Cart
Free US shipping over $10
Proud to be B-Corp

Building and Implementing a Security Certification and Accreditation Program Patrick D. Howard (Chief Information Security Officer, Nuclear Regulatory Commission, USA)

Building and Implementing a Security Certification and Accreditation Program By Patrick D. Howard (Chief Information Security Officer, Nuclear Regulatory Commission, USA)

Building and Implementing a Security Certification and Accreditation Program by Patrick D. Howard (Chief Information Security Officer, Nuclear Regulatory Commission, USA)


$7.05
Condition - Very Good
Only 1 left

Summary

Demonstrates the effectiveness of certification and accreditation (C&A) as a risk management methodology for IT systems in public and private organizations. This book offers security professionals with an overview of C&A components, showing them how to document the status of IT security controls and secure systems via standard processes.

Faster Shipping

Get this product faster from our US warehouse

Building and Implementing a Security Certification and Accreditation Program Summary

Building and Implementing a Security Certification and Accreditation Program: OFFICIAL (ISC)2 GUIDE to the CAPcm CBK by Patrick D. Howard (Chief Information Security Officer, Nuclear Regulatory Commission, USA)

Building and Implementing a Security Certification and Accreditation Program: Official (ISC)2 Guide to the CAP CBK demonstrates the practicality and effectiveness of certification and accreditation (C&A) as a risk management methodology for IT systems in both public and private organizations. It provides security professionals with an overview of C&A components, enabling them to document the status of the security controls of their IT systems, and learn how to secure systems via standard, repeatable processes.

This book consists of four main sections. It begins with a description of what it takes to build a certification and accreditation program at the organization level, followed by an analysis of various C&A processes and how they interrelate. The text then provides a case study of the successful implementation of certification and accreditation in a major U.S. government department. It concludes by offering a collection of helpful samples in the appendices.

Table of Contents

Building a Successful Enterprise Certification and
Accreditation Program
Key Elements of an Enterprise Certification and
Accreditation Program
Certification and Accreditation Roles and
Responsibilities
The Certification and Accreditation Life Cycle
Why Certification and Accreditation Programs Fail
Certification and Accreditation Processes
Certification and Accreditation Project Planning
System Inventory Process
Assessing Data Sensitivity and Criticality
System Security Plans
Coordinating Security for Interconnected Systems
Minimum Security Baselines and Best Practices
Assessing Risk
Security Procedures
Certification Testing
Remediation Planning
Essential Certification and Accreditation
Documentation
Documenting the Accreditation Decision
Certification and Accreditation Case Study
The Future of Certification and Accreditation
Appendices
Certification and Accreditation References
Glossary
Sample Statement of Work
Sample Project Work Plan
Sample Project Kickoff Presentation Outline
Sample Project Wrap-Up Presentation Outline
Sample System Inventory Policy
Sample Business Impact Assessment
Sample Rules of Behavior (General Support System)
Sample Rules of Behavior (Major Application)
Sample System Security Plan Outline
Sample Memorandum of Understanding
Sample Interconnection Security Agreement
Sample Risk Assessment Outline
Sample Security Procedure
Sample Certification Test Results Matrix
Sample Risk Remediation Plan
Sample Certification Statement
Sample Accreditation Letter
Sample Interim Accreditation Letter

Additional information

CIN0849320623VG
9780849320620
0849320623
Building and Implementing a Security Certification and Accreditation Program: OFFICIAL (ISC)2 GUIDE to the CAPcm CBK by Patrick D. Howard (Chief Information Security Officer, Nuclear Regulatory Commission, USA)
Used - Very Good
Hardback
Taylor & Francis Ltd
2005-12-15
344
N/A
Book picture is for illustrative purposes only, actual binding, cover or edition may vary.
This is a used book - there is no escaping the fact it has been read by someone else and it will show signs of wear and previous use. Overall we expect it to be in very good condition, but if you are not entirely satisfied please get in touch with us

Customer Reviews - Building and Implementing a Security Certification and Accreditation Program