In This Chapter
Understanding security management concepts
Putting data classification to good use
Knowing your missions, goals, and objectives
Practicing security policies, standards, guidelines, and procedures
Understanding various security roles and responsibilities
Taking stock of information security management practices
Outlining risk management concepts
Keeping it clean: Professional ethics
Finding additional security education, training, and awareness programs
The Information Security and Risk Management domain introduces many important concepts and overlaps with several other domains. Fortunately, it’s not an extremely technical domain, and the concepts that we discuss here are fairly straightforward and easy to understand.