Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

1/04/2013

Web-Based Labs Review

Web-Based Labs
Average Reviews:

(More customer reviews)
I just wanted to post a quick "review" for anyone who hasn't used a LabMentors product before like me. The CD itself is just a Demo CD that shows brief introductory videos on how to set up a new account, and how to navigate the on-line menu system. What you're paying for is the Pass Code that will let you set up a new account, as well as for on-line lab time. You're not actually going to install anything, since all lab work is browser based. Do not buy this product used unless the seller specifically states the Pass Code is unused, but even then I would be weary since you will not be able to access the on-line labs with a used Pass Code. I just recently got this product for a networking class, so I will update this to an actual review of the product itself, once I have completed the course.

Click Here to see more reviews about: Web-Based Labs

The Web-Based Labs provide an actual real-life Microsoft Windows network lab environment over the Internet. With step-by-step labs based on the hands-on projects in Course Technology's proven MCSE/MCSA Guides Microsoft Windows Server 2003, students can log on anywhere, anytime via a Web browser to gain essential hands-on experience with the actual Microsoft Windows Server 2003.

Buy NowGet 21% OFF

Click here for more information about Web-Based Labs

Read More...

6/21/2012

CISA: Certified Information Systems Auditor Study Guide Review

CISA: Certified Information Systems Auditor Study Guide
Average Reviews:

(More customer reviews)
First, this should not be your only reference. There: got that out of the way.
I recommend this book along with the official questions and answers book and the official questions and answers supplement.
This book does a very good job of covering every topic with which you need to be very familiar in order to pass the test. It covers the practice areas as updated for 2006, which haven't changed for 2007. However, the questions in this book are terrible and do not represent the questions you will be asked on the actual test. Also, there are many editing errors in this book so be on the lookout.
The official questions and answers book and its supplement are essential. The test questions are often misleadingly (or just poorly) worded and correctly answering the multiple choice questions often comes down to almost arbitrarily deciding which one is "most" correct. You will have a hard time on the exam if you haven't subjected yourself to this abuse before hand.
I do not recommend the official study guide. The official study guide is so terrible on so many levels I wished I could throw it at an ISACA official after wasting my time and money on it. The writing is terrible: redundant, dry, and often times of questionable use and technical accuracy. The book itself has terrible typography and pedagogy that make it painful to read. The softcover, oversized dimensions, and spiral binding make it very annoying to carry or store anywhere other than on a flat desktop since it flops around. That it was so obviously cheaply produced and yet costs more than $100 is insulting.
So, in summary: This book is worth your money despite its flaws and will help you pass the CISA exam. Make sure you also buy the official questions and answers book and its supplement. Avoid the official study guide.

Click Here to see more reviews about: CISA: Certified Information Systems Auditor Study Guide



Buy Now

Click here for more information about CISA: Certified Information Systems Auditor Study Guide

Read More...

6/14/2012

CompTIA Security+ Study Guide: Exam SY0-101 Review

CompTIA Security+ Study Guide: Exam SY0-101
Average Reviews:

(More customer reviews)
This is an excellent study guide for the Security+ exam. The sample questions on the CD are almost exactly what is on the real exam, in fact I actually found one question that was identical verbatim to what was on the CD. I think going through the chapter exams and reading on the subjects you miss questions on is the best way to study for the Security+ which is a fairly tough exam. This is the only resource I used and I got an 885/900. You will not be disappointed with this book and especially not with the CD which is worth the price by itself thanks to its excellent sample tests.

Click Here to see more reviews about: CompTIA Security+ Study Guide: Exam SY0-101

Take charge of your career with certification that can increase your marketability. This new Deluxe Edition of the top-selling Security + Study Guide is what you need to prepare for CompTIA's Security+ SY0-101 exam. Developed to meet the exacting requirements of today's certification candidates and aspiring IT security professionals, this fully updated, comprehensive book includes:* Clear and concise information on crucial security topics* Six practical exams and over 600 practice questions, more than any other CompTIA Security+ book on the market* Special Security Administrator's Troubleshooting Guide appendix* Practical examples and hands-on labs to prepare you for the real world* Leading-edge exam preparation software, including a test engine and electronic flashcardsInside, find authoritative and coverage of all key exam topics, including:* General security concepts* Communication security* Infrastructure security* Basics of cryptography* Operational and organizational securityThis book has been reviewed and approved as CompTIA Authorized Quality Curriculum (CAQC). Students derive a number of important study advantages with CAQC materials, including coverage of all exam objectives, implementation of important instructional design principles, and instructional reviews that help students assess their learning comprehension and readiness for the exam.Featured on the CDSYBEX TEST ENGINE: Test your knowledge with advanced testing software. Includes all chapter review questions plus bonus exams.ELECTRONIC FLASHCARDS: Reinforce your understanding with flashcards that can run on your PC, Pocket PC, or Palm device.

Buy Now

Click here for more information about CompTIA Security+ Study Guide: Exam SY0-101

Read More...

