Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice Review

The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice
Average Reviews:

(More customer reviews)
Are you a beginning security professional; as well as, a network and system administrator? If you are, then this book is for you! Author Jason Andress, has done an outstanding job of writing a book that can be used to develop a better understanding of how to protect information assets and defend against attacks; as well as, how to apply these concepts practically.
Andress, begins by covering some of the most basic concepts of information security. In addition, the author covers the security principles of identification and authentication. He then discusses the use of authorization and access control. The author then, discusses the use of auditing and accountability. He continues by discussing the use of cryptography. In addition, the author covers operational security. He then discusses physical security.
The author then shows you how to protect networks from a variety of different angles. Then, he explores hardening as one of the primary tools for securing the operating system and the steps that might be taken to do so. Finally, he shows you different ways in which to secure applications.
This most excellent book, provides the reader with a basic knowledge of information security in both theoretical and practical aspects. Perhaps more importantly, the concepts discussed in this book can be used to drive security projects and policies, in order to mitigate some of the issues discussed.

Click Here to see more reviews about: The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice



Buy NowGet 40% OFF

Click here for more information about The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice

Read More...

The CISSP and CAP Prep Guide: Platinum Edition Review

The CISSP and CAP Prep Guide: Platinum Edition
Average Reviews:

(More customer reviews)
I have just passed my CISSP exam, taken on Aug 2008. This guide was my sole reference book that I used and I also DID NOT attend the review seminar for CISSP. Having said that, I would not recommend it as your only source of CISSP reading material as it slightly outdated by now, as compared to some of the questions that I have encountered on the exam.
The quizzes listed on the book are also way too easy and nowhere near the trickery shown on the actual exam questions. For giggles and laughter, I actually visited the bookshop to review the 'Official ISC2 Guide to CISSP CBK' a couple days after taking the exam, and found out that the quiz questions listed in the book are worded similarly to the exam. I did not read through the chapters for that guide, so I could not make a sound comparison between the 2 books.
However, I could safely say that you should not just rely on one book and read the usual suspects of 'The All-In-One..', 'The Official Guide to CISSP CBK' and this book in your CISSP exam preparations.
Good luck!

Click Here to see more reviews about: The CISSP and CAP Prep Guide: Platinum Edition

This follow-on edition to The CISSP Prep Guide: Mastering CISSP and ISSEP offers value-add coverage not featured anywhere else! You'll prepare for passing CISSP with a revised review of each of the ten CISSP domains, updated to reflect current thinking/technology, especially in the areas of cyber-terrorism prevention and disaster recovery. You'll also cover CAP, a major section of the ISSEP that has been elevated from its status as part of an advanced concentration to its own certification. The accompanying CD-ROM contains revised test questions to make your preparation complete. Order your copy today and make your exam preparation complete!

Buy NowGet 45% OFF

Click here for more information about The CISSP and CAP Prep Guide: Platinum Edition

Read More...

Network Security for Dummies Review

Network Security for Dummies
Average Reviews:

(More customer reviews)
I bought this Network Security for Dummies after spending two frustrating hours in a large bookstore looking at one security text after another and finding that they were all written for people who already know a lot about networks. I suppose the assumption is that you won't get into network security until you have experience running a network, but the small company where I work only just set up a network and we need security right away. We can't afford to pay someone to run the network or be in charge of security. To my relief, the author of Network Security for Dummies understands this. It is obvious that she is just as knowledgeable about protecting networks as the authors of the other books I looked at (I was pretty amazed at what I found when I searched the web for the NRO, which the cover says is where she used to work). But she has taken the time to explain things to those of us who don't live and breathe computers. And she does so without talking down to you. At work we have already used some of the techniques she suggests and I feel confident we can make our network a lot more secure than it was, without spending a lot of money, but with the added advantage of really understanding what we are doing.

Click Here to see more reviews about: Network Security for Dummies

CNN is reporting that a vicious new virus is wreaking havoc on the world's computer networks. Somebody's hacked one of your favorite Web sites and stolen thousands of credit card numbers. The FBI just released a new report on computer crime that's got you shaking in your boots. The experts will tell you that keeping your network safe from the cyber-wolves howling after your assets is complicated, expensive, and best left to them. But the truth is, anybody with a working knowledge of networks and computers can do just about everything necessary to defend their network against most security threats.
Network Security For Dummies arms you with quick, easy, low-cost solutions to all your network security concerns. Whether your network consists of one computer with a high-speed Internet connection or hundreds of workstations distributed across dozens of locations, you'll find what you need to confidently:
Identify your network's security weaknesses
Install an intrusion detection system
Use simple, economical techniques to secure your data
Defend against viruses
Keep hackers at bay
Plug security holes in individual applications
Build a secure network from scratch

