03960nam 2200745Ia 450 991108819350332120251117115805.0978661276267397815973449061597344907978052093645405209364509781282762671128276267210.1525/9780520936454(CKB)1000000000000909(EBL)223871(OCoLC)475929109(SSID)ssj0000110749(PQKBManifestationID)11132915(PQKBTitleCode)TC0000110749(PQKBWorkID)10064717(PQKB)10413493(DE-B1597)520862(OCoLC)55749295(DE-B1597)9780520936454(Au-PeEL)EBL223871(CaPaEBR)ebr10058570(CaONFJC)MIL276267(Perlego)552557(MiAaPQ)EBC223871(EXLCZ)99100000000000090920021029d2003 ub 0engurnn#---|u||utxtccrBetween Sundays Black women and everyday struggles of faith /Marla F. Frederick1st ed.Berkeley University of California Press20031 online resource (276 p.)George Gund Foundation Book in African American StudiesDescription based upon print version of record.9780520233928 0520233921 9780520233942 0520233948 Includes bibliographical references and index.Front matter --Contents --Preface --Introduction --Monday. "Of The Meaning Of Progress" --Tuesday. Gratitude And Empathy --Revival. Reading Church History --Wednesday. Righteous Discontent --Revival. "Are We A Church Or A Social Change Organization?" --Thursday Televangelism. (And Shifting Discourses Of Progress) --Revival. "Loosed Women" --Friday. Financial Priorities --Saturday. Sexual Politics --Second Sunday. Conclusion --Notes --Bibliography --IndexTo be a black woman of faith in the American South is to understand and experience spirituality in a particular way. How this understanding expresses itself in everyday practices of faith is the subject of Between Sundays, an innovative work that takes readers beyond common misconceptions and narrow assumptions about black religion and into the actual complexities of African American women's spiritual lives. Gracefully combining narrative, interviews, and analysis, this book explores the personal, political, and spiritual commitments of a group of Baptist women whose experiences have been informed by the realities of life in a rural, southern community. In these lives, "spirituality" emerges as a space for creative agency, of vital importance to the ways in which these women interpret, inform, and reshape their social conditions--conditions often characterized by limited access to job opportunities, health care, and equitable schooling. In the words of these women, and in Marla F. Frederick's deft analysis, we see how spirituality-expressed as gratitude, empathy, or righteous discontent-operates as a transformative power in women's interactions with others, and in their own more intimate renegotiations of self.George Gund Foundation Book in African American StudiesAfrican American womenReligious lifeAfrican American womenSpiritual lifeAfrican American womenReligious life.African American womenSpiritual life.277.5/6/083/082Frederick Marla Faye1972-1621855MiAaPQMiAaPQMiAaPQBOOK9911088193503321Between Sundays4736259UNINA10754nam 22004693 450 991111769990332120260830110138.09781394423057(CKB)48347122000041(MiAaPQ)EBC32783126(Au-PeEL)EBL32783126(OCoLC)1601984277(CaSebORM)9781394423040(EXLCZ)994834712200004120260629d2026 uy 0engur|||||||||||txtrdacontentcrdamediacrrdacarrierCybersecurity Auditing Principles, Practices, and Frameworks1st ed.Newark :John Wiley & Sons, Incorporated,2026.©2026.1 online resource (593 pages)9781394423040 Cover -- Half Title Page -- Title Page -- Copyright -- Contents -- Preface -- Acknowledgments -- About the Companion Website -- Chapter 1: The Role of Audit in Security Governance, Risk, and Compliance -- Assurance Mandate Within the Three Lines Model -- Audit Charter, Authority, and Independence Boundaries -- Governance Interfaces: Board/Audit Committee, CISO, Legal, Privacy -- Policy-Standards-Procedures Architecture (Audit View) -- GRC Architecture: Control Library and Risk Register -- Exception and Waiver Governance -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 2: Security Standards and Regulations -- Auditor's Use of Frameworks -- Common Control Set and Cross-framework Traceability -- Multi-regime Scoping: Entities, Systems, and Data Classes -- Equivalency and Mapping Rules: Sufficiency and Residual Gaps -- Portfolio Evidence Packs and Evidence Reuse -- Inherited/Shared Controls and Third-party Reliance (SOC, Certifications) -- Deviations and Compensating Controls: Carve-outs and Documentation -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 3: Risk Assessment and Control Design for Modern Systems -- Cyber Risk Taxonomy and Materiality -- Control Design Choices -- Traceability -- Design Reviews and Auditor Boundaries -- Integration with Enterprise Architecture and Change Governance -- Design Documentation: Approvals, RACI, and