Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Information Security Management Handbook, Sixth Edition (Isc2 Press) Review

Information Security Management Handbook, Sixth Edition (Isc2 Press)
Average Reviews:

(More customer reviews)
Are you looking to buy Information Security Management Handbook, Sixth Edition (Isc2 Press)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Information Security Management Handbook, Sixth Edition (Isc2 Press). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Information Security Management Handbook, Sixth Edition (Isc2 Press) ReviewIf your goal is to pass the CISSP exam, this book may help, but there are better books out there. If your goal is to actually dig deep into the security domains, this book contains a vast collection of security related topics that may help you reach that goal.
I gave it a 2 star because I was disappointed at the number of errors and omissions I discovered in this book, for example chapter 4 has 4 dates for ITGI's begining which are all wrong, Chapter 8 has the correct date. as matter of fact if I was the editor of the book, I would remove the entire chapter 4. I was happy to see Kevin Henry bring up the "placement of security" but he does not take it far enough. So chapter 14 we are back to "IT" based information security. I think it is time for security experts to start writing outside the box, most companies have confidential information that is not "IT" related, take contracts as an example.
Chapter 76 "Intrusion in information system security simply means the attempts or actions of unauthorized entry into an IT system. " really!, this is 1990's way of thinking Gildas Deograt-Lumy Roy Naldo Please read The Art of Intrusion by Kevin D. Mitnick.
I would write a book describing all that is wrong with this book, only if I had the time and writing skills some of which was wasted reading this book, Oh by the way Mr.Ralph Spencer Poore, there are so many exciting new standards coming up with cryptographic key management you should have and could have written about, such as the 1619.3, but I guess I have to read yet another book to learn about it.
Information Security Management Handbook, Sixth Edition (Isc2 Press) OverviewConsidered the gold-standard reference on information security, the Information Security Management Handbookprovides an authoritative compilation of the fundamental knowledge, skills, techniques, and tools required of today's IT security professional. Now in its sixth edition, this 3200 pagestand-alone reference is organized under the CISSP Common Body of Knowledgedomains and has beenupdated yearly.Volumes 2,3, andthis year's Volume 4 reflect thechanges to the CBK in response to new laws and evolving technology.

Want to learn more information about Information Security Management Handbook, Sixth Edition (Isc2 Press)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts Review

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts
Average Reviews:

(More customer reviews)
Are you looking to buy Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts ReviewThis is a rather short (Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts Overview
It's no longer just a buzz word: "Security" is an important part of your job as a Systems Administrator. Most security books are aimed at security professionals, but Security for System Administrators is written for System Administrators. This book covers the basics of securing your system environment as well as security concepts and how these concepts can be implemented practically using common tools and applications. Whether you are new to this profession or have been in the field a while, you'll find valuable information in each chapter. The book's examples will focus on Windows Server 2008 R2 and Windows 7, but many concepts are platform agnostic.

Take all the confusion out of security including: network attacks, system failures, social networking, and even audits
Learn how to apply and implement general security concepts
Identify and solve situations within your network and organization


Want to learn more information about Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Credit Risk Management and Basel II Review

Credit Risk Management and Basel II
Average Reviews:

(More customer reviews)
Are you looking to buy Credit Risk Management and Basel II? Here is the right place to find the great deals. we can offer discounts of up to 90% on Credit Risk Management and Basel II. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Credit Risk Management and Basel II ReviewI am very disappointed with this book.
Being an opt-in bank, we were looking for a good book on credit risk for our Basel II implementation program. This book seemed the most appropriate - the description & table of contents looked good and had one good review. The fact that this was from riskbooks gave us additional assurance.
The book turned out to be a big disappointment:
1. Has no substance or insights and does not discuss the challenges in a Basel II implementation
2. Surpisingly, many of the descriptions/explanations are flawed - the description about linkages of credit risk to macroeconomic factors, a section on willingness to pay, transition risk and law of large numbers (to name a few) were amusing!!
3. Was not coherent at multiple places
Caveat Emptor
Credit Risk Management and Basel II OverviewWith the entire financial sector across the globe working on the implementation of the 2004 Basel II Accord in some form and intensity there is much work to be done at bank level.Credit Risk Management gives you the means to put in place the credit risk measurement and management framework, policies, procedures and practices that are needed.
As a unique implementation guide covering the entire spectrum of credit risk management, this book will assist you with your credit risk policy and help you to facilitate the establishment of risk processes and procedures and implementation of information technology.
Having assessed the vast amount of existing literature on this subject Bhatia found the bulk of it to be deficient in many areas, this book fills in the gaps for you by:
•Approaching explanations from a non- mathematical perspective, with the spirit behind the mathematics and equations explained in an accessible manner,
•Taking a holistic approach, with an end-to-end analysis of the credit risk problem; and
•Absorbing and integrating best practices echoed by the Basel Accord.
An excellent framework for analysis and implementation is provided and this information will be beneficial for a wide range of people from risk managers and compliance officers to credit risk administration personnel, front and middle office personnel, and students of GARP or financial engineering.

