Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

6/14/2012

CompTIA Security+ Study Guide: Exam SY0-101 Review

CompTIA Security+ Study Guide: Exam SY0-101
Average Reviews:

(More customer reviews)
This is an excellent study guide for the Security+ exam. The sample questions on the CD are almost exactly what is on the real exam, in fact I actually found one question that was identical verbatim to what was on the CD. I think going through the chapter exams and reading on the subjects you miss questions on is the best way to study for the Security+ which is a fairly tough exam. This is the only resource I used and I got an 885/900. You will not be disappointed with this book and especially not with the CD which is worth the price by itself thanks to its excellent sample tests.

Click Here to see more reviews about: CompTIA Security+ Study Guide: Exam SY0-101

Take charge of your career with certification that can increase your marketability. This new Deluxe Edition of the top-selling Security + Study Guide is what you need to prepare for CompTIA's Security+ SY0-101 exam. Developed to meet the exacting requirements of today's certification candidates and aspiring IT security professionals, this fully updated, comprehensive book includes:* Clear and concise information on crucial security topics* Six practical exams and over 600 practice questions, more than any other CompTIA Security+ book on the market* Special Security Administrator's Troubleshooting Guide appendix* Practical examples and hands-on labs to prepare you for the real world* Leading-edge exam preparation software, including a test engine and electronic flashcardsInside, find authoritative and coverage of all key exam topics, including:* General security concepts* Communication security* Infrastructure security* Basics of cryptography* Operational and organizational securityThis book has been reviewed and approved as CompTIA Authorized Quality Curriculum (CAQC). Students derive a number of important study advantages with CAQC materials, including coverage of all exam objectives, implementation of important instructional design principles, and instructional reviews that help students assess their learning comprehension and readiness for the exam.Featured on the CDSYBEX TEST ENGINE: Test your knowledge with advanced testing software. Includes all chapter review questions plus bonus exams.ELECTRONIC FLASHCARDS: Reinforce your understanding with flashcards that can run on your PC, Pocket PC, or Palm device.

Buy Now

Click here for more information about CompTIA Security+ Study Guide: Exam SY0-101

Read More...

5/01/2012

Computer Security: Art and Science Review

Computer Security: Art and Science
Average Reviews:

(More customer reviews)
Please understand that the Amazon star system, while very powerful has limits, I feel this book is 5 stars as a textbook for an undergrad computer security course, 4 stars for a graduate student and 3 stars for a book on the average information security worker's shelf.
Computer Security Art and Science has been years in the making and for good reason; it is over a thousand pages. The book seems best suited for four groups of readers. The first group is college students; this will probably be a popular choice as a textbook for undergraduate level students and with additional materials, graduate level students. It is a complete guide to computer security terminology and theory. Other groups of readers that would benefit from this book include security knowledgeable managers seeking to assess the knowledge of potential employees especially in policy and architecture positions. A third group includes anyone preparing for information security certifications. If you are wish to certify you will benefit from a close reading of this text before attempting your examination. Finally, anyone seeking to understand the big picture of information security would benefit from Computer Security Art and Science. However the book's value is primarily as a textbook!
Like most authors writing a security book, Matt has chosen to start at a basic level beginning with a discussion of confidentiality, integrity and availability. As a reviewer I was quietly wondering how long he would stay there. The answer proved to be one chapter only and at the back of the chapter one the author has included insightful, thought provoking study questions. If I were considering hiring someone who claimed to have experience in information security that could not answer these questions, I would show them the door.
Now to consider the rest of the book! On the first page of chapter two we are introduced to logical equations. This is where the casual reader is likely to get off the bus while the diligent student with a qualified instructor gets on. As soon as I saw the equations with no explanation of how to read them, I could see someone browsing in a bookstore shut the cover and move on. Be brave and press on is my advice; the book is well worth it even if some of the illustrations are beyond comprehension without a teacher's guide. It says in the preface this book was designed to be a college level textbook. They have to put a few inscrutable pages in the book so the professors can appear to be smarter than the students.
The cryptography section, chapters 9 - 11 are very approachable and while not as in depth as some other sections, they would help anyone preparing for the various industry security certifications including CompTIA's Security +, ISC2's CISSP and SANS' GSEC. In fact the entire book would be beneficial for any of these.
The table of contents says that part 6 of the book, assurance, chapters 18 - 21, were contributed by a different author, Elisabeth Sullivan. I read those chapters closely and could not detect a different tone or level of quality; the authors are to be congratulated for that. Nice use of humor on the heading title for 18.1.1, "The Need for Assurance" and where else can you read about "Extreme Programming".
No book is perfect, the intrusion detection and penetration testing discussions need to be beefed up, but chapter 29, Program Security more than makes up for them. That chapter should be required reading before anyone is allowed to touch a compiler.
I donate most of the books people send me to review to my local library, but this one stays on the shelf and I am setting an iCal reminder to re-read the policy and audit sections a couple months from now.

