Bayuk / Ehuan / Healey | Cybersecurity Policy Guidebook | Buch | 978-1-394-40740-8 | www.sack.de

Buch, Englisch, 288 Seiten

Bayuk / Ehuan / Healey

Cybersecurity Policy Guidebook


2. Auflage 2026
ISBN: 978-1-394-40740-8
Verlag: John Wiley & Sons Inc

Buch, Englisch, 288 Seiten

ISBN: 978-1-394-40740-8
Verlag: John Wiley & Sons Inc


Sound guidance on design, implementation, and governance of cybersecurity policy

Now in its Second Edition, the Cybersecurity Policy Guidebook delivers an issue-focused treatment of public, private, and individual cybersecurity policy alternatives for treatment of systemic cyber risks. Seven practitioners from government, industry, and academia analyze overlapping perspectives of decision-makers, technology professionals, and critical infrastructure engineers within the recently transformed digital landscape.

The first edition dealt with threats to impersonation, infrastructure access, intellectual property, internet access, nation-state conflict, operational continuity, privacy, and supply chain. New to this edition is coverage of AI's impact on cybersecurity, cyber-physical systems, and custodial issues for technology platforms and other cyber-enabled services. The book addresses threat intelligence across industry sectors, governance frameworks, and risk appetite thresholds. A policy catalog reflects pros and cons of pressing policy positions.

Key topics also include: - Communication strategies for conveying cybersecurity risk to decision makers across public and private levels of authority
- Policy objectives mapped to technology evolution, connecting operational choices with their broader strategic and regulatory implications
- Guidance on banking and financial services cybersecurity supervision, drawing on interagency regulatory frameworks and examination standards
- Operational technology and control system cybersecurity policy, addressing risks unique to industrial control systems and other cyber-physical systems
- Cross-disciplinary course alignment for programs in public policy, law, business, computer science, engineering, and social sciences

Cybersecurity Policy Guidebook serves leaders of public and private organizations, as well as technology professionals, industry analysts, scholars, and individuals seeking a structured reference on cybersecurity policy issues. Whatever the starting point of perspective, readers will gain the policy knowledge required to act with precision.

Bayuk / Ehuan / Healey Cybersecurity Policy Guidebook jetzt bestellen!

