Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

The New School of Information Security Review

The New School of Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy The New School of Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on The New School of Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The New School of Information Security ReviewWhat a delightful chapter title in Adam Shostack's and Andrew Stewart's new book, The New School of Information Security. They have produced a readable, compact tour of the information security field as it stands today - or perhaps as it lies in its crib. What we know intuitively the authors bring forward thoughtfully in their analysis of the information security industry: it is struggling to keep up with the defects in online communication, data storage, and business processes.
Shostack and Stewart helpfully review the stable of plagues on computing, communication, and remote commerce: spam, phishing, viruses, identity theft, and such. Likewise, they introduce the cast of characters in the security field, all of whom seem to be feeling along in the dark together.
Why are the lights off? Lack of data, they argue. Most information security decisions are taken in the absence of good information. The authors perceptively describe the substitutes for good information, like following trends, clinging to established brands, or chasing after studies produced by or for security vendors.
The authors revel in the breach data that has been made available to them thanks to disclosure laws like California's SB 1386. A purist must quibble with mandated disclosure when common law can drive consumer protection more elegantly. But good data is good data, and the happenstance of its availability in the breach area is welcome.
In the most delightful chapter in the book (I've used it as the title of this review), Shostack and Stewart go through the some of the most interesting problems in information security. Technical problems are what they are. Economics, sociology, psychology, and the like are the disciplines that will actually frame the solutions for information security problems.
In subsequent chapters, Shostack and Stewart examine security spending and advocate for the "New School" approach to security. I would summarize theirs as a call for rigor, which is lacking today. It's ironic that the world of information lacks for data about its own workings, and thus lacks sound decision-making methods, but there you go.
The book is a little heavy on "New School" talk. If the name doesn't stick, Shostack and Stewart risk looking like they failed to start a trend. But it's a trend that must take hold if information security is going to be a sound discipline and industry. I'm better aware for reading The New School of Information Security that info sec is very much in its infancy. The nurturing Shostack and Stewart recommend will help it grow.The New School of Information Security Overview

Want to learn more information about The New School of Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust Review

The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust
Average Reviews:

(More customer reviews)
Are you looking to buy The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust Review"The Visible Employee" presents the results of a four-year research project concerning prevailing workplace security measures and their side effects. On the one hand, deliberate or accidental employee misuse of information systems can cause havoc; on the other, too much monitoring and surveillance of employees can provoke conflict on all levels of hierarchy and cause drag on the efficiency of a business. Chapters present the perspectives of Information Technology professionals, managerial perspectives, employee perspectives, the pros and cons of different approaches to the quandary of balancing security against efficiency, and much more. Numerous appendices from employee interview protocol to a recommended password policy ("never use a dictionary word for a password" or "never send a password using email") and an index round out this valuable guide to businesses trying to successfully compete in a rapidly evolving and interconnected world.
The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust Overview

Want to learn more information about The Visible Employee: Using Workplace Monitoring and Surveillance to Protect Information Assets-Without Compromising Employee Privacy or Trust?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Principles of Information Security Review

Principles of Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy Principles of Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Principles of Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Principles of Information Security ReviewMaybe I'm not the books target audience, misunderstood the class I enrolled in, or went about it bass ackward, but this book is the pits! I studied my behind off (with books here at Amazon), took the security+ exam and passed. I then took what I thought was a intro to information security class at a local college to fill in the gaps of things I discovered while preparing for the security+ exam. I found this book to be very dry and in my opinion, places more weight on "champions in management", systems development life cycle and administrative issues over basics such as what is a IDS/IPS? why you'd rather use a switch than a hub or why you'd rather use AES than DES. Again maybe I'm comparing apples to oranges, but for what I thought I was going to learn, this text book missed the mark and I was very disappointed.Principles of Information Security Overview

Want to learn more information about Principles of Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Metrics and Methods for Security Risk Management Review

Metrics and Methods for Security Risk Management
Average Reviews:

(More customer reviews)
Are you looking to buy Metrics and Methods for Security Risk Management? Here is the right place to find the great deals. we can offer discounts of up to 90% on Metrics and Methods for Security Risk Management. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Metrics and Methods for Security Risk Management ReviewThis is a complete and informative book for a wide range of risk management topics. Most technical books contain at least a bit of useless filler and I didn't find that to be the case here at all -- it is expert, informative, and well written. I keep it by my desk and have found myself referring to it often for fundamental methodologies and metrics of risk analysis.
Keep in mind that the book focuses more on traditional security risk management, as in "likelihood, vulnerability, impact" types of assessment, and less on risk assessment and prediction technology (as can be found in some of the better SIEM tools out there). In fact - there is a lot of focus on physical security and less on cyber security - however the methods hold true. The lack of reference to modern tools, etc. is unfortunate but not a deal breaker for me -- as I said the methods and approaches are what this book is for, and those are presented in scientific detail.Metrics and Methods for Security Risk Management Overview

Want to learn more information about Metrics and Methods for Security Risk Management?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Assessing and Managing Security Risk in IT Systems: A Structured Methodology Review

Assessing and Managing Security Risk in IT Systems: A Structured Methodology
Average Reviews:

(More customer reviews)
Are you looking to buy Assessing and Managing Security Risk in IT Systems: A Structured Methodology? Here is the right place to find the great deals. we can offer discounts of up to 90% on Assessing and Managing Security Risk in IT Systems: A Structured Methodology. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Assessing and Managing Security Risk in IT Systems: A Structured Methodology ReviewThe book essentially describes the McCumber Cube information security methodology.
And the McCumber Cube methodology is indeed interesting and worth the read.
Unfortunately, the author wrote around it a whole book!
In the first part the author describes the bases on the information security and relates it to the McCumber Cube (without really describing what the Cube is! Luckily, the hardcover has a picture of it.)
In the second part he dwelves in a little more detail of the McCumber Cube methodology, repeating again and again the same concepts, just with slight viewpoint variations.
Obviously his methodology is described as superior to any other methodology! While he makes a few good points, often he just states this without really comparing it to the other technologies.
Worth the read if you have time to spare... it indeed has a few interesting ideas and viewpoints.
If only they were expressed in a tenth of the space!
Assessing and Managing Security Risk in IT Systems: A Structured Methodology Overview

Want to learn more information about Assessing and Managing Security Risk in IT Systems: A Structured Methodology?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Securing SCADA Systems Review

Securing SCADA Systems
Average Reviews:

(More customer reviews)
Are you looking to buy Securing SCADA Systems? Here is the right place to find the great deals. we can offer discounts of up to 90% on Securing SCADA Systems. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Securing SCADA Systems ReviewSupervisory Control And Data Acquisition (SCADA) is one of the most important control system architecture in the Infrastructure intensive world post the second world war. Nations and businesses all rely on SCADA systems to manage vast infrastructure from electrical systems (generation, transmission and distribution) to water infrastructure and the energy industry. The central role of SCADA systems which combine modern Information and Communication Systems (ICT) with dated relay systems in the control of infrastructure makes them logical targets in a world of cyber-warfare, cyber-espionage and , with increasing potentials for coordinate cyber terrorism.
As we have come to know, with increasing fervor in recent times, our information system is far from being secure. All modern commercial operating systems from Windows based OSs to Unix based systems (including Apple Mac and all Linux variants) are not immune from concerted bug-searching efforts nor are they immune from exploits by resourceful and single-minded attackers. While computer vendors continue to make giant strides to apply sound coding methods and practices to improve the quality and reduce attack surfaces of their off-the-shelve products, the computer "hackers" continue to wield the upper hand. Unfortunately, telecommunication networks as well as SCADA systems, in an effort to standardize platforms are adopting variants of commercial-off-the shelve operating systems; and even when these systems run on proprietory or special purpose platforms, their value to cyber-criminals and their ilks still make them attractive targets for subversion and attack.
Securing SCADA systems in light of their importance and consequence of exploits is a great necessity. Compromised SCADA systems could lead to unmanageable power outage, energy flow disruption, provide dangerous state secret to competing or enemy states; or in the hands of terrorist could facilitate a massive casualty attack. Since nuclear energy facilities are also fitted with SCADA systems, the impact of a compromised nuclear system SCADA system is yet to be fully comprehended. Also, the growing reliance on full network integration, and cohabitation of various platforms and systems makes the task of securing SCADA systems more onerous but essential. Securing SCADA Systems
The book, Security SCADA Systems by Ronald Krutz and published by provides a reasonably effective first step framework for securing SCADA systems. The book introduces SCADA in accessible term, describing essential components of most SCADA systems (SCADA architectural components including operator, human-machine interface, master terminal unit, communication, remote terminal unit; and the SCADA client-server architecture); basic SCADA definitions and applications; SCADA security issues (as the author sees them) and the role of SCADA systems in what the author determined as critical infrastructure; energy, utility and other control systems.
The just over 200 pages book is organized into eight chapters and three appendices with an index. The first chapter describes the essentials of SCADA systems from 30,000 feet, with a quick review of the origin, evolution and basic SCADA definitions, SCADA architecture and applications, Divergence of SCADA and IT and the relevance of conventional IT Security paradigm in SCADA systems and the essential value of redundancy and criticality of time in SCADA systems. Chapter two discusses SCADA systems in critical infrastructure including in the petroleum industry, nuclear power generation, 'conventional electric power generation, water purification systems, chemical plants and the need for securing the SCADA systems in these industries. Chapter three discusses the evolution of SCADA protocols, addressing the similarities and dissimilarities between the various SCADA protocols including the MODBUS Model, DNP3, UCA 2.0 and Controller Area Network. The chapter also discusses DeviceNet, ControlNet,EtherNet/IP, Profibus and FFB as well as the security implications of these disparate protocols and their ramification for standard TCP/IP based network security including firewall, demilitarized zone and VPN.
In Chapter four, the author discusses SCADA vulnerabilities and attacks surface looking at risk management for SCADA networks and systems, attack routes and deployment of SCADA HoneyNet. The author proceeds to describe his bias of security techniques and methods including intrusion based systems, security awareness programs and audit logs in chapter five and in chapter six describes some common security standards and reference documents in quite broad terms. The author used the last two chapters to bloviate on implementation guidelines and deliver a dire outlook of SCADA security today (2006).
The book is an easy and accessible read and provides a broad look on SCADA security, helping to fill some yawning gap in SCADA security literature, but falls grossly short of its title as it does not provide enough actionable program for securing SCADA systems, which may be far more difficult to do, given the widely disparate nature of SCADA systems, the lack of TCP/IP like all encompassing network architecture or the omnipresence like dominance of a single OS vendor which often make comprehensive programs easier to compile.
However, given the importance of SCADA systems, the book is a useful read, and a good first step.
http://woleakpose.orgSecuring SCADA Systems Overview

Want to learn more information about Securing SCADA Systems?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

A Practical Guide to Security Assessments Review

A Practical Guide to Security Assessments
Average Reviews:

(More customer reviews)
Are you looking to buy A Practical Guide to Security Assessments? Here is the right place to find the great deals. we can offer discounts of up to 90% on A Practical Guide to Security Assessments. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

A Practical Guide to Security Assessments ReviewExcellent. This book is a practical approach to security assessment from planning to the final report. Being in this field for over ten years, this is the first book that truly provides the appropriate level of guidance from not just the security assessment but also from the business standpoint where it looks at involved risks. The appendix is excellent and extremely useful, particularly the questionnaires, which can be modified, based on the type of assessment/client. The book is well structured and very clear, and provides a logical approach to addressing and assessing information security issues. Highly recommended reading.A Practical Guide to Security Assessments Overview

Want to learn more information about A Practical Guide to Security Assessments?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security Metrics Management: How to Manage the Costs of an Assets Protection Program Review

Security Metrics Management: How to Manage the Costs of an Assets Protection Program
Average Reviews:

(More customer reviews)
Are you looking to buy Security Metrics Management: How to Manage the Costs of an Assets Protection Program? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security Metrics Management: How to Manage the Costs of an Assets Protection Program. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security Metrics Management: How to Manage the Costs of an Assets Protection Program ReviewOverall a very good resource.
The book is written in a conversational style with the experience and expertise of the writers, along with evidence of their own personal ups and downs of getting business to buy into security risk management, peppered throughout the content.
A number of extremely valuable methodologies, approaches and tabulation of data to exhibit the true business benefits associated with security risk management and corporate asset protection programs. while the aesthetics of their data may lack at times, the underlying principles and arguments are outstanding.
A recommended addition to any professional resource library and a valuable reference for Chief Security Officers (CSO) around the globe.Security Metrics Management: How to Manage the Costs of an Assets Protection Program Overview