5/24/2012

CompTIA Security+ Certification Kit: SY0-201 Review

CompTIA Security+ Certification Kit: SY0-201
Average Reviews:

(More customer reviews)
I highly recommend this kit to anyone preparing to take the Security+ exam. I did it by reading the entire Security+ Study Guide while testing myself chapter by chapter using the CDs test engine (also included on the CD is the entire book in PDF format which can be quite convenient). Then I moved onto the Fast Pass book which reinforced what I already knew from the previous book. Also included in the Fast Pass book is another CD with a test engine on it (unfortunately no pdf of the book on this one though). That's really all I did. I studied for about 8-10 hours a day for about 11 days and on day 12 took the exam and passed; I'm now a CompTIA Security+ certified IT Professional!

Click Here to see more reviews about: CompTIA Security+ Certification Kit: SY0-201



Buy NowGet 37% OFF

Click here for more information about CompTIA Security+ Certification Kit: SY0-201

Read More...

5/22/2012

Logged On and Tuned Out: A Non-Techie's Guide to Parenting a Tech-Savvy Generation Review

Logged On and Tuned Out: A Non-Techie's Guide to Parenting a Tech-Savvy Generation
Average Reviews:

(More customer reviews)
Ms. Courtney shares honestly, with humor and without a didactic attitude of judgment. She uses her own experiences, both positive and negative, with her teens' usage of today's technology.
Each chapter explains what the technology is in a way that clarifies it for the most clueless parent and still provides needed cultural context for those of us who might feel pretty savvy. I really appreciated Courtney's perspective on the use of monitoring software. It's controversial, but she recommends it, and explains how and why she uses it to be able to make sure that her children (and their friends) are adhering to her guidelines and conducting themselves online in a way that is God-honoring.
This is a great resource for parents of kids aged ten and up. Certainly the parent of every teen should be well-versed in all of these areas. The social networking chapter was eye-opening to me. As savvy as I am (I mean, I have a blog, don't I?), I have had negatively judged myspace out of ignorance. She calls these sites the "virtual malt shop" of this generation. This is the way that kids connect. They don't have to hang out at the malt shop. Their community exists 24-7 on the world wide web. It gives all new meaning to the old warning, "It's 10:00pm. Do you know where your children are?" They could be at the desk in the study, on the internet, engaging in good clean fun, or perhaps participating in some behavior that they might later regret. If we as parents are tuned in instead of tuned out, we can help them stay in the world, and yet not be of the world.

Click Here to see more reviews about: Logged On and Tuned Out: A Non-Techie's Guide to Parenting a Tech-Savvy Generation



Buy NowGet 15% OFF

Click here for more information about Logged On and Tuned Out: A Non-Techie's Guide to Parenting a Tech-Savvy Generation

Read More...

5/01/2012

Computer Security: Art and Science Review

Computer Security: Art and Science
Average Reviews:

(More customer reviews)
Please understand that the Amazon star system, while very powerful has limits, I feel this book is 5 stars as a textbook for an undergrad computer security course, 4 stars for a graduate student and 3 stars for a book on the average information security worker's shelf.
Computer Security Art and Science has been years in the making and for good reason; it is over a thousand pages. The book seems best suited for four groups of readers. The first group is college students; this will probably be a popular choice as a textbook for undergraduate level students and with additional materials, graduate level students. It is a complete guide to computer security terminology and theory. Other groups of readers that would benefit from this book include security knowledgeable managers seeking to assess the knowledge of potential employees especially in policy and architecture positions. A third group includes anyone preparing for information security certifications. If you are wish to certify you will benefit from a close reading of this text before attempting your examination. Finally, anyone seeking to understand the big picture of information security would benefit from Computer Security Art and Science. However the book's value is primarily as a textbook!
Like most authors writing a security book, Matt has chosen to start at a basic level beginning with a discussion of confidentiality, integrity and availability. As a reviewer I was quietly wondering how long he would stay there. The answer proved to be one chapter only and at the back of the chapter one the author has included insightful, thought provoking study questions. If I were considering hiring someone who claimed to have experience in information security that could not answer these questions, I would show them the door.
Now to consider the rest of the book! On the first page of chapter two we are introduced to logical equations. This is where the casual reader is likely to get off the bus while the diligent student with a qualified instructor gets on. As soon as I saw the equations with no explanation of how to read them, I could see someone browsing in a bookstore shut the cover and move on. Be brave and press on is my advice; the book is well worth it even if some of the illustrations are beyond comprehension without a teacher's guide. It says in the preface this book was designed to be a college level textbook. They have to put a few inscrutable pages in the book so the professors can appear to be smarter than the students.
The cryptography section, chapters 9 - 11 are very approachable and while not as in depth as some other sections, they would help anyone preparing for the various industry security certifications including CompTIA's Security +, ISC2's CISSP and SANS' GSEC. In fact the entire book would be beneficial for any of these.
The table of contents says that part 6 of the book, assurance, chapters 18 - 21, were contributed by a different author, Elisabeth Sullivan. I read those chapters closely and could not detect a different tone or level of quality; the authors are to be congratulated for that. Nice use of humor on the heading title for 18.1.1, "The Need for Assurance" and where else can you read about "Extreme Programming".
No book is perfect, the intrusion detection and penetration testing discussions need to be beefed up, but chapter 29, Program Security more than makes up for them. That chapter should be required reading before anyone is allowed to touch a compiler.
I donate most of the books people send me to review to my local library, but this one stays on the shelf and I am setting an iCal reminder to re-read the policy and audit sections a couple months from now.

