Nelson Higher Education

Higher Education

Management of Information Security, 5th Edition

  • Michael E. Whitman
  • Herbert J. Mattord
  • ISBN-10: 130550125X
  • ISBN-13: 9781305501256
  • 592 Pages | Paperback
  • Previous Editions: 2014, 2011, 2008
  • COPYRIGHT: 2017 Published
Request a Copy for Review


About the Product

Give your students a managerially-focused overview of information security and how to effective administer it with Whitman/Mattord’s MANAGEMENT OF INFORMATION SECURITY, 5E. Prepare your students become information security management practitioners able to secure systems and networks to meet the challenges in a world where continuously emerging threats, ever-present attacks, and the success of criminals illustrate weaknesses in current information technologies. Future professional managers complete your course with the exceptional blend of skills and experiences to develop and manage the more secure computing environments that today’s organizations need. This edition offers a tightened focus on key executive and managerial aspects of information security while retaining the foundational instruction to reinforce key IT concepts. Updated content reflects the latest developments in the today’s field, such as NIST, ISO, and security governance.


  • CONTENT INTEGRATES CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONALS (CISSP) AND CERTIFIED INFORMATION SECURITY MANAGERS (CISM) INFORMATION. The authors have carefully incorporated both CISSP and CISM bodies of knowledge throughout the text to prepare your students for important CISSP and CISM certifications. Chapter scenarios follow a fictional company as it encounters various information security issues. Meaningful group discussion questions follow each scenario to prompt interaction within your classroom.

  • "VIEWPOINT" ESSAYS ILLUSTRATE INTRUIGING TOPICS. Students work with real-world examples as they examine concepts at work in today’s business environments.

  • ACTIVITIES, QUESTIONS AND PROJECTS REINFORCE SKILLS. Your students have numerous opportunities to apply what they are learning with in-depth review questions, hands-on activities, and case projects in each chapter.

About the Author

Michael E. Whitman

Michael Whitman, Ph.D., CISM, CISSP, is the executive director of the Institute for Cybersecurity Workforce Development and a professor of information security at Kennesaw State University. In 2004, 2007, 2012 and 2015, under his direction the Center for Information Security Education spearheaded K.S.U.’s successful bid for the prestigious National Center of Academic Excellence recognitions (CAE/IAE and CAE IA/CDE), awarded jointly by the Department of Homeland Security and the National Security Agency. Dr. Whitman is also the editor-in-chief of the Journal of Cybersecurity Education and Research and Practice, and he is director of the Southeast Collegiate Cyber Defense Competition. Dr. Whitman is an active researcher and author in information security policy, threats, curriculum development and ethical computing. He currently teaches graduate and undergraduate courses in information security. Dr. Whitman has several information security textbooks currently in print, including PRINCIPLES OF INCIDENT RESPONSE AND DISASTER RECOVERY; PRINCIPLES OF INFORMATION SECURITY; MANAGEMENT OF INFORMATION SECURITY; READINGS AND CASES IN THE MANAGEMENT OF INFORMATION SECURITY, VOLUMES I AND II; THE HANDS-ON INFORMATION SECURITY LAB MANUAL; THE GUIDE TO NETWORK SECURITY and THE GUIDE TO FIREWALLS AND NETWORK SECURITY. He has published articles in Information Systems Research, the Communications of the ACM, the Journal of International Business Studies, Information and Management and the Journal of Computer Information Systems. Dr. Whitman is a member of the Association for Computing Machinery, the Information Systems Security Association, ISACA and the Association for Information Systems. Previously, Dr. Whitman served the U.S. Army as an armored cavalry officer with additional duties as the automated data processing system security officer (ADPSSO).

Herbert J. Mattord

Herbert Mattord, Ph.D., CISM, CISSP, completed 24 years of IT industry experience as an application developer, database administrator, project manager and information security practitioner before joining the faculty at Kennesaw State University, where he is a professor of information security and assurance. Dr. Mattord currently teaches graduate and undergraduate courses in information security and assurance as well as information systems. He is also a senior editor of the Journal of Cybersecurity Education, Research and Practice. He and Dr. Michael Whitman have authored PRINCIPLES OF INCIDENT RESPONSE AND DISASTER RECOVERY, PRINCIPLES OF INFORMATION SECURITY, MANAGEMENT OF INFORMATION SECURITY, READINGS AND CASES IN THE MANAGEMENT OF INFORMATION SECURITY, THE GUIDE TO NETWORK SECURITY and THE HANDS-ON INFORMATION SECURITY LAB MANUAL. Dr. Mattord is an active researcher, author and consultant in information security management and related topics. He has published articles in the Information Resources Management Journal, Journal of Information Security Education, the Journal of Executive Education and the International Journal of Interdisciplinary Telecommunications and Networking. Dr. Mattord is a member of the Information Systems Security Association, ISACA and the Association for Information Systems. During his career as an IT practitioner, Dr. Mattord was an adjunct professor at Kennesaw State University, Southern Polytechnic State University, Austin Community College and Texas State University: San Marcos. He was formerly the manager of corporate information technology security at Georgia-Pacific Corporation, where he acquired much of the practical knowledge found in this and his other textbooks.

