The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments | by Craig S. Wright | ISBN: 9781597492669. IT Compliance Guideline. Information Systems Audit Program. Developing IT Security Policy. Vulnerability Assessment Tools. Information Systems Legislation

January 30, 2010 by kutenk
Filed under: Computer Books 

The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments

by Craig S. Wright
ISBN:9781597492669

Providing detailed information on testing all your IT security, policy and governance requirements, this roadmap guide presents a way of interpreting complex, confusing compliance requirements within the larger scope of an organization’s overall needs.

Get this Book by clicking below:

Get Book Now

The IT Regulatory and Standards Compliance Handbook—How to Survive Information Systems Audit and Assessments









Chapter 1 – Introduction to IT Compliance
Introduction
Does Security Belong within IT?
What Are Audits, Assessments, and Reviews?
Summary

Chapter 2 – Evolution of Information Systems
Introduction
The Primary Objective of Auditing
The Threat Scene
Attack Levels
Policy > Procedure > Audit
Summary

Chapter 3 – The Information Systems Audit Program
Introduction
Audit Checklists
Testing Your Organization’s Security
Developing an Audit Manual
Security Management Model
Summary

Chapter 4 – Planning
Introduction
Performance of Audit Work
Scope
Audit Planning
Summary

Chapter 5 – Information Gathering
Obtaining Information and Issuing Requests
How to Characterize Your Organization
What Happens if Documentation Is Incomplete or Unavailable?
What Information Is Required?
General Background Information
Side Issues with Gathering Passwords
Access Control Techniques and Types
Terms and Definitions
Summary

Chapter 6 – Security Policy Overview
Introduction
The Role of Policy and Procedures in Information Systems Defense
What’s What?
Interpreting Policy as an Auditor
Identifying Preventive, Detective and Corrective Controls
Developing a Security Policy
Policy Areas to Be Considered
Policy Frameworks
The SANS Security Policy Project
Example Policy: SANS InfoSec Acceptable Use Policy
More Information
Summary

Chapter 7 – Policy Issues and Fundamentals
Introduction
The Auditor’s Role in Relation to Policy Creation and Compliance
Summary





Chapter 8 – Assessing Security Awareness and Knowledge of Policy
Introduction
Security Awareness and Training
Example Slide Content
System Improvement Monitoring and Checks
Summary

Chapter 9 – An Introduction to Network Audit
Introduction
What Is a Vulnerability Assessment?
A Survey of Vulnerability Assessment Tools
Network Mapping
Auditing Routers, Switches, and Other Network Infrastructure
Network and Vulnerability Scanning
Summary




Chapter 10 – Auditing Cisco Routers and Switches
Introduction
Functions of a Router, Its Architectures, and Components
How a Router Can Play a Role in Your Security Infrastructure
Router Technology: A TCP/IP Perspective
Understanding the Auditing Issues with Routers
Sample Router Architectures in Corporate WANs
Router Audit Tool (RAT) and Nipper
Security Access Controls Performed by a Router
Security of the Router Itself and Auditing for Router Integrity
Identifying Security Vulnerabilities
Router Audit Steps
Sample Commands
Cisco Router Check Lists
Summary

Chapter 11 – Testing the Firewall
Introduction
OS Configuration
Firewall Configuration
Working with Firewall Builder
System Administration
Testing the Firewall Rulebase
Identifying Misconfigurations
Identifying Vulnerabilities
Packet Flow from All Networks
Change Control
Validated Firewalls
Summary

Chapter 12 – Auditing and Security with Wireless Technologies
Introduction
Capturing Wireless Traffic
Conducting Wireless Site Surveys
Common Misconceptions with Wireless Security
Techniques for Identifying and Locating Rogue APs
Wireless “Hacker” Tools to Evaluate Your Network
Designing and Deploying WLAN Intrusion Detection Services
Summary

Chapter 13 – Analyzing the Results
Introduction
Organizing the Mapping Results
Understanding the Map
Identifying Vulnerabilities
Follow-on Activities
Summary

Chapter 14 – An Introduction to Systems Auditing
Introduction
Automating the Audit Process
Progressive Construction of a Comprehensive Audit Program
Host Hardening
Physical, Electronic and Environmental Security
Password-Cracking Tools
Summary



Chapter 15 – Database Auditing
Introduction
Database Security
Tools
Introduction to SQL
Remote Testing
Local Security
Summary