Want to learn more information about Security Metrics Management: How to Manage the Costs of an Assets Protection Program?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Review

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program
Average Reviews:

(More customer reviews)
Are you looking to buy The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program ReviewThis book is the Boy Scout Senior Patrol Leader's handbook for Information Security Officers. " On my honor, I will do my best, to do my duty, to my corporation and profession...."It is a short book-I read it in an evening-that tries to be a complete guide to a very complex profession. Following this merit badge guidebook approach, the entire subject of risk is covered in 3 pages, and CP/DR is covered in just over 2. It just doesn't contain enough text to be the sole reference book for any single aspect of the job, but it does have some useful information that I'm not aware of in any other text. It is process and organizationally organized, and does not deal with technology at all.
My favorite chapter is the second one, "Understanding the Business and Management Environment." With a background in social science and significant experience in multi-cultural situations, the author is uniquely qualified to help an information security practitioner operate effectively within what is essentially an alien culture.
A question that I'm frequently asked, and I see often in infosec forums, is "What do I do to get into the security business?" Chapter 4 provides excellent advice on creating a career path, followed by Chapter 5 which contains suggestions on finding a new job. I recommend these chapters to anyone who is looking to break into this field, or who wants to advance their career.
If you have managed to find yourself a leadership role in infosec, and are wondering what you should do next, the chapter on creating security plans should be helpful. The chapter on establishing an infosec program is also helpful, and contains some excellent job descriptions for different infosec positions. This is hardly stimulating reading, but if you are an ISSO, your choice is to find usable boilerplate like this, or make it up yourself.
The author approaches the subject from a single point of view. All of the examples are drawn around a single hypothetical corporation, and it is obvious that the author has a law enforcement orientation. An infocop approach like this is not necessarily successful within every corporate culture, nor does everyone who is responsible for an information security program think of their role in corporate criminal justice terms.
I do think that anyone running an information security program would benefit from this book-or anyone who wants to work towards such a position. If you like org charts and job descriptions, you'll probably feel comfortable with it. For those who are not ISSOs, or those who just looking for an introductory guide to security, this is not the ideal text. For those who are ISSOs, or otherwise responsible for infosec programs, Thomas Wradlow's book, "The Process of Network Security," is a meatier and more sophisticated book that covers much of the same subject matter at a lower price. I recommend that anyone responsible for creating or implementing infosec programs get both books.The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Overview

Want to learn more information about The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Executive MBA in Information Security Review

The Executive MBA in Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy The Executive MBA in Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Executive MBA in Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Executive MBA in Information Security ReviewIn The Executive MBA in Information Security, author John Trinckes notes that according to Washington, D.C., think tank the Brookings Institution, an organization's information and other intangible data assets account for more than 80 percent of its market value. Such a statistic unequivocally demonstrates the imperative of a strong enterprise information security program.

With that in mind, Trinckes first points out that data security is a management decision, and as such, requires executive leadership to create an effective foundation.

Leadership alone will not get the organization to a state of effective security, however, and that is where the book comes in. The reader will find within this work an overview of all of the core areas in information security. The format and content generally mirror the (ISC)2 Common Body of Knowledge, a basis for (ISC)2's Certified Information Systems Security Professional (CISSP) certification.

While nothing in the book is ground-breaking, its value lies in the integration of this information into a single volume for the person who does not have a strong background in information security and risk management.

