Books > Information Security Policies Made Easy

Information Security Policies Made Easy
by Charles Cresson Wood, CISA, CISSP

Price: $795.00

The most comprehensive set of information security policies at your fingertips. The new Information Security Policies Made Easy v.9, contains a completely revised text, policies organized in ISO 17799 format and a web based CD-ROM version which is fully linked and searchable. Take the work out of creating, writing and implementing policies.

Read Review
ISPME Table of Contents
Index of Policies by Number
Index of New Policies in Version 9

Information Security Policies Made Easy is the definitive resource tool for information security policies. Version 9 now includes an updated collection of 1360 + security policies and templates covering virtually every aspect of corporate security. Used by over 70% of the Fortune 100, Information Security Policies Made Easy is written by security policy expert and consultant Charles Cresson Wood, CISA, CISSP, who has over 20 years writing and implementing security policies for companies worldwide.

Information Security Policies Made Easy is literally an all-in-one security policy resource with templates, advice and instructions to help you generate practical, clear, and compelling information security policies for your organization - whether your organization is large or small. These tools will save hours of time and thousands of dollars developing information security policies with:

  • 1360 + already-written information security policies accompanied by explanations and expert advice for each
  • Policies organized based on the ISO 17799 outline
  • Security policy samples are provided in print and on CD-ROM, with a web based application providing a fully linked and searchable version of the content, allowing users to quickly cut and paste policies into their own corporate documents.
  • Ready-to-use information security documents such as: a risk acceptance memo for the approval of out of compliance situations, a non-disclosure agreement, and a user policy acceptance agreement
  • Policies regarding the latest corporate security topics such as contingency planning with regards to terrorist attacks , reporting security incidents, network controls, Internet commerce privacy, and identity theft
  • Security policies that incorporate the latest security technology such as macroviruses, digital certificates, encryption public key infrastructure (PKI), intrusion detection systems, data replication, spam (junk email), and data mining
  • A step-by-step checklist of policy development tasks so that you can start immediately to get a policy development project underway
  • Extensive cross-references between policies that help the user quickly understand alternative solutions and complimentary controls

What's new in Version 9?
The new Version 9 of Information Security Policies Made Easy now offers 1360 + security policy templates including new policies to address key corporate security issues such as:

  • Recent government legislation including:
    • HIPAA - The Health Insurance Portability and Accountability Act
    • GLBA- The Gramm, Leach, Bliley Act
    • European government legislation such as the European Union Data Protection Directive
  • Digital signatures, digital certificates, and Public Key Infrastructure (PKI)
  • Recent security threats and attacks such as web bugs and viruses
  • Contingency planning and reporting of security incidents related to terrorism
  • Internet business usage, extranets, EDI over the Internet, e-commerce site protection, and Internet credit card fraud prevention/detection
  • The establishment, maintenance, and modification of firewalls and other network perimeter security devices
  • Dial-up communications security including connections made from wireless, mobile computers
  • Operational systems management regarding intranets and internal systems interconnection
  • Enterprise security management systems and consolidation of access control
  • Social engineering and masquerading

Also new in Information Security Policies Made Easy Version 9:

  • Policies organization based on the ISO 17799 outline
  • A graphic overview of the policy development process
  • 18 security policies that every company should have, updated and ready to use "as is"

Information Security Policies Made Easy Version 9 covers virtually every aspect of corporate information security including:

  • Web pages
  • Firewalls
  • Employee surveillance
  • Electronic commerce
  • Digital signatures
  • Computer viruses
  • Encryption
  • Contingency planning
  • Logging controls
  • Internet
  • Intranets
  • Privacy issues
  • Outsourcing security functions
  • Computer emergency response teams
  • Microcomputers
  • Local area networks
  • Password selection
  • Electronic mail
  • Data Classification
  • Telecommuting
  • Telephone systems
  • Portable computers
  • User training
  • Information Security Related Terrorism

{ top }

About the Author

Charles Cresson Wood is an author and independent information security consultant based in Sausalito, California. In the information security field on a full-time basis since 1979, he has worked as an information security management consultant at SRI International (formerly Stanford Research Institute) as well as lead network security consultant at the Bank of America. He has done information security work with over 120 organizations -- many of them Fortune 500 companies -- including a large number of financial institutions and high-tech companies. His consulting work has taken him to over twenty different countries around the world.

