Practical guidance for government security: manage risk, plan incidents, and design strong programs. This federal-focused handbook lays out clear, actionable steps for building effective computer security programs and practices.
This edition tackles how agencies can align security with mission needs, integrate risk management, and sustain a proactive security posture. It covers roles, processes, and practical controls across policy, program management, incident handling, training, and operational security, all tailored for federal contexts.
- Understand how to balance cost, risk, and security across the organization.
- Learn structured approaches to risk assessment, mitigation, and lifecycle planning.
- Explore incident handling, reporting, and coordination with law enforcement and partners.
- Discover how awareness, training, and governance support a resilient security program.
Ideal for readers working in government, defense, or related sectors who need practical, government-focused computer security guidance.