Leading national expert Chey Cobb fills you in on the basics of data security, and he explains more complex options you can use to keep your network safe as your grow your business. Among other things, you'll explore:
Developing risk assessments and security plans
Choosing controls without breaking the bank
Anti-virus software, firewalls, intrusion detection systems and access controls
Addressing Unix, Windows and Mac security issues
Patching holes in email, databases, Windows Media Player, NetMeeting, AOL Instant Messenger, and other individual applications
Securing a wireless network
E-Commerce security
Incident response and disaster recovery

Whether you run a storefront tax preparing business or you're the network administrator at a multinational accounting giant, your computer assets are your business. Let Network Security For Dummies provide you with proven strategies and techniques for keeping your precious assets safe.

Buy NowGet 7% OFF

Click here for more information about Network Security for Dummies

Read More...

Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security) Review

Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security)
Average Reviews:

(More customer reviews)
Wow! This is the most comprehensive book on information security out there! I keep it handy in my office at all times and have bought copies for all my employees, who refer to it on a near-daily basis. This really is a must-have for anyone in the industry to keep on top of the latest state-of-play for infosec. 5 stars!!

Click Here to see more reviews about: Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security)


This book presents information on how to analyze risks to your networks and the steps needed to select and deploy the appropriate countermeasures to reduce your exposure to physical and network threats. It also imparts the skills and knowledge needed to identify and counter some fundamental security risks and requirements, inlcuding Internet security threats and measures (audit trails IP sniffing/spoofing etc.) and how to implement security policies and procedures.

In addition, this book also covers security and network design with respect to particular vulnerabilities and threats. It also covers risk assessment and mitigation and auditing and testing of security systems.

From this book, the reader will also learn about applying the standards and technologies required to build secure VPNs, configure client software and server operating systems, IPsec-enabled routers, firewalls and SSL clients.

Chapter coverage includes identifying vulnerabilities and implementing appropriate countermeasures to prevent and mitigate threats to mission-critical processes. Techniques are explored for creating a business continuity plan (BCP) and the methodology for building an infrastructure that supports its effective implementation.

A public key infrastructure (PKI) is an increasingly critical component for ensuring confidentiality, integrity and authentication in an enterprise. This comprehensive book will provide essential knowledge and skills needed to select, design and deploy a PKI to secure existing and future applications.

This book will include discussion of vulnerability scanners to detect security weaknesses and prevention techniques, as well as allowing access to key services while maintaining systems security.

Chapters contributed by leaders in the field cover theory and practice of computer security technology, allowing the reader to develop a new level of technical expertise.
This book's comprehensive and up-to-date coverage of security issues facilitates learning and allows the reader to remain current and fully informed from multiple viewpoints.
Presents methods of analysis and problem-solving techniques, enhancing the readers grasp of the material and ability to implement practical solutions.


Buy NowGet 24% OFF

Click here for more information about Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security)

Read More...

CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50 Review

CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50
Average Reviews:

(More customer reviews)
This book is great. Why? Well it's not just because its a great study guide for the CEH exam (Certified Ethical Hacker), but also for the amount of info crammed into a small book. If you're wanting to learn the basics of ethical hacking, then this is the book. Its a quick read, packed full of interesting workable senarios.
What this book is:
1. A great book for your junior security people.
2. Very easy to work through the chapters as labs.
3. Lots of references to cool programs you can find and download.
What this book isn't:
1. Your not going to learn any code.
2. If you're already a better than average hacker this book is not for you.
3. You won't get CEH certified with this book as a stand alone.
4. You do need a basic understanding of networking, security and systems. (This book isnt hacking for dummies).

Click Here to see more reviews about: CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50



Buy NowGet 37% OFF

Click here for more information about CEH: Official Certified Ethical Hacker Review Guide: Exam 312-50

Read More...

Network Security Bible Review

Network Security Bible
Average Reviews:

(More customer reviews)
This is a great book; it goes in great detail about security in all aspects of the computer industry. However it lacks one critical aspect, how do I do that? Like all network and computer professionals, I do not know everything, so when you tell me I should do something a certain way I'd hope that you will also tell me how to do it. With this book I found myself saying, maybe they will tell me what to do later, over and over, never happens. If you want to buy a book that's a reference manual, this is the one to get. If you are looking for a "how to" as well as a "what to look for" book, consider looking elsewhere.

Click Here to see more reviews about: Network Security Bible



Buy NowGet 39% OFF

Click here for more information about Network Security Bible

Read More...