Click Here to see more reviews about: Computer Security: Art and Science



Buy NowGet 28% OFF

Click here for more information about Computer Security: Art and Science

Read More...

Windows Server 2008 Security Resource Kit (PRO - Resource Kit) Review

Windows Server 2008 Security Resource Kit (PRO - Resource Kit)
Average Reviews:

(More customer reviews)
Full Disclosure: I wrote the small business chapter.
To Peter who was disappointed because he wanted to see "real world templates for use in his firm". Once upon a time I was just like you and I went and volunteered in a standard setting body to find that magical elixar of a cookie cutter template that would secure me. I found that there isn't a magical button, nor is there a template that I can just magically deploy. No one knows my network but me. Therefore no one but me can secure it.
Remember Dorothy and how she had the power to go home all along but had to learn it? Same thing here. I can't give you the security template that fits my network because it's based on my needs, my risk, my business. It won't fit your needs, your business, your risk.
Each network is unique. So for those of you disappointed in the fact that this doesn't have a slam it down your network and magically it's secure template, be disappointed in yourself first.
You have to determine your own risk, and then you start tweaking and seeing what breaks. Notch the security back for that part, see if you are comfortable with that.

Click Here to see more reviews about: Windows Server 2008 Security Resource Kit (PRO - Resource Kit)



Buy NowGet 23% OFF

Click here for more information about Windows Server 2008 Security Resource Kit (PRO - Resource Kit)

Read More...

4/26/2012

LAN Switch Security: What Hackers Know About Your Switches Review

LAN Switch Security: What Hackers Know About Your Switches
Average Reviews:

(More customer reviews)
I really looked forward to reading LAN Switch Security (LSS), simply because it covered layer 2 issues. These days application security, rootkits, and similar topics get all the press, but the foundation of the network is still critical. Unfortunately, LSS disappointed me enough to warrant this three star review. I'm afraid those before me who wrote five star reviews 1) don't read enough other books or 2) don't set their expectations high enough.
Let me first say I am not anti-Cisco, nor anti-Cisco-book. For an earlier Cisco Press book I wrote "I really enjoyed reading Cisco Router Firewall Security (CRFS) by Richard Deal. This book delivers just what a technical Cisco book should: discussion of concepts, explanation of command syntax, and practical examples." LSS, however, is not what I like to see in a Cisco book. It suffers the major flaw found in almost all technical books featuring large numbers of writers (LSS has 2 authors, 4 contributors, 2 tech editors): incoherence and overlapping discussions. Furthermore, many of these contributors do not write clearly. I found large sections to be disjointed and inconsistent. It is clear that no one stepped up to the plate to see if the finished product made any sense from the reader's perspective.
The second major problem with this book is that older books easily overpower LSS. For example, in March 2006 I gave Hacking Exposed: Cisco Networks (HECN) four stars. HECN covers many of the same topics as LSS, more clearly, with more syntax, and better explanations. Anyone who wants to buy a book about layer 2 security should start with HECN. If you don't want to buy a book, just download the free 86-page Cisco IOS Switch Security Configuration Guide published by NSA.
If you read HECN or the NSA guide, you'll be struck by the amount of configuration syntax in those resources. If you glance through LSS you'll see syntax, but (and this bothered me greatly) not for all the features discussed. For example, LSS ch 16 (Wire Speed Access Control Lists) features sections titled "Working with RACL", "Working with VACL", and "Working with PACL". That's great -- six pages (pp 263-268), with no command syntax! Sure, you can read about using VACLs for traffic capture, but where are the examples? If you tell me they are the same as other examples, I want to see the proof. This is the sort of glaring omission that really frustrated me.
I did like some of LSS. I thought attacks against link aggregation protocols, discussions of control plane policy, and spanning tree protocol were interesting. Adding discussions of ARP spoofing a remote gateway using Yersinia would have been helpful. There's a decent number of typos (POP != "point of presence", replace "Ethernet" with "IP" on p 235), but technically the book seemed sound. (One of the authors was kind enough to confirm the p 235 typo; I wanted to be sure I hadn't missed something important.)
I notice Cisco is publishing a book titled Router Security Strategies: Securing IP Network Traffic Planes in December. Presumably that will be a counterpart to this title, except at layer 3. I hope that new book avoids the mistakes made by LSS.

