جزییات کتاب
Enterprise Cybersecurity empowers organizations of all sizes to defend themselves with next-generation cybersecurity programs against the escalating threat of modern targeted cyberattacks. This book presents a comprehensive framework for managing all aspects of an enterprise cybersecurity program. It enables an enterprise to architect, design, implement, and operate a coherent cybersecurity program that is seamlessly coordinated with policy, programmatics, IT life cycle, and assessment.Fail-safe cyberdefense is a pipe dream. Given sufficient time, an intelligent attacker can eventually defeat defensive measures protecting an enterprise’s computer systems and IT networks. To prevail, an enterprise cybersecurity program must manage risk by detecting attacks early enough and delaying them long enough that the defenders have time to respond effectively. Enterprise Cybersecurity shows players at all levels of responsibility how to unify their organization’s people, budgets, technologies, and processes into a cost-efficient cybersecurity program capable of countering advanced cyberattacks and containing damage in the event of a breach.The authors of Enterprise Cybersecurity explain at both strategic and tactical levels how to accomplish the mission of leading, designing, deploying, operating, managing, and supporting cybersecurity capabilities in an enterprise environment. The authors are recognized experts and thought leaders in this rapidly evolving field, drawing on decades of collective experience in cybersecurity and IT. In capacities ranging from executive strategist to systems architect to cybercombatant, Scott E. Donaldson, Stanley G. Siegel, Chris K. Williams, and Abdul Aslam have fought on the front lines of cybersecurity against advanced persistent threats to government, military, and business entities. What youll learnExecutives, managers, architects, IT professionals, customers and vendors of cybersecurity services, and engineering students will learn from this bookHow to create a data-driven and objectively-managed cybersecurity program optimally tailored to your organizationHow to organize, assess, and score cybersecurity programs using the authors’ enterprise cybersecurity architecture schemeThe methodology of targeted attacks and why they succeedThe processes of cybersecurity risk management, capability assessment, scope selection, operations, and supporting information systemsHow to audit and report your cybersecurity program in compliance with regulatory frameworksHow cybersecurity is evolving and projected to evolveWho this book is for Enterprise Cybersecurity is for people and organizations interested in modern cybersecurity and who are responsible for leading, designing, deploying, operating, managing, and supporting cybersecurity capabilities in an enterprise environment. Table of ContentsPart I: The Cybersecurity ChallengeChapter 1: Defining the Cybersecurity ChallengeChapter 2: Meeting the Cybersecurity ChallengePart II: A New Enterprise Cybersecurity ArchitectureChapter 3: Enterprise Cybersecurity ArchitectureChapter 4: Implementing Enterprise CybersecurityChapter 5: Operating Enterprise CybersecurityChapter 6: Enterprise Cybersecurity and the CloudChapter 7: Enterprise Cybersecurity for Mobile and BYODPart III: The Art of CyberdefenseChapter 8: Building an Effective DefenseChapter 9: Responding to IncidentsChapter 10: Managing a Cybersecurity CrisisPart IV: Enterprise Cyberdefense AssessmentChapter 11: Assessing Enterprise CybersecurityChapter 12: Measuring a Cybersecurity ProgramChapter 13: Mapping Against Cybersecurity FrameworksPart V: Enterprise Cybersecurity ProgramChapter 14: Managing an Enterprise Cybersecurity ProgramChapter 15: Looking to the FutureAppendices:Appendix A: Common CyberattacksAppendix B: Cybersecurity FrameworksAppendix C: Enterprise Cybersecurity CapabilitiesAppendix D: Sample Cybersecurity PolicyAppendix E: Cybersecurity Operational ProcessesAppendix F: Object MeasurementAppendix G: Cybersecurity Capability Value ScalesAppendix H: Cybersecurity Sample AssessmentAppendix I: Network SegmentationGlossaryBibliography