Meet Independent
Information Security Consultant
Charles Cresson Wood
CISA, CISM, CISSP


Recipient of Computer Security Institute's
Lifetime Achievement Award.

Consulting Services Include:

  • Performance of independent information systems risk analyses and EDP audits
  • Development of information security requirements documents including policies, guidelines, standards, architectures, and procedures
  • Compilation of information security roles and responsibility documents such as job descriptions, departmental mission statements, and committee charters
  • Synthesis of multiple competing objectives into coherent system designs for major information security projects (single sign-on, dynamic passwords, public key infrastructure, etc.)
  • Creation of custom information security training and awareness materials, including delivery of speeches, courses, and seminars

Charles Cresson Wood is an independent information security consultant based in Sausalito, California. In the information security field on a full-time basis since 1979, he has worked as an information security management consultant at SRI International (formerly Stanford Research Institute) as well as lead network security consultant at the Bank of America. He has done information security work with over 125 organizations -- many of them Fortune 500 companies -- including a large number of financial institutions and high-tech companies. His consulting work has taken him to over 20 different countries around the world.

He is noted for his ability to integrate competing objectives (like ease-of-use, speed, flexibility, privacy, and security) in customized and practical compromises that are acceptable to all parties involved. Acknowledging that information security is multi-disciplinary, multi- departmental, and often multi-organizational, he is additionally noted for his ability to synthesize a large number of complex considerations and then to document these in security architectures, system security requirements, risk assessments, project plans, policy statements, and other clear action-oriented documents.

He has published over 300 technical articles and six books in the information security field. In addition to TV and radio appearances, he has been quoted as an expert in publications such as Business Week, Christian Science Monitor, Computerworld, IEEE Spectrum, Infoworld, LA Times, Network Computing, Network World, PC Week, The Wall Street Journal, and Time. He has also presented cutting-edge information security ideas at over 125 technical and professional conferences around the globe.

Mr. Wood is Senior North American Editor for the journals 'Computers & Security' and 'Computer Fraud & Security Bulletin,' as well as a monthly columnist for 'Computer Security Alert.' He holds an MBA in financial information systems, an MSE in computer science, and a BSE in accounting from the Wharton School of Business at the University of Pennsylvania. He has passed the Certified Public Accountant (CPA) examination and is a Certified Information Systems Auditor (CISA), a Certified Information Security Manager (CISM), and a Certified Information Systems Security Professional (CISSP). In November 1996 he received the Lifetime Achievement Award from the Computer Security Institute for "sincere dedication to the computer security profession."



Charles Cresson Wood, CISA, CISM, CISSP

Independent Information Security Consultant & Author

InfoSecurity Infrastructure, Inc.
Post Office Box 2877
Sausalito, California 94966-2877 USA

For information about consulting services
415-289-0800 office voice
415-289-0808 office fax

For information about books by Charles Cresson Wood contact Information Shield at http:// www.informationshield.com
713-443-8428 (or) 888-641-0500

Copyright © 2005, InfoSecurity Infrastructure, Inc.
All Rights Reserved
information security consulting, information security books, information security investigations, information security infrastructure, computer
security, computer crime, computer security consulting, computer abuse, computer privacy, information security policies, information security policy, information systems acceptable use policy, information security guidelines, information security standards, Internet security, intranet security, extranet security, encryption, virtual private network, VPN, hacker, cracker, network security, firewall, security code reviews, systems certification, EDP audit, computer audits, infosecurity, INFOSEC, COMPSEC, COMSEC