Click Here to see more reviews about: LAN Switch Security: What Hackers Know About Your Switches

LAN Switch Security: What Hackers Know About Your SwitchesA practical guide to hardening Layer 2 devices and stopping campus network attacksEric VynckeChristopher Paggen, CCIE® No. 2659Contrary to popular belief, Ethernet switches are not inherently secure. Security vulnerabilities in Ethernet switches are multiple: from the switch implementation, to control plane protocols (Spanning Tree Protocol [STP], Cisco® Discovery Protocol [CDP], and so on) and data plane protocols, such as Address Routing Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP). LAN Switch Security explains all the vulnerabilities in a network infrastructure related to Ethernet switches. Further, this book shows you how to configure a switch to prevent or to mitigate attacks based on those vulnerabilities. This book also includes a section on how to use an Ethernet switch to increase the security of a network and prevent future attacks.Divided into four parts, LAN Switch Security provides you with steps you can take to ensure the integrity of both voice and data traffic traveling over Layer 2 devices. Part I covers vulnerabilities in Layer 2 protocols and how to configure switches to prevent attacks against those vulnerabilities. Part II addresses denial-of-service (DoS) attacks on an Ethernet switch and shows how those attacks can be mitigated. Part III shows how a switch can actually augment the security of a network through the utilization of wirespeed access control list (ACL) processing and IEEE 802.1x for user authentication and authorization. Part IV examines future developments from the LinkSec working group at the IEEE. For all parts, most of the content is vendor independent and is useful for all network architects deploying Ethernet switches.After reading this book, you will have an in-depth understanding of LAN security and be prepared to plug the security holes that exist in a great number of campus networks. Eric Vyncke has a master's degree in computer science engineering from the University of Liège in Belgium. Since 1997, Eric has worked as a Distinguished Consulting Engineer for Cisco, where he is a technical consultant for security covering Europe. His area of expertise for 20 years has been mainly security from Layer 2 to applications. He is also guest professor at Belgian universities for security seminars. Christopher Paggen, CCIE® No. 2659, obtained a degree in computer science from IESSL in Liège (Belgium) and a master's degree in economics from University of Mons-Hainaut (UMH) in Belgium. He has been with Cisco since 1996 where he has held various positions in the fields of LAN switching and security, either as pre-sales support, post-sales support, network design engineer, or technical advisor to various engineering teams. Christopher is a frequent speaker at events, such as Networkers, and has filed several U.S. patents in the security area.Contributing Authors:Jason Frazier is a technical leader in the Technology Systems Engineering group for Cisco.Steinthor Bjarnason is a consulting engineer for Cisco.Ken Hook is a switch security solution manager for Cisco.Rajesh Bhandari is a technical leader and a network security solutions architect for Cisco.Use port security to protect against CAM attacksPrevent spanning-tree attacks Isolate VLANs with proper configuration techniquesProtect against rogue DHCP serversBlock ARP snoopingPrevent IPv6 neighbor discovery and router solicitation exploitationIdentify Power over Ethernet vulnerabilitiesMitigate risks from HSRP and VRPPStop information leaks with CDP, PaGP, VTP, CGMP and other Cisco ancillary protocolsUnderstand and prevent DoS attacks against switchesEnforce simple wirespeed security policies with ACLsImplement user authentication on a port base with IEEE 802.1xUse new IEEE protocols to encrypt all Ethernet frames at wirespeed.This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.Category: Cisco Press—SecurityCovers: Ethernet Switch Security$60.00 USA / $69.00 CANLAN Switch Security: What Hackers Know About Your SwitchesA practical guide to hardening Layer 2 devices and stopping campus network attacksEric VynckeChristopher Paggen, CCIE® No. 2659Contrary to popular belief, Ethernet switches are not inherently secure. Security vulnerabilities in Ethernet switches are multiple: from the switch implementation, to control plane protocols (Spanning Tree Protocol [STP], Cisco® Discovery Protocol [CDP], and so on) and data plane protocols, such as Address Routing Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP). LAN Switch Security explains all the vulnerabilities in a network infrastructure related to Ethernet switches. Further, this book shows you how to configure a switch to prevent or to mitigate attacks based on those vulnerabilities. This book also includes a section on how to use an Ethernet switch to increase the security of a network and prevent future attacks.Divided into four parts, LAN Switch Security provides you with steps you can take to ensure the integrity of both voice and data traffic traveling over Layer 2 devices. Part I covers vulnerabilities in Layer 2 protocols and how to configure switches to prevent attacks against those vulnerabilities. Part II addresses denial-of-service (DoS) attacks on an Ethernet switch and shows how those attacks can be mitigated. Part III shows how a switch can actually augment the security of a network through the utilization of wirespeed access control list (ACL) processing and IEEE 802.1x for user authentication and authorization. Part IV examines future developments from the LinkSec working group at the IEEE. For all parts, most of the content is vendor independent and is useful for all network architects deploying Ethernet switches.After reading this book, you will have an in-depth understanding of LAN security and be prepared to plug the security holes that exist in a great number of campus networks. Eric Vyncke has a master's degree in computer science engineering from the University of Liège in Belgium. Since 1997, Eric has worked as a Distinguished Consulting Engineer for Cisco, where he is a technical consultant for security covering Europe. His area of expertise for 20 years has been mainly security from Layer 2 to applications. He is also guest professor at Belgian universities for security seminars. Christopher Paggen, CCIE® No. 2659, obtained a degree in computer science from IESSL in Liège (Belgium) and a master's degree in economics from University of Mons-Hainaut (UMH) in Belgium. He has been with Cisco since 1996 where he has held various positions in the fields of LAN switching and security, either as pre-sales support, post-sales support, network design engineer, or technical advisor to various engineering teams. Christopher is a frequent speaker at events, such as Networkers, and has filed several U.S. patents in the security area.Contributing Authors:Jason Frazier is a technical leader in the Technology Systems Engineering group for Cisco.Steinthor Bjarnason is a consulting engineer for Cisco.Ken Hook is a switch security solution manager for Cisco.Rajesh Bhandari is a technical leader and a network security solutions architect for Cisco.Use port security to protect against CAM attacksPrevent spanning-tree attacks Isolate VLANs with proper configuration techniquesProtect against rogue DHCP serversBlock ARP snoopingPrevent IPv6 neighbor discovery and router solicitation exploitationIdentify Power over Ethernet vulnerabilitiesMitigate risks from HSRP and VRPP...