Click Here to see more reviews about: Computer Security: Art and Science



Buy NowGet 28% OFF

Click here for more information about Computer Security: Art and Science

Read More...

4/23/2012

The Executive Guide to Information Security: Threats, Challenges, and Solutions Review

The Executive Guide to Information Security: Threats, Challenges, and Solutions
Average Reviews:

(More customer reviews)
A fun book on security for executives and managers? Unbelievable, you'd say? This one ("The Executive Guide to Information Security") comes pretty close.
On the down side, do not look at this book for technology coverage. Almost total lack of coverage of intrusion prevention, spyware, spam as well as some Symantec bias (understandable, considering the publisher) make this book much stronger on the policy, process and "big picture" coverage rather on modern technical threats and countermeasures. Slightly confusing coverage of vulnerability management also falls in the same category. However, given the target audience of CEOs and CFOs, this is certainly excusable.
The book introduces the executives to basic security concepts such as "defense-in-depth", "people, process, technology", etc, and goes into details on using them for organizing security for their organizations.
I also appreciated the sections on planning and executing a security strategy and measuring security by using various included checklists and questionnaires. 50-point security evaluation framework based on"best practices" was another valuable piece. The books also address one of the important questions of organizational security: in-house vs outsourced security.
Regulations and laws also occupy a significant part of the book. The coverage is high-level and provides few details, appropriate given the target audience. A section on future security was pretty insightful and enjoyable to read!
Overall, I think the book will be one of the first (and, so far, best) books about security for the "C-level" crowd.
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA is a Security Strategist with a major security company. He is an author of the book "Security Warrior" and a contributor to "Know Your Enemy II". In his spare time, he maintains his security portal info-secure.org


Click Here to see more reviews about: The Executive Guide to Information Security: Threats, Challenges, and Solutions

The book provides a pragmatic approach to evaluating security at a companyand putting together an effective information security program. The bookfocuses on three key themes; People, Processes, and Technology and isorganized according to the steps executives would follow in order to developan information security program for their company. Key elements of theprogram include staffing this function at a company, putting the necessaryinternal processes in place, and implementing the appropriate technology.Business executives will find this book a good primer for understanding the keyexisting and future security issues, and for taking the necessary action to ensurethe protection of their enterprise's information assets.The objective of this book is to provide a "short cut" for executives to learnmore about information security and how it will affect their business in thefuture. An overview of information security concepts is provided, so they canbe better prepared to evaluate how their company is addressing informationsecurity.

Buy NowGet 31% OFF

Click here for more information about The Executive Guide to Information Security: Threats, Challenges, and Solutions

Read More...

4/12/2012

CISSP All-in-One Exam Guide, Third Edition (All-In-One Certification) Review

CISSP All-in-One Exam Guide, Third Edition (All-In-One Certification)
Average Reviews:

(More customer reviews)
I've read some reviews and they are very controversial, so if you feel you're getting confused read this.
I've just got a confirmation that I passed the test, and I used only this book for studying. So that books is definitly not a joke and can get you through.
Why the reviews are so different?
First, the author's style. It's more like recorded lectures then a reference. The author included some jokes and funny examples. They are perfectly correct, not abusive, they add some spice to a highly proffesional text and I personally love them because they make reading that huge book not so boring, but looks like the fact the style is different drives some people mad.
Second, the nature of the exam. The covered area is very wide and includes more topic then most people normally know and use. So many readers think the topics they know the best could be written better. The problem is because of so wide coverage you can not go deeper then a certain level. The book is almost 1000 pages long and I personally think it's well balanced and provides adequate knowledge for the test. Yes, some chapters could be extended but then you'd be overwhelmed by the volume and I doubt it would improve your passing score significantly.
Some people complained about mistakes. Well, it's true, there are some. But, it's the same idea here. They are not crucial and don't really affect your score much.
It's like if you need to get to the airport and you friend offers help you don't really care what car he has. But if you go to dealership to buy a car every minor option gets so important. Same idea here. If your goal is to pass the test, the book can be used as the only training material and provides adequate up-to-date information in a resonable volume for a pretty cheap price. The book does it's job and does it well. It also has some personality so you may love or hate it, but it's just your emotional perception. The knowledge is there.

Click Here to see more reviews about: CISSP All-in-One Exam Guide, Third Edition (All-In-One Certification)

The Third Edition of this proven All-in-One exam guide provides total coverage of the CISSP certification exam, which has again been voted one of the Top 10 IT certifications in 2005 by CertCities. Revised and updated using feedback from Instructors and students, learn security operations in the areas of telecommunications, cryptography, management practices, and more. Plan for continuity and disaster recovery. Update your knowledge of laws, investigations, and ethics. Plus, run the CD-ROM and practice with more than 500 all new simulated exam questions. Browse the all new electronic book for studying on the go. Let security consultant and author Shon Harris lead you to successful completion of the CISSP.

