Chapter 8: Practical Aspects of Information Security Program Development Management
In this chapter, we will discuss the practical aspects of information security program development management and look at the methods, tools, and techniques for the development of an information security program. This chapter will help CISM aspirants understand the different types of cloud computing services. We will also discuss the different types of controls.
The following topics will be covered in this chapter:
- Cloud computing
- Controls and countermeasures
- Penetration testing
- Security program metrics and monitoring
- Common information security program challenges
Let's look at each one of the preceding topics in detail.