CISA Certified Information Systems Auditor Study Guide Review

CISA Certified Information Systems Auditor Study Guide
Average Reviews:

(More customer reviews)
First, this should not be your only reference. There: got that out of the way.
I recommend this book along with the official questions and answers book and the official questions and answers supplement.
This book does a very good job of covering every topic with which you need to be very familiar in order to pass the test. It covers the practice areas as updated for 2006, which haven't changed for 2007. However, the questions in this book are terrible and do not represent the questions you will be asked on the actual test. Also, there are many editing errors in this book so be on the lookout.
The official questions and answers book and its supplement are essential. The test questions are often misleadingly (or just poorly) worded and correctly answering the multiple choice questions often comes down to almost arbitrarily deciding which one is "most" correct. You will have a hard time on the exam if you haven't subjected yourself to this abuse before hand.
I do not recommend the official study guide. The official study guide is so terrible on so many levels I wished I could throw it at an ISACA official after wasting my time and money on it. The writing is terrible: redundant, dry, and often times of questionable use and technical accuracy. The book itself has terrible typography and pedagogy that make it painful to read. The softcover, oversized dimensions, and spiral binding make it very annoying to carry or store anywhere other than on a flat desktop since it flops around. That it was so obviously cheaply produced and yet costs more than $100 is insulting.
So, in summary: This book is worth your money despite its flaws and will help you pass the CISA exam. Make sure you also buy the official questions and answers book and its supplement. Avoid the official study guide.

Click Here to see more reviews about: CISA Certified Information Systems Auditor Study Guide

The industry-leading study guide for the CISA exam, fully updated
More than 27,000 IT professionals take the Certified Information Systems Auditor exam each year. SC Magazine lists the CISA as the top certification for security professionals. Compliances, regulations, and best practices for IS auditing are updated twice a year, and this is the most up-to-date book available to prepare aspiring CISAs for the next exam.
CISAs are among the five highest-paid IT security professionals; more than 27,000 take the exam each year and the numbers are growing
Standards are updated twice a year, and this book offers the most up-to-date coverage as well as the proven Sybex approach that breaks down the content, tasks, and knowledge areas of the exam to cover every detail
Covers the IS audit process, IT governance, systems and infrastructure lifecycle management, IT service delivery and support, protecting information assets, disaster recovery, and more

Anyone seeking Certified Information Systems Auditor status will be fully prepared for the exam with the detailed information and approach found in this book.

Buy NowGet 37% OFF

Click here for more information about CISA Certified Information Systems Auditor Study Guide

Read More...

CISSP Guide to Security Essentials Review

CISSP Guide to Security Essentials
Average Reviews:

(More customer reviews)
Peter Gregory is a prolific author and well-known computer security professional who is also very active in the information security community. Peter wrote this book to address the current situation in information security, which is stated in the Introduction, as "There aren't enough good security professionals to go around". Information security is a broad field with many sub disciplines. Many professionals feel they should know more about security, but don't know where to start. Peter's book is an attempt to change that situation by providing the foundational materials that every security professional needs to know before undertaking advanced or specialized study. The book is suitable for self-study or as a classroom text. Each chapter has a summary, a glossary of key terms, review questions, hands-on projects, and ideas for case projects. For those interested in obtaining the CISSP, they will find this book a good place to start. The strength of this book lies in its organization and clarity. The book's ten chapters map to the ten CISSP Common Body of Knowledge Domains. Each chapter is broken into many subheadings, with an outline-style organization that clarifies each distinct topic. Acronyms are defined in the text and in the glossaries, which are presented in each chapter and at the end of the book. There are two appendices. One appendix provides summary outlines of the ten domains of CISSP security; the other reproduces the code of ethics of CISSP professionals. The Introduction reviews the steps needed to obtain CISSP certification and, together with the code of ethics, gives a good sense of the knowledge, behavior, and attitude necessary to succeed as a security professional. A CD-ROM containing practice questions for the CISSP exam is included. No single book can provide all you need to know to be a CISSP, but this is a good place to start.

Click Here to see more reviews about: CISSP Guide to Security Essentials

CISSP GUIDE TO SECURITY ESSENTIALS CISSP Guide to Security Essentials provides readers with the tools and resources they need to develop a thorough understanding of the entire CISSP Certification Body of Knowledge. Using a variety of pedagogical features including study questions, case projects, and exercises, this book clearly and pointedly explains security basics. Coverage begins with an overview of information and business security today, security laws, and then progresses through the ten CISSP domains, including topics such as access control, cryptography and security architecture and design. With the demand for security professionals at an all-time high, whether you are a security professional in need of a reference, an IT professional with your sights on the CISSP certification, on a course instructor, CISSP GUIDE TO SECURITY ESSENTIALS CISSP Guide to Security Essentials has arrived just in time.

Buy NowGet 47% OFF

Click here for more information about CISSP Guide to Security Essentials

Read More...

