The CISSP Prep Guide
Chapter One
Security Management Practices
In our first chapter, we enter the domain of Security Management. Throughout
this book, you will see that many Information Systems Security (InfoSec)
domains have several elements and concepts that overlap. While all other
security domains are clearly focused, this domain, for example, introduces
concepts that we extensively touch upon in both the Operations Security
(Chapter 6, "Operations Security") and Physical Security (Chapter 10, "Physical
Security") domains. We will try to point out those occasions where the
material is repetitive, but be aware that if we describe a concept in several
domains, you need to understand it.
From the published (ISC) goals for the Certified Information Systems Security
Professional candidate:
"The candidate will be expected to understand the planning, organization, and roles of
individuals in identifying and securing an organization's information assets; the development
and use of policies stating management's views and position on particular topics
and the use of guidelines standards, and procedures to support the polices; security
awareness ... read full excerpt from The CISSP Prep Guide: Gold Edition ebook