The book is no longer in print, but a pre-publication draft is available here.
This  book review of the first edition includes a full content description. 
A short  book review of the second edition is in the July 2005 issue of Security Management.
A more thorough  book review of the second edition is in the November 2005 issue of The Information System Control Journal