He is noted for his ability to integrate competing objectives (like ease-of-use, speed, flexibility and security) in customized and practical compromises that are acceptable to all parties involved. Acknowledging that information security is multi-disciplinary, multi- departmental, and often multi-organizational, he is additionally noted for his ability to synthesize a large number of complex considerations and then to document these in security architectures, system security requirements, risk assessments, project plans, policy statements, and other clear and action-oriented documents.

He has published over 225 technical articles and five books in the information security field. In addition to TV and radio appearances, he has been quoted as an expert in publications such as Business Week, Christian Science Monitor, Computerworld, IEEE Spectrum, Infoworld, LA Times, Network Computing, Network World, PC Week, The Wall Street Journal, and Time. He has also presented cutting-edge information security ideas at over 100 technical and professional conferences around the globe.

Mr. Wood is Senior North American Editor for the journals 'Computers & Security' and 'Computer Fraud & Security Bulletin,' as well as a monthly columnist for 'Computer Security Alert.' He holds an MBA in financial information systems, an MSE in computer science, and a BSE in accounting from the Wharton School of Business at the University of Pennsylvania. He has passed the Certified Public Accountant (CPA) examination and is both a Certified Information Systems Auditor (CISA) and a Certified Information Systems Security Professional (CISSP). In November 1996 he received the Lifetime Achievement Award from the Computer Security Institute for "sincere dedication to the computer security profession."


{ top }

Review We are proud of outstanding reviews like these:

"This is the gold standard Policy reference for any serious security practitioner to have in their arsenal of tools, a must have! The instructions and examples for establishing security polices and implementation processes add real value to this edition"
John B. Kramer, CISSP, CISA
Information Security Manager - UPMCHS
September, 2002

"Wood has created a complete kit of proven best practices that any organization can use and customize to make policies meeting their exact needs."
Jay Heiser, Columnist, "Information Security" magazine
September, 2002

"In 1993, I was asked to develop my first information security policy. I began by cutting and pasting a serious of thoughts and calling that a policy. Usually these policies were rejected by management. To ensure that my organization had strong Information Security policies in place, I purchased a copy of Information Security Policies Made Easy. Quickly I learned that creating a policy was a process that included writing policies, editing policies, obtaining management approval, communicating policies, and implementing controls to meet the policy requirements. The book provides the reader with the tools necessary to develop policies, including an easy to use CD ( fully-linked and searchable)."
Diana-Lynn Contesti, CISSP, SSCP
Information Security Officer - Dofasco Inc.
September, 2002

"Charles Cresson Wood...is an expert's expert, and knows more about computer security policies than anyone I know."
Michael Alexander, Editor, Datamation

"This book is invaluable to those responsible for creating or maintaining an information security policy manual or similar documents."
Belden Menkus, Editor, EDPACS

"It gave us everything we needed to help us write standards and communicate [policies] in a clear, concise manner with no ambiguity or technical jargon ... the book paid for itself in two weeks."
Jonah Goldsmith, Data Security Consultant to Large Medical Insurance Company, LAN Times

"If I could have only six books in my professional library, this would be one of them."
Dr. Harold Highland, Editor, Emeritus of Computers & Security magazine

"The [ISPME] guidelines have saved three months of manual effort that would have been required to research and write policies."
Douglas Feil, EDP Audit Manager, City & County of San Francisco, Network Management Systems & Strategies

Take a look at who uses ISPME:

  • Ford Motor Company
  • Reuters
  • Amoco Corporation
  • Harvard University
  • RJR Tobacco
  • American Telephone and Telegraph (AT&T)
  • Hewlett Packard
  • Rykoff-Sexton
  • Swiss Bank Corp
  • Simon & Schuster
  • Hyundai Electronics
  • Sumitomo Bank
  • Automatic Data Processing (ADP)
  • Sun Microsystems
  • Blue Cross/Blue Shield
  • International Moscow Bank
  • ITT Aerospace
  • Johnson & Johnson
  • British Airways
  • Burroughs Wellcome
  • Exxon
  • ... and many others.

Information Security Policies Made Easy, Version 9 Hardcover - 730 pp. includes CD-ROM and organization-wide license to republish the materials. Published by PentaSafe Security Technologies.


{ top }

   
1-800-421-8031 | Contact Us | Privacy Policy