Network Warrior Review

Network Warrior
Average Reviews:

(More customer reviews)
Upshot: And you may find yourself...in a machine room or data center. You will need this book. Pros: If you just passed your CCNA exam, or have started working with enterprise level Cisco kit, there's a lot here for you. Cons: If you DON'T work with Cisco kit, why are you here?
For anyone not acquainted with data-centers & network operations, this book shows you how the other hardware half lives. When the author says `you should have passed the CCNA' he's very serious. There are NO EXPLANATIONS of basic Cisco terms. If you are not versed in TCP/IP and SOME Cisco kit, you will be spending a LOT of time in Google. And probably asking yourself why you bought this book.
Those cautions aside, there are gems of `best practices' for non Cisco or smaller network techs here: Amid the Cisco jargon you will find practical advice even for your small business or SOHO LAN, like in Ch. 27 `Basic Firewall Theory', or Chapter 29 on different flavors of 802.11x WiFi and how to secure it. The author even introduces IPv6, with one of the most straightforward explanations I've read yet.
But what really makes this book worth it are the backstories & practical advice from a veteran to new engineers on how to handle failure scenarios as well as the politics involved in maintaining large networks.
In fact, everything from Chapter 39 (`Failure'), Chapter 40 (`GAD's Maxims') to Chapter 41 (`Avoiding Frustration') would be welcome in any IT, infosec or dev reference.
In short, I would somewhat recommend this book for non-CCNA folks interested in Network Engineering or Infrastructure. But I would highly recommend Network Warrior for the audience for which it was intended.
Disclosure: I received the eBook download from O'Reilly for review purposes. I'm not a CCNA but have been around.

Click Here to see more reviews about: Network Warrior


Pick up where certification exams leave off. With this practical, in-depth guide to the entire network infrastructure, you'll learn how to deal with real Cisco networks, rather than the hypothetical situations presented on exams like the CCNA. Network Warrior takes you step by step through the world of routers, switches, firewalls, and other technologies based on the author's extensive field experience. You'll find new content for MPLS, IPv6, VoIP, and wireless in this completely revised second edition, along with examples of Cisco Nexus 5000 and 7000 switches throughout.

Topics include:

An in-depth view of routers and routing
Switching, using Cisco Catalyst and Nexus switches as examples
SOHO VoIP and SOHO wireless access point design and configuration
Introduction to IPv6 with configuration examples
Telecom technologies in the data-networking world, including T1, DS3, frame relay, and MPLS
Security, firewall theory, and configuration, as well as ACL and authentication
Quality of Service (QoS), with an emphasis on low-latency queuing (LLQ)
IP address allocation, Network Time Protocol (NTP), and device failures


Buy NowGet 39% OFF

Click here for more information about Network Warrior

Read More...

CISSP Study Guide Review

CISSP Study Guide
Average Reviews:

(More customer reviews)
Obviously I am biased since I am a fellow SANS instructor, but will try to support my thoughts with data. I agree with another poster that the one star ratings are unfair, especially the guy that had not read the book; too funny. Well I have read the book, cover to cover on airplanes and some sections I have read twice. Why four stars? I am concerned that if this is the only CISSP prep you have, you will not be fully prepared for the exam. On the other hand, if you have taken a CISSP review course or read another book, this will be a great supplemental tool. I am a big fan of the Shawn Harris CISSP prep book as well, but you really can't take that monster with you on a trip, this book fit right in my carry on outside pocket.
OK, let's drill down into the book:
Ch 1: How to pass the exam, 5*s, clear and practical
Ch 2: Information Security Governance, 5*s, complete, concise, nothing missing that I can see
Ch 3: Access Control: 4*s, this chapter gets a bit muddy, the authors chose to cover some of the data flow access models in Ch 6 which is fine. First half of the chapter is true to the spirit of the book, the types of attackers section seems to be a touch superficial, thought the Metasploit "Point, click and root" was a chuckle.
Ch 4:Cryptography, 5*s, in my view this is the strongest chapter in the book, clearest explanations I have ever seen with one exception, in 2nd edition I would rework the Vienere Cipher section.
Ch 5: Physical Security, 5*s, complete, concise, let's you review the material in the shortest amount of time
Ch 6:Security Architecture, 4*s, I think there is a risk that the exam could cover more virtualization than the book prepares the candidate for. Not that I have knowledge of what is on the exam, but it is one of the most important topics in security right now and it only gets three paragraphs. I would also rework polyinstantiation, most of the sections are crystal clear, but this is a bit muddy.
Ch 7: Business Continuity, 4*s, I think this chapter could have been a touch shorter to be true to the spirit and approach of the book, all the information is there, but I had to force myself to read it, in second edition, suggest a do over.
Ch 8: Telecommunications, 5*s, authors are true domain experts, so they are able to concisely explain the material
Ch 9: Application Development Security, 5*s, same comment as above, since the authors know this stuff cold, they can make it very clear
Ch 10: Operations Security, 5*s, I do wish ISC2 would get on board with the better incident response model, but that is not the author's fault, this chapter is also true to the spirit of the book.
Ch 11: Legal regulations, 5*s, authors did a better job overall than I do with my course ( I will start the rewrite this week). I would suggest adding the concept of attestation to Chain of Custody.
The remainder of the book is a self test and the authors have additional practice testing on their web site. The Glossary is complete and also concise.


