Information Security and Networking – MIS450
Corporate Computer Security, 4th Edition Randall J. Boyle & Raymond R. Panko
Chapter 2 Planning and Policy
PAGES (80-90) AND (97-136)
Justify the need for formal management processes.
Explain the planprotectrespond security management cycle.
Describe compliance laws and regulations.
Describe organizational security issues.
Describe risk analysis.
Describe technical security infrastructure.
Explain policy-driven implementation.
Know governance frameworks.
Learning Objectives
3
4
The first chapter focused on threats
The rest of the book focuses on defense
In this chapter, we will see that defensive thinking is build around the plan-protect-respond cycle
In this chapter, we will focus on planning
Chapters 3 to 9 focus on protection
Chapter 10 focuses on response
Orientation
5
Whats Next?
2.1 Introduction & Terminology
2.2 Compliance Laws and Regulations
2.3 Organization
2.4 Risk Analysis
2.5 Technical Security Architecture
2.6 Policy-Driven Implementation
2.7 Governance Frameworks



Recent Comments