Showing posts with label cissp. Show all posts
Showing posts with label cissp. Show all posts

The New School of Information Security Review

The New School of Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy The New School of Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on The New School of Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The New School of Information Security ReviewWhat a delightful chapter title in Adam Shostack's and Andrew Stewart's new book, The New School of Information Security. They have produced a readable, compact tour of the information security field as it stands today - or perhaps as it lies in its crib. What we know intuitively the authors bring forward thoughtfully in their analysis of the information security industry: it is struggling to keep up with the defects in online communication, data storage, and business processes.
Shostack and Stewart helpfully review the stable of plagues on computing, communication, and remote commerce: spam, phishing, viruses, identity theft, and such. Likewise, they introduce the cast of characters in the security field, all of whom seem to be feeling along in the dark together.
Why are the lights off? Lack of data, they argue. Most information security decisions are taken in the absence of good information. The authors perceptively describe the substitutes for good information, like following trends, clinging to established brands, or chasing after studies produced by or for security vendors.
The authors revel in the breach data that has been made available to them thanks to disclosure laws like California's SB 1386. A purist must quibble with mandated disclosure when common law can drive consumer protection more elegantly. But good data is good data, and the happenstance of its availability in the breach area is welcome.
In the most delightful chapter in the book (I've used it as the title of this review), Shostack and Stewart go through the some of the most interesting problems in information security. Technical problems are what they are. Economics, sociology, psychology, and the like are the disciplines that will actually frame the solutions for information security problems.
In subsequent chapters, Shostack and Stewart examine security spending and advocate for the "New School" approach to security. I would summarize theirs as a call for rigor, which is lacking today. It's ironic that the world of information lacks for data about its own workings, and thus lacks sound decision-making methods, but there you go.
The book is a little heavy on "New School" talk. If the name doesn't stick, Shostack and Stewart risk looking like they failed to start a trend. But it's a trend that must take hold if information security is going to be a sound discipline and industry. I'm better aware for reading The New School of Information Security that info sec is very much in its infancy. The nurturing Shostack and Stewart recommend will help it grow.The New School of Information Security Overview

Want to learn more information about The New School of Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise Review

Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise
Average Reviews:

(More customer reviews)
Are you looking to buy Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise? Here is the right place to find the great deals. we can offer discounts of up to 90% on Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise ReviewThis book is really interesting. It will open up your mind to things you have never thought of before. The book is really a risk management text book but you would never know that until the very end. The book explains a whole new way to look at risk management. It is sort of like the Book "Black Swan". The book lays out how you can redo our start a risk management program that will revolutionize your operation.
He does a good job of explaining the why we need to do this. All you have to do is pay attention to the news. The authors takes this information and adds to it. The added information will make you stand up in shock. For example the authors list all of the companies that have failed recently. The number will shock you. Another shocking fact is how the life span of fortune 500 companies is only like 45 years.
It throws out the old way of risk management. The book focuses people to deal with the extremes. The authors say people should do this in a comprehensive way, not just piling up the sand bags for the inevitable flood which will be coming.
The book is easy to read. It has lots of real world examples that brings the concepts alive in new ways. Then the authors offer the academic way to explain the concept. His ideas also will change how your company operates.
If you want to stretch your mind read this book. It also might save your job too.
Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise Overview

Want to learn more information about Surviving and Thriving in Uncertainty: Creating The Risk Intelligent Enterprise?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

CISSP Practice Exams (All-in-One) Review

CISSP Practice Exams (All-in-One)
Average Reviews:

(More customer reviews)
Are you looking to buy CISSP Practice Exams (All-in-One)? Here is the right place to find the great deals. we can offer discounts of up to 90% on CISSP Practice Exams (All-in-One). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

CISSP Practice Exams (All-in-One) ReviewI'm not one to write reviews prior to finishing the material, especially prior to taking the certification test that this book helps study for, but I purchased this book to help reinforce my knowledge of the material for the upcoming (1 month away) CISSP exam in my area and noticed there are no other reviews of this book. So, since other people may be purchasing this book very soon to help study, I figured I'd provide a little more information than what Amazon provides just to help guide people into making a wise purchase since nobody else is. So - is it worth it? Beats me, I'll update this in about 6 weeks. Here's what I can tell you so far:
The book itself is divided into one chapter each for each area of the CISSP exam. Each chapter has 25 questions in it, so there really isn't a ton of content in the book itself. What is nice is that every answer (A, B, C, or D) is explained in detail so you know why an answer is or isn't something, and that lengthy answer is why the book is longer than it otherwise would be with only 25 questions for each section. If this was the only content provided, the book would be an easy 1-star, pass and walk away recommendation - BUT it comes with a link to extra online bonus content which I feel (at least right now) makes the book worth my cash. Here's what's on the website:
1.5GB (~124 files) (~30-ish hours ?I think?) worth of MP3s which are recordings of Shon providing training to, well, me. I'm only through the first chapter, but she appears to be a good trainer and has a good voice (which, if you've heard bad audio trainers or audiobooks, you know will drive you crazy). I will continue listening to all of the other recordings (1+ hour drive to work everyday helps, lol), and I would recommend this resource to people. The one drawback is that the MP3s appear to be very dated. The modified date is from 2005 but in one of the recordings she references the soon-to-be-released Windows Server 2003 (HA!). That said, most of the material carries over from year to year all the same, but if you're looking for the audio training to mirror the newest objectives - look elsewhere. As I always say, this is a great supplemental material, but not "prime" material. I'm a fan of using a ton of supplemental material to get the biggest, overall picture anyway. If Shon or her publishers read this - thanks for the MP3s, they're great in the car!
The website also includes 3-4 online flash quizzes for each section of study (about 33 total quizzes, all said). Each quiz has approximately 50 questions, for a total of a ton of questions. Each question tells you once you submit it whether you're right or not and why (although it doesn't break it down into why each individual answer is wrong like the book does). I prefer to know the answer right away, so I'm glad it doesn't make me wait until question 50 to learn the answer to question 2.
If you can't tell by now, so far I think the book is a good study aide. I'll update this after I take the test to let you know how well it helped, and whether or not the questions were similar in content/context/writing than the actual test. In my opinion, knowing how the question is written is nearly as important as knowing the answer to it. It's amazing how difficult you can make an easy question just by wording it in an awkward way. For now - I'm happy I got this book & would recommend it to others. Sorry for being so wordy.
***UPDATE***
After a few weeks, I continue to agree with myself that this book is overpriced for the print-content alone. Q&A is good, but it all sums up to the size of one practice test. I might pay 10 bucks for that content, but not what the current price is. I also still agree with myself that the online content makes this book worth its retail price, but I have two complaints about the online content & need to append my previous comments about the online Q&A interface. First - after you answer one question, but before you move on to the next, the system tells you if you're right or wrong. If you're wrong, it provides an explanation. What's odd is that the explanation doesn't actually say what the right answer is and very frequently you still can't tell from the explanation given. No problem, you think, it's cool, because after I complete the test I can go back to the previous questions and see what the correct answer is. This is correct because, once the test is done, you can select a previous question from a drop-down list and it'll have a red X next to your wrong answer and a green check mark next to the correct answer. Problem here (my Second complaint) is that now that you can see the correct answer, there is no way to bring up the explanation of the problem again. So, if you don't remember the explanation 50 questions and an hour later, you're really out of luck.
Summing up this update - I think the programmers & editors dropped the ball in the 2 mentioned usability aspects of the online Q&A software. It works, but can be frustrating quite often. This doesn't kill the deal, or my rating (still 4 out of 5 stars), but it is something they should work on for future versions.CISSP Practice Exams (All-in-One) Overview

