 |
Information Security Policies
Made Easy
by Charles Cresson Wood, CISA, CISSP
Price: $795.00
The most comprehensive set of information security policies at
your fingertips. The new Information Security Policies Made Easy
v.9, contains a completely revised text, policies organized in ISO
17799 format and a web based CD-ROM version which is fully linked
and searchable. Take the work out of creating, writing and implementing
policies.
Read Review
ISPME
Table of Contents
Index
of Policies by Number
Index
of New Policies in Version 9
Information Security Policies Made Easy
is the definitive resource tool for information security
policies. Version 9 now includes an updated collection
of 1360 + security policies and templates covering virtually every
aspect of corporate security. Used by over 70% of the Fortune 100,
Information Security Policies Made Easy is written by security policy
expert and consultant Charles Cresson Wood, CISA, CISSP, who has
over 20 years writing and implementing security policies for companies
worldwide.
Information Security Policies Made Easy
is literally an all-in-one security policy resource with templates,
advice and instructions to help you generate practical, clear, and
compelling information security policies for your organization -
whether your organization is large or small. These tools will save
hours of time and thousands of dollars developing information security
policies with:
- 1360 + already-written information security policies accompanied
by explanations and expert advice for each
- Policies organized based on the ISO 17799 outline
- Security policy samples are provided in print and on CD-ROM,
with a web based application providing a fully linked and searchable
version of the content, allowing users to quickly cut and paste
policies into their own corporate documents.
- Ready-to-use information security documents such as: a risk
acceptance memo for the approval of out of compliance situations,
a non-disclosure agreement, and a user policy acceptance agreement
- Policies regarding the latest corporate security topics such
as contingency planning with regards to terrorist attacks , reporting
security incidents, network controls, Internet commerce privacy,
and identity theft
- Security policies that incorporate the latest security technology
such as macroviruses, digital certificates, encryption public
key infrastructure (PKI), intrusion detection systems, data replication,
spam (junk email), and data mining
- A step-by-step checklist of policy development tasks so that
you can start immediately to get a policy development project
underway
- Extensive cross-references between policies that help the user
quickly understand alternative solutions and complimentary controls
What's new in Version 9?
The new Version 9 of Information Security Policies Made Easy now
offers 1360 + security policy templates including new policies to
address key corporate security issues such as:
- Recent government legislation including:
- HIPAA - The Health Insurance Portability and Accountability
Act
- GLBA- The Gramm, Leach, Bliley Act
- European government legislation such as the European Union
Data Protection Directive
- Digital signatures, digital certificates, and Public Key Infrastructure
(PKI)
- Recent security threats and attacks such as web bugs and viruses
- Contingency planning and reporting of security incidents related
to terrorism
- Internet business usage, extranets, EDI over the Internet,
e-commerce site protection, and Internet credit card fraud prevention/detection
- The establishment, maintenance, and modification of firewalls
and other network perimeter security devices
- Dial-up communications security including connections made
from wireless, mobile computers
- Operational systems management regarding intranets and internal
systems interconnection
- Enterprise security management systems and consolidation of
access control
- Social engineering and masquerading
Also new in Information Security Policies Made Easy Version
9:
- Policies organization based on the ISO 17799 outline
- A graphic overview of the policy development process
- 18 security policies that every company should have, updated
and ready to use "as is"
Information Security Policies Made Easy Version 9
covers virtually every aspect of corporate information security
including:
- Web pages
- Firewalls
- Employee surveillance
- Electronic commerce
- Digital signatures
- Computer viruses
- Encryption
- Contingency planning
- Logging controls
- Internet
- Intranets
- Privacy issues
- Outsourcing security functions
- Computer emergency response teams
- Microcomputers
- Local area networks
- Password selection
- Electronic mail
- Data Classification
- Telecommuting
- Telephone systems
- Portable computers
- User training
- Information Security Related Terrorism