Buy Now

Click here for more information about CISSP All-in-One Exam Guide, Third Edition (All-In-One Certification)

Read More...

3/19/2012

Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management Review

Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management
Average Reviews:

(More customer reviews)
If you want to find out the relation between Policies, Procedures and Standards buy this book. Although the flow of text is somewhat discontinuous but the author clearly explains the underlying concepts. The examples are very illustrative and have a real world feel. The author has been on the frontlines (clearly evident throughout the text) and this distinguishes the book from rest in the pack. Very few books talk about ISO 17799 and BS7799 in detail. This book goes beyond just reproducing the standard and explains the positioning of such guidelines. The tables and checklists found in the appendices alone are worth many times the cost of the book.

Click Here to see more reviews about: Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management

By definition, information security exists to protect your organization's valuable information resources. But too often information security efforts are viewed as thwarting business objectives. An effective information security program preserves your information assets and helps you meet business objectives. Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management provides the tools you need to select, develop, and apply a security program that will be seen not as a nuisance but as a means to meeting your organization's goals.Divided into three major sections, the book covers: writing policies, writing procedures, and writing standards. Each section begins with a definition of terminology and concepts and a presentation of document structures. You can apply each section separately as needed, or you can use the entire text as a whole to form a comprehensive set of documents. The book contains checklists, sample policies, procedures, standards, guidelines, and a synopsis of British Standard 7799 and ISO 17799.Peltier provides you with the tools you need to develop policies, procedures, and standards. He demonstrates the importance of a clear, concise, and well-written security program. His examination of recommended industry best practices illustrates how they can be customized to fit any organization's needs. Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management helps you create and implement information security procedures that will improve every aspect of your enterprise's activities.

Buy NowGet 20% OFF

Click here for more information about Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management

Read More...

3/04/2012

CISSP: Certified Information Systems Security Professional Study Guide Review

CISSP: Certified Information Systems Security Professional Study Guide
Average Reviews:

(More customer reviews)
I must admit a soft spot for Sybex (and Ed Tittel) study guides, having used them extensively for Microsoft exams. This book follows in that tradition, providing a good balance between detailed explanation and comprehensive coverage of the exam topics.
The bundled CD is useful. I raced through the 250 flash cards in an hour, which is good for jogging the memory. The four bonus exams, of 75 questions each, are good, but are not as difficult as the real thing. These exams provide grades broken down by each CISSP exam domain, which is excellent for identifying topics for revision.
One book can not guarantee coverage of all CISSP exam topics, particularly given the long list of references on the CISSP suggested reading list. I also skimmed through a friend's copy of Shon Harris's "All-in-One" exam guide. I would still rate this book higher, but Harris's book covers some topics in more detail then the Sybex book. The "All-in-One" practice exams are more difficult, though some of the questions are not clearly worded.
The biggest disappoint I have with the exam preparation experience is with the CISSP's ten domains. The examination questions are based on 'good exam fodder' from topics in the ten domains. The topics lean towards an academic approach to security, rather then knowledge needed by a working security professional.
The other references I would strongly suggest to help to gain a security brain, as well as a high exam score include: Stephen Northcutt's `Inside Network Perimeter Security', Ross Anderson's `Security Engineering', and Syngress's `Special Ops'. Maybe I should take one of the SANS security exams, which are much more practical in nature.
And best of luck with the exam!

Click Here to see more reviews about: CISSP: Certified Information Systems Security Professional Study Guide



Buy NowGet 38% OFF

Click here for more information about CISSP: Certified Information Systems Security Professional Study Guide

Read More...

2/25/2012

Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2 Press) Review

Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2 Press)
Average Reviews:

(More customer reviews)
Many people have commented that the Second Edition of the Official (ISC)2 Guide to the CISSP CBK was a big improvement over the first edition. I have to wonder how bad the first edition must have been?
Before getting into the details of my concerns, let's look at the layout of this hardbound, 968 page "brick".
The book is organized in a 1:1 correspondence with the 10 Domains of the CISSP CBK (i.e. one chapter per domain). This organization is nice as compared with the All-In-One CISSP 4th Edition, which has something like 12 chapters to cover the 10 domains (which can make it hard to cross reference concepts).
Each domain is written by a different author (or authors) who are CISSP's and experts in the field covered by the domain. In concept this is a good idea, and in a few places it was clear that the authors tried to impart some real-world knowledge and experience (such as the BCP/DRP chapter). However, it also leads to contrasting writing styles and some issues with "continuity".
As one might expect, many domains have concepts that overlap. On occasion, the text of the book will call attention to areas that relate or overlap with other domains, but this is inconsistent and sometimes results in the reader having some questions in their mind about the 'big picture' of the concepts. Given the CISSP is primarily a managerial level certification, understanding the big picture is critically important.
In general, the content seemed relevant, though the organization left something to be desired (more on that later). However, I was a bit surprised to see quite a bit of disparate information in this book when compared with the official (ISC)2 Review Seminar course material. There were at least a few topics covered in one, but not the other. I would have expected there to be better alignment between two current and "official" (ISC)2 sources, and it left me somewhat questioning which resource to focus on.
Speaking of the content, as compared to the All-In-One CISSP (Shon Harris) book mentioned above, this book is more of a traditional technical guide. Shon Harris' books occasionally interject opinion that borders on 'soapbox' material. And I find her "jokes" to generally not be funny, and often distracting. Some might consider the Official (ISC)2 Guide to be dry in comparison, but in technical reference books I prefer clear and succinct writing.
As mentioned, the layout of the individual chapters could be improved. The book does follow a typical hierarchy for introducing concepts (i.e. the main topic introduced with large, bold font, sub-topics using smaller fonts, italics, etc). However, in many cases the context of the material was not introduced well at the start, leading the reader to question whether a "sub-heading" represents a new topic, or a topic relating to the previous topic. In many cases the material gets nested 5 or 6 layers deep, making it hard to differentiate whether a new section is a sub-topic or a new upper level topic. This is a bit hard to explain so I hope that is clear. Again, this certification is not about memorization, but rather concepts and how they interrelate, so the book's organization is important.
Another area that was lacking was the use of tables, figures, and diagrams. There are some tables, etc, but there really should have been a few more. This could have really helped in providing additional context for some of the topics (see previous paragraph). This is an area where the Shon Harris All-In-One CISSP is better.
I also wish the editor/publisher would have taken a bit more time to improve the index. How can key elements such as "Software Development Lifecycle" and "Common Criteria" not even have index entries? My recommendation is when reading this book and taking notes, be sure to notate page numbers in your own notes for future reference.
There were also the usual amount of typo's and a few technical errors. The quantity of errors in tech books seems to be on a slow, steady rise, so I'd consider this book to be typical or maybe only slightly worse than typical.
Ultimately, for those studying for the CISSP I would recommend this book simply because no single book covers the entire CISSP scope. Couple this book with either the CISSP All-in-One Exam Guide, Fifth Edition, or perhaps the CISSP For Dummies 3rd Edition if you are looking for a cheaper option that might serve an an easier introduction to the material.
UPDATE: I forgot to add that I did pass the CISSP using primarily this book, coupled with the Review Seminar mentioned above. Took the test August 8 of 2010, received notification that I passed in September, and received my certificate in October.
My approach was as follows:
I started studying for the exam in late May, targeting a test date of August 8 (note the date on my review was August 7). I basically counted the number of days I had to prepare, subtracted 1 week for review time and about 7 "off" days to allow for days off or catch up. I also subtracted one week for the review seminar course that I took the week prior to the exam. I then took the number of remaining days an divided the number of pages in the book by that to set a pages per day goal. I think the result was something like 18 or 19 pages per day.
That was my goal - read 19 pages per day and take notes as I read. The next day I'd review the previous day's notes, and read another 19 pages and take notes. I used the Shon Harris book as a supplement to fill in gaps that I felt were unclear.

Click Here to see more reviews about: Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2 Press)



Buy NowGet 35% OFF

Click here for more information about Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2 Press)

Read More...

2/23/2012

Cryptography : Theory and Practice Review

Cryptography : Theory and Practice
Average Reviews:

(More customer reviews)
As other people have pointed out, this is not a mathematics book, and it is not an algorithm (recipies) book. It could be a great book for people that are interested in learning these tools to actually use them, either in a research or product development context (something besides homework). Unfortunately, the number of typos, in key mathematical expressions AND PORTIONS OF THE EXPLANATIONS is staggering. Go to the author's web page and you will find that some chapters, like 4 for example, average more than one typo per page (and some of these 'typos' are full sentences, or math expressions that do not look like anything that is actually printed on the page). If you do not have that errata sheet handy, you will waste a lot of time trying to understand the text, or trying to solve the exercises. If you are trying to learn from this book, without attending a class and without the errata, you will simply give up. It is a real shame because it has all the makings of a great book.

Click Here to see more reviews about: Cryptography : Theory and Practice



Buy Now

Click here for more information about Cryptography : Theory and Practice

Read More...

