The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program | List Price: $41.95 Discount Price: $22.99

| Binding: Paperback
Practitioner's perspective [Posted on 2003-11-25] Dr. Kovacich has updated one of the classic management works for the people who are responsible for the overal design, development and delivery of a comprehensive, enterprise-wide protection program. There are lots of books out there that will assist those who have technical responsibilities for security in doing a better job. There are very few that help develop the manager's who must harmonize people, processes and technology to address the rapidly increasing range of risks that can impact organizations that are all becoming ever more dependent on information technology to accomplish their objectives. If you are now or aspire to be a manager or director of information security for an organization this is an essential guidebook that will advise and assist you in meeting the challenges inherent in that role.
The Security Officers must have book [Posted on 2004-01-08] Once again Dr. Kovacich has excelled. He has produced an updated version of already 'must have' book for any information security officer. It is the sort of book that is useful to both the experienced information security officer and to the person who is new to the area. The book is written in a format that makes it very readable and also that you can easily find that piece of information that you can remember seeing but can't exactly recall where.. I wish that he had been writing this type of book when I first started out in the Infosec field. If you only buy one information security book - make sure it is this one.
Not for the INFOSEC professional [Posted on 2006-06-16] I personally think this book (actually having read it impartially) is not good for any Information Security professional, corporate or government (IA, IAM, IASO, ISSO, ect), but, if you had to place it in any category I guess it would be in the business management end of communication compliance (maybe for a Policy Compliance Officer). Also I really think that some of the other reviewers here must have been working to promote this book. I unfortunately say this because the author creates entirely too many unique and extremely complex management policy theories on communication development, which frankly gets way off the subject of INFOSEC, and even has him chasing his own tail in the narrated scenarios. The author even goes so far as to concoct and create possibly 20-30 new acronyms (as if you didn't have enough already as a real INFOSEC professional), which almost became a little comedic by the end of the book, especially when hearing even the author try recap each chapter and make each new theory tie into another new theory. Although I'm sure the author is a very distinguished professional in his own right, I unfortunately found this book weak to incorporate into any of my perceived Information Security plans. Do yourself a favor and skip this one and move onto the next, and make sure the books you choose on this topic do not try to reinvent the wheel.
Incoherent gobblydegook [Posted on 2006-09-01] There's simply nothing useful in this book. One would have to have never heard of the Internet or the Web, and never to have worked anywhere, to benefit from it. The author repeats infosec and management bromides ad nauseum, waves the bloody flag of 9/11 to puff up the importance of the field, and introduces new acronyms faster than the Pentagon.
It's also frequently incomprehensible, due to the author's poor control of English grammar.
If you're in infosec, don't let your bosses read this -- they may think you're as full of hot air as Kovacich.
Also note that at least 3 of the 5 star reviews below are by sometime coauthors of Kovacich.
Good information, very dry [Posted on 2007-02-18] This book has good information but is very, very dry. I had to fight very hard to not fall asleep at times.
Kovacich does make some very good points about balancing the information security needs with the needs of the business. He also stress that information security needs to utilize existing business processes and be aligned with the goals of the organization. This is the best material he provides and details in several chapters.
Click here for more details and discount information...
|