Version Control -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 4: Evidence, Sampling, and Testing Techniques -- Evidence Quality and Chain of Custody -- Building Populations and Defensible Sampling Strategies -- Test Types: Design vs. Operating Effectiveness -- Inspection and Re-performance Procedures -- Analytics-assisted Testing and Tooling Considerations -- Period Coverage, Timing, and Frequency of Tests.Workpaper Standards and Reviewability -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 5: Auditor Ethics, Independence, and Professional Judgment -- Code of Ethics and Objectivity in Cyber Audits -- Independence Threats and Safeguards -- Confidentiality, Data Handling, and Sensitive Evidence -- Professional Skepticism and Cognitive Bias Awareness -- Forming Conclusions Under Uncertainty and Incomplete Evidence -- Managing Management Pressure and Disagreement -- Documenting Judgment -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 6: Identity and Access Management -- Identity Life cycle: Joiner-Mover-Leaver and Sources of Truth -- Authentication Controls: MFA, SSO, Federation, and Risk-based Access -- Privileged Access: PAM, Break-glass, Session Monitoring -- Service Accounts, Nonhuman Identities, and Secrets Handling -- Evidence Locations: IdP, PAM, HRIS, Ticketing, and Logs -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 7: Network and Perimeter Security -- Network Segmentation and Trust Zones -- Firewall and Egress Controls (Allowlists, Rule Hygiene, Change History) -- Secure Edge/SASE and Remote Access (VPN/ZTNA Posture) -- DNS, Web Proxies, and URL Filtering (Policy Alignment) -- Intrusion Prevention/Threat Intel at the Edge -- Device/Config Management: Baselines, Backups, and Drift -- Evidence Locations -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 8: Application and API Security/CI-CD -- SDLC Governance and "Policy as Code -- Code and Dependency Scanning: SAST, SCA, and Secrets Detection -- Dynamic Testing and API Security: DAST, AuthN/AuthZ, and Rate Limits -- Infrastructure as Code and Environment Hardening -- Release Governance: Change Approval Gates and Rollback Paths -- Evidence Locations: Repos, Pipelines, Registries, and API Gateways.Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 9: Cloud and SaaS Security -- Shared Responsibility and Tenant Scope (IaaS/PaaS/SaaS) -- Identity Boundaries in Cloud: Roles, Policies, and SCPs/Guardrails -- Baseline Configurations -- Logging/Telemetry in Cloud and SaaS -- Data-plane Protections: Keys, Secrets, and Segmentation -- Evidence Locations: CSP Config State, Org Policies, SaaS Admin Exports -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 10: Data Protection -- Data Classification and Handling Requirements -- Encryption in Transit and at Rest -- Key Management: Generation, Rotation, Custody, and Separation of Duties -- Hardware/Cloud KMS/HSM Controls and Access Boundaries -- Tokenization, Masking, and DLP Policy Design -- Data Flow Mapping and High-risk Stores/Paths -- Evidence Locations: KMS/HSM Logs, Key Policies, DLP Events, and Configs -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 11: Logging, Monitoring, and Detection -- Log Coverage Model: Sources, Depth, and Retention Targets -- Integrity and Tamper Resistance -- Detection Content Quality: Precision/Recall, Tuning, and Suppression -- Use-case Catalog and Ownership -- Alert Triage Interfaces and Escalation Paths -- Telemetry Gaps and Compensating Signals -- Evidence Locations: SIEM/Log Platform, Detection Repositories, and Tuning Records -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 12: Incident Response and Crisis Management -- IR Operating Model -- Detection Handoffs and Case Life Cycle (from Alert to Closure) -- Forensics and Evidence Handling (Chain of Custody) -- Communications and Regulatory Notifications -- Backup/Restore Readiness and BCP/DR Alignment (RTO/RPO) -- Tabletop Exercises and Post-incident Learning.Evidence Locations: IR Plans, Case Systems, Forensic Repositories, and DR Reports -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 13: Vulnerability Management and Pen Test Oversight -- Asset Coverage and Scan Cadence -- Prioritization: KEV, EPSS, Exploitability, and Business Context -- Remediation SLAs, Exceptions, and Risk Acceptance -- Validation of Fixes and Regression Controls -- Penetration Testing Governance: Independence, Scope, and Reporting -- Findings Life cycle and Cross-team Accountability -- Evidence Locations: Scanners, Ticketing, Exception Registers, and Pen Test Artifacts -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 14: Third-party and Supply-chain