INDEX

access control (AC)

based on need to know 155

defined xxv

failures/vulnerabilities 60, 1403

ISO/IEC 27001 controls 1578

NIST SP 800-53 Revision 4 controls 162

user accounts 188

wireless 1534

accountability 19

controls 1623

accreditation 20, 267, 93

of ICT systems 119

see also certification

Accreditors 107, 115

active content 139

administrative privileges, control of 154, 188

AIRMIC (Association of Insurance and Risk Managers) 194, 203

application software

failures and errors 133, 134

interdependencies 133

resilience 98

security 153

see also software

asset management controls 157

assets

defined xvi, xxv

return of 149

see also information assets

asynchronous replication 96

attacks

defined xvixvii, xxv

denial of service attacks 17

Get Information Risk Management: A practitioner’s guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.