Click Here to see more reviews about: CISSP Study Guide


The CISSP Study Guide is aligned to cover all of the material included in the exam, complete with special attention to recent updates. The10 domains are covered completely and as concisely as possible with an eye to passing the exam thr first time. Each of the 10 domains has its own chapter that includes specially-designed pedagogy to aid you in passing the exam.

Clearly Stated Exam Objectives
Unique Terms / Definitions
Exam Warnings
Helpful Notes
Learning By Example
Stepped Chapter Ending Questions
Self Test Appendix
Detailed Glossary
Web Site (http://booksite.syngress.com/companion/conrad) Contains Two Practice Exams and Ten Podcasts-One for Each Domain




Buy NowGet 37% OFF

Click here for more information about CISSP Study Guide

Read More...

Build Your Own Security Lab: A Field Guide for Network Testing Review

Build Your Own Security Lab: A Field Guide for Network Testing
Average Reviews:

(More customer reviews)
I'll be completely honest. I went through this in about two hours, and I plan on returning it. It simply didn't have anything new for me. I was expecting it to be more along the lines of setting up a virtual network, attempting to hack the VMs, and then checking the procedures to see if you did it right.
Instead, this book covers things like how to install OSes into VMs, gives basic overviews of tools, etc. However, this is a great book if you're at the appropriate level for it. I think this makes a good follow-up to CompTIA's Security+ certification. It'll help novices get their feet wet with actual hands-on activities. I've done nearly everything in this book on my own, and that's really the only problem with it. While I didn't pay a great deal of attention to every bit of text, it seemed to be technically accurate and free from errors.
I wish I could give a more detailed review, but I thought I'd at least post this since no one has reviewed it yet. Just take your skill level into account when considering this title. If you want more advanced books, check out the Hacking Exposed series, Grey Hat Hacking, and the Penetration Tester's Open Source Toolkit.

Click Here to see more reviews about: Build Your Own Security Lab: A Field Guide for Network Testing

If your job is to design or implement IT security solutions or if you're studying for any security certification, this is the how-to guide you've been looking for. Here's how to assess your needs, gather the tools, and create a controlled environment in which you can experiment, test, and develop the solutions that work. With liberal examples from real-world scenarios, it tells you exactly how to implement a strategy to secure your systems now and in the future.
Note: CD-ROM/DVD and other supplementary materials are not included as part of eBook file.

Buy NowGet 40% OFF

Click here for more information about Build Your Own Security Lab: A Field Guide for Network Testing

Read More...

Hands-On Information Security Lab Manual Review

Hands-On Information Security Lab Manual
Average Reviews:

(More customer reviews)
There was no revision number listed on the website for this book. I purchased incorrect revision for this book (should have been rev 2). I had to returned it with extra return fee.

Click Here to see more reviews about: Hands-On Information Security Lab Manual



Buy NowGet 34% OFF

Click here for more information about Hands-On Information Security Lab Manual

Read More...

CISSP All-in-One Exam Guide, Fifth Edition Review

CISSP All-in-One Exam Guide, Fifth Edition
Average Reviews:

(More customer reviews)
There is no simple formula to prepare for the CISSP certification, and no single resource which can guarantee success on the certification exam since every applicant's background is unique. However, this book (fifth edition) was my only resource in preparing for the exam and I passed on my first attempt (April 24, 2010).
I spent 60+ hours in preparation for the exam... that's 60+ hours of DEDICATED individual study using this book and CD, not 60+ hours spent web surfing during lunch hours or commercial breaks. My recent background is in middle management, with 20 years experience in network architecture and data security, so I already had a firm technical foundation for the test areas dealing with protocols and encryption variations. I also have an MS in Computer Science. Nonetheless, the exam was so broad, with topics covering general principles and concepts, that I could have prepared twice as long and still left the exam with questions about the outcome.
My personal opinion is that formal classroom instruction, through one of the many organizations offering CISSP preparation courses, is a worthwhile companion to Shon Harris' book. A study group is also a good idea. You will not obtain CISSP certification if you take the exam without preparation. This book (fifth edition) was sufficient, but not 100% comprehensive, to prepare me for passing the CISSP test.
Note: Some reviewers do not appreciate Shon's frequent analogies and humor. Most of her analogies helped me internalize the complex topics, but that's my personal learning style. The efforts at humor were generally awful, but every once in a while she was subtle and brilliant enough to make me laugh out loud. Working through Shon's unique writing style was not a problem for me... I actually found it refreshing.

