You Can Stop Stupid: Stopping Losses from Accidental and Malicious Actions
暫譯: 停止愚蠢行為:防止意外與惡意行動造成的損失
Winkler, Ira, Brown, Tracy Celaya
- 出版商: Wiley
- 出版日期: 2020-12-03
- 售價: $1,440
- 貴賓價: 9.5 折 $1,368
- 語言: 英文
- 頁數: 368
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1119621984
- ISBN-13: 9781119621980
海外代購書籍(需單獨結帳)
相關主題
商品描述
Stopping Losses from Accidental and Malicious Actions
Around the world, users cost organizations billions of dollars due to simple errors and malicious actions. They believe that there is some deficiency in the users. In response, organizations believe that they have to improve their awareness efforts and making more secure users. This is like saying that coalmines should get healthier canaries. The reality is that it takes a multilayered approach that acknowledges that users will inevitably make mistakes or have malicious intent, and the failure is in not planning for that. It takes a holistic approach to assessing risk combined with technical defenses and countermeasures layered with a security culture and continuous improvement. Only with this kind of defense in depth can organizations hope to prevent the worst of the cybersecurity breaches and other user-initiated losses.
Using lessons from tested and proven disciplines like military kill-chain analysis, counterterrorism analysis, industrial safety programs, and more, Ira Winkler and Dr. Tracy Celaya's You CAN Stop Stupid provides a methodology to analyze potential losses and determine appropriate countermeasures to implement.
- Minimize business losses associated with user failings
- Proactively plan to prevent and mitigate data breaches
- Optimize your security spending
- Cost justify your security and loss reduction efforts
- Improve your organization's culture
Business technology and security professionals will benefit from the information provided by these two well-known and influential cybersecurity speakers and experts.
商品描述(中文翻譯)
**防止因意外和惡意行為造成的損失**
全球各地的用戶因簡單錯誤和惡意行為使組織損失數十億美元。他們認為用戶存在某種缺陷。作為回應,組織認為必須提高用戶的安全意識,讓用戶變得更安全。這就像說煤礦應該有更健康的金絲雀。事實是,這需要一種多層次的方法,承認用戶不可避免地會犯錯或有惡意,失敗在於未能為此做好規劃。這需要一種全面的方法來評估風險,結合技術防禦和對策,並與安全文化和持續改進相結合。只有這種深度防禦,組織才能希望防止最嚴重的網絡安全漏洞和其他用戶引發的損失。
借鑒軍事殺傷鏈分析、反恐分析、工業安全計劃等經過驗證的學科的教訓,Ira Winkler 和 Dr. Tracy Celaya 的 *You CAN Stop Stupid* 提供了一種分析潛在損失並確定適當對策的方法論。
- 最小化與用戶失誤相關的商業損失
- 主動規劃以防止和減輕數據洩露
- 優化您的安全支出
- 為您的安全和減損努力提供成本合理性
- 改善您組織的文化
商業技術和安全專業人士將從這兩位知名且有影響力的網絡安全演講者和專家的信息中受益。
作者簡介
Ira Winkler, CISSP is President of Secure Mentem and is considered one of the world's most influential security professionals. He has gained media notoriety for performing espionage simulations, where he physically and technically "broke into" some of the largest companies in the World and investigating crimes against them, and telling them how to cost effectively protect their information and computer infrastructure. He continues to perform these espionage simulations, as well as assisting organizations in developing cost effective security programs. Ira also won the Hall of Fame award from the Information Systems Security Association, as well as several other prestigious industry awards. Most recently, CSO Magazine named Ira a CSO Compass Award winner as The Awareness Crusader. Ira is also a columnist for DarkReading and ComputerWorld, and writes for several other industry publications. Mr. Winkler has been a keynote speaker at almost every major information security related event, on 6 continents, and has keynoted events in many diverse industries.
Dr. Tracy Celaya Brown, CISSP is President of Go Consulting Int'l. She is a sought-after consultant in IT Security Program Management, Organizational Development, and Change Management, and a U.S. Air Force veteran. As an international and top-rated speaker, she has been a guest lecturer at Arizona State University and spoken at some of the most well-known security related events in the world including RSA USA, RSA Asia-Pacific, ISACA CSX North America & Europe, and SecureCISO.
作者簡介(中文翻譯)
,CISSP 是 Secure Mentem 的總裁,被認為是全球最具影響力的安全專業人士之一。他因進行間諜模擬而獲得媒體的廣泛關注,這些模擬中他實際上和技術上「闖入」了一些全球最大的公司,調查針對這些公司的犯罪行為,並告訴他們如何以具成本效益的方式保護他們的信息和計算機基礎設施。他持續進行這些間諜模擬,並協助組織開發具成本效益的安全計劃。Ira 還獲得了信息系統安全協會的名人堂獎,以及其他幾個著名的行業獎項。最近,CSO Magazine 將 Ira 評選為 CSO Compass Award 的得主,稱他為意識的鬥士。Ira 也是 DarkReading 和 ComputerWorld 的專欄作家,並為其他幾個行業出版物撰寫文章。Winkler 先生幾乎在六大洲的每一個主要信息安全相關活動中擔任主題演講者,並在許多不同的行業中擔任主題演講。
Dr. Tracy Celaya Brown,CISSP 是 Go Consulting Int'l 的總裁。她是 IT 安全計劃管理、組織發展和變更管理方面的熱門顧問,並且是一名美國空軍退伍軍人。作為一位國際知名的頂尖演講者,她曾在亞利桑那州立大學擔任客座講師,並在全球一些最知名的安全相關活動上發言,包括 RSA USA、RSA 亞太區、ISACA CSX 北美和歐洲,以及 SecureCISO。