Nelson Higher Education

Higher Education

Principles of Information Security, 6th Edition

  • Michael E. Whitman
  • Herbert J. Mattord
  • ISBN-10: 1337102067
  • ISBN-13: 9781337102063
  • 656 Pages | Paperback
  • Previous Editions: 2015, 2012, 2009
  • COPYRIGHT: 2018 Published
Request a Copy for Review


About the Product

Introduce the latest technology and developments with the book specifically oriented to the needs of information systems students: PRINCIPLES OF INFORMATION SECURITY, 6E. Taking a managerial approach, this market-leading introductory book emphasizes all the aspects of information security -- not just the technical control perspective. Students gain a broad overview of the entire field of information security and related elements with the detail to ensure understanding. Students review terms used in the field, a history of the discipline, and an overview of how to manage an information security program. Current and relevant, this edition highlights the latest practices with fresh examples that explore the impact of emerging technologies, such as the Internet of Things, Cloud Computing, and DevOps. Updates address technical security controls, emerging legislative issues, digital forensics, and ethical issues in IS security, making it ideal for business decision-makers.


  • THIS BOOK ILLUSTRATES HOW INFORMATION SECURITY IS BOTH A MANAGEMENT AND TECHNOLOGY CHALLENGE. Students clearly see how information security in today’s modern organization is a problem for management to solve and not simply a problem that technology alone can answer. Readers examine how security problems have important economic consequences, for which management is held accountable.

  • ENGAGING, REVELANT CHAPTER OPENERS EMPHASIZE THE CRITICAL NATURE OF INFORMATION SECURITY. Each chapter opens with a short story that follows the same fictional company as it encounters actual real-world issues within modern information security. At the end of the chapter, discussion questions complete the case study scenario, giving you and your students opportunities to discuss the underlying issues.

  • OFFLINE AND TECHNICAL DETAILS BOXES HIGHLIGHT INTERESTING TOPICS AND CONTEMPORARY TECHNICAL ISSUES. Interspersed throughout the textbook, these captivating features enable your students to delve into key concepts more deeply.

  • CHAPTERS END WITH A SUMMARY, REVIEW QUESTIONS AND EXERCISES DESIGNED TO EXTEND STUDENT UNDERSTANDING. These end-of-chapter features enable students to examine the information security arena outside of the classroom. Exercises prompt students to research, analyze, and write to reinforce learning objectives and deepen their understanding of the key issues within this edition.

  • BOOK CONSISTENTLY EMPHASIZES REAL-WORLD APPLICATION. Students understand the relevance of what they are learning as this edition is packed with the latest timely, hands-on examples of information security issues, tools, and practices implemented in today's organizations.

  • UP-TO-DATE MANAGERIAL CONTENT EQUIPS STUDENTS FOR SUCCESS. This book’s managerial approach offers general, but valuable, information without bogging readers down with extraneous, highly specific details.

  • THE TEXT PROVIDES SUPPORT FOR MAPPING TO LEADING STANDARDS. With this edition, you can easily map to both the NIST National Initiative for Cybersecurity Education (NICE) Workforce framework and DHS/NSA National Center of Academic Excellence in Cyber Defense Education designation.

About the Author

Michael E. Whitman

Michael Whitman, Ph.D., CISM, CISSP, is the executive director of the Institute for Cybersecurity Workforce Development and a professor of information security at Kennesaw State University. In 2004, 2007, 2012 and 2015, under his direction the Center for Information Security Education spearheaded K.S.U.’s successful bid for the prestigious National Center of Academic Excellence recognitions (CAE/IAE and CAE IA/CDE), awarded jointly by the Department of Homeland Security and the National Security Agency. Dr. Whitman is also the editor-in-chief of the Journal of Cybersecurity Education and Research and Practice, and he is director of the Southeast Collegiate Cyber Defense Competition. Dr. Whitman is an active researcher and author in information security policy, threats, curriculum development and ethical computing. He currently teaches graduate and undergraduate courses in information security. Dr. Whitman has several information security textbooks currently in print, including PRINCIPLES OF INCIDENT RESPONSE AND DISASTER RECOVERY; PRINCIPLES OF INFORMATION SECURITY; MANAGEMENT OF INFORMATION SECURITY; READINGS AND CASES IN THE MANAGEMENT OF INFORMATION SECURITY, VOLUMES I AND II; THE HANDS-ON INFORMATION SECURITY LAB MANUAL; THE GUIDE TO NETWORK SECURITY and THE GUIDE TO FIREWALLS AND NETWORK SECURITY. He has published articles in Information Systems Research, the Communications of the ACM, the Journal of International Business Studies, Information and Management and the Journal of Computer Information Systems. Dr. Whitman is a member of the Association for Computing Machinery, the Information Systems Security Association, ISACA and the Association for Information Systems. Previously, Dr. Whitman served the U.S. Army as an armored cavalry officer with additional duties as the automated data processing system security officer (ADPSSO).