Chapter 16 – Microsoft Windows Security and Audits
Introduction
Basic System Information
Patch levels
Network-Based Services
Local Services
Installed Software
Security Configuration
Group Policy Management
Service Packs, Patches and Backups
Auditing and Automation
Log aggregation, management and analysis
Maintaining a Secure Enterprise
Creating Your Checklist
Summary

Chapter 17 – Auditing UNIX and Linux
Introduction
Patching and Software Installation
Minimizing System Services
Logging
File System Access Control
Additional Security Configuration
Backups and Archives
Auditing to Create a Secure Configuration
Auditing to Maintain a Secure Configuration



Chapter 18 – Auditing Web-Based Applications
Introduction
Cross-Site Scripting
DNS Rebinding Attacks
p0wf (Passing Fingerprinting of Web Content Frameworks)
Splogging

Chapter 19 – Other Systems
Introduction
Mainframes and Legacy Systems
UML
Code Reviews and Testing Third-Party Software
Encryption
Summary

Chapter 20 – Risk Management, Security Compliance, and Audit Controls
Introduction
Risk Analysis
Creating an Information Systems Risk Program
Risk Summary
Business Impact Analysis
Defense in Depth
Data Classification
Summary

Chapter 21 – Information Systems Legislation
Introduction
Civil and Criminal Law
Legal Requirements
Jurisdiction
Defamation and Injurious Falsehood
Harassment and Cyber Stalking
Pornography and Obscenity
Privacy
Searches and the Fourth Amendment
Authorization
Intellectual Property
Evidence Law
Interpol and Information Technology Crime
Reporting an Incident
Document Retention
Due Care and Due Diligence
Electronic Discovery
Reviewing and Auditing Contracts
Prevention Is the Key
Summary

Chapter 22 – Operations Security
Introduction
Administrative Management
Individual Accountability
Operational Controls
Intrusion Detection
Auditing to Determine What Went Wrong
Summary

For 1000+ more Computer Books & Computer Auditing Books, click below:

Computer Books
Business & Management Books
Science & Engineering Books

Related posts:

  1. The Executive MBA in Information Security | by John J. Trinckes, Jr. | 2010 | ISBN: 9781439810071. Information Security Management. IT Audit and Compliance. Effective Information Security Program. Administrative Controls. Technical Controls. Application Controls. Perimeter Controls
  2. Computer and Information Security Handbook | by John R. Vacca (ed) | 2009 | ISBN: 9780123743541. System and Network Security. TEN STEPS TO BUILDING A SECURE ORGANIZATION. Unix and Linux Security. Internet Security. Information Technology Security Management. Security Management Systems. Computer Forensics
  3. Application Security in the ISO27001 Environment | by Vinod Vasudevan et al. | ISBN: 9781905356355. International Information Security Standards. Secure Application Development Lifecycle. Information Security Management System.
  4. Fraud Risk Assessment: Building a Fraud Audit Program | by Leonard W. Vona | ISBN: 9780470129456. Fraud Management Books. Payroll Fraud Schemes. Fraud Risk Control Strategy. Sample Fraud Audit Report. Travel Expense Concealment Strategies. Fraud in Expenditure. Contract Fraud Audit Plan
  5. Handbook of Research on Information Security and Assurance | by Jatinder N. D. Gupta and Sushil K. Sharma (eds) | 2009 | ISBN: 9781599048550. E-Commerce Security Risks and Countermeasures. Information Security Management Research. Effective Security Policies and Procedures.
  6. Cyber Security and Global Information Assurance: Threat Analysis and Response Solutions | by Kenneth J. Knapp (ed) | 2009 | ISBN: 9781605663265. Insider Threat Prevention, Detection and Mitigation. Information Security Management Standards. Approach to Managing Identity Fraud. Emergency Response Planning
  7. Safety and Security Review for the Process Industries: Application of HAZOP, PHA and What-If Reviews, 2nd Edition | by Dennis P. Nolan | ISBN: 9780815515463. Qualitative Safety Reviews. Security Vulnerability Analysis (SVA). Process Hazard Analysis Reviews. Quality Assurance Audit Checklist.
  8. Information Security Management Handbook, Sixth Edition, Volume 3 | by Harold F. Tipton and Micki Krause (eds) | 2009 | ISBN: 9781420090925. Identity Management Systems. Mobile Data Security. Web Application Firewalls. Botnets.
  9. Handbook of Research on Building Information Modeling and Construction Informatics: Concepts and Technologies | by Jason Underwood and Umit Isikdag (eds) | 2010 | ISBN: 9781605669281. INFORMATION MODELING TOOLS. Geospatial Information Systems.
  10. Homeland Security Preparedness and Information Systems: Strategies for Managing Public Policy | by Christopher G. Reddick | 2010 | ISBN: 9781605668345. Citizen-Centric E-Government. EMERGENCY MANAGEMENT WEBSITE CONTENT ANALYSIS. THREAT PROTECTION MECHANISMS.
  11. Brink’s Modern Internal Auditing: A Common Body of Knowledge, Seventh Edition | by Robert R. Moeller | 2009 | ISBN: 9780470293034. The Professional Internal Auditor Reference Book. Internal Control Framework. Internal Controls Standards. Audit Tools and Techniques.
  12. Data Protection: Governance, Risk Management, and Compliance | by David G. Hill | 2010 | ISBN: 9781439806920. Business Continuity management. Disaster Recovery. Information Lifecycle Management. Data Retention Policy Management.
  13. Computer Security Handbook, Fifth Edition | by Seymour Bosworth, M.E. Kabay and Eric Whyne (eds) | 2009 | ISBN: 9780471716525. Computer Books. IT EBooks. Information System Security Books.
  14. Strategic Information Management: Challenges and Strategies in Managing Information Systems, Third Edition | by Robert D. Galliers and Dorothy E. Leidner (eds) | ISBN: 9780750656191. Strategic Information Systems. Information Systems Planning Process. Information Systems–Business Strategy Alignment
  15. Under Control: Governance Across the Enterprise | by Jacob Lamm et al. | 2009 | ISBN: 9781430215929. Governance of Risk and Compliance. IT Compliance Controls. Information Government Framework. Controls Monitoring and Reporting.
  16. Schneier on Security | by Bruce Schneier | ISBN: 9780470395356. Information Security Books. The Architecture of Security. The Risks of Cyberterrorism. Identity-Theft Disclosure Laws. The Security of RFID Passports. Cybercrime and Cyberwar. Software Vulnerabilities
  17. 12 Security Services that are Critical for Successful E-Commerce Security. Comprehensive Safeguards Assessment for your E-Commerce and Web Server.
  18. Wiley CPA Exam Review 2010: Auditing and Attestation | by O. Ray Whittington and Patrick R. Delaney | ISBN: 9780470453490. Auditor’s Consideration of Internal Control. Financial Statement Audit Reports. Programs and Controls Related to Fraud. Government Auditing Standards.
  19. Securing Intellectual Property: Protecting Trade Secrets and Other Information Assets | by Information Security | 2009 | ISBN: 9780750679954. How to Sell Your Intellectual Property Protection Program. Top Ten Ways to Shut Down Hackers. Checklist for Reporting a Theft of Trade Secrets Offense.
  20. Security Engineering: A Guide to Building Dependable Distributed Systems, Second Edition | by Ross J. Anderson | ISBN: 9780470068526. Electronic and Information Warfare. Network Attack and Defense.
  21. Water and Wastewater Engineering. Water Supply Systems Security | by Larry W. Mays (ed) | 2004 | ISBN: 9780071425315. DRINKING WATER SECURITY AND SAFETY. WATER SYSTEM EMERGENCY RESPONSE PLAN. SECURITY HARDWARE AND SURVEILLANCE SYSTEMS FOR WATER SUPPLY SYSTEMS
