Security Controls Evaluation, Testing, and Assessment Handbook, Second Edition, provides a current and well-developed approach to evaluate and test IT security controls to prove they are functioning correctly. This handbook discusses the world of threats and potential breach actions surrounding all industries and systems. Sections cover how to take FISMA, NIST Guidance, and DOD actions, while also providing a detailed, hands-on guide to performing assessment events for information security professionals in US federal agencies. This handbook uses the DOD Knowledge Service and the NIST Families assessment guides as the basis for needs assessment, requirements and evaluation efforts.
Honestly, this is a pretty solid Information Assurance (IA) handbook. Anyone who is newer to the Information System Security Officer (ISSO) realm with 3 years of experience or less, I think this would be a very valuable supplemental resource and something to be referenced/kept handy.
The author did a really great job going beyond just copy/pasting NIST/DoD/RMF documentation and mashing it all together and slapping on a price tag.