While not the definitive text on the subject, The Executive MBA in Information Security provides a good start for any executive or professional looking to get a thorough understanding of the fundamentals of information security.
The Executive MBA in Information Security Overview

Want to learn more information about The Executive MBA in Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security) Review

Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security)
Average Reviews:

(More customer reviews)
Are you looking to buy Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security) ReviewIf Shakespeare were to write an information security tragedy, it would not be titled Hamlet, rather Bayuk. The story of Jennifer Bayuk is tragic in that she spent a decade as CISO at Bear, Stearns, building up its security group to be one of the best in the business; only to find it vaporized when the firm collapsed and was acquired by J.P. Morgan Clearing Corp. After all that toil and sweat, Bayuk was out of a job. (Full disclosure: Bayuk and I have given a presentation together in the past, and I did get a copy of this book for free.)
While the information security engineering group that was at Bear, Stearns is no more, Bayuk has taken her vast expertise and put it in a great new book: Enterprise Security for the Executive: Setting the Tone from the Top. While many other books equate security with technology, and are written for technologists; Bayuk writes that information security is all about management control. And to the extent which a CxO controls assets, is the extent to which others can't use them in unexpected ways.
The book is written to help CxO's and business executives become familiar with information security concepts and techniques to make sure they are able to manage and support the efforts of their security team. This is an issue, as a big problem for the poor state of information security is that CxO's are far too often disconnected from their information security groups. No story is more manifest than that of when Heartland Payment Systems CEO Robert Carr blamed his PCI auditors for his firm's security problems. Carr is a perfect example of the type of person that needs to read this book. As an aside, for an excellent reply to Carr's kvetching, read what Rich Mogull wrote in An Open Letter to Robert Carr, CEO of Heartland Payment Systems.
While many CxO's think that security is about firewalls and other cool security products, it is truly a top-down management approach, and not a technology one. The book notes that the only way for information security to succeed in an organization is when management understands what their role is.
What is unique about the book is that Bayuk uses what she calls SHS (security horror stories). Rather than typical FUD stories, the horror stories detail systematic security problems and how they could have been obviated. By seeing how these companies have done it wrong, it makes it easier for pragmatic organizations to accomplish effective security by setting a strong tone from the top down.
Bayuk details the overall problem in the introduction and notes that many CxO's have wrongly spent significant amounts of money on security to avert security incidents; but have done that without any context of a greater information security methodology. The leads to executives thinking that security as nothing more than one long spending pattern.
Chapter 1 - Tone at The Top, notes that tone exists at the top, whether it is set or not. The tone is reflected in how an organization thinks about the things it really cares about. Employees can tell how a CxO cares about security by their level of personal involvement. Not that a CxO needs to be, or should be involved with minutia of firewall configuration or system administration; the key is rather that they are for example, championing the effective and consistent use of firewalls and how systems are securely administered.
In chapter 5 - Security through Matrix Management - Bayuk does a good job of detailing the various places that the security group can be placed in an organization. The chapter notes that there are as many ways to organize security as there are organization structures. Bayuk writes for example that if CxO's in a given organization are a tight-knit group, accustomed to close coordination, then it should not matter to which CxO the person managing information security reports to. If that is not the case, there may be multiple security programs that end up far too below the required C-levels that are needed for effective security. The chapter provides a number of different organizational scenarios, with requisite roles and responsibilities.
Chapter 5 closes with an important observation that a CxO should task the human resources department to put a line in all performance reviews whereby managers attest (or not) that the person being reviewed follows security policy. A CxO should fire people who willfully avoid compliance with security policy. Whatever tone at the top exists should be employed to make sure that everyone knows that the CxO is serious about the corporate security program. Such a tone clearly demonstrates an organization that is resolute about information security.
One thing that Bayuk does very well repeatedly throughout the book is to succinctly identify an issue and its cause. In chapter 6 - Navigating the Regulatory Landscape - she writes that if a CxO does not have management control over an organization, then the organization will fail the audit. It will fail because even if the organization is secure today, there is no assurance that it will be going forward. In addition, control means that the CxO will ensure that the organization is attempting to do the right thing. And in such cases, passing an audit is much easier.
Overall, Enterprise Security for the Executive is a fantastic book. It provides a no-nonsense approach to attaining effective information security. For those executives that are serious about security, the book will be their guiding light down the dark information security tunnel. In its 8 chapters (and a case study), the book focuses on a straightforward and plain-speaking approach to enable CxO's to get a handle on information security. As such, it is hoped that Enterprise Security for the Executive will soon find its way onto every executive's required reading list.Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security) Overview

Want to learn more information about Enterprise Security for the Executive: Setting the Tone from the Top (PSI Business Security)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...