Table of Contents:
“...Government Organization -- Chapter Six: Insider with
a ConscienceAn Austrian Retailer -- Chapter Seven: Collaborative Threat
A Telecommunications Company in the
U.S. -- Chapter Eight: Outbreak from Within
A Financial Organization in the
U.
K. -- Chapter Nine: Mixing Revenge and Passwords
A Utility Company in Brazil -- Chapter Ten: Rapid Remediation
A University in the United States -- Chapter Eleven: Suspicious Activity
A Consulting Company in Spain -- Chapter Twelve: Insiders Abridged -- Malicious use of Medical Records -- Hosting Pirated Software -- Pod-Slurping -- Auctioning State Property -- Writing Code for another Company -- Outsourced Insiders -- Smuggling Gold in Rattus Norvegicus -- -- Part III: The Extensibility of ESM -- Chapter Thirteen: Establishing Chain-of-Custody
Best Practices with ESM -- Disclaimer -- Monitoring and disclosure -- Provider Protection Exception -- Consent Exception --
Computer Trespasser Exception -- Court Order Exception --
Best Practices -- Canadian
Best Evidence Rule -- Summary Points -- -- Chapter Fourteen: Addressing Both Insider Threats and Sarbanes-Oxley with ESM --
A Primer on Sarbanes-Oxley -- Section 302: Corporate Responsibility for Financial Reports -- Section 404: Management Assessment of Internal Controls -- Separation of Duties -- Monitoring Interaction with Financial
Processes -- Detecting Changes in Controls over Financial Systems -- Section 409: Real-time Issuer Disclosures -- Summary Points -- -- Chapter Fifteen: Incident Management with ESM -- Incident Management Basics -- Improved Risk Management -- Improved Compliance -- Reduced Costs -- Current Challenges --
o Process --
o Organization --
o Technology -- Building an Incident Management
Program --
o Defining Risk -- Five Steps to Risk Definition for Incident Management --
o Process --
o Training --
o Stakeholder Involvement --
o Remediation --
o Documentation -- Reporting and Metrics -- Summary Points -- -- Chapter Sixteen: Insider Threat Questions and Answers -- Introduction -- Insider Threat Recap -- Question One - Employees --
o The Hiring
Process --
o Reviews --
o Awareness --
o NIST 800-
50 --
o Policies --
o Standards --
o Security Memorandum Example -- Question Two - Prevention -- Question Three Asset Inventories -- Question Four Log Collection --
o Security Application Logs --
o Operating System Log --
o Web Server Logs --
o NIST 800-
92 -- Question Five Log Analysis -- Question Six - Specialized Insider Content -- Question Seven Physical and Logical Security Convergence -- Question Eight IT Governance --
o NIST 800-
53 --
o Network Account Deletion maps to NIST 800-
53 section
AC-
2 --
o Vulnerability Scanning maps to NIST 800-
53 section
RA-
5 --
o Asset Creation maps to NIST 800-
53 section
CM-
4 --
o Attacks and Suspicious Activity from Public Facing Assets maps to NIST 800-
53 section
SC-
14 --
o Traffic from Internal to External Assets maps to NIST 800-
53 section
SC-
7 -- Question Nine - Incident Response -- Question
10 Must Haves -- -- Appendix AExamples of Cyber Crime Prosecutions....
”
Call Number:
Loading...
Located:
Loading...
Connect to the full text of this electronic book
eBook