Page 8 - CISSO_Prep_ Guide
P. 8
What is Risk? ............................................................................ 72
What is Risk Assessment? ........................................................ 81
Identifying the Entity/Asset ...................................................... 82
Implementing Risk Response ................................................... 97
Chapter Three: Information Security program development and
management ............................................................................ 104
Security Program Development .............................................. 104
Third Party Relationships ....................................................... 111
Access Controls ...................................................................... 131
Identification ........................................................................... 132
Authentication ......................................................................... 134
Authorization .......................................................................... 140
Accounting / Auditing ............................................................. 144
Identity Management .............................................................. 145
Single Sign-on ......................................................................... 147
Human Resources Security ..................................................... 163
Training, Awareness and Education ....................................... 168
Networks and Communications Security ................................ 171
Chapter Five: Incident Management ....................................... 205
Appendix A: Certifications and Examinations ....................... 222