Buy NowGet 29% OFF

Click here for more information about LAN Switch Security: What Hackers Know About Your Switches

Read More...

4/24/2012

Security+ Certification Exam Cram 2 (Exam Cram SYO-101) Review

Security+ Certification Exam Cram 2 (Exam Cram SYO-101)
Average Reviews:

(More customer reviews)
I have never used the Exam Cram series books as a single source to prepare for any certification exam. I believe that their intent is to provide a good final review of the subject matter in preparation for an exam -- sort of like the old Cliff Notes that we used to buy in college. Coupled with the PrepLogic exam on the CD (you would do well to purchase the complete set of questions), it is an adequate preparation tool.
The only criticism that I can offer is that the material in the book (as well as the PrepLogic practice exams) tends to err on the easy side. I found myself scoring consistently in the low 90's on the first take of each practice exam, whereas I passed the actual test with a score of 828.
The Security+ exam is not an overly difficult test, but it is not a pushover either. If you use this book as it was intended to be used, it will probably help you. If you use it as your sole source of study, you will probably be disappointed with the outcome.

Click Here to see more reviews about: Security+ Certification Exam Cram 2 (Exam Cram SYO-101)



Buy Now

Click here for more information about Security+ Certification Exam Cram 2 (Exam Cram SYO-101)

Read More...

4/15/2012

Mapping Security: The Corporate Security Sourcebook for Today's Global Economy Review

Mapping Security: The Corporate Security Sourcebook for Today's Global Economy
Average Reviews:

(More customer reviews)
Creating an effective information security infrastructure for a large multi-national company is a challenge. Above and beyond the technology, the software, and the hardware, there are non-tangibles, specificially the cultures and laws where the security solutions, people, and technology will be deployed. Deploying technology without considering the local environment and culture is a sure-fire way to undermine a project.
Today's technology infrastructure is getting more and more complex. Companies are more global with more porous borders. Outsourcing is increasing dramatically, creating an additional need to understand the cultures in the remote locations.
Given all that, Mapping Security: The Corporate Security Sourcebook for Today's Global Economy is a valuable guidebook to deploying information security outside of the United States. Author Tom Patterson is a former Big 4 Information Security partner whose job responsibilities saw him living abroad for much of his adult life. The book is not so much a network security title, but rather a guide to performing the business of security across various cultural and physical borders. Mapping Security is management-level source book for companies and organizations that do - or plan to do - business outside of the United States. Patterson takes his years of living abroad, his successes and his failures, his war stories, and his challenges, and maps them into a usable framework so the reader can better deploy an information security program.
In the book, Patterson details the various opportunities and challenges in each geographic sector across the globe and provides security best practices, rules, and customs for 30 countries. Patterson does a good job of explaining how and where Americans are often perceived to be arrogant by having a overly U.S.-centric view of things.
The book is divided in three parts. Part 1 details the manner in which an effective information security infrastructure can be developed. Chapters 1 through 7 show the necessary steps to building an effective security culture. The book, especially Part 1, is focused not so much on specific technology but rather the processes in which to develop such a security infrastructure.
The heart of the book is in Part 2 where Patterson details his Mapping Security Index (MSI). The function of the MSI is to provide the reader with a metric to determine how an organization can perform security functions in a different country. The book has an MSI for 30 countries, but it does not detail every country, only those where U.S.organizations are likely to do business.
Peterson's expertise comes from living abroad extensively and bringing to the table how business should be done in whatever country you are dealing with. Two of the countries with the highest MSI are Netherlands (90) and Canada (93), with Russia (26) and Saudi Arabia (32) at the bottom. The main advantages of the Netherlands and Canada are that they both have a safe, stable, and effective infrastructure in which to build an information security organization.
Russia, on the other hand, while having a strong technical outsourcing potential has a legal and technical infrastructure that is significantly lacking. Additionally, most other business services are not yet on par with the rest of the region. As to Saudi Arabia, Patterson notes that while it provides a growing domestic marketing, it is an extremely difficult security partner to deal with and has very little cross-border activity. There is extremely little opportunity for women when it comes to the region. He notes that it is practically impossible for women to do business there and observes that "surrendering gender equity is simply the cost of doing business in Saudi Arabia".
Part 3 of the book deals with that challenge of mapping various laws and regulations from different countries. Part of the challenge and headache is dealing with laws from different countries that are contradictory. For example, one country might require an organization to capture and report customer information, while another country forbids it. The question becomes whose law do you break? That is not an easy question to answer, but it is one that needs to be considered.
The author notes that security standards and regulations are the biggest drivers for security around the world and a misstep in dealing with regulations can create the scenario where one could face business impairments, fines, or even prison.
Overall, Mapping Security: The Corporate Security Sourcebook for Today's Global Economy is a very valuable reference guide for anyone who needs to deal with information security in different countries and cultures. By relating security to the international community, the book enables the reader to avoid making those mistakes that can sink a security project.
Patterson has a keen business insight, and the book provides many of his war stories (from illegal barbeques in Germany to an innocuous racial fax paus in South Africa). The book is not overly technical in nature and is both entertaining and informative. For anyone that plans to deploy security outside of the United States Mapping Security should be required reading.