2/11/2012

CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) Review

CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)
Average Reviews:

(More customer reviews)
Not sure why this book is so highly rated. Having taken (and passed) the CISSP several years ago, I need to retake this exam and bought three books for review and study purposes. I have a previous version of the Harris book and it is ~900 pages. This new version is 1100+ pages, but seems to be filled more with fluff and some of the actually useful knowledge has been removed! One example which stands out is the removal of the effectiveness and acceptance charts for biometrics methods. This is an important concept and it is entirely ignored in this version. Other things have been changed to no real benefit. The CIA triad (as is the de-facto acronym, even in her previous book) has been renamed to the ICA triad. There is no reason for this.
Finally, the entire book is written in a dumbed-down, cutesy fashion in an attempt (I believe) to make the book more approachable. All it has done, IMO, has increased the number of pages, possibly forcing out relevant materials.
I will pass this test, but it won't be because of this book. Buy the ISC book and the Krutz book (and/or a previous version of the Harris book) - you will not be disappointed.
UPDATE: ok, took the test in Sept and passed. I won't turn this into a test review as this is about the book, but when you buy a certification book, your primary requirement is that the book will be timely and relevant to the test material. The 4th Edition Harris book does just that. ISC has made significant changes to both the content and nature of the test (in large part to keep its test current on security trends and to satisfy a larger target audience) and Shon has captured those changes very well. So, having said all that, it is my revised opinion that this book is more than adequate for passing the test (although it is still filled with fluff.) If I could change the review, I would probably give it 4 stars at this point. The ISC book and the Krutz book are both excellent references to actually apply the knowledge in a meaningful way, however if you just want to pass the test, the Harris book will serve you well.

Click Here to see more reviews about: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)


All-in-One is All You Need

Fully revised for the latest exam release, this authoritative volume offers thorough coverage of all the material on the Certified Information Systems Security Professional (CISSP) exam. Written by a renowned security expert and CISSP, this guide features complete details on all 10 exam domains developed by the International Information Systems Security Certification Consortium (ISC²). Inside, you'll find learning objectives at the beginning of each chapter, exam tips, practice questions, and in-depth explanations. CISSP All-in-One Exam Guide, Fourth Edition will not only help you pass the test, but also be your essential on-the-job reference.

Covers all 10 subject areas on the exam:

Access control
Application security
Business continuity and disaster recovery planning
Cryptography
Information security and risk management
Legal, regulations, compliance, and investigations
Operations security
Physical (environmental) security
Security architecture and design
Telecommunications and network security

The CD-ROM features:

Simulated exam with practice questions and answers
Video training from the author
Complete electronic book


Buy Now

Click here for more information about CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)

Read More...

2/08/2012

Security Metrics: Replacing Fear, Uncertainty, and Doubt Review

Security Metrics: Replacing Fear, Uncertainty, and Doubt
Average Reviews:

(More customer reviews)
I read Security Metrics right after finishing Managing Cybersecurity Resources, a book by economists arguing that security decisions should be made using cost-benefit analysis. On the face of it, cost-benefit analysis makes perfect sense, especially given the authors' analysis. However, Security Metrics author Andy Jaquith quickly demolishes that approach (confirming the problem I had with the MCR plan). While attacking the implementation (but not the idea) of Annual Loss Expectancy for security events, Jaquith writes on p 33 "[P]ractitioners of ALE suffer from a near-complete inability to reliably estimate probabilities [of occurrence] or losses." Bingo, game over for ALE and cost-benefit analysis. It turns out the reason security managers "herd" (as mentioned in MCR) is that they have no clue what else to do; they seek safety in numbers by emulating peers and then claim that as a defense when they are breached.
Fortunately, Security Metrics offers another solution. The book gives readers three sets of information: theory, metrics, and tools (concepts, not programs). The theory chapters (1 and 2) were so concise yet insightful I was tempted to underline every sentence. (I am not kidding.) Even the Preface made me glad to be reading the book when it associated "security ROI" with "the Macarena" and called it a "needless distraction." I laughed in agreement when I saw Andy call "security enablement" the "Abominable Snowman: it is rarely spotted, but legions of people swear it exists. After all, as my friend Dan geer puts it, 'You don't usually see airlines advertising how their planes fall out of the sky less often than their competitors.'" Why is that? My answer is simple: security is assumed and expected. Advertising anything else has no effect or makes people suspicious. I knew this book would be good.
The metrics chapters probably list hundreds of metrics you can extract verbatim and apply to your own environment. To the reviewer who wanted to reprint them in an appendix: they're called chapters 3 and 4. My main concern with the metrics was the focus on input-centric measurements instead of results. I would have liked to read more metrics on measuring whether security programs are working, rather than what techniques and tools are applied up front.
The tools chapters were helpful to anyone needing a statistics refresher. The visualization sections were especially helpful. (Feel free to dismiss yet another ignorant review from WB, who thinks a "review" means writing a few paragraphs after flipping through the pages of five books a day.) Andy's examples of turning lousy graphs and charts into information visualization vehicles should be followed by all managers.
Security Metrics is strengthened by the many stories from the author's consulting experience. I sensed that his techniques work and are not the product of the thought laboratory alone. I found his "Balanced Scorecard" approach to be interesting, especially to the degree it ties real metrics to business operations.
I had a few issues with terminology, such as using the term "threats" on p 231 when "attacks" is more accurate. (The football analogy is correct, however.) I semi-agreed with the author's suggestion to abandon "risk management" in favor of metrics-based approaches, but I didn't think two pages (4-5) were really enough to make the case. On p 264, threats are not risks, but they help instantiate risks. On pp 78-7, "risk of exploit" should be "ease of exploitation."
These are minor concerns, given the overwhelming concentration of practical and implementation-worthy pieces of information in Security Metrics. You must read this book if you care to measure security progress. Now we need Dan Geer to extend beyond writing wise forewords and articles into the world of his own book!

