Business Continuity and Disaster Recovery for InfoSec Managers

Rittinghouse, PhD, CISM, John; Ransome, PhD, CISM, CISSP, James F.

In stock
Regular price 12.250 KD inc. VAT
License
Table of contents
  • Cover
  • Contentsv
  • Forewordxv
  • Foreword by Mr. Paul Kurtzxv
  • Introductionxix
  • Introduction: Business Security 101xix
  • The State of the BCP and Network Disaster Recovery Industry: Where Are We and Why?xx
  • Threats to Personal Privacyxxiii
  • Fraud and Theftxxiv
  • Internet Fraudxxiv
  • Employee Sabotagexxvii
  • Infrastructure Attacksxxvii
  • Malicious Hackersxxvii
  • Malicious Codersxxviii
  • Industrial Espionagexxix
  • Social Engineeringxxxi
  • Educate Staff and Security Personnelxxxiii
  • Managing Accessxli
  • Physical Accessxli
  • Access Controlxlii
  • Access Control Modelsxliv
  • Password Managementlvii
  • Security Management Practiceslxiii
  • Chapter Summarylxiv
  • Endnoteslxv
  • Acknowledgmentslxix
  • Chapter 1. Contingency and Continuity Planning1
  • 1.1 Business Continuity Planning2
  • 1.2 BCP Standards and Guidelines11
  • 1.3 BCP Project Organization14
  • 1.4 Chapter Summary20
  • 1.5 Endnotes21
  • Chapter 2. Assessing Risk23
  • 2.1 Determining Threats23
  • 2.2 Risk Management27
  • 2.3 The Risk Manager28
  • 2.4 Risk Assessment28
  • 2.5 Emergency Incident Assessment30
  • 2.6 Business Risk Assessment65
  • 2.7 Business Impact Analysis (BIA)69
  • 2.8 Information Security, IT and Communications86
  • 2.9 Chapter Summary93
  • 2.10 Endnotes94
  • Chapter 3. Mitigation Strategies97
  • 3.1 Preventative Measures for Information Security Managers100
  • 3.2 Information Security Preventative Controls107
  • 3.3 Other Preventative Controls110
  • 3.4 Summary of Existing Emergency Procedures115
  • 3.5 Key Personnel for Handling Emergency Procedures115
  • 3.6 External Emergency Services129
  • 3.7 Premises Issues131
  • 3.8 Chapter Summary131
  • 3.9 Endnotes132
  • Chapter 4. Preparing for a Possible Emergency133
  • 4.1 Backup and Recovery Procedures133
  • 4.2 IT Systems Recovery136
  • 4.3 Key BCP Personnel and Supplies152
  • 4.4 Key Documents and Procedures152
  • 4.5 Chapter Summary153
  • 4.6 Endnotes153
  • Chapter 5. Disaster Recovery Phase155
  • 5.1 Disaster Recovery Legal Issues156
  • 5.2 Planning for Handling the Emergency158
  • 5.3 Disaster Recovery Team Management Actions165
  • 5.4 Notification and Reporting in Disaster Recovery Phase166
  • 5.5 Disaster Recovery Phase Report168
  • 5.6 Chapter Summary169
  • 5.7 Endnotes169
  • Chapter 6. Business Recovery Phase171
  • 6.1 Business Recovery Planning Process171
  • 6.2 Planning Business Recovery Activities185
  • 6.3 Chapter Summary190
  • Chapter 7. Testing, Auditing, and Training193
  • 7.1 Testing the Business Recovery Process194
  • 7.2 Security Testing197
  • 7.3 The Open Source Security Testing Methodology Manual200
  • 7.4 Monitoring and Updating202
  • 7.5 Hardening Systems203
  • 7.6 System Patches206
  • 7.7 Auditing Fundamentals207
  • 7.8 Auditor's Role in Developing Security Policies208
  • 7.9 Auditing Standards and Groups210
  • 7.10 Audit Oversight Committee214
  • 7.11 Auditing and Assessment Strategies214
  • 7.12 Basic Audit Methods and Tools221
  • 7.13 General Information Systems (IS) Audit Process225
  • 7.14 Perimeter Audits228
  • 7.15 Using Nmap229
  • 7.16 Mapping the Network with Nmap231
  • 7.17 Analyzing Nmap Scan Results232
  • 7.18 Penetration Testing Using Nessus233
  • 7.19 Training Staff for the Business Recovery Process234
  • 7.20 Chapter Summary237
  • 7.21 Endnotes238
  • Chapter 8. Maintaining a Business Continuity Plan241
  • 8.1 How to Maintain the Business Continuity Plan241
  • 8.2 BCP Maintenance245
  • 8.3 BCP Distribution Issues247
  • 8.4 Awareness and Training Programs248
  • 8.5 Monitor and Review249
  • 8.6 Roles and Responsibilities for Maintaining the BCP Plan249
  • 8.7 Chapter Summary250
  • BCP/DR Glossary253
  • General References275
  • A. Sample Recovery Checklist283
  • A.1 Recovery Checklist (Incident Response Team)283
  • B Physical Facility Questionnaire291
  • C Organizational Security Management295
  • C.1 Organizational Security Management295
  • C.2 Security Management Areas of Responsibility299
  • C.3 Security Policies307
  • C.4 Security Personnel313
  • C.5 Management of Security Professionals318
  • C.6 Summary321
  • C.7 Endnotes322
  • Index323
Book details
  • Vendor Elsevier S & T
  • SKU 9781555583392R150
  • ISBN-13 9780080528335
  • Author Rittinghouse, PhD, CISM, John; Ransome, PhD, CISM, CISSP, James F.
  • Category Computers
  • Subject Information Technology

Do you have questions about this book?

Ask an expert!

Every year, nearly one in five businesses suffers a major disruption to its data or voice networks or
communications systems. Since 9/11 it has become increasingly important for companies to implement a
plan for disaster recovery. This comprehensive book addresses the operational and day-to-day security
management requirements of business stability and disaster recovery planning specifically tailored for the needs and requirements of an Information Security Officer.

This book has been written by battle tested security consultants who have based all the material, processes and problem- solving on real-world planning and recovery events in enterprise environments world wide.

John has over 25 years experience in the IT and security sector. He is an often sought management consultant for large enterprise and is currently a member of the Federal Communication Commission's Homeland Security Network Reliability and Interoperability Council Focus Group on Cybersecurity, working in the Voice over Internet Protocol workgroup.

James has over 30 years experience in security operations and technology assessment as a corporate security executive and positions within the intelligence, DoD, and federal law enforcement communities. He has a Ph.D. in information systems specializing in information security and is a member of Upsilon Pi Epsilon (UPE), the International Honor Society for the Computing and Information Disciplines. He is currently an Independent Consultant.

· Provides critical strategies for maintaining basic business functions when and if systems are shut down
· Establishes up to date methods and techniques for maintaining second site back up and recovery
· Gives managers viable and efficient processes that meet new government rules for saving and protecting data in the event of disasters