Click Here to see more reviews about: Mapping Security: The Corporate Security Sourcebook for Today's Global Economy



Buy NowGet 31% OFF

Click here for more information about Mapping Security: The Corporate Security Sourcebook for Today's Global Economy

Read More...

4/07/2012

CompTIA Security+ Deluxe Study Guide: Exam SY0-301 Review

CompTIA Security+ Deluxe Study Guide: Exam SY0-301
Average Reviews:

(More customer reviews)
Curious as to what the differences are between the standard edition of the study guide (which sells for much less) and the "Deluxe" edition, it turns out the most significant difference is in the media. For some reason, the publisher isn't going out of their way to make it readily apparent, but the Deluxe/hardbound edition has a CD which includes a slew of items not in the standard edition. Among them: almost an hour of video on security topics, a "simulation engine" that lets you test your knowledge with something other than multiple choice, more bonus tests and a whole lot of PDFs - lab exercises, cabling info, etc. There is so much value in the CD alone, that it would be nice to see it packaged and sold separate or at least advertised as being the differentiator between the two books.

Click Here to see more reviews about: CompTIA Security+ Deluxe Study Guide: Exam SY0-301

Get a host of extras with this Deluxe versionincluding a Security Administration Simulator!
Prepare for CompTIA's new Security+ exam SY0-301 with this Deluxe Edition of our popular CompTIA Security+ Study Guide, 5th Edition. In addition to the 100% coverage of all exam essentials and study tools you'll find in the regular study guide, the Deluxe Edition gives you over additional hands-on lab exercises and study tools, three additional practice exams, author videos, and the exclusive Security Administration simulator. This book is a CompTIA Recommended product.

Provides 100% coverage of all exam objectives for Security+ exam SY0-301 including:
Network security
Compliance and operational security
Threats and vulnerabilities
Application, data and host security
Access control and identity management
Cryptography

Features Deluxe-Edition-only additional practice exams, value-added hands-on lab exercises and study tools, and exclusive Security Administrator simulations, so you can practice in a real-world environment
Covers key topics such as general security concepts, communication and infrastructure security, the basics of cryptography, operational security, and more
Shows you pages of practical examples and offers insights drawn from the real world

Get deluxe preparation, pass the exam, and jump-start your career. It all starts with CompTIA Security+ Deluxe Study Guide, 2nd Edition.


Buy NowGet 45% OFF

Click here for more information about CompTIA Security+ Deluxe Study Guide: Exam SY0-301

Read More...

4/01/2012

CompTIA Security+Study Guide: Exam SY0-201 Review

CompTIA Security+Study Guide: Exam SY0-201
Average Reviews:

(More customer reviews)
The book is built on a clean language, the ideas are well organized inside each chapter, but you could perceive that chapters themselves are not in the optimal order...Sometimes you have to jump from one chapter to another to cover completely an idea exposed in this book.
On the other hand, you will have to buy additional simulations and practice questions to complete your preparation, because this book does not offer you practice questions with the appropiate level of complexity compared to the real exam.

Click Here to see more reviews about: CompTIA Security+Study Guide: Exam SY0-201

Comprehensive Coverage to Help You Prepare for the SY0-201 Exam and Beyond

This CompTIA Authorized Study Guide provides complete coverage of the objectives for CompTIA's Security+ Exam (SY0-201), with clear and concise information on crucial security topics. Learn from practical examples and insights drawn from real-world experience and review your newly acquired knowledge with cutting-edge exam preparation software, including a test engine and electronic flashcards. Find authoritative coverage of key exam topics like general security concepts, communication security, infrastructure security, the basics of cryptography and operational and organizational security.

Coverage includes:

General Security Concepts
Identifying Potential Risks
Infrastructure and Connectivity
Monitoring Activity and Intrusion Detection
Implementing and Maintaining a Secure Network
Securing the Network and Environment
Cryptography Basics, Methods, and Standards
Security Policies and Procedures
Security Administration

FEATURED ON THE CD:

Sybex Test Engine including an assessment test and practice exam
Chapter Review Questions
Electronic Flashcards
Entire book in a searchable PDF

Note: CD-ROM/DVD and other supplementary materials are not included as part of eBook file.

