This book addresses the uses and practical aspects of the analysis, design and specification of information systems security, and will represent the intersection of the work in computer security and current work in systems analysis and auditing. Written from a management information perspective rather than from the standpoint of computer science or from the standpoint of the security consultant, the book looks at both the managerial, organizational and social implications as well as the underlying technology. The book further discusses the problems created by computer security and analyses the managerial justification of information systems controls.