Information Security Program Management
In this chapter, you will learn about the practical aspects of information security program management and the methods, tools, and techniques used for the management of an information security program. This chapter will help CISM aspirants understand different types of cloud computing services and study different types of controls.
The following topics will be covered in this chapter:
- Information Security Control Design and Selection
- Security Baseline Controls
- Information Security Awareness and Training
- Management of External Services and Relationships
- Documentation
- Information Security Program Objectives
- Security Budget
- Security Program Management and Administrative Activities
- Privacy Laws
- Cloud Computing