Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« CAN-SPAM Violation: TJ Web Productions Must Pay $465,000 Fine And Perform Additional Actions for 5 Years | Main | Free Awareness from the FTC: Phishing »

"Say What You Do": My New Book Now Available!

I had the great privilege and pleasure to work with Dorian Cougias, an award-winning author and information security practitioner, Marcelo Halpern, an internationally acclaimed lawyer, and Karsten Koop, also an award winning author and highly experienced IT auditor, to co-author our newly released book, "Say What You Do."

The full title is "Say What You Do: Building a framework of IT controls, policies, standards, and procedures" and is now available through the saywhatyoudo website, or at any other bookstore of your choosing, such as on Amazon.

I'm really excited about this book and the help I know it will provide to information security and privacy professionals. It is described as "the definitive guide to process documentation." My co-authors are brilliant at being able to communicate difficult concepts and explain things clearly. And the book is easy to read, understand, and entertaining to boot!

Creating effective information security and privacy policies, procedures and standards is an activity most organizations struggle with, and most of the practitioners I know either hate to do, or just don't have time to do in the most effective manner. "Say What You Do" walks the reader through all of the steps necessary for creating a risk-based, compliance-driven information controls framework, policies, standards, and procedures. Included are techniques for solid writing, editing, and policy, standard, and procedure dissemination. Plus, a ton of examples, forms and tools.

If you are going to the RSA conference next week please stop by the NetIQ booth; they like our new book so much they have purchased 100 copies that they are giving away there. Plus, Dorian Cougias will be there signing them, so you can meet him and let him know your feedback directly.

Please take a look and let me know what you think! :)

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/303

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.