TY - BOOK AU - Braithwaite,Timothy TI - Securing e-business systems: a guide for managers and executives SN - 0471072982 AV - HF5548.32 .B73 2002 PY - 2002/// CY - New York PB - Wiley KW - Electronic commerce KW - Security measures KW - Business enterprises KW - Computer networks KW - Internet N1 - Includes bibliographic references and index; Electronic Business Systems Security -- How Is E-Business Security Defined? -- Can E-Business Security Be Explained More Simply? -- Is E-Business Security Really Such a Big Deal? -- Is E-Business Security More Important Than Other Information Technology Initiatives? -- How Does an Organization Get Started? -- Instead of Playing "Catch-Up," What Should an Organization Be Doing to Design E-Business Systems That Are Secure in the First Place? -- E-Business Systems and Infrastructure Support Issues -- E-Business Defined -- A Short History of E-Business Innovations -- The Need for Secure E-Business Systems -- Software: The Vulnerable Underbelly of Computing -- The Interoperability Challenge and E-Business Success -- E-Business Security: An Exercise in Trade-Offs -- Few Systems Are Designed to Be Secure -- Security Weaknesses in E-Business Infrastructure and "Best Practices" Security -- Fundamental Technical Security Threats -- The Guiding Principles of Protection -- "Best Practice" Prevention, Detection, and Countermeasures and Recovery Techniques -- Managing E-Business Systems and Security -- Misconceptions and Questionable Assumptions -- Managing E-Business Systems as a Corporate Asset -- E-Business Security Program Management -- A "Just-in-Time" Strategy for Securing the E-Business System: The Role for Security Monitoring and Incident Response -- The Current State of E-Business Security -- Standard Requirements of an E-Business Security Strategy -- A New Security Strategy -- The Crucial Role of Security Monitoring and Incident Response to the Securing of E-Business Systems -- The Current State of Intrusion Detection Systems (IDS) -- Defining a Cost-Effective Security Monitoring and Incident Response Capability -- Alternatives to Building "Your Own" Security Monitoring and Incident Response Capability -- Designing and Delivering Secured E-Business Application Systems -- Past Development Realities -- Contemporary Development Realities -- Developing Secured E-Business Systems -- Using the SDR Framework -- Choosing a Systems Development Methodology That Is Compatible with the SDR Framework -- Participants in the Identification of Security and Integrity Controls -- Importance of Automated Tools -- A Cautionary Word About New Technologies -- Justifying E-Business Security and the Security Management Program -- The "Quantifiable" Argument -- Emerging "Nonquantifiable" Arguments -- Benefits Justifications Must Cover Security Program Administration -- Computers, Software, Security, and Issues of Liability -- Evolving Theories of Responsibility -- Likely Scenarios -- How Might a Liability Case Unfold? -- Questions to Be Asked to Ensure That Reasonable Care Has Been Taken in Developing a Secure E-Business System -- The National Critical Infrastructure Protection (CIP) Initiative -- The Problem of Dependency -- Critical Infrastructure Protection (CIP) Purpose, Directives, Organizations, and Relationships -- Frequently Asked Questions About the IT-ISAC -- Critical Information Infrastructure Protection Issues that Need Resolution -- Y2K Lessons Learned and Their Importance for E-Business Security -- Systems Development Review Framework for E-Business Development Projects -- A Corporate Plan of Action for Securing E-Business Systems (Sample) -- E-Business Risk Management Review Model Instructions for Use N2 - Today's e-business depends on the security of its networks and information technology infrastructure to safeguard its customers and its profits. But with rapid innovation and the emergence of new threats and new countermeasures, keeping up with security is becoming more complex than ever. Securing E-Business Systems offers a new model for developing a proactive program of security administration that works as a continuous process of identifying weaknesses and implementing solutions. This book offers a real, working design for managing an IT security program with the attention it truly warrants, treating security as a constant function that adapts to meet a company's changing security needs ER -