Security Risk Assessment Handbook

Regular price €137.99
A01=Douglas Landoll
advanced organisational risk evaluation
Assessment Team
Author_Douglas Landoll
Be
Category=GPQD
Category=UR
Category=UTF
Category=UTN
compliance frameworks
Cumulative Distribution Function
cyber risk management
cyber security risk
cyber security risk assessment
cybersecurity for business
cybersecurity risk
cybersecurity risk assessment
cybersecurity risk management
Data Set
enterprise data protection
eq_bestseller
eq_computing
eq_isMigrated=1
eq_isMigrated=2
eq_nobargain
eq_non-fiction
information security
Information Security Organization
Information Security Program
Information Security Risk
Information Security Risk Assessment
Performing Security Risk Assessments
Physical Security Controls
Potential Threat Actions
RIIOT methodology
risk modelling
Security Controls
Security Risk
Security Risk Analysis
security risk assessment
Security Risk Assessment Approaches
Security Risk Assessment Methods
Security Risk Assessment Process
Security Risk Assessment Project
Security Risk Assessment Team
Security Risk Calculation
Sensitive Information
supply chain cyber risk
Technical Security Controls
Threat Actions
Threat Agent
vulnerability assessment

Product details

  • ISBN 9780367547479
  • Weight: 1043g
  • Dimensions: 178 x 254mm
  • Publication Date: 28 Sep 2021
  • Publisher: Taylor & Francis Ltd
  • Publication City/Country: GB
  • Product Form: Hardback
Delivery/Collection within 10-20 working days

Our Delivery Time Frames Explained
2-4 Working Days: Available in-stock

10-20 Working Days: On Backorder

Will Deliver When Available: On Pre-Order or Reprinting

We ship your order once all items have arrived at our warehouse and are processed. Need those 2-4 day shipping items sooner? Just place a separate order for them!

Conducted properly, information security risk assessments provide managers with the feedback needed to manage risk through the understanding of threats to corporate assets, determination of current control vulnerabilities, and appropriate safeguards selection. Performed incorrectly, they can provide the false sense of security that allows potential threats to develop into disastrous losses of proprietary information, capital, and corporate value. Picking up where its bestselling predecessors left off, The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments, Third Edition gives you detailed instruction on how to conduct a security risk assessment effectively and efficiently, supplying wide-ranging coverage that includes security risk analysis, mitigation, and risk assessment reporting.

The third edition has expanded coverage of essential topics, such as threat analysis, data gathering, risk analysis, and risk assessment methods, and added coverage of new topics essential for current assessment projects (e.g., cloud security, supply chain management, and security risk assessment methods). This handbook walks you through the process of conducting an effective security assessment, and it provides the tools, methods, and up-to-date understanding you need to select the security measures best suited to your organization.

Trusted to assess security for small companies, leading organizations, and government agencies, including the CIA, NSA, and NATO, Douglas J. Landoll unveils the little-known tips, tricks, and techniques used by savvy security professionals in the field. It includes features on how to

  • Better negotiate the scope and rigor of security assessments
  • Effectively interface with security assessment teams
  • Gain an improved understanding of final report recommendations
  • Deliver insightful comments on draft reports

This edition includes detailed guidance on gathering data and analyzes over 200 administrative, technical, and physical controls using the RIIOT data gathering method; introduces the RIIOT FRAME (risk assessment method), including hundreds of tables, over 70 new diagrams and figures, and over 80 exercises; and provides a detailed analysis of many of the popular security risk assessment methods in use today. The companion website (infosecurityrisk.com) provides downloads for checklists, spreadsheets, figures, and tools.

Douglas Landoll has over two decades of information security experience. He has led security risk assessments and established security programs for top corporations and government agencies. He is an expert in security risk assessment, security risk management, security criteria, and building corporate security programs. His background includes evaluating security at the National Security Agency (NSA), North Atlantic Treaty Organization (NATO), Central Intelligence Agency (CIA), and other government agencies; co-founding the Arca Common Criteria Testing Laboratory, co-authoring the systems security engineering capability maturity model (SSE-CMM); teaching at NSA’s National Cryptologic School; and running the southwest security services division for Exodus Communications.

Doug is currently the CEO of Lantego, specializing in risk assessment, policy and training. He is a certified information systems security professional (CISSP) and certified information systems auditor (CISA). He holds a BS degree from James Madison University and an MBA from the University of Texas at Austin. He has published numerous information security articles, speaks regularly at conferences, and serves as an advisor for several high-tech companies.