Want to learn more information about Credit Risk Management and Basel II?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Risk Management Review

Risk Management
Average Reviews:

(More customer reviews)
Are you looking to buy Risk Management? Here is the right place to find the great deals. we can offer discounts of up to 90% on Risk Management. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Risk Management ReviewI bought this book because some readers highly recommended it. I'm a financial derivatives strategist and risk management consultant. When a reviewed the book I disappointed in five main particular points: 1) The chapter on VaR is unsatisfactory and insufficient. The authors discuss this subject in a general approach. From my view point I have a preference for Jorion's Value At Risk. 2) There is no discussion about GARCH models, which decrease the importance of this book. I recognise "Risk Management" is a great book. It's a vast encyclopaedia of risk. 3) There's a great discussion of all types of risk, but without any practical solved case. This particular point demerit the seriousness and greatness of the book. 4) The level of mathematics in the book is a little advanced and without any support en practical cases, these poor numerical exercises and calculus tools are useless. 5) Montecarlo simulation approach is bad. There is a great discussion on this subject in Hull's Options, Futures and other derivatives, where the theme is practical, objective and concise. Finally and taking into account these five particular disadvantages, I'll give my rating to this book: 3 stars.Risk Management OverviewThis is the all-in-one banker's and financial manager's guide for implementing and using an effective risk management program. In today's world of multibillion-dollar credit losses and bailouts, it has become increasingly imperative for corporate and banking leaders to monitor and manage risk on all fronts. "Risk Management" introduces and explores the latest financial and hedging techniques in use around the world, and provides the foundation for creating an integrated, consistent, and effective risk management strategy.The tested and comprehensive analysis and insights in "Risk Management" give bankers and financial managers all the necessary information for: Risk Management Overview - from the history of risk management to the new regulatory and trading environment, a look at risk management past and present; Risk Management Program Design - techniques to organize the risk management function, and design a system to cover your organization's many risk exposures; and, Risk Management Implementation - how to use the myriad systems and products value at risk (VaR), stress-testing, derivatives, and more for measuring and hedging risk in today's marketplace.In the financial world, the need for a dedicated risk management framework is a relatively recent phenomenon. But as the Long-Term Capital Management and BankAmerica crises attest, lack of up-to-date knowledge concerning its many components can be devastating.For financial managers in both the banking and business environments, "Risk Management" will introduce and illustrate the many aspects of modern risk management and strengthen every financial risk management program. Exploding global competition, increasing regulations, and the ever-changing product mix of innovative, intricate derivative and securitization products have pushed risk management to the forefront of today's financial landscape. Corporate and banking executives trying to make sense of this environment often find themselves wasting valuable time searching for details and actually creating risk through innocent misinterpretations or misguided hedging strategies."Risk Management" consolidates the entire field of corporate risk administration from data and technological infrastructure to investment and hedging strategies that include innovative derivatives credit risk securitization techniques into one all-inclusive, easily accessible reference.Michel Crouhy, Dan Galai, and Robert Mark, seasoned finance professionals with an unmatched breadth of experience covering banking, corporate, and academic risk management applications walk you through risk management with the focus on concrete, results-oriented tips and analysis. The result is, quite frankly, the only reference you'll need for a quick, thorough understanding of today's complex financial risk management challenges.Look to the expert analysis and proven suggestions in "Risk Management" for a no-nonsense overview of: Integrated Risk Management - how to understand and develop the necessary tools for measuring and managing all of your firm's risk in terms of a common unit; Regulatory Environment - group of 30 (G-30) policy recommendations, BIS 1998 models, and the standardized approach proposed by the Basle Committee; Market Risk- new rules set by the SEC for traded companies to disclose their risk management policies and quantify their exposure to market risk; Practical Measurement Issues - utilizing historical, implied, and stochastic models to measure volatility, plus helpful summaries of measuring correlations and the yield curve; and, Future Considerations - expected conditions and effects of the BIS 2000+ Accord, with review of the G-12 recommendations to improve counter party risk management practices.Never before have the fields of banking and corporate financial risk management been as complicated and the stakes as unyielding. Whether used as an essential resource for institutional financial risk management, a comprehensive text for courses concentrating on bank risk management, or simply as an unprecedented reference covering every important aspect of the discipline, "Risk Management" will bring you up-to-date on an area that promises to increase in importance as we enter the uncharted waters of the 21st century.

