Anyone looking for an overview of the elements that make up an information security program can turn to a comprehensive guide released by the National Institute of Standards and Technology (NIST) titled Information Security Handbook: A Guide for Managers. The handbook covers every aspect of security, from awareness and training issues to incident response and recovery strategies. Intended for senior managers, it’s as appropriate for the private sector as it is for government readers; as the authors note, while private- and public-sector requirements may differ, “the underlying principles of information security are the same.” @ Security Management Online has the NIST handbook.
Comments