Implementing ISO27001 in a Windows(R) Environment - Bookswagon
Book 1
Book 2
Book 3
Book 1
Book 2
Book 3
Book 1
Book 2
Book 3
Book 1
Book 2
Book 3
Home > Computing and Information Technology > Computer security > Implementing ISO27001 in a Windows(R) Environment
Implementing ISO27001 in a Windows(R) Environment

Implementing ISO27001 in a Windows(R) Environment


     0     
5
4
3
2
1



Out of Stock


Notify me when this book is in stock
X
About the Book

The information security management standard (ISMS), ISO/IEC 27001, provides a significant implementation challenge for all organisations. ISO27001 is a management standard: it sets out a specification for how management should identify, from a business risk perspective, the controls and safeguards that should be applied to information assets in order to assure their confidentiality, integrity and confidentiality. Management - and also the ISMS implementation project manager - will usually have a general or quality management background. A significant number of the controls to be applied will, of necessity, be technical and will relate to how IT hardware and software are set up and configured. The technical knowledge to carry out this configuration is usually within the IT or corporate information security team and, because information security is a business responsibility, this team should never have overall accountability for determining the actual controls required by the ISMS. As a result, there is often a gulf in understanding as to what is required between the ISO27001 ISMS project manager and those responsible for implementing the technical controls. This book does an outstanding job of helping parties on both sides to bridge the gulf. It identifies the recommended technical controls of ISO27001's Annex A and, for a Microsoft environment, provides guidance on how (if, on the basis of a risk assessment, they are considered necessary) to implement them. This book fills a major hole in the guidance literature for ISO27001 and will make a significant contribution to helping both project managers and IT and security staff get to grips with what controls are appropriate to mitigate identified risks.

Table of Contents:
Introduction 14 Chapter 1: Information and Information Security 18 Information security concepts 19 Other information security concepts 19 The importance of information security 21 Chapter 2: Using an ISMS to Counter the Threats 24 System security versus information security 25 The structure of an ISMS 26 Managing exceptions to the policy 31 Chapter 3: An Introduction to ISO27001 33 The ISO27000 standards family 34 History of ISO27001 36 What is in the ISO27001 standard? 37 The plan, do, check and act cycle (PDCA) 39 What are the benefits of ISO27001? 42 Chapter 4: Identify your Information Assets 44 Define the scope of the ISMS 44 Identifying your information security assets 45 Chapter 5: Conducting a Risk Assessment 49 What is risk? 50 Managing risks 55 The different types of risk analysis 57 Risk management tools 62 Chapter 6: An Overview of Microsoft Technologies 65 Microsoft(R) Windows Server(R) 2008 66 Microsoft(R) Windows Vista(R) 72 Microsoft(R) ForefrontA' 76 Microsoft(R) Systems Center 78 Microsoft(R) Windows Server(R) Update Services 79 Microsoft(R) Baseline Security Analyzer 80 Microsoft Security Risk Management Guide 80 Microsoft(R) SPIDER Technical Compliance Management 81 Microsoft(R) Threat Analysis and Modeling Enterprise Edition 82 Microsoft(R) CAT.NET 83 Microsoft(R) Source Code Analyzer for SQL Injection 84 XSS Detect Beta Code Analysis Tool 84 Chapter 7: Implementing ISO27001 in a Microsoft Environment 85 Section 4 Information security management system 86 Section A.5 Security policy 91 Section A.6 Organisational security 92 Section A.7 Asset management 96 Section A.8 Human resource security 99 Section A.9 Physical and environmental security 103 Section A.10 Communications and operations management 109 Section A.11 Access control 131 Section A.12 Information systems acquisition development and maintenance 147 Section A.13 Information security incident management 157 Section A.14 - Business continuity management 168 Section A.15 Compliance 170 Chapter 8: Securing the Windows(R) Environment 177 Windows Server(R) 2008 architecture 177 Domain user accounts naming standards 182 Chapter 9: Securing the Microsoft(R) Windows Server(R) Platform 187 Recommended settings 190 Chapter 10: Auditing and Monitoring 193 Configuring auditing of file and resource access 198 Event log settings 199 Events to record 201 Chapter 11: Securing your Servers 204 Protecting files and directories 256 Appendix 1: Overview of Security Settings for Windows Server(R) 2008 Servers and Domain Controllers 257 Service pack and hotfixes 257 Account and audit policies 258 Event log settings 263 Security settings 266 Service settings 286 User rights 294 Registry permissions 302 File and registry auditing 302 Appendix 2: Bibliography, Reference and Further Reading 303 ISO27001 resources 303 Microsoft resources 303 Microsoft products 305 Other resources 306 ITG Resources 307

About the Author :
Brian Honan is recognised as an industry expert on information security, in particular the ISO27001 information security standard, and has addressed a number of major conferences relating to the management and securing of information technology. An independent consultant based in Dublin, Ireland, Brian provides consulting services to clients in various industry segments and his work also includes advising various Government security agencies and the European Commission. Brian also established Ireland's first ever national Computer Security Incident Response Team. He has also had a number of technical papers published and has been technical editor and reviewer of a number of industry-recognised publications. Brian is also the European editor for the SANS Institute's weekly SANS NewsBites, a semi-weekly electronic newsletter. He is a member of the Information Systems Security Association, Irish Information Security Forum, Information Systems Audit and Control Association, a member of the Irish Computer Society and the Business Continuity Institute, and was a founding member of the Irish Corporate Windows NT(R) User Group.