  22. Audit Committee Essentials | by Curtis C. Verschoor | ISBN: 9780471699590. Internal Auditors Guide. AUDITING AND INTERNAL CONTROL. CHARACTERISTICS OF AN EFFECTIVE BOARD MEMBER. ETHICS AND COMPLIANCE PROGRAMS. Oversight of Financial Statements and Financial Disclosures. Effective Board Processes.
  23. IT Compliance and Controls: Best Practices for Implementation | by James J. DeLuccia IV | ISBN: 9780470145012. INFORMATION TECHNOLOGY INTERNAL CONTROLS. Enterprise Risk Analysis. Life-Cycle Management. BUILDING INCIDENT RESPONSE CAPABILITY.
  24. New Information Security Framework. Six security elements—availability, utility, integrity, authenticity, confidentiality, and possession.
  25. IT Governance: Implementing Frameworks and Standards for the Corporate Governance of IT | by Alan Calder | 2009 | ISBN: 9781905356904. IT Regulatory Compliance. ITIL/COBIT/ISO27002 Joint Framework. ISO/IEC 38500. Calder-Moir Framework.
  26. Security in RFID and Sensor Networks | by Yan Zhang and Paris Kitsos (eds) | 2009 | ISBN: 9781420068399. Multi-Tag RFID Systems. How to Attack RFID Systems. RFID Relay Attacks Implementation. Designing Secure Wireless Embedded Systems. Security Schemes Against Jamming in Wireless Sensor Networks
  27. The CSSLP Prep Guide: Mastering the Certified Secure Software Lifecycle Professional | by Ronald L. Krutz and Alexander J. Fry | 2009 | ISBN: 9780470461907. Software Engineering Books. Security Design Principles. Software Development Methodologies. Standards for Software Quality Assurance
  28. Knowledge Management Strategies for Business Development | by Meir Russ (ed) | 2010 | ISBN: 9781605663487. How to Create Agile Alignment of Enterprise Execution Capabilities with Strategy. Knowledge Assessment Review and Management Audit. Organizational Knowledge Management Strategic Dilemmas.
  29. Utilizing Information Technology Systems Across Disciplines: Advancements in the Application of Computer Science | by Evon M. O. Abu-Taieh, Asim A. El-Sheikh and Jeihan Abu-Tayeh | 2009 | ISBN: 9781605666167. Information Technology Research. Information Resources Management
  30. Highway Engineering, Seventh Edition | by Paul H. Wright, Karen Dixon and Michael Meyer | ISBN: 9780471264613. Traffic Engineering. Advanced Transportation Management Systems. Highway Maintenance and Rehabilitation. Geometric Design of Highways. Highway Materials. Traffic Control Devices and Systems.
  31. Implementing Program Management: Templates and Forms Aligned with the Standard for Program Management , Second Edition | by Ginger Levin and Allen R. Green | 2010 | ISBN: 9781439816059. Program Governance Plan. Program Architecture Plan. Program Transition Plan.
  32. Architecting Secure Software Systems | by Asoke K. Talukder and Manish Chaitanya | 2009 | ISBN: 9781420087840. How to Construct Secured and Safe C/UNIX Programs. How to Construct Secured Web Services. ASP.NET Security. Java Security.
  33. Web Services Security Development and Architecture: Theoretical and Practical Issues | by Carlos Gutiérrez and Mario Piattini | 2010 | ISBN: 9781605669502. Security Analysis of Service Oriented Systems. Forensics over Web Services.
  34. Program Management Books. Fundamentals of Effective Program Management: A Process Approach Based on the Global Standard | by Paul Sanghera | ISBN: 9781932159691. Program Management Controls. Program Integration Management
  35. Power Systems Modelling and Fault Analysis: Theory and Practice | by Nasser D. Tleis | ISBN: 9780750680745. Power System Equipments. Practical Short-Circuit Current Assessments in Large-Scale AC Power Systems. Modelling of Multi-Conductor Overhead Lines and Cables. Modelling of AC Rotating Machines
  36. Service Science for Socio-Economical and Information Systems Advancement: Holistic Methodologies | by Adamantios Koumpis (ed) | 2010 | ISBN: 9781605666839. Information Systems Books. Computer Science Books. THE SERVICE ANALYSIS MODEL (SAM). SERVICE DEVELOPMENT PROCESS
  37. IT Best Practices for Financial Managers | by Janice Roehl-Anderson | 2010 | ISBN: 9780470508282. Information Technology Planning Process. ERP Software Selection. Implementing Automated Financial Systems. Product Information Management.
  38. Handbook of Research on Innovations in Database Technologies and Applications: Current and Future Trends | by Viviana E. Ferraggine, Jorge Horacio Doorn and Laura C. Rivero (eds) | 2009 | ISBN: 9781605662428. Data Reengineering of Legacy Systems. Self-Tuning Database Management Systems. Database Reverse Engineering Tools. Database Support for Workflow Management Systems. DATA CLUSTERING TECHNIQUES. Differential Learning Expert System in Data Management
  39. Strategies and Technologies for Developing Online Computer Labs for Technology-Based Courses | by Lee Chao | ISBN: 9781599045078. Web-Based Teaching Systems and Technologies. Learning Management Systems. Online Computer Lab Development Process. Multimedia Course Content Development.
  40. Security Testing Handbook for Banking Applications | by Arvind Doraiswamy et al. | 2009 | ISBN: 9781905356829. 12 Basic Security Tests and Techniques. Credit Card Payment Management applications. Loan Management application. Electronic payment switch.

Comments

One Comment on The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments | by Craig S. Wright | ISBN: 9781597492669. IT Compliance Guideline. Information Systems Audit Program. Developing IT Security Policy. Vulnerability Assessment Tools. Information Systems Legislation

  1. Anonymous on Wed, 10th Mar 2010 1:05 am
  2. I wish I was able to do the same…

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.