Table of Contents

UNIT I: Foundations of Information Security.
1. Introduction to Management of Information Security.
2. Compliance: Law and Ethics.
UNIT II: Strategic Information Security Management.
3. Governance and Strategic Planning for Security.
4. Security Policy.
5. Developing the Security Program.
6. Risk Management: Identifying and Assessing Risk.
7. Risk Management: Controlling Risk.
UNIT III: Operational Information Security Management.
8. Security Management Models.
9. Security Management Practices.
10. Planning for Contingencies.
11. Personnel and Security.
12. Protection Mechanisms. Appendix.

New to this edition

  • TIGHTENED FOCUS EMPHASIZES KEY EXECUTIVE AND MANAGERIAL ASPECTS OF INFORMATION SECURITY. Students become proficient in the most important areas of information security and management while still studying the foundational material necessary to reinforce key concepts.
  • UPDATES HIGHLIGHT THE LATEST ADVANCEMENTS IN THE FIELD. This edition presents the most current information on NIST, ISO, security governance, and other relevant changes related to today’s information security.
  • MINDTAP® OFFERS A PERSONALIZED TEACHING EXPERIENCE WITH RELEVANT ASSIGNMENTS. MindTap® guides students in analyzing, applying, and improving thinking while allowing you to measure skills and outcomes with ease.
  • CURRICULUM MAPS TO NATIONAL INITIATIVE FOR CYBERSECURITY EDUCATION STANDARDS. For interested institutions, curriculum mapping to the newly released National Initiative for Cybersecurity Education (NICE) standards is available with this edition.


All supplements have been updated in coordination with the Main title.
Please see Main title page for new to this edition information.

Instructor Supplements

Instructor's Web Site  (ISBN-10: 1305501268 | ISBN-13: 9781305501263)

Everything you need for your course in one place. This collection of product-specific lecture and class tools is available online via the instructor resource center at You'll be able to access and download materials such as PowerPoint® presentations, images, instructor’s manual, videos, and more.

Cengage Testing, powered by Cognero® Instant Access  (ISBN-10: 1305501470 | ISBN-13: 9781305501478)

Cengage Learning Testing. powered by Cognero®, is a flexible, online system that allows you to import, edit, and manipulate content from the text's test bank or elsewhere, including your own favorite test questions. Create multiple test versions in an instant and deliver tests from your LMS, your classroom, or wherever you want.

MindTap Information Security, 1 term (6 months) Instant Access for Whitman/Mattord's Management of Information Security  (ISBN-10: 1305949420 | ISBN-13: 9781305949423)

MindTap Networking & Security for Whitman/Mattord’s Management of Information Security is the digital learning solution that powers students from memorization to mastery. It gives you complete control of your course—to provide engaging content, to challenge every individual, and to build their confidence. Empower students to accelerate their progress with MindTap. MindTap: Powered by You. MindTap helps students master skills for today’s workforce. Research shows employers need critical thinkers, troubleshooters and creative problem-solvers. MindTap helps you achieve this with assignments, activities and labs that provide hands-on practice, real-life relevance and mastery of difficult concepts. Assignments progress from basic to more challenging problems. Readings and “Whiteboard Shorts” support the lecture, while “In The News” assignments encourage students to stay current. Analytics track class progress.

Student Supplements

MindTap Information Security, 1 term (6 months) Instant Access for Whitman/Mattord's Management of Information Security  (ISBN-10: 1305949420 | ISBN-13: 9781305949423)

MindTap Information Security for Whitman/Mattord's Management of Information Security, 5th Edition helps you learn on your terms. INSTANT ACCESS IN YOUR POCKET. Take advantage of the MindTap Mobile App to learn on your terms. Read or listen to textbooks and study with the aid of instructor notifications, flashcards, and practice quizzes. MINDTAP HELPS YOU CREATE YOUR OWN POTENTIAL. GEAR UP FOR ULTIMATE SUCCESS. Track your scores and stay motivated toward goals. Whether you have more work to do or are ahead of the curve, you’ll know where to focus your efforts. And MindTap Green Dot will charge your confidence along the way. MINDTAP HELPS YOU OWN YOUR PROGRESS. MAKE THE TEXT YOURS. No one knows what works for you better than you. Highlight key text, add notes, and create custom flashcards. When it’s time to study, everything you’ve flagged can be gathered into a guide you organize.