Want to learn more information about Risk Management?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Cobert's Manual of Drug Safety and Pharmacovigilance Review

Cobert's Manual of Drug Safety and Pharmacovigilance
Average Reviews:

(More customer reviews)
Are you looking to buy Cobert's Manual of Drug Safety and Pharmacovigilance? Here is the right place to find the great deals. we can offer discounts of up to 90% on Cobert's Manual of Drug Safety and Pharmacovigilance. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Cobert's Manual of Drug Safety and Pharmacovigilance ReviewWorking in Drug Safety for the past five years, I have waited for a book specific to the field. Previous understanding and knowledge was reduced to searching the CFR, reading ICH regulations, memorizing company SOP's, attending training presentations, etc. The book brings all the scattered pieces of information and regulations into a cohesive organization that allows it to be used as a comprehensive read or as a reference for drug safety information.
If read from chapter to chapter, the reader can bridge missing information, clarify ambiguous areas, and further understand Drug Safety. If used as a reference, all the pertinent facets of drug safety are presented, and appropriately indexed by concepts, which facilitates finding certain information or resource.
I'm pleased that someone took the initiative to write a long overdue drug safety book. I have already personally recommended to various colleagues, and I recommend it for other current or future professionals who want to improve their working practices in the field.
Paul
PharmD.Cobert's Manual of Drug Safety and Pharmacovigilance OverviewCompletely revised and updated, the Manual of Drug Safety and Pharmacovigilance, Second Edition is a how-to manual for those working in the fields of drug safety, clinical research, pharmacology, regulatory affairs, government and legal professions. This comprehensive and practical guide discusses the theory and the practicalities of drug safety (also known as pharmacovigilance) and side effects, as well as providing essential information on drug safety and regulations, including: recognizing, monitoring, reporting and cataloging serious adverse drug reactions. The Manual of Drug Safety and Pharmacovigilance, Second Edition teaches the ins and outs of drug safety in the industry, hospitals, FDA, and other health agencies both in the US and around the world, and presents critical information about what is done when confronted with a drug safety problem.

Want to learn more information about Cobert's Manual of Drug Safety and Pharmacovigilance?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Principles and Practice of Business Continuity: Tools and Techniques Review

Principles and Practice of Business Continuity: Tools and Techniques
Average Reviews:

(More customer reviews)
Are you looking to buy Principles and Practice of Business Continuity: Tools and Techniques? Here is the right place to find the great deals. we can offer discounts of up to 90% on Principles and Practice of Business Continuity: Tools and Techniques. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Principles and Practice of Business Continuity: Tools and Techniques ReviewThis book should be a staple in your library if you are responsible for business continuity and DR planning at your company. I was new to the field so I really appreciated how the book was layed out and how easy it was to transfer the information to my plan. There are a lot of applicable practices, tools, cheatsheets, etc that you can easily incorporate into your plan. I was very pleased with this book.Principles and Practice of Business Continuity: Tools and Techniques OverviewUnique Opportunity to Learn from a World-RenownedPioneer and Legend in Business Continuity ManagementIn his preface, Lyndon Bird, Technical Services Director for The Business Continuity Instituteobserves:Jim Burtles is one of the few practitioners who has both the depth of knowledge and length of experience to write what might arguably be the most comprehensive review of the subject ever produced....gives us an authoritative view from someone who has really seen and done it all during a long and outstanding BCM career.This comprehensive how-to guide captures the distilled wisdom and experience of Jim Burtles, a Founding Fellow of the Business Continuity Institute;an internationally renowned pioneer and legend in business continuity management, withover 30 years of experience and teaching across 22 countries;and a veteran of varied practical experience that includes not only recovery work with victims of bombings, earthquakes, storms and fires, but also technical assistance in more than 90 disasters and guidance for clients in over 200 emergency situations.As such, this book is a gold mine of practical information, based on solid theoretical underpinnings. It is an ideal combination of the practice of business continuity standards, best practices, global perspectives and the process of business continuity planning, development, implementation, and maintenance.Jim presents a clear picture of not only how to do what needs to be done, but also why. By striking a balance between theory and practice, Jim's approach makes the reader's job much easier and more effective.If you re a beginner needing to learn the basic theory and practice of business continuity management (BCM), or a seasoned professional wishing to gain new insights, this book offers you the unique opportunity to learn from one of the best in the business. It includes a wealth of features:***Comprehensive how-to guide with basic BCM principles, best practices, and case studiesgleaned from around the world.***Accompanying BCP Tool Kit on CD with 24 planning and analysis tools,including sample plans for business continuity, evacuation, emergency response, and crisis management; scripts and plot development tools for creating exercises to test and audit plans; analysis tools for fire exposure, service impact, resource requirements, etc.; checklists; case studies; reader self-assessment; and Web references.***Chapter overviews and conclusions; charts, graphs and checklists throughout.***Glossy of 90 business continuity terms.***Ideal for training courses--for upper-level undergraduate, graduate, certificate and corporate includes Instructor Materials on CD, PowerPoint slides, test bank, syllabus and instructor s manual.CONTENTS OF CD WITH BCP TOOL KIT1. Risk Assessment Tool2. Impact Analysis Tool3. Key Function Selection List4. Recovery Needs Analysis Tool5. Critical Data Checklist6. Dummy Business Continuity Plan7. Business Continuity Plan Checklist8. Sample Evacuation Plan9. Emergency Evacuation Checklist10. Sample Emergency Response Plan11. Emergency Manager's Notes12. Emergency Response Checklist13. Systems Recovery Checklist14. Sample Crisis Management Plan15. Fire Exposure Analysis Tool16. Service Impact Analysis Tool17. Resource Requirements Analysis Tool18. Plot Development Tool for Exercise Scenarios19. Emergency Move Checklist20. Sample Exercise Script21. Exercise Facilitator's Checklist22. Exercise Log23. Sample Exercise Report24. Outline Holding Statement

Want to learn more information about Principles and Practice of Business Continuity: Tools and Techniques?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Essentials of Risk Management Review

The Essentials of Risk Management
Average Reviews:

(More customer reviews)
Are you looking to buy The Essentials of Risk Management? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Essentials of Risk Management. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Essentials of Risk Management ReviewThis book provides an introduction to the field of risk management for readers who do not yet want to get deeply involved in the mathematical formalism that is typically used. The authors wrote the book so that it is "accessible to everyone", and they have done a fine job. Those readers who need a more quantitative treatment will have to consult another book or the vast research literature on the subject. Risk management, as they see it, is an attempt to estimate both the `expected' losses and the `unexpected' losses, and being able to differentiate between these two concepts goes to the core of the subject. Thus the book emphasizes the "intuition" behind risk management, and not the formalism. However, one must not conclude from this that "intuition" and "formalism" are distinct, and the belief that they are has resulted in a lot of confusion (and financial losses) in recent years. The authors clearly do not believe that they are, but have merely emphasized "intuition" from a pedagogical point of view.
The authors classify risk into eight categories, namely market, credit, liquidity, operational, legal and regulatory, business, strategic, and reputation risk. Financial risk, as they see it, is composed of two of these, namely market and credit risk. Their discussion of corporate risk management is very interesting, in that it begins with the observation first made almost forty years ago that the value of a firm is not altered solely by financial transactions. This is due to their assumption of the perfect market hypothesis, which effectively suppresses the ability of the firm to gain significant advantages over an individual investor. Therefore with this assumption a firm should not concern itself with risks outside of the ones that all other firms face. This is an interesting conclusion, particularly in the context of using hedging via derivatives, as it implies that it cannot compete with ordinary self-insurance, due to the presence of transaction costs. The authors discuss in fair detail why the perfect market assumption is faulty, and therefore why managing risk with hedging is a viable strategy.
The regulatory environment, particularly in the banking industry, has enormous ramifications for risk management, as the authors discuss in the book. This is due in part to the Basel Accords of 1988 and 1996, and Basel II which is due to be in place at the end of 2007. The Basel accords are essentially a standardization for capital reserves, defining a `assets-to-capital' multiple and a `risk-based capital' ratio. The authors review the 1988 Accord and discuss the elementary relationships involved, including the `Cooke ratio' and how to obtain the credit equivalent for the off-balance-sheet exposures. They also discuss the reasons for the 1996 amendment, which essentially were the result of the new trading activities that banks were indulging themselves in. It would have been interesting if the authors had included a (historical) discussion on the efficacy of the Basel Accords in suppressing banking failures. They do mention the fiasco with Barings Bank, claiming that its demise would have been adverted if it were prohibited from racking up huge exchange-traded futures positions. This is certainly true, but any regulation needs to be validated by historical data, to the extent that this is possible, and this requires of course tracking of the financial institutions that are under the umbrella of the regulation. In this regard though, the authors do view bank regulation as a `research lab' for risk management, implying that they are aware of the need for validation of any regulations that are actually put in place. It will be fascinating therefore to see the impact of the new Basel II accords when they become active, and indeed observe, if possible, any `regulatory arbitrage' that occurs. This also brings up the question of how to assess the quality of the risk management strategies of a particular financial institution. The authors spend a little time discussing this, with one of them referring to a method analogous to credit scoring.
No book on risk management could be complete without discussion of academic research on the topic, for the reason that much of this research has found practical application and has greatly influenced portfolio management and risk valuation. The authors review four theoretical models, namely modern portfolio theory, the capital asset pricing model, the Black-Scholes option-pricing model, and the Modigliani-Miller theory of corporate finance. Even though the discussions are very short, one has to admire the authors' ability to avoid complicated mathematics in discussing all of these theories without sacrificing clarity. The more mathematically-mature reader may perhaps be annoyed with the omission of mathematical formalism, but a natural question that might arise for such a reader is whether or not risk can indeed be put in a general axiomatic framework that will encompass all of its different manifestations, such as credit risk, operational risk, etc. Such a framework would allow a complete mathematical characterization of risk, and would allow various general and quantitative statements to be made about it.
Due to the extent of mortgage portfolios in the United States at the present time, and due to the sensitive dependence of their values on interest rates, the authors spend a fair amount of time discussing interest-rate risk and how to hedge it with derivatives. Thus they speak of the `sensitivity' of financial instruments to certain risk factors, and study the case of fixed-income products via the `DV01' risk measure, which is the change in value of a security after a change in interest rate of 1 basis point. This measure gives a `first-order' approximation to the change in yield, but the authors show how to obtain a `second-order' approximation using the `convexity' adjustment.
For complex portfolios, the most popular method for risk management has been the value-at-risk or VAR, and so it is not surprising that the authors devote an entire chapter to it in the book. The authors view it as a more sophisticated method because of its ability to deal with volatilities and correlations. However, they point out that its efficacy is restricted to relatively short time scales and under `normal' market conditions. The fiasco at LTCM (Long Term Capital Management) is discussed as an example of the failure of VAR to measure risk over long time scales and under abnormal market conditions. They do not however give any detailed evidence for this claim, but a perusal of the research literature (surprisingly rather slim) reveals that LTCM made "major" errors in terms of their risk management, if viewed from the standpoint of VAR. This still leaves open the question as to whether it made "major" errors from the standpoint of some other method for measuring and evaluating risk that is possibly radically different from VAR.The Essentials of Risk Management Overview
Risk management is no longer confined solely to risk management specialists. Stakeholders ranging from employees to investors must understand how to quantify the tradeoffs of risk against the potential return. The failure to understand the essential nature of risk can have devastating consequences.

Globally renowned risk and corporate governance experts Michel Crouhy, Dan Galai, and Robert Mark have updated and streamlined their bestselling professional reference Risk Management to introduce you to the world of risk management without requiring you to know the intricate formulas and mathematical details.

The Essentials of Risk Management is the first book to make even the most sophisticated risk management approaches simultaneously accessible to both risk and non risk professionals. It will help you to:

Increase the transparency of your risk management program to satisfy shareholders, employees, regulators, and other important constituencies
Keep on top of the continuing evolution of best-practice risk policies and methodologies and associated risk infrastructures
Implement and efficiently communicate an organization-wide Enterprise Risk Management (ERM) approach that encompasses market, credit, liquidity, operational, legal and regulatory, business, strategic and reputation risks
Navigate thorny areas including risk policies, risk methodologies, economic capital, regulatory capital, performance measurement, asset-liability management, and more
Efficiently allocate limited corporate resources to comply with the new generation of risk regulation and corporate governance regulation

As a non-risk professional or board member, you are being called on more than ever before to make sophisticated assessments of your organization's risk exposures as well as play a critical role in its formal risk management process. The Essentials of Risk Management tells you what you need to know to succeed in this challenging new environment.