Weitere Infos & Material


Chapter 1. Building Blocks

1.1 Definitions

1.2 Cybersecurity Policy Domains

1.2.1 Individuals

1.2.2 Organizations

1.2.3 Dependencies

1.2.4 Adversaries

1.2.5 Cyberspace

1.2.6 Public Policy

1.3 Cybersecurity Policy Catalog

Chapter 2 Cybersecurity Evolution

2.1 The Dawn of the internet

2.2 Timeline

1960s

1970s

1980s

1990s

2000s

2010s

2020s

2.3 Ongoing Challenges

Chapter 3 Cybersecurity Policy Objectives

3.1 Cybersecurity Risk Issues

3.2 Governance and Management

3.2.1 Cybersecurity Policy

3.2.2 Procedures

3.2.3 Guidelines

3.3 Metrics

3.4 Risk Management

3.4.1 Financial Services

3.4.1.1 Contagion Mechanisms

3.4.1.2 Illustrative Contagion Scenarios

3.4.1.3 Contagion Accelerators

3.4.1.4 Case Study: The SWIFT Banking Network

3.4.1.5 From Institutional Risk to Systemic Risk

3.4.1.6 Additional Cybersecurity Challenges in Financial Services

3.4.2 Industrial Control Systems (ICS)

3.4.2.1 Control System Functions

3.4.1.4 Case Study: Stuxnet

3.4.2.2 Operational Technology

3.4.2.3 Level 0

3.4.2.4 Ongoing Challenges

3.4.3. Technology Platforms

3.4.3.1 Dispossession

3.4.3.2 Case Study: Cambridge Analytica

3.4.3.3 Technology Platform Industry Standards

3.4.3.5 Ongoing Technology Platform Cybersecurity Challenges

3.4.4 Artificial Intelligence (AI)

3.4.4.1 Cybersecurity Risk Issues Unique to AI

3.4.4.2 AI Case Study

3.4.4.3 AI Cybersecurity Standards

3.4.4.4 AI Anthropomorphism

3.4.4.3 Ongoing Artificial Intelligence Challenges

3.5 Conclusion

Chapter 4 Cybersecurity Communication

4.1 Cybersecurity Frameworks

4.1.1 Governance and Oversight Frameworks

4.1.2 Cybersecurity Program Frameworks

4.1.3 Dependency Frameworks

4.1.4 Assessing Framework Compliance

4.2 Threats and Vulnerabilities

4.2.1 Threats

4.2.1 Cybersecurity Incidents

4.2.2 Vulnerabilities

4.2.3 Vulnerability Marketplaces

4.3 Institutions for Communication and Collaboration

4.3.1 FIRST

4.3.2 The National Incident Management System and Cybersecurity Incident Coordination

4.3.3 National Infrastructure Protection Plan

4.4 Trend Analysis

4.5 Communication Challenges

4.5.1 Organizational Challenges

4.5.2 IT, OT, and ICS

4.5.3 Vulnerability Reporting

4.5.4 Public/Private Conflicts

4.5.5 Crisis Communications Systems

4.6 Conclusion

Chapter 5 Guidance for Decision Makers

5.1 Innovation, Change, and Risk

5.2 Governance

5.4 Strategic Choices

5.5 Focus on Risk and Controls

5.6 Policy Essentials

5.7 Moving from Policy to Implementation

5.7.1 Implementation of the Controls Architecture

5.8 Conclusion

Chapter 6 The Cybersecurity Workforce

6.1 Cybersecurity versus Engineering

6.2 Academic Curriculum on Cybersecurity

6.3 Certification of Cybersecurity Professionals

6.4 Cybersecurity Job Roles

6.5 Conclusion

Chapter 7: One Government’s Approach to Cyber Security Policy

7.1 US Federal Cyber Security Strategy

7.2 Infrastructure Awareness and Early Coordination

7.2.1 The Bombing of New York's World Trade Center

7.2.2 Cyber Attacks Against the United States Air

7.2.3 The Citibank Caper

7.2.4 Murrah Federal Building, Oklahoma City

7.2.5 Presidential Decision Directive 39

7.2.6 President’s Commission on Critical Infrastructure Protection

7.2.7 Eligible Receiver

7.2.8 Solar Sunrise

7.2.9 Presidential Decision Directive 63

7.2.10 National Infrastructure Protection Center (NIPC) and Information Sharing and Analysis Centers (ISACs)

7.2.12 Joint Task Force – Computer Network Defense (JTF-CND)

7.3 Homeland Security and Federal Consolidation

7.3.1 Terrorist Attacks Against the USA

7.3.2 US Government Response to the September 11, 2001 Terrorist Attacks

7.3.3 Homeland Security Presidential Directives in the Bush Administration

7.3.4 National Strategies in the Bush Administration

7.3.5 First National-Level DDoS Campaign, Estonia

7.3.6 Cyber-Kinetic Coordination, Georgia

7.3.7 Buckshot Yankee (Agent.btz)

7.4 Operationalization of Cyber Power

7.4.1 Early Cyber Warfare, Stuxnet

7.4.2 State Sponsored Espionage

7.4.3 US Cyber Command

7.4.4 Expansion of USCYBERCOM Service Cyber Components

7.4.5 Notable events

7.4.6 Congressional Actions

