Security without Obscurity: Frequently Asked Questions (FAQ)
暫譯: 不隱藏的安全:常見問題解答 (FAQ)

Stapleton, Jeff

  • 出版商: CRC
  • 出版日期: 2022-05-30
  • 售價: $2,020
  • 貴賓價: 9.5$1,919
  • 語言: 英文
  • 頁數: 254
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 0367708132
  • ISBN-13: 9780367708139
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Security without Obscurity: Frequently Asked Questions (FAQ) complements Jeff Stapleton's three other Security without Obscurity books to provide clear information and answers to the most commonly asked questions about information security (IS) solutions that use or rely on cryptography and key management methods. There are good and bad cryptography, bad ways of using good cryptography, and both good and bad key management methods. Consequently, information security solutions often have common but somewhat unique issues. These common and unique issues are expressed as an FAQ organized by related topic areas.

The FAQ in this book can be used as a reference guide to help address such issues. Cybersecurity is based on information technology (IT) that is managed using IS controls, but there is information, misinformation, and disinformation. Information reflects things that are accurate about security standards, models, protocols, algorithms, and products. Misinformation includes misnomers, misunderstandings, and lack of knowledge. Disinformation can occur when marketing claims either misuse or abuse terminology, alluding to things that are inaccurate or subjective. This FAQ provides information and distills misinformation and disinformation about cybersecurity.

This book will be useful to security professionals, technology professionals, assessors, auditors, managers, and hopefully even senior management who want a quick, straightforward answer to their questions. It will serve as a quick reference to always have ready on an office shelf. As any good security professional knows, no one can know everything.

商品描述(中文翻譯)

《安全無需模糊:常見問題解答(FAQ)》補充了 Jeff Stapleton 的另外三本《安全無需模糊》書籍,提供有關使用或依賴加密技術和金鑰管理方法的信息安全(IS)解決方案的常見問題的清晰信息和答案。加密技術有好有壞,使用良好加密技術的方式也有不當之處,金鑰管理方法同樣有好有壞。因此,信息安全解決方案通常面臨一些共同但又獨特的問題。這些共同和獨特的問題以常見問題解答的形式表達,並按相關主題區域進行組織。

本書中的常見問題解答可作為參考指南,幫助解決這些問題。網絡安全基於使用信息安全控制管理的信息技術(IT),但存在信息、錯誤信息和虛假信息。信息反映了有關安全標準、模型、協議、算法和產品的準確內容。錯誤信息包括誤稱、誤解和知識缺乏。虛假信息則可能出現在市場宣稱中,這些宣稱要麼錯誤使用,要麼濫用術語,暗示不準確或主觀的內容。本常見問題解答提供有關網絡安全的信息,並提煉出錯誤信息和虛假信息。

本書將對安全專業人士、技術專業人士、評估者、審計員、管理者,甚至希望獲得快速、直接答案的高層管理人員有所幫助。它將作為一個快速參考,隨時可以放在辦公室的書架上。正如任何優秀的安全專業人士所知,沒有人能知道所有的事情。