Click Here to see more reviews about: Security Metrics: Replacing Fear, Uncertainty, and Doubt

The Definitive Guide to Quantifying, Classifying, and Measuring Enterprise IT Security Operations


Security Metrics is the first comprehensive best-practice guide to defining, creating, and utilizing security metrics in the enterprise.

Usingsample charts, graphics, case studies, and war stories, Yankee GroupSecurity Expert Andrew Jaquith demonstrates exactly how to establisheffective metrics based on your organization's unique requirements.You'll discover how to quantify hard-to-measure security activities,compile and analyze all relevant data, identify strengths andweaknesses, set cost-effective priorities for improvement, and craftcompelling messages for senior management.

Security Metrics successfullybridges management's quantitative viewpoint with the nuts-and-boltsapproach typically taken by security professionals. It brings togetherexpert solutions drawn from Jaquith's extensive consulting work in thesoftware, aerospace, and financial services industries, including newmetrics presented nowhere else. You'll learn how to:

• Replace nonstop crisis response with a systematic approach to security improvement
• Understand the differences between "good" and "bad" metrics
•Measure coverage and control, vulnerability management, passwordquality, patch latency, benchmark scoring, and business-adjusted risk
• Quantify the effectiveness of security acquisition, implementation, and other program activities
• Organize, aggregate, and analyze your data to bring out key insights
• Use visualization to understand and communicate security issues more clearly
• Capture valuable data from firewalls and antivirus logs, third-party auditor reports, and other resources
• Implement balanced scorecards that present compact, holistic views of organizational security effectiveness

Whetheryou're an engineer or consultant responsible for security and reportingto management–or an executive who needs better information fordecision-making–Security Metrics is the resource you have been searching for.

Andrew Jaquith, programmanager for Yankee Group's Security Solutions and Services DecisionService, advises enterprise clients on prioritizing and managingsecurity resources. He also helps security vendors develop product,service, and go-to-market strategies for reaching enterprise customers.He co-founded @stake, Inc., a security consulting pioneer acquired bySymantec Corporation in 2004. His application security and metricsresearch has been featured in CIO, CSO, InformationWeek, IEEE Security and Privacy, and The Economist.

Foreword
Preface
Acknowledgments
About the Author
Chapter1 Introduction:Escaping the Hamster Wheel ofPain
Chapter2 Defining SecurityMetrics
Chapter 3 Diagnosing Problems and Measuring Technical Security
Chapter4 Measuring ProgramEffectiveness
Chapter 5 Analysis Techniques
Chapter 6 Visualization
Chapter 7 Automating Metrics Calculations
Chapter 8 Designing Security Scorecards
Index




Buy NowGet 42% OFF

Click here for more information about Security Metrics: Replacing Fear, Uncertainty, and Doubt

Read More...

1/23/2012

Mike Meyers' CISSP(R) Certification Passport Review

Mike Meyers' CISSP(R) Certification Passport
Average Reviews:

(More customer reviews)
The CISSP strikes terror for some, since it is not an easy exam to prepare for. I picked up this book because of its portability (I travel so I need something light to carry around), not expecting anything substantial to be inside, only pointers to help me remember some of the material I have already covered. Instead, I found this book to be a gem, a book full of concise material written in style that is uncluttered, presented in a format that is structured. Plus, the book offers online questions for practice. Besides the occasional typo or two, the only fault I can criticize about the book is its Q&A section--it seemed a little too simple for a professional exam.
Overall, I would recommend this book as a good first book to use, to quickly gain as much grasp of the security concepts in as little time as possible, and then slowly graduate to the more substantial offerings from QUE or Wiley.

Click Here to see more reviews about: Mike Meyers' CISSP(R) Certification Passport



Buy Now

Click here for more information about Mike Meyers' CISSP(R) Certification Passport

Read More...

