Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

The New School of Information Security Review

The New School of Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy The New School of Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on The New School of Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The New School of Information Security ReviewWhat a delightful chapter title in Adam Shostack's and Andrew Stewart's new book, The New School of Information Security. They have produced a readable, compact tour of the information security field as it stands today - or perhaps as it lies in its crib. What we know intuitively the authors bring forward thoughtfully in their analysis of the information security industry: it is struggling to keep up with the defects in online communication, data storage, and business processes.
Shostack and Stewart helpfully review the stable of plagues on computing, communication, and remote commerce: spam, phishing, viruses, identity theft, and such. Likewise, they introduce the cast of characters in the security field, all of whom seem to be feeling along in the dark together.
Why are the lights off? Lack of data, they argue. Most information security decisions are taken in the absence of good information. The authors perceptively describe the substitutes for good information, like following trends, clinging to established brands, or chasing after studies produced by or for security vendors.
The authors revel in the breach data that has been made available to them thanks to disclosure laws like California's SB 1386. A purist must quibble with mandated disclosure when common law can drive consumer protection more elegantly. But good data is good data, and the happenstance of its availability in the breach area is welcome.
In the most delightful chapter in the book (I've used it as the title of this review), Shostack and Stewart go through the some of the most interesting problems in information security. Technical problems are what they are. Economics, sociology, psychology, and the like are the disciplines that will actually frame the solutions for information security problems.
In subsequent chapters, Shostack and Stewart examine security spending and advocate for the "New School" approach to security. I would summarize theirs as a call for rigor, which is lacking today. It's ironic that the world of information lacks for data about its own workings, and thus lacks sound decision-making methods, but there you go.
The book is a little heavy on "New School" talk. If the name doesn't stick, Shostack and Stewart risk looking like they failed to start a trend. But it's a trend that must take hold if information security is going to be a sound discipline and industry. I'm better aware for reading The New School of Information Security that info sec is very much in its infancy. The nurturing Shostack and Stewart recommend will help it grow.The New School of Information Security Overview

Want to learn more information about The New School of Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Guide to Firewalls and VPNs Review

Guide to Firewalls and VPNs
Average Reviews:

(More customer reviews)
Are you looking to buy Guide to Firewalls and VPNs? Here is the right place to find the great deals. we can offer discounts of up to 90% on Guide to Firewalls and VPNs. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Guide to Firewalls and VPNs ReviewI'm forced to learn from this book due to a networking class. I thought it would be a fun class learning about different hacker attacks. I was disappointed with what he gave us to read so far. First the book gives you asinine information about what forces of nature are a threat to networks. I would understand if they listed them, but no they explained what the event was, wasting a page in a half with common knowledge, such as "Flood-An overflowing of water onto land that is normally dry" & "Lighting-An, abrupt, discontinuous natural electric discharge in the atmosphere". The worst though, is the questions at the end in which we are tested on. They hark on odd definitions that many in an online community have assigned to other meanings. One of these cases is when they ask about the differences between vulnerability and a exploit, and a the difference between vulnerability and exposure.
Now, I'm new to the subject so to others it may make sense, but to me they did a poor job of explaining definitions. On the bright side they give corny names to people in their examples like "Harriet Allthumbs" an employee who accidentally deleted the one copy of a critical report. I hope the book gets better as time goes on, but man for a hundred bucks you should look around if you have a choice.
Guide to Firewalls and VPNs Overview

Want to learn more information about Guide to Firewalls and VPNs?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Principles of Information Security Review

Principles of Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy Principles of Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Principles of Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Principles of Information Security ReviewMaybe I'm not the books target audience, misunderstood the class I enrolled in, or went about it bass ackward, but this book is the pits! I studied my behind off (with books here at Amazon), took the security+ exam and passed. I then took what I thought was a intro to information security class at a local college to fill in the gaps of things I discovered while preparing for the security+ exam. I found this book to be very dry and in my opinion, places more weight on "champions in management", systems development life cycle and administrative issues over basics such as what is a IDS/IPS? why you'd rather use a switch than a hub or why you'd rather use AES than DES. Again maybe I'm comparing apples to oranges, but for what I thought I was going to learn, this text book missed the mark and I was very disappointed.Principles of Information Security Overview

Want to learn more information about Principles of Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Review

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program
Average Reviews:

(More customer reviews)
Are you looking to buy The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program ReviewThis book is the Boy Scout Senior Patrol Leader's handbook for Information Security Officers. " On my honor, I will do my best, to do my duty, to my corporation and profession...."It is a short book-I read it in an evening-that tries to be a complete guide to a very complex profession. Following this merit badge guidebook approach, the entire subject of risk is covered in 3 pages, and CP/DR is covered in just over 2. It just doesn't contain enough text to be the sole reference book for any single aspect of the job, but it does have some useful information that I'm not aware of in any other text. It is process and organizationally organized, and does not deal with technology at all.
My favorite chapter is the second one, "Understanding the Business and Management Environment." With a background in social science and significant experience in multi-cultural situations, the author is uniquely qualified to help an information security practitioner operate effectively within what is essentially an alien culture.
A question that I'm frequently asked, and I see often in infosec forums, is "What do I do to get into the security business?" Chapter 4 provides excellent advice on creating a career path, followed by Chapter 5 which contains suggestions on finding a new job. I recommend these chapters to anyone who is looking to break into this field, or who wants to advance their career.
If you have managed to find yourself a leadership role in infosec, and are wondering what you should do next, the chapter on creating security plans should be helpful. The chapter on establishing an infosec program is also helpful, and contains some excellent job descriptions for different infosec positions. This is hardly stimulating reading, but if you are an ISSO, your choice is to find usable boilerplate like this, or make it up yourself.
The author approaches the subject from a single point of view. All of the examples are drawn around a single hypothetical corporation, and it is obvious that the author has a law enforcement orientation. An infocop approach like this is not necessarily successful within every corporate culture, nor does everyone who is responsible for an information security program think of their role in corporate criminal justice terms.
I do think that anyone running an information security program would benefit from this book-or anyone who wants to work towards such a position. If you like org charts and job descriptions, you'll probably feel comfortable with it. For those who are not ISSOs, or those who just looking for an introductory guide to security, this is not the ideal text. For those who are ISSOs, or otherwise responsible for infosec programs, Thomas Wradlow's book, "The Process of Network Security," is a meatier and more sophisticated book that covers much of the same subject matter at a lower price. I recommend that anyone responsible for creating or implementing infosec programs get both books.The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Overview

Want to learn more information about The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...