Click Here to see more reviews about: CISSP All-in-One Exam Guide, Fifth Edition

Get complete coverage of the latest release of the Certified Information Systems Security Professional (CISSP) exam inside this comprehensive, fully updated resource. Written by the leading expert in IT security certification and training, this authoritative guide covers all 10 CISSP exam domains developed by the International Information Systems Security Certification Consortium (ISC2). You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass the CISSP exam with ease, this definitive volume also serves as an essential on-the-job reference.
COVERS ALL 10 CISSP DOMAINS:
Information security and risk management
Access control
Security architecture and design
Physical and environmental security
Telecommunications and network security
Cryptography
Business continuity and disaster recovery planning
Legal regulations, compliance, and investigations
Application security
Operations security

THE CD-ROM FEATURES:
Hundreds of practice exam questions
Video training excerpt from the author
E-book

Shon Harris, CISSP, is a security consultant, a former member of the Information Warfare unit in the Air Force, and a contributing writer to Information Security Magazine and Windows 2000 Magazine. She is the author of the previous editions of this book.

Buy NowGet 48% OFF

Click here for more information about CISSP All-in-One Exam Guide, Fifth Edition

Read More...

Network Security Auditing (Networking Technology: Security) Review

Network Security Auditing (Networking Technology: Security)
Average Reviews:

(More customer reviews)
The subtitle of Network Security Auditing is the complete guide to auditing security, measuring risk, and promoting compliance. The book does in fact live up to that and is a comprehensive reference to all things network security audit related.
In 12 chapters at almost 450 pages, the book covers all of the key areas around network security that is of relevance to those working in information security.
As a Cisco Press title, written by a Cisco technical solutions architect, the book naturally has a heavy Cisco slant to it. Nonetheless, it is still an excellence reference even for those not working in a Cisco environment.
While the first 3 chapters of the book provide an overview that is great even for a security newbie, the overall style of the book is highly technical and comprehensive.
Chapters 1-3 provide an introduction to the principles of auditing, information security and the law, and governance, frameworks and standards. Each chapter is backed with a significant amount of information and the reader is presented with a thorough overview of the concepts.
Chapter 3 does a good job of providing the reader with the details of current frameworks and standards, including PCI DSS, ITIL, ISO 17799/27001 and others. Author Chris Jackson does a good job of explaining the differences between them and where they are best used. Given this is a Cisco-centric book, he also shows how the various Cisco security products can be integrated for such regulatory and standards support.
Throughout the book, the author makes excellent use of many auditing checklists for each area that can be used to quickly ascertain the level of security audit compliance.
Chapter 6 is perhaps the best chapter in the book on the topic of Policy, Compliance and Management, and the author provides an exceptionally good overview of the need for auditing security policies. This is a critical area as far too many organizations create an initial set of information security policies, but subsequently never take the time to go back and see if they are indeed effective and providing the necessary levels of data protection.
Jackson notes that accessing the effectiveness of a policy requires the auditor to look at the policy from the viewpoint of those who will interpreting its meaning. A well intentioned policy might recommend a particular course of action, but unless specific actions are required, there is little an organization can expect the policy to actually accomplish to help the organization protect its data assets if it is misinterpreted.
The chapter suggests that the auditor ask questions such as: is the policy implementable, enforceable, easy to understand, based on risk, in line with business objectives, cost effective, effectively communicated and more. If these criteria are not well-defined and delineated, then the policies will exist in text only, offering little information security protection to the organization.
Jackson also writes of the need to measure how well policies are implemented as part of a security assessment. He suggested using a maturity model as a way to gauge if the organization is in its evolution towards fully integrating security into its business process or if it already has a formal integration process in place.
In chapter 8 on Perimeter Intrusion Prevention, Jackson writes that protecting a network perimeter used to be a relatively easy task. All an organization would have to do is stick a firewall on its Internet connection, lock down the unused ports and monitor activity. But in most corporate networks today, the perimeter has been significantly collapsed. If you compound that with increased connectivity, third-party access, and more; and then bring in advanced persistent threats into the equation, it is no longer a simple endeavor to protect a network.
Chapter 8 provides detailed framework on how to perform a perimeter design review and assessment. As part of the overall review, the chapter details other aspects of the assessment including the need for reviews of the logical and physical architectures, in addition to a review of the firewall. Jackson also lists a large number of security tools that can be used to during an audit.
Chapter 11 covers endpoint protection with a focus on the end-user. Jackson notes that users never cease to amaze with their abilities to disappoint by opening suspicious file attachments, running untrusted Facebook applications, and much more. The book notes that organizations today face significantly higher levels of risk from endpoint security breaches than ever before due to our highly mobile and connected workforce.
The chapter details an endpoint protection operational control review that can be used to assess the organizations processes for identifying threats and performing proactive management of endpoint devices. While the chapter is quite Cisco-centric, with references to the Cisco SIO (Security Intelligence Operations) and a number of other Cisco products, the chapter does provide a good overview of the fundamentals of endpoint protection and how to do it the right way.
Overall, Network Security Auditing is highly technical and detailed reference that makes for an excellent primary reference on the fundamental of information security. With ample amounts of checklist, coding refences, detailed diagrams and just the right amount of screen shots, Network Security Auditing makes an excellent guide that any technical member of an IT or security group should find quite informative.


