Chapter 4. Governance and Risk Management

Chapter Objectives

After reading this chapter and completing the exercises, you will be able to do the following:

Image Choose the appropriate type of policies to document a security programme

Image Distinguish among the roles of standards, regulations, baselines, procedures, and guidelines

Image Organize a typical standards and policies library

Classify assets according to standard principles

Incorporate the separation ...

Get Information Security: Principles and Practices, Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.