Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

Network Security Evaluation Using the NSA IEM Review

Network Security Evaluation Using the NSA IEM
Average Reviews:

(More customer reviews)
Are you looking to buy Network Security Evaluation Using the NSA IEM? Here is the right place to find the great deals. we can offer discounts of up to 90% on Network Security Evaluation Using the NSA IEM. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Network Security Evaluation Using the NSA IEM ReviewI am a security consultant in the DC area, so I have heard the NSA IAM and IEM terms bandied about the Beltway. I read Network Security Evaluation Using the NSA IEM (NSE) to get a better understanding of the IEM side of the equation. I found the business process coverage of this book helpful, along with the general understanding of the goals of the IAM and IEM. For these two reasons you may find NSE helpful too.
The Prologue, ch 1, ch 2, and Part I (which oddly begins with ch 3 and ends with ch 6) occupies about 40% of the book. None of the material is technical, but it helps the reader understand why the NSA IAM and IEM exist, how the methodologies help clients, and what you as a security consultant owe clients when providing an IEM-centric service. These business issues, which largely sit outside the NSA's purview, are very helpful for those of us trying to provide good services to clients. I found contracting advice in ch 2 to be especially useful. Warnings about scope creep, salespeople over-promising, and setting expectations all rang true. I also liked the legal section (ch 5), but I wished it had avoided trotting out the tiresome links to "cyber terror"; cut pages 100-103 in the second edition! I did learn a critical legal lesson, however: consultants should avoid even the pretense of interpreting laws like SOX or HIPPA when advising clients. This could be misconstrued as "practicing law," which is illegal without a license!
Part II discusses "on-site" evaluation issues, which for ch 8-10 means discussing tools to accomplish the ten IEM baseline activities. These tool sections were fairly generic, and anyone with decent security experience will not learn anything new. One exception for me was Ophcrack, a recent password cracker. Ch 9 boasted of getting Unix-centric Nessus to run on Windows using Cygwin, but disappointed by providing no further details. Ch 10 mentions network protocol analysis as the tenth IEM baseline activity, but has nothing helpful to say besides mentioning running Ethereal or EtherPeek. If the purpose of protocol analysis is discovering insecure protocols or cleartext passwords, avoid Ethereal -- run a password grabber like dsniff or similar.
Part III addresses tasks done in the post-evaluation phase, like report-writing and delivery. Some of the material is superfluous and preachy, e.g. p 316 "Knowledge is individualistic. It is inherent to individuals and is acquired through the natural process of experience and learning." Ch 14 finally displays the 17 IAM (not IEM) categories, which had been alluded to in previous chapters but never explained (which would have been helpful for those unaware of the IAM). The sample Technical Evaluation Plan in Appendix B is a good way to provide concrete examples for IEM beginners.
I would like to see a second edition of NSE after an editor reads the entire book, as I just did. That editor should strive to remove as much extra and redundant information as possible. For example, there are sections repeated nearly word-for-word in ch 2 (p 40-43) and ch 4 (p 74-78). The risk triangle appears on p 246 and 383. CVE is introduced in ch 7 and again in ch 13. Calculating ROI is presented in ch 3 and again in the same words in ch 14. These duplications are the result of ten people contributing to a 400 page book.
Overall, I still recommend reading NSE. I return to the first 170 pages of the book for its best advice, such as entire chapter on scoping an engagement (ch 4). There are far too few security books that explain how to deliver a valuable service to a client. NSE addresses that issue in great detail, and for that reason I commend the authors.Network Security Evaluation Using the NSA IEM Overview

Want to learn more information about Network Security Evaluation Using the NSA IEM?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure Review

Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure
Average Reviews:

(More customer reviews)
Are you looking to buy Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure? Here is the right place to find the great deals. we can offer discounts of up to 90% on Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure Reviewi got this because it was fairly recent, but not as useful as the the other SCADA protection books out there (which are cheaper). It is broad in scope as it covers assessments, physical security, but barely touches on the mechanics of the types of cyberattacks that SCADA systems are vulnerable to. I found even the "Securing SCADA Systems" by Krutz more helpful, as it was basic but clearly written. I also found the Botnet detection books and malware forensics helpful to cover this book's cyber threat gap. Clearly, a collection of experts in the field, but more substance and editing and less war stories would have created a better product.Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure Overview

Want to learn more information about Techno Security's Guide to Securing SCADA: A Comprehensive Handbook On Protecting The Critical Infrastructure?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Guide to Firewalls and VPNs Review

Guide to Firewalls and VPNs
Average Reviews:

(More customer reviews)
Are you looking to buy Guide to Firewalls and VPNs? Here is the right place to find the great deals. we can offer discounts of up to 90% on Guide to Firewalls and VPNs. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Guide to Firewalls and VPNs ReviewI'm forced to learn from this book due to a networking class. I thought it would be a fun class learning about different hacker attacks. I was disappointed with what he gave us to read so far. First the book gives you asinine information about what forces of nature are a threat to networks. I would understand if they listed them, but no they explained what the event was, wasting a page in a half with common knowledge, such as "Flood-An overflowing of water onto land that is normally dry" & "Lighting-An, abrupt, discontinuous natural electric discharge in the atmosphere". The worst though, is the questions at the end in which we are tested on. They hark on odd definitions that many in an online community have assigned to other meanings. One of these cases is when they ask about the differences between vulnerability and a exploit, and a the difference between vulnerability and exposure.
Now, I'm new to the subject so to others it may make sense, but to me they did a poor job of explaining definitions. On the bright side they give corny names to people in their examples like "Harriet Allthumbs" an employee who accidentally deleted the one copy of a critical report. I hope the book gets better as time goes on, but man for a hundred bucks you should look around if you have a choice.
Guide to Firewalls and VPNs Overview

Want to learn more information about Guide to Firewalls and VPNs?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Principles of Information Security Review

Principles of Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy Principles of Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Principles of Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Principles of Information Security ReviewMaybe I'm not the books target audience, misunderstood the class I enrolled in, or went about it bass ackward, but this book is the pits! I studied my behind off (with books here at Amazon), took the security+ exam and passed. I then took what I thought was a intro to information security class at a local college to fill in the gaps of things I discovered while preparing for the security+ exam. I found this book to be very dry and in my opinion, places more weight on "champions in management", systems development life cycle and administrative issues over basics such as what is a IDS/IPS? why you'd rather use a switch than a hub or why you'd rather use AES than DES. Again maybe I'm comparing apples to oranges, but for what I thought I was going to learn, this text book missed the mark and I was very disappointed.Principles of Information Security Overview

Want to learn more information about Principles of Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Metrics and Methods for Security Risk Management Review

Metrics and Methods for Security Risk Management
Average Reviews:

(More customer reviews)
Are you looking to buy Metrics and Methods for Security Risk Management? Here is the right place to find the great deals. we can offer discounts of up to 90% on Metrics and Methods for Security Risk Management. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Metrics and Methods for Security Risk Management ReviewThis is a complete and informative book for a wide range of risk management topics. Most technical books contain at least a bit of useless filler and I didn't find that to be the case here at all -- it is expert, informative, and well written. I keep it by my desk and have found myself referring to it often for fundamental methodologies and metrics of risk analysis.
Keep in mind that the book focuses more on traditional security risk management, as in "likelihood, vulnerability, impact" types of assessment, and less on risk assessment and prediction technology (as can be found in some of the better SIEM tools out there). In fact - there is a lot of focus on physical security and less on cyber security - however the methods hold true. The lack of reference to modern tools, etc. is unfortunate but not a deal breaker for me -- as I said the methods and approaches are what this book is for, and those are presented in scientific detail.Metrics and Methods for Security Risk Management Overview

Want to learn more information about Metrics and Methods for Security Risk Management?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Review

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program
Average Reviews:

(More customer reviews)
Are you looking to buy The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program ReviewThis book is the Boy Scout Senior Patrol Leader's handbook for Information Security Officers. " On my honor, I will do my best, to do my duty, to my corporation and profession...."It is a short book-I read it in an evening-that tries to be a complete guide to a very complex profession. Following this merit badge guidebook approach, the entire subject of risk is covered in 3 pages, and CP/DR is covered in just over 2. It just doesn't contain enough text to be the sole reference book for any single aspect of the job, but it does have some useful information that I'm not aware of in any other text. It is process and organizationally organized, and does not deal with technology at all.
My favorite chapter is the second one, "Understanding the Business and Management Environment." With a background in social science and significant experience in multi-cultural situations, the author is uniquely qualified to help an information security practitioner operate effectively within what is essentially an alien culture.
A question that I'm frequently asked, and I see often in infosec forums, is "What do I do to get into the security business?" Chapter 4 provides excellent advice on creating a career path, followed by Chapter 5 which contains suggestions on finding a new job. I recommend these chapters to anyone who is looking to break into this field, or who wants to advance their career.
If you have managed to find yourself a leadership role in infosec, and are wondering what you should do next, the chapter on creating security plans should be helpful. The chapter on establishing an infosec program is also helpful, and contains some excellent job descriptions for different infosec positions. This is hardly stimulating reading, but if you are an ISSO, your choice is to find usable boilerplate like this, or make it up yourself.
The author approaches the subject from a single point of view. All of the examples are drawn around a single hypothetical corporation, and it is obvious that the author has a law enforcement orientation. An infocop approach like this is not necessarily successful within every corporate culture, nor does everyone who is responsible for an information security program think of their role in corporate criminal justice terms.
I do think that anyone running an information security program would benefit from this book-or anyone who wants to work towards such a position. If you like org charts and job descriptions, you'll probably feel comfortable with it. For those who are not ISSOs, or those who just looking for an introductory guide to security, this is not the ideal text. For those who are ISSOs, or otherwise responsible for infosec programs, Thomas Wradlow's book, "The Process of Network Security," is a meatier and more sophisticated book that covers much of the same subject matter at a lower price. I recommend that anyone responsible for creating or implementing infosec programs get both books.The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program Overview

Want to learn more information about The Information Systems Security Officer's Guide, Second Edition: Establishing and Managing an Information Protection Program?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...