Want to learn more information about The Essentials of Risk Management?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security Metrics: Replacing Fear, Uncertainty, and Doubt Review

Security Metrics: Replacing Fear, Uncertainty, and Doubt
Average Reviews:

(More customer reviews)
Are you looking to buy Security Metrics: Replacing Fear, Uncertainty, and Doubt? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security Metrics: Replacing Fear, Uncertainty, and Doubt. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security Metrics: Replacing Fear, Uncertainty, and Doubt ReviewI read Security Metrics right after finishing Managing Cybersecurity Resources, a book by economists arguing that security decisions should be made using cost-benefit analysis. On the face of it, cost-benefit analysis makes perfect sense, especially given the authors' analysis. However, Security Metrics author Andy Jaquith quickly demolishes that approach (confirming the problem I had with the MCR plan). While attacking the implementation (but not the idea) of Annual Loss Expectancy for security events, Jaquith writes on p 33 "[P]ractitioners of ALE suffer from a near-complete inability to reliably estimate probabilities [of occurrence] or losses." Bingo, game over for ALE and cost-benefit analysis. It turns out the reason security managers "herd" (as mentioned in MCR) is that they have no clue what else to do; they seek safety in numbers by emulating peers and then claim that as a defense when they are breached.
Fortunately, Security Metrics offers another solution. The book gives readers three sets of information: theory, metrics, and tools (concepts, not programs). The theory chapters (1 and 2) were so concise yet insightful I was tempted to underline every sentence. (I am not kidding.) Even the Preface made me glad to be reading the book when it associated "security ROI" with "the Macarena" and called it a "needless distraction." I laughed in agreement when I saw Andy call "security enablement" the "Abominable Snowman: it is rarely spotted, but legions of people swear it exists. After all, as my friend Dan geer puts it, 'You don't usually see airlines advertising how their planes fall out of the sky less often than their competitors.'" Why is that? My answer is simple: security is assumed and expected. Advertising anything else has no effect or makes people suspicious. I knew this book would be good.
The metrics chapters probably list hundreds of metrics you can extract verbatim and apply to your own environment. To the reviewer who wanted to reprint them in an appendix: they're called chapters 3 and 4. My main concern with the metrics was the focus on input-centric measurements instead of results. I would have liked to read more metrics on measuring whether security programs are working, rather than what techniques and tools are applied up front.
The tools chapters were helpful to anyone needing a statistics refresher. The visualization sections were especially helpful. (Feel free to dismiss yet another ignorant review from WB, who thinks a "review" means writing a few paragraphs after flipping through the pages of five books a day.) Andy's examples of turning lousy graphs and charts into information visualization vehicles should be followed by all managers.
Security Metrics is strengthened by the many stories from the author's consulting experience. I sensed that his techniques work and are not the product of the thought laboratory alone. I found his "Balanced Scorecard" approach to be interesting, especially to the degree it ties real metrics to business operations.
I had a few issues with terminology, such as using the term "threats" on p 231 when "attacks" is more accurate. (The football analogy is correct, however.) I semi-agreed with the author's suggestion to abandon "risk management" in favor of metrics-based approaches, but I didn't think two pages (4-5) were really enough to make the case. On p 264, threats are not risks, but they help instantiate risks. On pp 78-7, "risk of exploit" should be "ease of exploitation."
These are minor concerns, given the overwhelming concentration of practical and implementation-worthy pieces of information in Security Metrics. You must read this book if you care to measure security progress. Now we need Dan Geer to extend beyond writing wise forewords and articles into the world of his own book!Security Metrics: Replacing Fear, Uncertainty, and Doubt OverviewThe Definitive Guide to Quantifying, Classifying, and Measuring Enterprise IT Security Operations


Security Metrics is the first comprehensive best-practice guide to defining, creating, and utilizing security metrics in the enterprise.

Usingsample charts, graphics, case studies, and war stories, Yankee GroupSecurity Expert Andrew Jaquith demonstrates exactly how to establisheffective metrics based on your organization's unique requirements.You'll discover how to quantify hard-to-measure security activities,compile and analyze all relevant data, identify strengths andweaknesses, set cost-effective priorities for improvement, and craftcompelling messages for senior management.