Click Here to see more reviews about: Network Security Auditing (Networking Technology: Security)

This complete new guide to auditing network security is an indispensable resource for security, network, and IT professionals, and for the consultants and technology partners who serve them.Cisco network security expert Chris Jackson begins with a thorough overview of the auditing process, including coverage of the latest regulations, compliance issues, and industry best practices. The author then demonstrates how to segment security architectures into domains and measure security effectiveness through a comprehensive systems approach.Network Security Auditing thoroughly covers the use of both commercial and open source tools to assist in auditing and validating security policy assumptions. The book also introduces leading IT governance frameworks such as COBIT, ITIL, and ISO 17799/27001, explaining their values, usages, and effective integrations with Cisco security products. This book arms you with detailed auditing checklists for each domain, realistic design insights for meeting auditing requirements, and practical guidance for using complementary solutions to improve any company's security posture.Master the five pillars of security auditing: assessment, prevention, detection, reaction, and recovery.

Buy NowGet 20% OFF

Click here for more information about Network Security Auditing (Networking Technology: Security)

Read More...

Hacking For Dummies Review

Hacking For Dummies
Average Reviews:

(More customer reviews)
I used to wonder why anyone would want to break into my computer, there's not much there of any interest. Even I don't find it all that interesting. Then one day I was puzzled when my ISP asked why my machine was putting out millions of bytes of stuff to the point where it was bogging down their T1 line. I didn't know. We unpluged the machine from the network and it stopped sending. We plugged it back in and it wasn't sending. But the next day it was.
It wasn't until we got an e-mail telling us to stop sending out copyrighted movies that we realized what had happened. It wasn't anything in my computer they wanted, it was the bandwidth. Knowing what to look for it wasn't all that hard to stop. Google quickly provided links on this problem.
This book is aimed at people just like me. It gives an overall, if fairly light, view of the overall security problem. Like the other For Dummies books it has a writing style that doesn't (quite) put you to sleep. It has enough humor to enable you to get through it. It won't make you an expert, but it will point out the problem areas so that you can go deeper into those that are important to you. It's a good introduction.

Click Here to see more reviews about: Hacking For Dummies

A new edition of the bestselling guide-now updated to cover the latest hacks and how to prevent them!
It's bad enough when a hack occurs-stealing identities, bank accounts, and personal information. But when the hack could have been prevented by taking basic security measures-like the ones described in this book-somehow that makes a bad situation even worse. This beginner guide to hacking examines some of the best security measures that exist and has been updated to cover the latest hacks for Windows 7 and the newest version of Linux.
Offering increased coverage of Web application hacks, database hacks, VoIP hacks, and mobile computing hacks, this guide addresses a wide range of vulnerabilities and how to identify and prevent them. Plus, you'll examine why ethical hacking is oftentimes the only way to find security flaws, which can then prevent any future malicious attacks.
Explores the malicious hackers's mindset so that you can counteract or avoid attacks completely
Covers developing strategies for reporting vulnerabilities, managing security changes, and putting anti-hacking policies and procedures in place
Completely updated to examine the latest hacks to Windows 7 and the newest version of Linux
Explains ethical hacking and why it is essential

Hacking For Dummies, 3rd Edition shows you how to put all the necessary security measures in place so that you avoid becoming a victim of malicious hacking.

Buy NowGet 36% OFF

Click here for more information about Hacking For Dummies

Read More...

