Showing posts with label it security. Show all posts
Showing posts with label it security. Show all posts

The CISSP and CAP Prep Guide: Platinum Edition Review

The CISSP and CAP Prep Guide: Platinum Edition
Average Reviews:

(More customer reviews)
I have just passed my CISSP exam, taken on Aug 2008. This guide was my sole reference book that I used and I also DID NOT attend the review seminar for CISSP. Having said that, I would not recommend it as your only source of CISSP reading material as it slightly outdated by now, as compared to some of the questions that I have encountered on the exam.
The quizzes listed on the book are also way too easy and nowhere near the trickery shown on the actual exam questions. For giggles and laughter, I actually visited the bookshop to review the 'Official ISC2 Guide to CISSP CBK' a couple days after taking the exam, and found out that the quiz questions listed in the book are worded similarly to the exam. I did not read through the chapters for that guide, so I could not make a sound comparison between the 2 books.
However, I could safely say that you should not just rely on one book and read the usual suspects of 'The All-In-One..', 'The Official Guide to CISSP CBK' and this book in your CISSP exam preparations.
Good luck!

Click Here to see more reviews about: The CISSP and CAP Prep Guide: Platinum Edition

This follow-on edition to The CISSP Prep Guide: Mastering CISSP and ISSEP offers value-add coverage not featured anywhere else! You'll prepare for passing CISSP with a revised review of each of the ten CISSP domains, updated to reflect current thinking/technology, especially in the areas of cyber-terrorism prevention and disaster recovery. You'll also cover CAP, a major section of the ISSEP that has been elevated from its status as part of an advanced concentration to its own certification. The accompanying CD-ROM contains revised test questions to make your preparation complete. Order your copy today and make your exam preparation complete!

Buy NowGet 45% OFF

Click here for more information about The CISSP and CAP Prep Guide: Platinum Edition

Read More...

CISSP Guide to Security Essentials Review

CISSP Guide to Security Essentials
Average Reviews:

(More customer reviews)
Peter Gregory is a prolific author and well-known computer security professional who is also very active in the information security community. Peter wrote this book to address the current situation in information security, which is stated in the Introduction, as "There aren't enough good security professionals to go around". Information security is a broad field with many sub disciplines. Many professionals feel they should know more about security, but don't know where to start. Peter's book is an attempt to change that situation by providing the foundational materials that every security professional needs to know before undertaking advanced or specialized study. The book is suitable for self-study or as a classroom text. Each chapter has a summary, a glossary of key terms, review questions, hands-on projects, and ideas for case projects. For those interested in obtaining the CISSP, they will find this book a good place to start. The strength of this book lies in its organization and clarity. The book's ten chapters map to the ten CISSP Common Body of Knowledge Domains. Each chapter is broken into many subheadings, with an outline-style organization that clarifies each distinct topic. Acronyms are defined in the text and in the glossaries, which are presented in each chapter and at the end of the book. There are two appendices. One appendix provides summary outlines of the ten domains of CISSP security; the other reproduces the code of ethics of CISSP professionals. The Introduction reviews the steps needed to obtain CISSP certification and, together with the code of ethics, gives a good sense of the knowledge, behavior, and attitude necessary to succeed as a security professional. A CD-ROM containing practice questions for the CISSP exam is included. No single book can provide all you need to know to be a CISSP, but this is a good place to start.

Click Here to see more reviews about: CISSP Guide to Security Essentials

CISSP GUIDE TO SECURITY ESSENTIALS CISSP Guide to Security Essentials provides readers with the tools and resources they need to develop a thorough understanding of the entire CISSP Certification Body of Knowledge. Using a variety of pedagogical features including study questions, case projects, and exercises, this book clearly and pointedly explains security basics. Coverage begins with an overview of information and business security today, security laws, and then progresses through the ten CISSP domains, including topics such as access control, cryptography and security architecture and design. With the demand for security professionals at an all-time high, whether you are a security professional in need of a reference, an IT professional with your sights on the CISSP certification, on a course instructor, CISSP GUIDE TO SECURITY ESSENTIALS CISSP Guide to Security Essentials has arrived just in time.

Buy NowGet 47% OFF

Click here for more information about CISSP Guide to Security Essentials

Read More...

Unauthorised Access: Physical Penetration Testing For IT Security Teams Review

Unauthorised Access: Physical Penetration Testing For IT Security Teams
Average Reviews:

(More customer reviews)
Unauthorised Access is nothing short of a manual for corporate espionage. Author Wil Allsopp, is a "penetration tester", a hired gun brought in by companies to find out how effective the security defences protecting their premises are.
While conventional penetration testing ("pentesting") involves remote hacking, typically through software vulnerabilities, physical pen-testers gain access to a company's offices or data centre with the goal of connecting to a restricted network, planting a bug or even an imitation explosive device
With ten years experience as a pen-tester, Allsopp offers superb insight into common methods used by criminals to manipulate employees, from phone calls to outright espionage. The chapter on social engineering, in particular, is guaranteed to spark paranoia and sleepless nights among even the most grizzled chief security officers.
Specific tactics he reveals include employing politeness, inducing fear, faking supplication, invoking authority, ingratiation and deference, and even sexual manipulation.
Another chapter details several successful pen-tests conducted by Allsopp and his team, including attacks on a UK power plant and a supercomputing facility conducting spatial modelling of nuclear explosions for the military. He also describes the antics of a pentester who bypassed the security of a large corporate by observing the uniform of the firm's security guard, then showing up the next day in identical costume, pulling rank and relieving the man of duty
The enjoyment Allsopp clearly derives from his work is reflected in his book; he writes with that particular tone of repressed glee common among white hat hackers. This, together with his tendency to adopt a Boy's Own adventure narrative style, makes the book very readable but occasionally somewhat glib. And at times it is hard to tell whether Allsopp is offering advice to the CSO, helping the reader start their own pen-testing company or trying to prove to a less salubrious readership how clever he is.
Indeed, many of the techniques described in Unauthorised Access are open to abuse. Allsopp gives the excuse that "the bad guys already know", before urging the reader to consider taking up lock picking as a rewarding hobby.

Click Here to see more reviews about: Unauthorised Access: Physical Penetration Testing For IT Security Teams

The first guide to planning and performing a physical penetration test on your computer's security
Most IT security teams concentrate on keeping networks and systems safe from attacks from the outside-but what if your attacker was on the inside? While nearly all IT teams perform a variety of network and application penetration testing procedures, an audit and test of the physical location has not been as prevalent. IT teams are now increasingly requesting physical penetration tests, but there is little available in terms of training. The goal of the test is to demonstrate any deficiencies in operating procedures concerning physical security.
Featuring a Foreword written by world-renowned hacker Kevin D. Mitnick and lead author of The Art of Intrusion and The Art of Deception, this book is the first guide to planning and performing a physical penetration test. Inside, IT security expert Wil Allsopp guides you through the entire process from gathering intelligence, getting inside, dealing with threats, staying hidden (often in plain sight), and getting access to networks and data.
Teaches IT security teams how to break into their own facility in order to defend against such attacks, which is often overlooked by IT security teams but is of critical importance
Deals with intelligence gathering, such as getting access building blueprints and satellite imagery, hacking security cameras, planting bugs, and eavesdropping on security channels
Includes safeguards for consultants paid to probe facilities unbeknown to staff
Covers preparing the report and presenting it to management

In order to defend data, you need to think like a thief-let Unauthorised Access show you how to get inside.

Buy NowGet 43% OFF

Click here for more information about Unauthorised Access: Physical Penetration Testing For IT Security Teams

Read More...