessing Security Awareness and Knowledge of Policy
  13. Chapter 9. An Introduction to Network Audit
  14. Chapter 10. Auditing Cisco Routers and Switches
  15. Testing the Firewall
  16. Chapter 12. Auditing and Security with Wireless Technologies
  17. Chapter 13. Analyzing the Results
  18. Chapter 14. An Introduction to Systems Auditing
  19. Chapter 15. Database Auditing
  20. Chapter 16. Microsoft Windows Security and Audits
  21. Chapter 17. Auditing UNIX and Linux
  22. Chapter 18. Auditing Web-Based Applications
  23. Chapter 19. Other Systems
  24. Chapter 20. Risk Management, Security Compliance, and Audit Controls
  25. Chapter 21. Information Systems Legislation
  26. Chapter 22. Operations Security
  27. Index
52.15.59.163