Best Sellers


Product Details
  • ISBN-13: 9781905356799
  • Publisher: IT Governance Publishing
  • Publisher Imprint: IT Governance Publishing
  • Language: English
  • ISBN-10: 190535679X
  • Publisher Date: 03 Feb 2009
  • Binding: Digital (delivered electronically)
  • No of Pages: 308


Similar Products

Add Photo
Add Photo

Customer Reviews

REVIEWS      0     
Click Here To Be The First to Review this Product
Implementing ISO27001 in a Windows(R) Environment
IT Governance Publishing -
Implementing ISO27001 in a Windows(R) Environment
Writing guidlines
We want to publish your review, so please:
  • keep your review on the product. Review's that defame author's character will be rejected.
  • Keep your review focused on the product.
  • Avoid writing about customer service. contact us instead if you have issue requiring immediate attention.
  • Refrain from mentioning competitors or the specific price you paid for the product.
  • Do not include any personally identifiable information, such as full names.

Implementing ISO27001 in a Windows(R) Environment

Required fields are marked with *

Review Title*
Review
    Add Photo Add up to 6 photos
    Would you recommend this product to a friend?
    Tag this Book Read more
    Does your review contain spoilers?
    What type of reader best describes you?
    I agree to the terms & conditions
    You may receive emails regarding this submission. Any emails will include the ability to opt-out of future communications.

    CUSTOMER RATINGS AND REVIEWS AND QUESTIONS AND ANSWERS TERMS OF USE

    These Terms of Use govern your conduct associated with the Customer Ratings and Reviews and/or Questions and Answers service offered by Bookswagon (the "CRR Service").


    By submitting any content to Bookswagon, you guarantee that:
    • You are the sole author and owner of the intellectual property rights in the content;
    • All "moral rights" that you may have in such content have been voluntarily waived by you;
    • All content that you post is accurate;
    • You are at least 13 years old;
    • Use of the content you supply does not violate these Terms of Use and will not cause injury to any person or entity.
    You further agree that you may not submit any content:
    • That is known by you to be false, inaccurate or misleading;
    • That infringes any third party's copyright, patent, trademark, trade secret or other proprietary rights or rights of publicity or privacy;
    • That violates any law, statute, ordinance or regulation (including, but not limited to, those governing, consumer protection, unfair competition, anti-discrimination or false advertising);
    • That is, or may reasonably be considered to be, defamatory, libelous, hateful, racially or religiously biased or offensive, unlawfully threatening or unlawfully harassing to any individual, partnership or corporation;
    • For which you were compensated or granted any consideration by any unapproved third party;
    • That includes any information that references other websites, addresses, email addresses, contact information or phone numbers;
    • That contains any computer viruses, worms or other potentially damaging computer programs or files.
    You agree to indemnify and hold Bookswagon (and its officers, directors, agents, subsidiaries, joint ventures, employees and third-party service providers, including but not limited to Bazaarvoice, Inc.), harmless from all claims, demands, and damages (actual and consequential) of every kind and nature, known and unknown including reasonable attorneys' fees, arising out of a breach of your representations and warranties set forth above, or your violation of any law or the rights of a third party.


    For any content that you submit, you grant Bookswagon a perpetual, irrevocable, royalty-free, transferable right and license to use, copy, modify, delete in its entirety, adapt, publish, translate, create derivative works from and/or sell, transfer, and/or distribute such content and/or incorporate such content into any form, medium or technology throughout the world without compensation to you. Additionally,  Bookswagon may transfer or share any personal information that you submit with its third-party service providers, including but not limited to Bazaarvoice, Inc. in accordance with  Privacy Policy


    All content that you submit may be used at Bookswagon's sole discretion. Bookswagon reserves the right to change, condense, withhold publication, remove or delete any content on Bookswagon's website that Bookswagon deems, in its sole discretion, to violate the content guidelines or any other provision of these Terms of Use.  Bookswagon does not guarantee that you will have any recourse through Bookswagon to edit or delete any content you have submitted. Ratings and written comments are generally posted within two to four business days. However, Bookswagon reserves the right to remove or to refuse to post any submission to the extent authorized by law. You acknowledge that you, not Bookswagon, are responsible for the contents of your submission. None of the content that you submit shall be subject to any obligation of confidence on the part of Bookswagon, its agents, subsidiaries, affiliates, partners or third party service providers (including but not limited to Bazaarvoice, Inc.)and their respective directors, officers and employees.

    Accept

    Fresh on the Shelf


    Inspired by your browsing history


    Your review has been submitted!

    You've already reviewed this product!