Herbert J. Mattord

Herbert Mattord, Ph.D., CISM, CISSP, completed 24 years of IT industry experience as an application developer, database administrator, project manager and information security practitioner before joining the faculty at Kennesaw State University, where he is a professor of information security and assurance. Dr. Mattord currently teaches graduate and undergraduate courses in information security and assurance as well as information systems. He is also a senior editor of the Journal of Cybersecurity Education, Research and Practice. He and Dr. Michael Whitman have authored PRINCIPLES OF INCIDENT RESPONSE AND DISASTER RECOVERY, PRINCIPLES OF INFORMATION SECURITY, MANAGEMENT OF INFORMATION SECURITY, READINGS AND CASES IN THE MANAGEMENT OF INFORMATION SECURITY, THE GUIDE TO NETWORK SECURITY and THE HANDS-ON INFORMATION SECURITY LAB MANUAL. Dr. Mattord is an active researcher, author and consultant in information security management and related topics. He has published articles in the Information Resources Management Journal, Journal of Information Security Education, the Journal of Executive Education and the International Journal of Interdisciplinary Telecommunications and Networking. Dr. Mattord is a member of the Information Systems Security Association, ISACA and the Association for Information Systems. During his career as an IT practitioner, Dr. Mattord was an adjunct professor at Kennesaw State University, Southern Polytechnic State University, Austin Community College and Texas State University: San Marcos. He was formerly the manager of corporate information technology security at Georgia-Pacific Corporation, where he acquired much of the practical knowledge found in this and his other textbooks.

Table of Contents

1. Introduction to Information Security.
2. The Need for Security.
3. Legal, Ethical, and Professional Issues in Information Security.
4. Planning for Security.
5. Risk Management.
6. Security Technology: Firewalls, VPNs, and Wireless.
7. Security Technology: Intrusion Detection and Prevention Systems and Other Security Tools.
8. Cryptography.
9. Physical Security.
10. Implementing Information Security.
11. Security and Personnel.
12. Information Security Maintenance and eDiscovery.

New to this edition

  • COMPLETELY UP TO DATE CONTENT REFLECTS THE LATEST DEVELOPMENTS FROM THE FIELD. Your students examine new innovations in technology and methodologies with this edition’s updated examples and references. This edition ensures you are able to present the most current coverage of emerging issues available.
  • REFINED TERMS AND GREATER IN-DEPTH CONTENT ON INFORMATION SECURITY THREATS INCREASE THIS EDITION’S RELEVANCE. Updated definitions and timely context of key terminology ensures a contemporary understanding and logical flow of the text. In addition, refined coverage of threats and attacks with added insights and depth on threat levels and severities and reorganized coverage of attacks against information systems prepares students for security challenges.
  • UPDATED MATERIAL PREVIEWS THE LATEST IN TECHNICAL SECURITY CONTROLS. Students examine how today’s control environment continues its migration to an environment with less emphasis on the network perimeter and more reliance on Cloud Computing and the Internet of Things.


All supplements have been updated in coordination with the Main title.
Please see Main title page for new to this edition information.

Instructor Supplements

Instructor's Companion Site  (ISBN-10: 133727500X | ISBN-13: 9781337275002)

Find everything you need for your course in one place. This collection of product-specific lecture and class tools is available online via the instructor resource center at You'll be able to access and download materials such as PowerPoint® presentations, instructor’s manual, test banks, and more.

Cengage Testing, powered by Cognero® Instant Access  (ISBN-10: 1337275026 | ISBN-13: 9781337275026)

Cengage Learning Testing, powered by Cognero®, is a flexible, online system that allows you to import, edit, and manipulate content from the text’s test bank or elsewhere, including your own favorite test questions. Create multiple test versions in an instant and deliver tests from your LMS, your classroom, or wherever you want.

MindTap Information Security, 1 term (6 months) Instant Access for Whitman/Mattord's Principles of Information Security  (ISBN-10: 1337281646 | ISBN-13: 9781337281645)

MindTap Information Security for Whitman/Mattord's Principles of Information Security is the digital learning solution that helps instructors engage and transform today's students into critical thinkers. Through paths of dynamic assignments and applications that you can personalize, real-time course analytics, and an accessible reader, MindTap helps you turn cookie-cutter into cutting-edge, apathy into engagement, and memorizers into higher-level thinkers. MindTap Information Security for Whitman/Mattord's Principles of Information Security is designed to help students master the skills they need in today’s workforce. Research shows employers need critical thinkers, troubleshooters and creative problem-solvers to stay relevant in our fast paced technology-driven world. MindTap helps you achieve this with assignments and activities that provide hands-on practice, real life relevance and mastery of difficult concepts. Students are guided through assignments that progress from basic knowledge and understanding to more challenging problems. All MindTap activities and assignments are tied to learning objectives. The hands-on labs provide real-life application and practice. Readings and “Whiteboard Shorts” support the lecture, while “In the News” assignments encourage students to stay current. Pre- and post-course assessments allow you to measure how much students have learned using analytics and reporting that makes it easy to see where the class stands in terms of progress, engagement and completion rates. Use the content and learning path as-is or pick and choose how our material will wrap around yours. You control what the students see and when they see it. Learn more at

Student Supplements

MindTap Information Security, 1 term (6 months) Instant Access for Whitman/Mattord's Principles of Information Security  (ISBN-10: 1337281646 | ISBN-13: 9781337281645)

It’s 1 AM, there are 20 tabs open on your computer, you lost your flashcards for the test, and you’re so tired you can’t even read. It’d be nice if someone came up with a more efficient way of studying. Luckily, someone did. With a single login for MindTap Information Security for Whitman/Mattord's Principles of Information Security you can connect with your instructor, organize coursework, and have access to a range of study tools, including e-book and apps all in one place! Manage your time and workload without the hassle of heavy books! The MindTap Reader keeps all your notes together, lets you print the material, and will even read text out loud. Need extra practice? Find pre-populated flashcards and the entire eBook in the MindTap Mobile App, as well as quizzes and important course alerts. Stay current with what’s going on in your field! Browse the In the News features which offer links to blogs, podcasts, and news sources from the cybersecurity field. Need additional support? Watch the whiteboard shorts found throughout the learning path. These vignettes explain challenging topics through detailed animations and simple narration that break down core concepts and make them easy to understand. Want to know where you stand? Use the Progress app to track your performance in relation to other students.