{ top }
About the Author
Charles Cresson Wood is an author and independent
information security consultant based in Sausalito, California.
In the information security field on a full-time basis since 1979,
he has worked as an information security management consultant at
SRI International (formerly Stanford Research Institute) as well
as lead network security consultant at the Bank of America. He has
done information security work with over 120 organizations -- many
of them Fortune 500 companies -- including a large number of financial
institutions and high-tech companies. His consulting work has taken
him to over twenty different countries around the world.
He is noted for his ability to integrate competing objectives (like
ease-of-use, speed, flexibility and security) in customized and
practical compromises that are acceptable to all parties involved.
Acknowledging that information security is multi-disciplinary, multi-
departmental, and often multi-organizational, he is additionally
noted for his ability to synthesize a large number of complex considerations
and then to document these in security architectures, system security
requirements, risk assessments, project plans, policy statements,
and other clear and action-oriented documents.
He has published over 225 technical articles and five books in
the information security field. In addition to TV and radio appearances,
he has been quoted as an expert in publications such as Business
Week, Christian Science Monitor, Computerworld, IEEE Spectrum, Infoworld,
LA Times, Network Computing, Network World, PC Week, The Wall Street
Journal, and Time. He has also presented cutting-edge information
security ideas at over 100 technical and professional conferences
around the globe.
Mr. Wood is Senior North American Editor for the journals 'Computers
& Security' and 'Computer Fraud & Security Bulletin,' as
well as a monthly columnist for 'Computer Security Alert.' He holds
an MBA in financial information systems, an MSE in computer science,
and a BSE in accounting from the Wharton School of Business at the
University of Pennsylvania. He has passed the Certified Public Accountant
(CPA) examination and is both a Certified Information Systems Auditor
(CISA) and a Certified Information Systems Security Professional
(CISSP). In November 1996 he received the Lifetime Achievement Award
from the Computer Security Institute for "sincere dedication
to the computer security profession."

{ top }
Review We are proud of outstanding
reviews like these:
"This is the gold standard Policy reference for any serious
security practitioner to have in their arsenal of tools, a must
have! The instructions and examples for establishing security polices
and implementation processes add real value to this edition"
John B. Kramer, CISSP, CISA
Information Security Manager - UPMCHS
September, 2002
"Wood has created a complete kit of proven best practices
that any organization can use and customize to make policies meeting
their exact needs."
Jay Heiser, Columnist, "Information Security"
magazine
September, 2002
"In 1993, I was asked to develop my first information
security policy. I began by cutting and pasting a serious of thoughts
and calling that a policy. Usually these policies were rejected
by management. To ensure that my organization had strong Information
Security policies in place, I purchased a copy of Information Security
Policies Made Easy. Quickly I learned that creating a policy was
a process that included writing policies, editing policies, obtaining
management approval, communicating policies, and implementing controls
to meet the policy requirements. The book provides the reader with
the tools necessary to develop policies, including an easy to use
CD ( fully-linked and searchable)."
Diana-Lynn Contesti, CISSP, SSCP
Information Security Officer - Dofasco Inc.
September, 2002
"Charles Cresson Wood...is an expert's expert, and knows
more about computer security policies than anyone I know."
Michael Alexander, Editor, Datamation
"This book is invaluable to those responsible for creating
or maintaining an information security policy manual or similar
documents."
Belden Menkus, Editor, EDPACS
"It gave us everything we needed to help us write standards
and communicate [policies] in a clear, concise manner with no ambiguity
or technical jargon ... the book paid for itself in two weeks."
Jonah Goldsmith, Data Security Consultant to Large Medical
Insurance Company, LAN Times
"If I could have only six books in my professional library,
this would be one of them."
Dr. Harold Highland, Editor, Emeritus of Computers &
Security magazine
"The [ISPME] guidelines have saved three months of manual
effort that would have been required to research and write policies."
Douglas Feil, EDP Audit Manager, City & County of San
Francisco, Network Management Systems & Strategies
Take a look at who uses ISPME:
- Ford Motor Company
- Reuters
- Amoco Corporation
- Harvard University
- RJR Tobacco
- American Telephone and Telegraph (AT&T)
- Hewlett Packard
- Rykoff-Sexton
- Swiss Bank Corp
- Simon & Schuster
- Hyundai Electronics
- Sumitomo Bank
- Automatic Data Processing (ADP)
- Sun Microsystems
- Blue Cross/Blue Shield
- International Moscow Bank
- ITT Aerospace
- Johnson & Johnson
- British Airways
- Burroughs Wellcome
- Exxon
- ... and many others.
Information Security Policies Made Easy, Version 9
Hardcover - 730 pp. includes CD-ROM and organization-wide license
to republish the materials. Published by PentaSafe Security Technologies.

{ top }
|