Security -- Vendor Risk Segmentation and Due Diligence Depth -- Contractual Security Clauses and Right-to-audit/Assurance Rights -- Assurance Artifacts: SOC Reports, SIG/CAIQ, and Certifications -- Continuous Monitoring: Questionnaires, Signals, and Triggers -- Software Supply Chain: SBOM, Dependency Risk, and Build Provenance -- Remediation and Offboarding/Exit Strategies -- Evidence Locations: Procurement/TPRM Systems, Contracts, and Assurance Repos -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 15: OT/ICS and Critical Infrastructure Audits -- Safety and Availability Constraints (Risk Trade-offs) -- Zones and Conduits: Network Segmentation for ICS -- Allowlist/Whitelist Controls and Remote Access Methods -- Patch/Change Realities: Compensating Controls and Windows -- Monitoring and Physical/Environmental Dependencies -- Regulatory and Standards Context -- Evidence Locations: ICS Diagrams, Change Logs, Site Procedures, and Operator Logs -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 16: Sector Overlays (Financial, Healthcare, Public.Overlay Scoping: Identifying In-scope Systems, Data, and Obligations -- Financial Services (FFIEC/GLBA): Controls Emphasis and Artifacts -- Healthcare (HIPAA/HITRUST): Safeguards, Mappings, and Evidence Nuances -- Public Sector (FedRAMP, State/Local): Authorizations and Continuous Monitoring -- PCI DSS: Prescriptive Requirements and Segmentation/Scope Control -- Reconciling Conflicts: Precedence Rules and Documentation -- Evidence Locations: Regulator-specific Workpapers, ATO Packages, ROC/SAQ -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 17: Automation, Continuous Auditing, and Advanced Analytics -- Objectives and Scope of Automated Assurance -- Data Sources and Pipelines (Lineage, Quality, and Access Controls) -- Job Design and Governance (Change Control, Versioning, and Approvals) -- Automated Control Tests: Types, Frequencies, and Coverage Models -- Accuracy and Reliability: Ground-truthing, Thresholds, and Drift in Tests -- Dashboards and Variance Analysis (Interpreting Results and Triggering Follow-ups) -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 18: AI Threat Modeling and Attack Surfaces -- Scoping AI Assets: Models, Datasets, Prompts, Tools, and Agents -- Threat Modeling Methods for AI Systems (STRIDE/ATT& -- CK Extensions) -- Core Attack Surfaces: Prompt Injection, Data Leakage, and Model Theft/Extraction -- Data Integrity Risks: Poisoning, Backdoors, and Training Set Governance -- Abuse Paths via Integrations: Plugins, Connectors, and Tool Invocation -- Control Objectives and Risk Acceptance Criteria for AI Systems -- Documentation and Traceability: from Threat to Control to Evidence -- Conclusion -- Auditor Recommendations -- Chapter Questions -- Chapter 19: Secure MLOps and Model/Endpoint Controls -- Supply Chain Integrity: Artifacts, Registries, Signing, and Provenance.Environment Hardening: Build/Train/Serve Isolation and Access Boundaries.Practical guide to cybersecurity controls, systems, programs, and management This book is a comprehensive, field-tested guide to the full spectrum of cybersecurity auditing, enabling readers to assess, evaluate, and improve security controls across today's complex IT environments.005.8Edwards Jason919105MiAaPQMiAaPQMiAaPQBOOK9911117699903321Cybersecurity Auditing4804724UNINA04040nam 22008054a 450 991114286530332120260415134148.097866121956249781282195622128219562X978311916644731191664489783110201932311020193310.1515/9783110201932(CKB)1000000000520864(EBL)325618(OCoLC)191926301(SSID)ssj0000188086(PQKBManifestationID)11165782(PQKBTitleCode)TC0000188086(PQKBWorkID)10162995(PQKB)10023787(MiAaPQ)EBC325618(DE-B1597)32950(OCoLC)741344593(OCoLC)853258587(DE-B1597)9783110201932(Au-PeEL)EBL325618(CaPaEBR)ebr10197210(CaONFJC)MIL219562(OCoLC)319050111(Perlego)1156933(EXLCZ)99100000000052086420060721d2006 uy 0gerurun#---|u||utxtccrKonstruktionen der Fremde Erfahren, verschriftlicht und erlesen am Beispiel Japan /Uta Schaffers1st ed.Berlin W. de Gruyter20061 online resource (404 p.)Spectrum Literaturwissenschaft,1860-210X ;8The author's Habilitationsschrift--Universitat zu Koln, 2005.9783110188622 3110188627 Includes bibliographical references (p. [346]-389)and index.Front matter --Inhaltsverzeichnis --1 Einleitung --2 Fremde und Fremderfahrung --3 Die Fremde als Sehnsuchtsraum: Japan im Werk Bernhard Kellermanns --4 Die Fremde als Lebens- und Erfahrungswelt: Briefe aus Japan in die Heimat --5 In der Fremde lesen --6 Zusammenfassung und bildungspragmatische Überlegungen --Back matterDieses Buch untersucht, wie und unter welchen Bedingungen die 'Fremde' zunächst in einer