12/22/2011

CISSP All-in-One Exam Guide, Fifth Edition Review

CISSP All-in-One Exam Guide, Fifth Edition
Average Reviews:

(More customer reviews)
There is no simple formula to prepare for the CISSP certification, and no single resource which can guarantee success on the certification exam since every applicant's background is unique. However, this book (fifth edition) was my only resource in preparing for the exam and I passed on my first attempt (April 24, 2010).
I spent 60+ hours in preparation for the exam... that's 60+ hours of DEDICATED individual study using this book and CD, not 60+ hours spent web surfing during lunch hours or commercial breaks. My recent background is in middle management, with 20 years experience in network architecture and data security, so I already had a firm technical foundation for the test areas dealing with protocols and encryption variations. I also have an MS in Computer Science. Nonetheless, the exam was so broad, with topics covering general principles and concepts, that I could have prepared twice as long and still left the exam with questions about the outcome.
My personal opinion is that formal classroom instruction, through one of the many organizations offering CISSP preparation courses, is a worthwhile companion to Shon Harris' book. A study group is also a good idea. You will not obtain CISSP certification if you take the exam without preparation. This book (fifth edition) was sufficient, but not 100% comprehensive, to prepare me for passing the CISSP test.
Note: Some reviewers do not appreciate Shon's frequent analogies and humor. Most of her analogies helped me internalize the complex topics, but that's my personal learning style. The efforts at humor were generally awful, but every once in a while she was subtle and brilliant enough to make me laugh out loud. Working through Shon's unique writing style was not a problem for me... I actually found it refreshing.

Click Here to see more reviews about: CISSP All-in-One Exam Guide, Fifth Edition

Get complete coverage of the latest release of the Certified Information Systems Security Professional (CISSP) exam inside this comprehensive, fully updated resource. Written by the leading expert in IT security certification and training, this authoritative guide covers all 10 CISSP exam domains developed by the International Information Systems Security Certification Consortium (ISC2). You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass the CISSP exam with ease, this definitive volume also serves as an essential on-the-job reference.
COVERS ALL 10 CISSP DOMAINS:
Information security and risk management
Access control
Security architecture and design
Physical and environmental security
Telecommunications and network security
Cryptography
Business continuity and disaster recovery planning
Legal regulations, compliance, and investigations
Application security
Operations security

THE CD-ROM FEATURES:
Hundreds of practice exam questions
Video training excerpt from the author
E-book

Shon Harris, CISSP, is a security consultant, a former member of the Information Warfare unit in the Air Force, and a contributing writer to Information Security Magazine and Windows 2000 Magazine. She is the author of the previous editions of this book.

Buy NowGet 49% OFF

Click here for more information about CISSP All-in-One Exam Guide, Fifth Edition

Read More...

10/09/2011

Principles of Information Security Review

Principles of Information Security
Average Reviews:

(More customer reviews)
This book does provide a broad overview of the concepts of information security. Whatever good information this book does provide is, to some extent, offset by three problems: First, the book is filled with many, many typographical errors. While reading the book, I constantly found myself going back and trying to determine what the writer meant by many of the mangled sentences (or pieces of sentences) in the book. Second, there are a few errors in information. Finally, there are areas where important explanations or details about concepts are completely omitted. The writers needed to do some additional work and editing to make the book's portrayal of many of the concepts it covers clearer and more comprehensive.
There are plenty of free online resources (NIST's Computer Security Resource Center, for example) that would be better places to learn about information security than this text.

Click Here to see more reviews about: Principles of Information Security

The fourth edition of Principles of Information Security explores the field of information security and assurance with updated content including new innovations in technology and methodologies. Readers will revel in the comprehensive coverage that includes a historical overview of information security, discussions on risk management and security technology, current certification information, and more. The text builds on internationally recognized standards and bodies of knowledge to provide the knowledge and skills students need for their future roles as business decision-makers. Information security in the modern organization is a management issue which technology alone cannot answer; it is a problem that has important economic consequences for which management will be held accountable. Readers can feel confident that they are using a standards-based, content-driven resource to prepare for their work in the field.

Buy NowGet 21% OFF

Click here for more information about Principles of Information Security

Read More...

9/14/2011

FISMA Principles and Best Practices: Beyond Compliance Review

FISMA Principles and Best Practices: Beyond Compliance
Average Reviews:

(More customer reviews)
this is one of the better titles on FISMA.
If you work in the govt. arena and have to deal with FISMA, check this book out.
Written by an insider who knows his stuff.

