Principles of Information Systems Security: Texts and Cases
暫譯: 資訊系統安全原則:文本與案例

Gurpreet Dhillon

  • 出版商: Wiley
  • 出版日期: 2006-03-17
  • 售價: $4,380
  • 貴賓價: 9.5$4,161
  • 語言: 英文
  • 頁數: 464
  • 裝訂: Hardcover
  • ISBN: 0471450561
  • ISBN-13: 9780471450566
  • 相關分類: Penetration-test
  • 無法訂購

買這商品的人也買了...

相關主題

商品描述

Description

The real threat to information system security comes from people, not computers. That's why students need to understand both the technical implementation of security controls, as well as the softer human behavioral and managerial factors that contribute to the theft and sabotage proprietary data.

Addressing both the technical and human side of IS security, Dhillon's Princliples of Information Systems Security: Texts and Cases equips managers (and those training to be managers) with an understanding of a broad range issues related to information system security management, and specific tools and techniques to support this managerial orientation. Coverage goes well beyond the technical aspects of information system security to address formal controls (the rules and procedures that need to be established for bringing about success of technical controls), as well as informal controls that deal with the normative structures that exist within organizations.

 

Table of Contents

Preface.

Chapter 1. Information System Security: Nature and Scope.

PART I: TECHNICAL ASPECTS OF INFORMATION SYSTEM SECURITY.

Chapter 2. Security of Technical Systems in Organizations: an introduction.

Chapter 3. Models for Technical Specification of Information System Security.

Chapter 4. Cryptography and Technical Information System Security.

Chapter 5. Network Security.

PART II: FORMAL ASPECTS OF INFORMATION SYSTEM SECURITY.

Chapter 6. Security of Formal Systems in Organizations: an introduction.

Chapter 7. Planning for Information System Security.

Chapter 8. Designing Information System Security.

Chapter 9. Information System Risk Management.

PART III: INFORMAL ASPECTS OF INFORMATION SYSTEM SECURITY.

Chapter 10. Security of Informal Systems in Organizations: an introduction.

Chapter 11. Corporate Governance for IS Security.

Chapter 12. Culture and IS Security.

PART IV: REGULATORY ASPECTS OF INFORMATION SYSTEM SECURITY.

Chapter 13. Information System Security Standards.

Chapter 14. Legal Aspects of IS Security.

Chapter 15. Computer Forensics.

Chapter 16. Summary principles for Information System Security.

CASES.

Case 1: Case of a Computer Hack.

Case 2: Botnet: Anatomy of a Case.

Case 3: Cases in Computer Crime.

Case 4: IS Security at Southam Council.

Case 5: Security Management at the Tower.

Case 6: Computer crime and the demise of Barings Bank.

Case 7: Technology Enabled Fraud and the Demise of Drexel Burnham Lambert.

Case 8: It won’t part you hair: the INSLAW Affair.

Case 9: Taylor City Police Department Security Breach.

Case 10: Developing a Security Policy at M & M Procurement, Inc.

Index.

商品描述(中文翻譯)

**描述**

資訊系統安全的真正威脅來自於人,而非電腦。因此,學生需要理解安全控制的技術實施,以及促成專有數據盜竊和破壞的人類行為和管理因素。

《資訊系統安全原則:文本與案例》一書同時針對資訊系統安全的技術和人為方面進行探討,為管理者(以及正在培訓成為管理者的人)提供了對資訊系統安全管理相關廣泛議題的理解,以及支持這一管理導向的具體工具和技術。內容不僅涵蓋資訊系統安全的技術層面,還涉及正式控制(需要建立的規則和程序,以確保技術控制的成功)以及處理組織內部存在的規範結構的非正式控制。

**目錄**

前言。

第一章:資訊系統安全:性質與範圍。

第一部分:資訊系統安全的技術層面。

第二章:組織中技術系統的安全:簡介。

第三章:資訊系統安全的技術規範模型。

第四章:密碼學與技術資訊系統安全。

第五章:網路安全。

第二部分:資訊系統安全的正式層面。

第六章:組織中正式系統的安全:簡介。

第七章:資訊系統安全的規劃。

第八章:設計資訊系統安全。

第九章:資訊系統風險管理。

第三部分:資訊系統安全的非正式層面。

第十章:組織中非正式系統的安全:簡介。

第十一章:資訊系統安全的企業治理。

第十二章:文化與資訊系統安全。

第四部分:資訊系統安全的法規層面。

第十三章:資訊系統安全標準。

第十四章:資訊系統安全的法律層面。

第十五章:電腦取證。

第十六章:資訊系統安全的總結原則。

案例。

案例1:電腦駭客案例。

案例2:Botnet:案例解剖。

案例3:電腦犯罪案例。

案例4:南漢市議會的資訊系統安全。

案例5:塔樓的安全管理。

案例6:電腦犯罪與巴林銀行的垮台。

案例7:技術驅動的詐騙與德雷克塞爾·伯納姆·蘭伯特的垮台。

案例8:這不會讓你分開頭髮:INSLAW事件。

案例9:泰勒市警察局的安全漏洞。

案例10:在M & M採購公司制定安全政策。

索引。