konkreten Begegnung erfahren und anschließend schreibend und lesend konstruiert, also in Texten verfügbar gemacht und im Rezeptionsprozess erneut hergestellt wird. Dabei werden auch Fragen nach den Bedingungen, Spielräumen und Grenzen des Fremdverstehens reflektiert. Im Mittelpunkt der Untersuchung stehen exemplarisch deutschsprachige Texte über Japan, u. a. von Bernhard Kellermann, Max Dauthendey und Gerhard Roth. Herausgearbeitet und analysiert werden auf inhaltlicher, sprachlicher und formaler Ebene insbesondere die Strukturen und Tradierungen sowie die Musterbildungen, in denen sich die Konstruktionen der 'Fremde Japan' vollziehen. Einen ersten Schwerpunkt der Untersuchung bilden die japanbezogenen Werke Bernhard Kellermanns. Anhand der Textsorte Brief wird dann eine spezifische Form des Schreibens aus und über Japan genauer fokussiert. Die Untersuchung der Komponenten 'Lesen' und 'Schrift' als inhaltliche Elemente der Texte zeigt abschließend, inwiefern 'Lesen' als Metaphernkomplex und als Wahrnehmungshaltung die Grundfigur der Fremdbegegnung bildet, und wie die 'fremde Schrift' als 'unlesbar' konstruiert und funktionalisiert wird.Spectrum Literaturwissenschaft ;8.German literature19th centuryHistory and criticismGerman literature20th centuryHistory and criticismAlienation (Social psychology) in literatureGermansJapanJapanIn literatureGerman literatureHistory and criticism.German literatureHistory and criticism.Alienation (Social psychology) in literature.Germans830GE 5206rvkSchaffers UtaMiAaPQMiAaPQMiAaPQBOOK9911142865303321UNINA04202nam 2200769Ia 450 991114902170332120251117115608.09786612358241978128235824912823582439780520939288052093928X9781597344500159734450810.1525/9780520939288(CKB)111090529079620(EBL)224570(OCoLC)808037855(SSID)ssj0000092615(PQKBManifestationID)11114332(PQKBTitleCode)TC0000092615(PQKBWorkID)10023398(PQKB)10348720(DE-B1597)518878(OCoLC)55538532(DE-B1597)9780520939288(Au-PeEL)EBL224570(CaPaEBR)ebr10057097(CaONFJC)MIL235824(Perlego)550830(MiAaPQ)EBC224570(EXLCZ)9911109052907962020031010d2004 uy 0engurnn#---|u||utxtrdacontentcrdamediacrrdacarrierThe $800 million pill the truth behind the cost of new drugs /Merrill Goozner1st ed.Berkeley University of California Press20041 online resource (304 pages)Description based upon print version of record.9780520246706 0520246705 9780520239456 0520239458 Includes bibliographical references and index.Front matter --Contents --Introduction --PART ONE. BIOHYPE --PART TWO. DIRECTED RESEARCH --PART THREE. BIG PHARMA --Notes --Bibliography --Acknowledgments --IndexWhy do life-saving prescription drugs cost so much? Drug companies insist that prices reflect the millions they invest in research and development. In this gripping exposé, Merrill Goozner contends that American taxpayers are in fact footing the bill twice: once by supporting government-funded research and again by paying astronomically high prices for prescription drugs. Goozner demonstrates that almost all the important new drugs of the past quarter-century actually originated from research at taxpayer-funded universities and at the National Institutes of Health. He reports that once the innovative work is over, the pharmaceutical industry often steps in to reap the profit. Goozner shows how drug innovation is driven by dedicated scientists intent on finding cures for diseases, not by pharmaceutical firms whose bottom line often takes precedence over the advance of medicine. A university biochemist who spent twenty years searching for a single blood protein that later became the best-selling biotech drug in the world, a government employee who discovered the causes for dozens of crippling genetic disorders, and the Department of Energy-funded research that made the Human Genome Project possible--these engrossing accounts illustrate how medical breakthroughs actually take place. The00 Million Pill suggests ways that the government's role in testing new medicines could be expanded to eliminate the private sector waste driving up the cost of existing drugs. Pharmaceutical firms should be compelled to refocus their human and financial resources on true medical innovation, Goozner insists. This book is essential reading for everyone concerned about the politically charged topics of drug pricing, Medicare coverage, national health care, and the role of pharmaceutical companies in developing countries.Eight hundred million dollar pillPrescription pricingDrugsPricesPharmaceutical industryConsumer educationPrescription pricing.DrugsPrices.Pharmaceutical industry.Consumer education.338.4/3/61510973Goozner Merrill1950-MiAaPQMiAaPQMiAaPQBOOK9911149021703321UNINA