For Instructors: Teaching supplements are available for this title.


Buy NowGet 47% OFF

Click here for more information about CompTIA Security+Study Guide: Exam SY0-201

Read More...

3/30/2012

CompTIA Security+ Certification Study Guide, Third Edition: Exam SY0-201 3E Review

CompTIA Security+ Certification Study Guide, Third Edition: Exam SY0-201 3E
Average Reviews:

(More customer reviews)
The book came quickly and was in great shape!
I own two other books on the Security+ exam,( Sybex's CompTIA Security+ Review Guide: SY0-201 and CompTIA Security+ Exam Cram (1st Edition)) This one from Syngress is clearly the better study guide! Loved the chapter on virtual technology. They cover the exam completely and in some areas they give more than scope of the exam.
I'm very impressed with the way exam objectives are clearly outlined and detailed to the CompTIA way of doing things. It's one thing to know IT security, but for the exam you also need to know how the CompTIA exam author(s) think. If your looking for a quick easy study guide to pass the Security+ exam I think this is one of the best books to pick-up.
-Bruce Security+, Project+, Linux+, A+, CISSP, MCSE, CCENT, ITIL

Click Here to see more reviews about: CompTIA Security+ Certification Study Guide, Third Edition: Exam SY0-201 3E


CompTIA's Security+ certification is a globally-recognized, vendor neutral exam that has helped over 60,000 IT professionals reach further and higher in their careers. The current Security+ exam (SY0-201) focuses more on being able to deal with security issues rather than just identifying them.



The new exam covers six major topics: Systems Security, Network Infrastructure, Access Control, Assessments and Audits, Cryptography, and Organizational Security.

This third edition has been updated to follow and cover the new exam objectives. After reading this book not only will you be able to pass the exam but you will have a working knowledge of cryptography, security legislation, vulnerability assessments, logical access control methods, and much more.
*Complete exam-prep package includes full coverage of new Security+ objectives andtwo complete practice exams*Authored by a leading Microsoft security expert.*A good reference for both beginning security professionals and a seasoned IT person, this book goes beyond the exam objectives to cover the technology, and how that technology is currently being deployed in the business world and what the future of the technology may be. These insights provide the reader a look "inside" security, both today and in the future.

Buy NowGet 38% OFF

Click here for more information about CompTIA Security+ Certification Study Guide, Third Edition: Exam SY0-201 3E

Read More...

3/09/2012

Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption Review

Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption
Average Reviews:

(More customer reviews)
Agree completely with all of the other reviewers in respect to practical working examples and detailed information. This is nothing more than a high-level overview of documentation and specifications you can easily find yourself on the internet. Look elsewhere (and yeah, I'm still looking myself) for solid information about how to design and deploy WS-* applications.

Click Here to see more reviews about: Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption



Buy NowGet 32% OFF

Click here for more information about Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption

Read More...

3/03/2012

CompTIA Security+ Deluxe Study Guide: SY0-201 Review

CompTIA Security+ Deluxe Study Guide: SY0-201
Average Reviews:

(More customer reviews)
I purchased this book 3 weeks before I sat for the exam. The book content, flash cards and 4 practice exams were just the right balance to pass the exam. I would recommend this book to anyone needing/wanting to get the Security+ certification.

Click Here to see more reviews about: CompTIA Security+ Deluxe Study Guide: SY0-201



Buy NowGet 37% OFF

Click here for more information about CompTIA Security+ Deluxe Study Guide: SY0-201

Read More...

2/28/2012

MPLS VPN Security Review

MPLS VPN Security
Average Reviews:

