Data Breaches Exposed: Downs, Ups, and How to End Up Better Off
暫譯: 數據洩漏揭露:挑戰、機遇及如何獲得更好的結果

Sherri Davidoff

商品描述

Why do some organizations emerge from a data breach unscathed, while others are badly damaged, or even collapse? How can you make smart choices to protect your organization before and after a data breach? This book exposes the high-octane world of data breach disclosure and response, where IT help desk staff have the power to save or destroy a company, and cutting-edge attorneys must often parachute in to save the day. You’ll watch as one of the world’s most experienced cybersecurity professionals dissects high-profile data breaches, reveals what happened, and reveals exactly what you can do to navigate a massive data breach -- quickly mitigating damage to your digital assets, finances, and organizational reputation.

 

Sherri Davidoff teaches through storytelling, making this book powerfully accessible and practically useful to everyone from the boardroom to the server closet. Along the way, she reveals what the press didn’t cover about attacks on ChoicePoint, TJ Maxx, Heartland, Target, Anthem, and many other leading organizations -- and presenting specific lessons you can start applying right now, regardless of your technical or business infrastructure.

 

Drawing on her immense personal experience with digital forensics, incident response, security awareness training, penetration testing, and web security assessment -- and her work teaching in venues from Black Hat to the Department of Defense -- Davidoff introduces today’s most comprehensive and practical framework for data breach response. You’ll discover:

  • Critical turning points throughout data breach events, and how to respond to each of them
  • How breach response lifecycles are changing: why classic incident response approaches are no longer sufficient, and what to do instead
  • How internal politics can affect data breach response, and what to do about it
  • How to read between the lines of public statements and notifications (or lack thereof)
  • What you need to know about breaches in retail and other specific industries -- and the limitations of standards such as PCI/DSS
  • How to protect against and recover from ransomware
  • How to assess products and services such as Commercial Off-The-Shelf Breach Response, cybersecurity insurance, and crisis management services
  • What you can do right now to make breach response less traumatic

商品描述(中文翻譯)

為什麼有些組織在資料外洩事件中毫髮無傷,而另一些則受到重創,甚至崩潰?在資料外洩之前和之後,您該如何做出明智的選擇來保護您的組織?本書揭示了資料外洩披露和應對的高壓世界,在這裡,IT客服人員擁有拯救或摧毀公司的權力,而尖端律師則常常需要緊急出動以挽救局面。您將看到世界上最有經驗的網路安全專業人士之一剖析高知名度的資料外洩事件,揭示發生了什麼,並具體說明您可以採取哪些措施來應對大規模的資料外洩——迅速減輕對您的數位資產、財務和組織聲譽的損害。

Sherri Davidoff透過故事講述進行教學,使本書對從董事會到伺服器機櫃的每個人都極具可讀性和實用性。在此過程中,她揭示了媒體未報導的關於ChoicePoint、TJ Maxx、Heartland、Target、Anthem及其他許多領先組織的攻擊事件,並提供了您現在就可以開始應用的具體教訓,無論您的技術或商業基礎設施如何。

根據她在數位取證、事件應對、安全意識訓練、滲透測試和網路安全評估方面的豐富個人經驗,以及她在從Black Hat到國防部等場所的教學工作,Davidoff介紹了當今最全面和實用的資料外洩應對框架。您將發現:

- 資料外洩事件中的關鍵轉折點,以及如何對每個轉折點作出反應
- 資料外洩應對生命週期的變化:為什麼傳統的事件應對方法已不再足夠,以及應該採取什麼替代措施
- 內部政治如何影響資料外洩應對,以及該如何處理
- 如何解讀公開聲明和通知(或缺乏通知)中的潛台詞
- 您需要了解的零售及其他特定行業的資料外洩情況——以及像PCI/DSS這樣的標準的局限性
- 如何防範和從勒索病毒中恢復
- 如何評估商業現成的資料外洩應對、網路安全保險和危機管理服務等產品和服務
- 您現在可以做什麼來減輕資料外洩應對的創傷感