xi
© 2011 by Taylor & Francis Group, LLC
Foreword
Information security is a complex eld that requires not only a strong technical
acumen, but also the ability to apply management principles to the development
and implementation of an eective information security management program.
Information security executiveschief information security ocers, senior secu-
rity executives, chief information ocers, and chief technology ocers—must be
able to understand risks to organizational assets and determine how to best allo-
cate nancial and personnel resources to achieve information security management
goals and fulll all compliance requirements. We have an unprecedented need for
leaders in this eld who are equipped with the knowledge and experience necessary
to ensure that our systems and networks are operating securely and reliably.
Information security managers and executives are entrusted with ensuring
that their organizations proprietary information is secure. Failure to achieve and
maintain compliance with government and industry regulations can disrupt criti-
cal business operations, ultimately devastating the company, its stakeholders, and
its business partners. We believe that eective information security management
begins with certifying and educating the information security workforce—from
top security executives building the foundation for an organizations security
framework to security practitioners who are down in the trenches, actively protect-
ing our systems and networks.
e Certied Information Systems Security Professional-Information Systems
Security Management Professional (CISSP-ISSMP) assesses an individuals under-
standing of security management practices, management of compliance initiatives,
business continuity and disaster recovery planning, and legal issues. Obtaining
the CISSP-ISSMP validates that you have the knowledge to create and implement
eective information security management programs to meet the security needs of
your organization.
As the recognized global leader in the eld of information security education
and certication, (ISC)
2
s mission is to promote the development of information
security professionals throughout the world. It is our pleasure to provide you with
this comprehensive reference. We believe you will nd the CISSP-ISSMP to be an
informative and challenging step in advancing your career development.
xii ◾  Foreword
© 2011 by Taylor & Francis Group, LLC
As you review the information in this book and study for the CISSP-ISSMP
certication exam, remember that venturing beyond the solid foundation of the
CISSP certication should ultimately help to enhance your career path as well as
your ability to mentor up-and-coming information security professionals.
We wish you success in your journey toward earning the CISSP-ISSMP
certication.
W. Hord Tipton, CISSP-ISSEP, CAP
Executive Director
(ISC)²

Get Official (ISC)2® Guide to the ISSMP® CBK® now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.