(More customer reviews)
MPLS VPN Security (Paperback)
by Michael H. Behringer, Monique J. Morrow ISBN 1587051834
As Multiprocotol Label Switching (MPLS) is becoming widely deployed for providing virtual private network (VPN) services. Security becomes a major concern for companies planning to migrate from the legacy VPN's to MPLS VPN's. This book provides an indepth look at what are the real security issues that both service providers providing MPLS VPN's and companies utlizing such services face. The authors provide a clear understanding of how the MPLS VPN's work differently from other VPN technologies.
The book is divided into four parts MPLS VPN and Security Fundamentals form Part One. The first part of the book provides an excellent overview on the three basic components of security: the architecture, design and operations and defines the "zones of trust" for an MPLS VPN environment. It provides an excellent Security Reference Model for MPLS VPNs. The various threats to a VPN are broken down into parts for better understanding, like threat, intrusion, Denial of Service against a VPN. Threat against an Extranet site. Threats against the core, and from within a Zone of trust.
Part Two of the book provides an analysis of Advanced MPLS VPN Security Issues like VPN Seperation (Address Space and traffic), Robustness against attacks (where and how), protection against spoofing, Specific Inter-AS considerations and comparisons. And other issues not addressed by the MPLS Architecture. It examines in detail Secure MPLS VPN designs and shows how to design a DOS resistant network and the tradeoffs between DOS resistance and network cost. The security recommendations provide tips on general router security, basic templates and ACL Examples. CE-Specific router security and topology design considerations. LAN Security Issues. CE-PE routing Security Best Practices. IPSec both CE to CE and PE to PE. And a comprehensive checklist for securing Core and Routing.
Part Three provides practical guidelines to MPLS VNP Security and shows how IPSec complements MPLS. It explains the deployment of IPSec on MPLS and use of other encryption techniques. It underlines the importance of security of MPLS Layer 2 VPNs and the various generic Layer 2 security considerations. The section ends with providing a plan for the operation management and maintenance of a MPLS core. It deals with the secure management of CE devices, management of VRF and VRF details.
Part Four provides deployment examples and lessons learned, highlighting theoretical discussion points from the previous chapters. It also provides various scenarios for internet access and points out security considerations for each example.
The coauthor Michael H. Behringer is an active member of the IETF and has published work on MPLS VPN security since 2001.
The coauthor Monique J. Morrow (CCIE # 1711) is active in both IETF and ITU-T SG 13 with a focus on OAM. She is currently engaged in MPLS OAM standards development.
I feel this book would be extremely useful for security and operations staff of enterprises that deploy MPLS or subscribe to a service based on MPLS.
I give this book 5 stars on a scale of 5, 5 being the highest. I strongly recommend this book.
Niloufer Tamboly, CISSP



Click Here to see more reviews about: MPLS VPN Security

A practical guide to hardening MPLS networksDefine "zones of trust" for your MPLS VPN environment Understand fundamental security principles and how MPLS VPNs work Build an MPLS VPN threat model that defines attack points, such as VPN separation, VPN spoofing, DoS against the network's backbone, misconfigurations, sniffing, and inside attack forms Identify VPN security requirements, including robustness against attacks, hiding of the core infrastructure, protection against spoofing, and ATM/Frame Relay security comparisons Interpret complex architectures such as extranet access with recommendations of Inter-AS, carrier-supporting carriers, Layer 2 security considerations, and multiple provider trust model issues Operate and maintain a secure MPLS core with industry best practices Integrate IPsec into your MPLS VPN for extra security in encryption and data origin verification Build VPNs by interconnecting Layer 2 networks with new available architectures such as virtual private wire service (VPWS) and virtual private LAN service (VPLS) Protect your core network from attack by considering Operations, Administration, and Management (OAM) and MPLS backbone security incidentsMultiprotocol Label Switching (MPLS) is becoming a widely deployed technology, specifically for providing virtual private network (VPN) services. Security is a major concern for companies migrating to MPLS VPNs from existing VPN technologies such as ATM. Organizations deploying MPLS VPNs need security best practices for protecting their networks, specifically for the more complex deployment models such as inter-provider networks and Internet provisioning on the network. MPLS VPN Security is the first book to address the security features of MPLS VPN networks and to show you how to harden and securely operate an MPLS network. Divided into four parts, the book begins with an overview of security and VPN technology. A chapter on threats and attack points provides a foundation for the discussion in later chapters. Part II addresses overall security from various perspectives, including architectural, design, and operation components. Part III provides practical guidelines for implementing MPLS VPN security. Part IV presents real-world case studies that encompass details from all the previous chapters to provide examples of overall secure solutions. Drawing upon the authors' considerable experience in attack mitigation and infrastructure security, MPLS VPN Security is your practical guide to understanding how to effectively secure communications in an MPLS environment."The authors of this book, Michael Behringer and Monique Morrow, have a deep and rich understanding of security issues, such as denial-of-service attack prevention and infrastructure protection from network vulnerabilities. They offer a very practical perspective on the deployment scenarios, thereby demystifying a complex topic. I hope you enjoy their insights into the design of self-defending networks."—Jayshree V. Ullal, Senior VP/GM Security Technology Group, Cisco Systems®

Buy NowGet 19% OFF

Click here for more information about MPLS VPN Security

Read More...

2/23/2012

Cryptography : Theory and Practice Review

Cryptography : Theory and Practice
Average Reviews:

(More customer reviews)
As other people have pointed out, this is not a mathematics book, and it is not an algorithm (recipies) book. It could be a great book for people that are interested in learning these tools to actually use them, either in a research or product development context (something besides homework). Unfortunately, the number of typos, in key mathematical expressions AND PORTIONS OF THE EXPLANATIONS is staggering. Go to the author's web page and you will find that some chapters, like 4 for example, average more than one typo per page (and some of these 'typos' are full sentences, or math expressions that do not look like anything that is actually printed on the page). If you do not have that errata sheet handy, you will waste a lot of time trying to understand the text, or trying to solve the exercises. If you are trying to learn from this book, without attending a class and without the errata, you will simply give up. It is a real shame because it has all the makings of a great book.

Click Here to see more reviews about: Cryptography : Theory and Practice



Buy Now

Click here for more information about Cryptography : Theory and Practice

Read More...