For all the IS Managers
NIST has released SP800-100, Information Security Handbook: A Guide for Managers. I'm sure it'd benefit everyone in the security community, since you either are or one day will be a manager (or at least help make managers make more informed decisions). Here's a quick run down on the sections it covers:
blog comments powered by Disqus
- Introduction
- Information Security Governance
- System Development Life Cycle
- Awareness and Training
- Capital Planning and Investment Control
- Interconnecting Systems
- Performance Measures
- Security Planning
- Information Technology Contingency Planning
- Risk Management
- Certification, Accreditation, and Security Assessments
- Security Services and Products Acquisition
- Incident Response
- Configuration Management