Want to learn more information about CISSP Practice Exams (All-in-One)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Assessing and Managing Security Risk in IT Systems: A Structured Methodology Review

Assessing and Managing Security Risk in IT Systems: A Structured Methodology
Average Reviews:

(More customer reviews)
Are you looking to buy Assessing and Managing Security Risk in IT Systems: A Structured Methodology? Here is the right place to find the great deals. we can offer discounts of up to 90% on Assessing and Managing Security Risk in IT Systems: A Structured Methodology. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Assessing and Managing Security Risk in IT Systems: A Structured Methodology ReviewThe book essentially describes the McCumber Cube information security methodology.
And the McCumber Cube methodology is indeed interesting and worth the read.
Unfortunately, the author wrote around it a whole book!
In the first part the author describes the bases on the information security and relates it to the McCumber Cube (without really describing what the Cube is! Luckily, the hardcover has a picture of it.)
In the second part he dwelves in a little more detail of the McCumber Cube methodology, repeating again and again the same concepts, just with slight viewpoint variations.
Obviously his methodology is described as superior to any other methodology! While he makes a few good points, often he just states this without really comparing it to the other technologies.
Worth the read if you have time to spare... it indeed has a few interesting ideas and viewpoints.
If only they were expressed in a tenth of the space!
Assessing and Managing Security Risk in IT Systems: A Structured Methodology Overview

Want to learn more information about Assessing and Managing Security Risk in IT Systems: A Structured Methodology?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Review

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program
Average Reviews:

(More customer reviews)
Are you looking to buy The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program ReviewThis book is the Boy Scout Senior Patrol Leader's handbook for Information Security Officers. " On my honor, I will do my best, to do my duty, to my corporation and profession...."It is a short book-I read it in an evening-that tries to be a complete guide to a very complex profession. Following this merit badge guidebook approach, the entire subject of risk is covered in 3 pages, and CP/DR is covered in just over 2. It just doesn't contain enough text to be the sole reference book for any single aspect of the job, but it does have some useful information that I'm not aware of in any other text. It is process and organizationally organized, and does not deal with technology at all.
My favorite chapter is the second one, "Understanding the Business and Management Environment." With a background in social science and significant experience in multi-cultural situations, the author is uniquely qualified to help an information security practitioner operate effectively within what is essentially an alien culture.
A question that I'm frequently asked, and I see often in infosec forums, is "What do I do to get into the security business?" Chapter 4 provides excellent advice on creating a career path, followed by Chapter 5 which contains suggestions on finding a new job. I recommend these chapters to anyone who is looking to break into this field, or who wants to advance their career.
If you have managed to find yourself a leadership role in infosec, and are wondering what you should do next, the chapter on creating security plans should be helpful. The chapter on establishing an infosec program is also helpful, and contains some excellent job descriptions for different infosec positions. This is hardly stimulating reading, but if you are an ISSO, your choice is to find usable boilerplate like this, or make it up yourself.
The author approaches the subject from a single point of view. All of the examples are drawn around a single hypothetical corporation, and it is obvious that the author has a law enforcement orientation. An infocop approach like this is not necessarily successful within every corporate culture, nor does everyone who is responsible for an information security program think of their role in corporate criminal justice terms.
I do think that anyone running an information security program would benefit from this book-or anyone who wants to work towards such a position. If you like org charts and job descriptions, you'll probably feel comfortable with it. For those who are not ISSOs, or those who just looking for an introductory guide to security, this is not the ideal text. For those who are ISSOs, or otherwise responsible for infosec programs, Thomas Wradlow's book, "The Process of Network Security," is a meatier and more sophisticated book that covers much of the same subject matter at a lower price. I recommend that anyone responsible for creating or implementing infosec programs get both books.The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Overview

Want to learn more information about The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...