libri scuola books Fumetti ebook dvd top ten sconti 0 Carrello


Torna Indietro

hansche susan (curatore) - official (isc)2® guide to the cissp®-issep® cbk®
Zoom

Official (ISC)2® Guide to the CISSP®-ISSEP® CBK®




Disponibilità: Non ordinabile


PREZZO
76,98 €



Questo prodotto usufruisce delle SPEDIZIONI GRATIS
selezionando l'opzione Corriere Veloce in fase di ordine.


Pagabile anche con Carta della cultura giovani e del merito, Carta della Cultura e Carta del Docente


Facebook Twitter Aggiungi commento


Spese Gratis

Dettagli

Genere:Libro
Lingua: Inglese
Pubblicazione: 09/2005
Edizione: 1° edizione





Note Editore

The Official (ISC)2® Guide to the CISSP®-ISSEP® CBK® provides an inclusive analysis of all of the topics covered on the newly created CISSP-ISSEP Common Body of Knowledge. The first fully comprehensive guide to the CISSP-ISSEP CBK, this book promotes understanding of the four ISSEP domains: Information Systems Security Engineering (ISSE); Certification and Accreditation; Technical Management; and an Introduction to United States Government Information Assurance Regulations. This volume explains ISSE by comparing it to a traditional Systems Engineering model, enabling you to see the correlation of how security fits into the design and development process for information systems. It also details key points of more than 50 U.S. government policies and procedures that need to be understood in order to understand the CBK and protect U.S. government information.About the AuthorSusan Hansche, CISSP-ISSEP is the training director for information assurance at Nortel PEC Solutions in Fairfax, Virginia. She has more than 15 years of experience in the field and since 1998 has served as the contractor program manager of the information assurance training program for the U.S. Department of State.




Sommario

ISSE DOMAIN 1: INFORMATION SYSTEMS SECURITY ENGINEERING (ISSE)ISSE Introduction Introduction SE and ISSE OverviewThe ISSE ModelLife Cycle and ISSERisk ManagementDefense in DepthSummary ReferencesISSE Model Phase 1: Discover Information ProtectionNeeds Introduction Systems Engineering Activity: Discover NeedsISSE Activity: Discover Information Protection NeedsIdentifying Security Services and Developingthe Information Protection Policy Creating the Information Protection Policy (IPP) Creating the IPP Document The Information Management Plan (IMP) Final Deliverable of Phase 1 Summary ReferencesISSE Model Phase 2: Define System Security RequirementsIntroduction System Engineering Activity: DefiningSystem RequirementsISSE Activity: Defining System Security Requirements Final Deliverable of Phase 2 Summary ReferencesISSE Model Phase 3: Define SystemSecurity Architecture Introduction Defining System and Security ArchitectureSystem Engineering Activity: Designing System Architecture ISSE Activity: Define the Security Architecture Final Deliverable of Phase 3Summary ReferencesISSE Model Phase 4: Develop Detailed Security Design Introduction Systems Engineering Activity: System Design ISSE Activity: System Security Design ISSE Design and Risk ManagementFinal Deliverables of Phase 4Summary ReferencesWeb Sites Software Design and Development BibliographyISSE Model Phase 5: Implement System Security Introduction System Engineering Activity: System Implementation ISSE and System Security ImplementationISSE and Risk ManagementFinal Deliverable of Phase 5Summary ReferencesWeb Sites ISSE Model Phase 6: Assess Security Effectiveness Introduction System Engineering Activity: System AssessmentISSE and System Security AssessmentISSE and Risk ManagementFinal Deliverable of Phase 6Summary ReferencesWeb Sites ISSE DOMAIN 2: CERTIFICATION AND ACCREDITATIONDITSCAP and NIACAPIntroduction DITSCAP and NIACAP Overview DITSCAP/NIACAP Definition Phase 1: Definition Phase 2: Verification Phase 3: Validation Phase 4: Post AccreditationSummary C&A NIST SP 800-37 Introduction The C&A Process Phase 1: Initiation Phase 2: Security Certification Phase 3: Security AccreditationPhase 4: Continuous Monitoring Summary Domain 2 References Web Sites AcronymsISSE DOMAIN 3: TECHNICAL MANAGEMENTTechnical Management Introduction Planning the EffortManaging the Effort Technical Roles and ResponsibilitiesTechnical DocumentationTechnical Management ToolsSummary ReferencesWeb Sites ISSEP DOMAIN 4: INTRODUCTION TO UNITED STATES GOVERNMENT INFORMATION ASSURANCE REGULATIONSInformation Assurance Organizations, Public Laws, andPublic PoliciesIntroduction Section 1: Federal Agencies and Organizations Section 2: Federal Laws, Executive Directives and Orders, and OMBDirectives Summary ReferencesWeb Sites Department of Defense (DoD) Information AssuranceOrganizations and PoliciesIntroduction Overview of DoD Policies DoD Information Assurance (IA) Organizations and DepartmentsDoD Issuances Summary ReferencesWeb Sites Committee on National Security SystemsIntroduction Overview of CNSS and NSTISSC CNSS and NSTISSC Issuances CNSS PoliciesCNSS Directive CNSS Instructions CNSS Advisory MemorandaSummary ReferencesWeb Sites National Institute of Standards and Technology (NIST)PublicationsIntroduction Federal Information Processing Standards (FIPS) NIST Special PublicationsSummary ReferencesWeb Sites National Information Assurance Partnership (NIAP) andCommon Criteria (CC)Introduction Historical View of IT Security Evaluations National Information Assurance Partnership (NIAP) The Common Criteria CC Scenario Summary ReferencesWeb Sites APPENDIX A: LINKING ISSE PHASES TO SE PhasesAPPENDIX B: ENTERPRISE ARCHITECTUREAPPENDIX C: COMBINING NIST SP 800-55 AND SP 800-26APPENDIX D: COMMON CRITERIA SECURITY ASSURANCE REQUIREMENTS










Altre Informazioni

ISBN:

9780849323416

Condizione: Nuovo
Collana: (ISC)2 Press
Dimensioni: 9.25 x 6.25 in Ø 3.45 lb
Formato: Copertina rigida
Illustration Notes:143 b/w images and 103 tables
Pagine Arabe: 1024


Dicono di noi