Click Here to see more reviews about: FISMA Principles and Best Practices: Beyond Compliance

While many agenciesstruggle to comply with Federal Information Security Management Act (FISMA) regulations, those that have embraced its requirements have found that their comprehensive and flexible nature provides a sound security risk management framework for the implementation of essential system security controls. Detailing a proven approach for establishing and implementing a comprehensive information security program, FISMA Principles and Best Practices: Beyond Compliance integrates compliance review, technical monitoring, and remediation efforts to explain how to achieve and maintain compliance with FISMA requirements.Based on the author's experience developing, implementing, and maintaining enterprise FISMA-based information technology security programs at three major federal agencies, including the U.S. Department of Housing and Urban Development, the book gives you workable solutions for establishing and operating an effective security compliance program. It delineates the processes, practices, and principles involved in managing the complexities of FISMA compliance. Describing how FISMA can be used to form the basis for an enterprise security risk management program, the book:Provides a comprehensive analysis of FISMA requirementsHighlights the primary considerations forestablishing an effective security compliance programIllustrates successful implementation of FISMA requirements with numerous case studiesClarifying exactly what it takes to gain and maintain FISMA compliance, Pat Howard, CISO of the Nuclear Regulatory Commission, provides detailed guidelines so you can design and staff a compliance capability, build organizational relationships, gain management support, and integrate compliance into the system development life cycle. While there is no such thing as absolute protection, this up-to-date resource reflects the important security concepts and ideas for addressing information security requirements mandated for government agencies and companies subject to these standards.

Buy NowGet 17% OFF

Click here for more information about FISMA Principles and Best Practices: Beyond Compliance

Read More...

9/13/2011

Information Security: Principles and Practices Review

Information Security: Principles and Practices
Average Reviews:

(More customer reviews)
This is the worst textbook I have ever read. I have two degrees and have attended eight different colleges or universities. This book stands alone as being the worst textbook it has been my displeasure to use. The authors cannot follow a simple logical flow on a single topic. Their categorizations wander around. Their examples are sophomoric. Their diagrams are often next to useless. They spend considerable time examining useless minutia and then fail to address key points. Their chapter review questions are either pointlessly easy or completely unintelligible. In many cases, you cannot discern the answers with the book open. Yet, somehow, the exams that accompany the text are an even greater disappointment. They violate every principle of good testing to reinforce objectives and key points. They state in the book that "security through obscurity" is a flawed concept. Yet, they seem to adhere to the principle of "education through obfuscation". Stay away! Stay far away!

Click Here to see more reviews about: Information Security: Principles and Practices

For an introductory course in information security covering principles and practices. This text covers the ten domains in the Information Security Common Body of Knowledge, which are Security Management Practices, Security Architecture and Models, Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP), Law, Investigations, and Ethics, Physical Security, Operations Security, Access Control Systems and Methodology, Cryptography, Telecommunications, Network, and Internet Security.

Buy NowGet 22% OFF

Click here for more information about Information Security: Principles and Practices

Read More...

9/11/2011

Computer Forensics: Principles and Practices Review

Computer Forensics: Principles and Practices
Average Reviews:

(More customer reviews)
I liked the book. It opened my eyes to a lot of areas I knew nothing about. I can understand previous reviewers who weren't happy with the book. Some material is dated and it isn't an All-In-One text on the subject. But, if you're just starting out, like me, it is a great first read. Also, by actually doing the Projects in the back of each chapter, especially Chapter 7 and 8, you'll get a ton of information on very useful forensic topics and techniques including, software that you can download and use for free, etc...
If some websites for the software don't exist anymore, Google the names and the info on where to get it will come up. If you are into learning forensics, having to find this info shouldn't discourage you, otherwise you're learning the wrong subject.
I had a blast with this book and it really wet my appetite to learn more. What more could you want from an introductory text on any subject.

Click Here to see more reviews about: Computer Forensics: Principles and Practices

For introductory and intermediate courses in computer forensics, digital investigations, or computer crime investigationBy applying information systems, computer security, and criminal justice principles and practices to crime investigations and other legal actions, this text teaches students how to use forensically-sound methodologies and software to acquire admissible electronic evidence (e-evidence) with coverage of computer and email forensics, cell phone and IM forensics, and PDA and Blackberry forensics.

Buy NowGet 27% OFF

Click here for more information about Computer Forensics: Principles and Practices

Read More...

9/10/2011

CISSP Practice Questions Exam Cram (2nd Edition) Review

CISSP Practice Questions Exam Cram (2nd Edition)
Average Reviews:

(More customer reviews)
And I have always used and had success with Exam Cram/Prep products. Ever since I went to the methodology of Exam Cram + whatever the best on line testing software, I've never failed a test. That includes Novell, Microsoft (MCSE+I), CCNA (several times), A+, Network+ and Security+. The books have the required information in a readable format. Leading a CISSP group for my company and this is what I have them buy.
The standard for CISSP is the humongous Shon Harris book. To bad it is impossible to get folks to read that one. The DO read the Exam Cram.

Click Here to see more reviews about: CISSP Practice Questions Exam Cram (2nd Edition)



Buy NowGet 29% OFF

Click here for more information about CISSP Practice Questions Exam Cram (2nd Edition)

Read More...