Security Metrics successfullybridges management's quantitative viewpoint with the nuts-and-boltsapproach typically taken by security professionals. It brings togetherexpert solutions drawn from Jaquith's extensive consulting work in thesoftware, aerospace, and financial services industries, including newmetrics presented nowhere else. You'll learn how to:

• Replace nonstop crisis response with a systematic approach to security improvement
• Understand the differences between "good" and "bad" metrics
•Measure coverage and control, vulnerability management, passwordquality, patch latency, benchmark scoring, and business-adjusted risk
• Quantify the effectiveness of security acquisition, implementation, and other program activities
• Organize, aggregate, and analyze your data to bring out key insights
• Use visualization to understand and communicate security issues more clearly
• Capture valuable data from firewalls and antivirus logs, third-party auditor reports, and other resources
• Implement balanced scorecards that present compact, holistic views of organizational security effectiveness

Whetheryou're an engineer or consultant responsible for security and reportingto management–or an executive who needs better information fordecision-making–Security Metrics is the resource you have been searching for.

Andrew Jaquith, programmanager for Yankee Group's Security Solutions and Services DecisionService, advises enterprise clients on prioritizing and managingsecurity resources. He also helps security vendors develop product,service, and go-to-market strategies for reaching enterprise customers.He co-founded @stake, Inc., a security consulting pioneer acquired bySymantec Corporation in 2004. His application security and metricsresearch has been featured in CIO, CSO, InformationWeek, IEEE Security and Privacy, and The Economist.

Foreword
Preface
Acknowledgments
About the Author
Chapter1 Introduction:Escaping the Hamster Wheel ofPain
Chapter2 Defining SecurityMetrics
Chapter 3 Diagnosing Problems and Measuring Technical Security
Chapter4 Measuring ProgramEffectiveness
Chapter 5 Analysis Techniques
Chapter 6 Visualization
Chapter 7 Automating Metrics Calculations
Chapter 8 Designing Security Scorecards
Index




Want to learn more information about Security Metrics: Replacing Fear, Uncertainty, and Doubt?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Anti-Fraud Risk and Control Workbook (Wiley) Review

Anti-Fraud Risk and Control Workbook (Wiley)
Average Reviews:

(More customer reviews)
Are you looking to buy Anti-Fraud Risk and Control Workbook (Wiley)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Anti-Fraud Risk and Control Workbook (Wiley). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Anti-Fraud Risk and Control Workbook (Wiley) Review
Peter Goldmann has written what I consider a must have book for any manager, auditor or fraud professional that wants to understand the fundamental concepts and applications that are available to deter and fight business fraud. As soon as the reader is presented the statistic that firms' lose an average 7% of gross revenues due to fraud, the book becomes a valuable investment in how to reduce that 7% as much as possible. In other words, the book is about how to fraud!
The ample use of actual life cases brings theory and real world practice together, leaving very few aspects of fraud uncovered or unexplained for the reader. . A unique instructional feature of the book is its quizzing of the reader as to how each fraud case could have been prevented, with an appendix of answers against which the reader can compare his or her own responses.
An additional and fresh perspective that Goldmann brings to us is the hands on workshop approach of the book augmented by a wonderful set of specific steps and recommendations for each topic. For example, the Red Flags of External Fraud is a comprehensive list of situations that can be immediately implemented by any company that wants to start the journey of fighting fraud and observe how results improve--, without a major investment.
The structure of the book is easy to follow with eight chapters structured from a very basic explanation of fraud in Chapter 1 to the advanced fraud detection tools and techniques of Chapter 8. Readers also have direct access to the short cases so that immediate feedback can be obtained on those real life fraud situations.
My experience with fraud has guided me to constantly read new literature and new cases related to the topic. As I compare the existing literature with Goldmann's Antifraud Risk and Control Workbook I can only conclude that it represents a magnificent yet simple to follow combination of theory, practice and techniques that are currently available to all of us that deal with this first (... or second) epidemic of the 21st century.
Arnoldo J. Rodriguez, Ph.D.
Associate Professor of Business
Webster University
Anti-Fraud Risk and Control Workbook (Wiley) OverviewProven guidance for fraud detection and prevention in a practical workbook format
An excellent primer for developing and implementing an anti-fraud program, Anti-Fraud Risk and Control Workbook engages readers in an absorbing self-paced learning experience to develop familiarity with the practical aspects of fraud detection and prevention.
Whether you are an internal or external auditor, accountant, senior financial executive, accounts payable professional, credit manager, or financial services manager, this invaluable resource provides you with timely discussion on:

Why no organization is immune to fraud

The human element of fraud

Internal fraud at employee and management levels

Conducting a successful fraud risk assessment

Basic fraud detection tools and techniques

Advanced fraud detection tools and techniques

Written by a recognized expert in the field of fraud detection and prevention, this effective workbook is filled with interactive exercises, case studies, and chapter quizzes and shares industry-tested methods for detecting, preventing, and reporting fraud.
Discover how to become more effective in protecting your organization against financial fraud with the essential techniques and tools in Anti-Fraud Risk and Control Workbook.

