Security Policies and Principles and Practices was created to teach information security policies and procedures and provide students with hands-on practice developing a security policy.This book provides an introduction to security policy, coverage of information security regulation and framework, and policies specific to industry sectors, including financial, healthcare and small business.
A very useful reference book. All sound security concepts. Was occassionally a bit to high level at times. Four stars, not because I was engrossed in it, but because it has practical and applicable information. Obviously written by someone familiar with policy and procedure document authoring because she started off by discussing definitions for each topic. One of the appendices should be extremely valuable going forward, the sample policies. Good stuff.
This is the best book I've seen yet on how-to write policies and procedures. If your starting at group zero building your security program this book can help you get started on the right foot.