Security of Information and Communication Networks (IEEE Press Series on Information & Communication Networks Security) Review

Security of Information and Communication Networks (IEEE Press Series on Information and Communication Networks Security)
Average Reviews:

(More customer reviews)
This book was evidently written in haste with little editing. There are too many errors, grammatical and technical, throughout the book; e.g. the numerical work in 8.2.1 (page 176) is incorrect. Chapter 2, Mathematical Foundations, should be longer, with more examples and exercises for the reader who would be exposed to this material for the first time. There are also errors in this chapter; e.g. on page 43, line 11, "random" should be "prime".


Click Here to see more reviews about: Security of Information and Communication Networks (IEEE Press Series on Information & Communication Networks Security)

Information and communications security is a hot topic in private industry as well as in government agencies. This book provides a complete conceptual treatment of securing information and transporting it over a secure network in a manner that does not require a strong mathematical background. It stresses why information security is important, what is being done about it, how it applies to networks, and an overview of its key issues. It is written for anyone who needs to understand these important topics at a conceptual rather than a technical level.

Buy NowGet 25% OFF

Click here for more information about Security of Information and Communication Networks (IEEE Press Series on Information & Communication Networks Security)

Read More...

Mobile Malware Attacks and Defense Review

Mobile Malware Attacks and Defense
Average Reviews:

(More customer reviews)
Security threats on mobile platforms are one of the key topics and main targets for the next couple of years, given the ubiquity and popularity of these devices, plus their advanced capabilities and use of sensitive application: micro payments, online banking and e-commerce, access to "the cloud", etc.
This book is one of the few references, if not the only one (till very recently), focused on the multiple security aspects of the mobile ecosystem. As such, it constitutes a great historical reference about what mobile malware (referred as MM) and threats were until its publication, in late 2008.
The book starts by introducing mobile malware, although it can be a bit confusing for the novice reader, as it mixes up attacks, tools and threats (most them Bluetooth based), and for example, WiFi is not even mentioned (yet). The next chapter (ch 2) provides an interesting overview on how mobile malware shows up in a terminal from a user perspective, including the most common behaviors and the kind of interaction expected from the user. It would be great to have a detailed explanation of the propagation method, as with CommWarrior, for all the samples analyzed in this chapter.
The next three chapters (ch 3-5) are a really valuable historical reference about mobile malware, including its timeline, how it has evolved since 2000 till 2008, the types of threats, categorized by malware families, the most significant or famous specimens, such as Cabir in the Bluetooth side, plus an extensive taxonomy of mobile malware and threats based on the infection strategy, distribution and payload. Although some tables, with more than 400 references, could have been moved to an appendix to facilitate the reading, this set of chapters summarizes how mobile malware seriously started, back in 2004, and evolved over time. The comparison of different pieces of malware, and the extra analysis of the most relevant specimens, together with the technical details they used to survive, makes this section of the book a very good "encyclopedia".
Then, the book reflects the influence of multiple authors, presenting different unconnected and independent chapters. The phishing, SMSishing and Vishing chapter moves out of the mobile space, covering lots of details about these threats on traditional environments, such as common web browser based solutions, and the usage and purpose of the network captures attached is still not clear to me. I still remember my surprise from a technical perspective when I read that the transmitted data between the client and the verification server could not be identified, as they were using an SSL connection: "What about using a HTTP(S) interception proxy?" Finally, it includes an extensive phishing academic research mainly based on Bayesian networks and a distributed framework, which on my opinion, is clearly out of the scope of the book.
The more technical chapters come next; chapter 7 focuses on the core elements for the most widely used mobile platforms, their protection mechanisms and how they have been bypassed in the past, covering mainly Windows Mobile (WM), iPhone, Symbian, BlackBerry and J2ME (Java). It includes a extremely short summary on prevention and exploitation. This is complemented by the techniques, methods and tools available for the analysis of mobile malware (ch 8), the in-depth details for the disassembly and debugging of associated binaries (ch 10), plus the strategy and main constraints to perform a forensic analysis on this type of devices (chapters 8 and 9). This is by far the most relevant technical portion of the book.
The book follows the old and useful Syngress layout tradition of adding a few common sections at the end of each chapter to reinforce the material covered: Summary, Solutions Fast Track, and FAQ.
The first portion of the book (ch 1-5) will be an eye opener for a non-technical audience; highly recommended, together with the last chapter (ch 11) focused on the defensive side and how to mitigate all the threats covered along the book. The second portion for the book (ch 7-10) is focused on security professionals, mainly incident handlers and forensic analyst that need to deal with the technical aspects of mobile attacks and infections.
Due to the new mobile threats and issues that turned up in 2009 for the advanced smartphone platforms (like iPhone or Android), and the trend for new and more dangerous specimens expected in 2010, a second volume or edition would be a must.


Click Here to see more reviews about: Mobile Malware Attacks and Defense



Buy NowGet 19% OFF

Click here for more information about Mobile Malware Attacks and Defense

Read More...