7.4.7 Federal Cybersecurity and Infrastructure Executive Orders

7.5 Institutional Maturation and Strategic Competition

7.5.1 Integration of Cyber with Joint Operations Doctrine

7.5.2 The Rise of Ransomware as a National Security Threat

7.5.3 Creation of CISA (the DHS Agency)

7.5.4 Election Security and Critical Infrastructure Protection

7.5.5 Solarium Commission

7.6 Systemic Risk, Resilience, and Whole-of-Nation Governance

7.6.1 Supply Chain and Software Assurance Policy

7.6.2 Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

7.6.3 Federal Cybersecurity and Infrastructure Executive Orders

7.6.4 National Cybersecurity Strategy (Biden Administration)

7.6.5 Public-Private Collaboration and Operational Integration

7.6.6 Offensive Cyber Operations and Deterrence Doctrine

7.7 Emerging Policy Frontiers

7.7.1 Zero Trust, Cloud, and Identity Modernization

7.7.2 Quantum Computing and Cryptographic Forecasts

7.7.3 Operational Technology (OT) and Industrial Control Systems (ICS)

7.7.4 Artificial Intelligence Policy and Cognitive Security

7.8 Conclusion

Chapter 8 Cybersecurity Policy Catalog

8.1 Individual Example Policy Statements

8.2 Organization Example Policy Statements

8.3 Public Example Policy Statements

8.4 Adversary Example Policy Statements

8.5 Dependency Example Policy Statements

8.6 Cyberspace Example Policy Statements

Chapter 9 Conclusion


Jennifer L. Bayuk, PhD, is an independent cybersecurity consultant, CEO of Decision Framework Systems, and cybersecurity professor. Previously a Wall Street CISO and Bell Labs security software engineer, she has numerous publications on security architecture, risk management, and cybersecurity forensics.

Art Ehuan is Executive Director of Duke University's Master of Engineering in Cybersecurity and CISO Executive Certificate programs. A former FBI Supervisory Special Agent, he served as cyber expert on breaches at Heartland, Sony Pictures, Target, Anthem, Equifax, Capital One, and Marriott.

Jason Healey is a Senior Research Scholar at Columbia University's School for International and Public Affairs. He founded the Atlantic Council's Cyber Statecraft Initiative and was a founding member of the White House Office of the National Cyber Director.

Paul Rohmeyer, PhD, is an IT management consultant and Information Systems faculty member at Stevens Institute of Technology. He serves on the editorial boards of Computers & Security Journal and Cybersecurity & Cybercrime Journal, with expertise spanning banking, finance, healthcare, and life sciences.

Marcus H. Sachs, PE, is Senior Vice President and Chief Engineer at the Center for Internet Security. A retired U.S. Army officer and former White House appointee, he previously served as CSO of the North American Electric Reliability Corporation and VP for National Security Policy at Verizon.

Donald Saxinger is an independent financial sector regulatory policy consultant. As an FDIC banking supervisor for over three decades, he chaired the FFIEC IT Examination Handbook and Cybersecurity and Critical Infrastructure Working Groups, authored banking industry cybersecurity guidance, led interagency cyber rulemaking, and advised central banks internationally.

Joseph Weiss, PE is Managing Partner of Applied Control Solutions, LLC, an independent control system cybersecurity consultant. An ISA Life Fellow and member of Control's Process Automation Hall of Fame, he has published over 100 papers and holds patents on instrumentation, control systems, and OT networks.



Ihre Fragen, Wünsche oder Anmerkungen
Vorname*
Nachname*
Ihre E-Mail-Adresse*
Kundennr.
Ihre Nachricht*
Lediglich mit * gekennzeichnete Felder sind Pflichtfelder.
Wenn Sie die im Kontaktformular eingegebenen Daten durch Klick auf den nachfolgenden Button übersenden, erklären Sie sich damit einverstanden, dass wir Ihr Angaben für die Beantwortung Ihrer Anfrage verwenden. Selbstverständlich werden Ihre Daten vertraulich behandelt und nicht an Dritte weitergegeben. Sie können der Verwendung Ihrer Daten jederzeit widersprechen. Das Datenhandling bei Sack Fachmedien erklären wir Ihnen in unserer Datenschutzerklärung.