Want to learn more information about Anti-Fraud Risk and Control Workbook (Wiley)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance) Review

Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance)
Average Reviews:

(More customer reviews)
Are you looking to buy Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance) ReviewThe book lists a series of financial theories without bringing any clear connection to operational risk. The tools and techniques presented can be seen in any other finance book. No examples are presented in general, making questionable the author's experience in the "measurement of operational risk" as stated in the title. This book will not raise your knowledge in the field.Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance) OverviewA comprehensive and innovative look at how to protect financial institutions from operational risksOperational risk is the risk associated with human error, systems failures, and inadequate controls and procedures in information systems or internal controls that will result in an unexpected loss. According to a recent survey, about seventy percent of banks consider operational risk as important as market or credit risks. Nearly a quarter of the same banks admit to operation-related losses of more than $1.6 million-many cases are so embarrassing that banks will not actually admit any error on their part. Firms are just beginning to develop their own operational risk management systems and they need guidance on how to do it. This book will help them identify, measure, and manage their operational risks.Christopher Marshall (Singapore) is Associate Director of the Center for Financial Engineering at the National University of Singapore. He has written numerous articles in Risk magazine and Harvard Business School cases.

Want to learn more information about Measuring and Managing Operational Risks in Financial Institutions: Tools, Techniques, and other Resources (Wiley Frontiers in Finance)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series) Review

Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series)
Average Reviews:

(More customer reviews)
Are you looking to buy Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series) ReviewThe Book has explicit information on how ERM could be implemented from a consultant's perspective. The details of various risk areas is also a good reference point for new risk managers.
Thank you.Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series) OverviewEnterprise Risk Management (ERM) represents a fundamental shift in the way businesses must approach risk. As the economy becomes more service driven and globally oriented, businesses cannot afford to let new, unforeseen areas of risk remain unidentified. Currency fluctuations, human resources in foreign countries, evaporating distribution channels, corporate governance, and unprecedented dependence on technology are just a few of the new risks businesses must assess.
This accessible book, aimed at the implementers and practitioners of ERM, provides a highly structured approach so you can easily implement processes in your own organization. You'll find a number of case studies and practical examples from a variety of industries. The chapters are organized in a way that leads you through ERM implementation and include risk identification techniques, risk modelling methods, and the underlying statistics. Order your copy today!

Want to learn more information about Simple Tools and Techniques for Enterprise Risk Management (The Wiley Finance Series)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers Review

Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers
Average Reviews:

(More customer reviews)
Are you looking to buy Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers? Here is the right place to find the great deals. we can offer discounts of up to 90% on Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers ReviewSeveral of the highly acknowledged ISCRIM researchers (International Supply Chain Risk Management Network) have contributed to the chapters in this book and this makes it well worth taking a closer look at it, particularly if risk modeling and decision-making is your field.
According to the authors, the book serves two purposes:
(1)Understanding and assessing risk in the supply chain
(2)Decision making and risk mitigation in the supply chain
Thus, the book has two sections covering the above divisions, with 4 and 5 chapters each, written by top ranking researchers from around the world. That much is true, as I recognize many, but not all of the names of the chapter authors.
Personally, the first section is the part of the book that I like best. Forecasting and stochastic modeling for decision making are not really my cup of tea; I'm much more a man of visions, strategies, and concepts, and that is very well covered in the first part. That said, the 2nd section does have very interesting articles for me as well, it's not all math and equations.Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers OverviewManaging Supply Chain Risk and Vulnerability, a book that both practitioners and students can use to better understand and manage supply chain risk, presents topics on decision making related to supply chain risk.Leading academic researchers, as well as practitioners, have contributed chapters focusing on developing an overall understanding of risk and its relationship to supply chain performance; investigating the relationship between response time and disruption impact; assessing and prioritizing risks; and assessing supply chain resilience.Supply chain managers will find Managing Supply Chain Risk and Vulnerability a useful tool box for methods they can employ to better mitigate and manage supply chain risk. On the academic side, the book can be used to teach senior undergraduate students, as well as graduate-level students. Additionally, researchers may use the text as a reference in the area of supply chain risk and vulnerability.

Want to learn more information about Managing Supply Chain Risk and Vulnerability: Tools and Methods for Supply Chain Decision Makers?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...