Security De-Engineering: Solving the Problems in Information Risk Management (Paperback)
暫譯: 安全去工程化:解決資訊風險管理中的問題 (平裝本)

Ian Tibble

  • 出版商: Auerbach Publication
  • 出版日期: 2011-12-13
  • 售價: $3,150
  • 貴賓價: 9.5$2,993
  • 語言: 英文
  • 頁數: 332
  • 裝訂: Paperback
  • ISBN: 1439868344
  • ISBN-13: 9781439868348
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

As hacker organizations surpass drug cartels in terms of revenue generation, it is clear that the good guys are doing something wrong in information security. Providing a simple foundational remedy for our security ills, Security De-Engineering: Solving the Problems in Information Risk Management is a definitive guide to the current problems impacting corporate information risk management. It explains what the problems are, how and why they have manifested, and outlines powerful solutions.

Ian Tibble delves into more than a decade of experience working with close to 100 different Fortune 500s and multinationals to explain how a gradual erosion of skills has placed corporate information assets on a disastrous collision course with automated malware attacks and manual intrusions. Presenting a complete journal of hacking feats and how corporate networks can be compromised, the book covers the most critical aspects of corporate risk information risk management.

  • Outlines six detrimental security changes that have occurred in the past decade
  • Examines automated vulnerability scanners and rationalizes the differences between their perceived and actual value
  • Considers security products—including intrusion detection, security incident event management, and identity management

The book provides a rare glimpse at the untold stories of what goes on behind the closed doors of private corporations. It details the tools and products that are used, typical behavioral traits, and the two types of security experts that have existed since the mid-nineties—the hackers and the consultants that came later. Answering some of the most pressing questions about network penetration testing and cloud computing security, this book provides you with the understanding and tools needed to tackle today’s risk management issues as well as those on the horizon.

商品描述(中文翻譯)

隨著駭客組織在收入產生方面超越毒品卡特爾,顯然在資訊安全領域,正義的一方正在做錯事。提供一個簡單的基礎解決方案來應對我們的安全問題,《Security De-Engineering: Solving the Problems in Information Risk Management》是一本針對當前影響企業資訊風險管理的問題的權威指南。它解釋了問題是什麼、如何以及為什麼這些問題會出現,並概述了強有力的解決方案。

Ian Tibble深入探討了與近100家不同的《財富》500強企業和跨國公司合作超過十年的經驗,解釋了技能的逐漸流失如何使企業資訊資產與自動化惡意軟體攻擊和手動入侵之間的碰撞走上災難性的道路。這本書呈現了一個完整的駭客成就日誌,以及企業網路如何被攻破,涵蓋了企業風險資訊風險管理的最關鍵方面。

- 概述過去十年發生的六個有害的安全變化
- 檢視自動化漏洞掃描器,並合理化其感知價值與實際價值之間的差異
- 考慮安全產品,包括入侵檢測、安全事件管理和身份管理

這本書提供了一個罕見的視角,揭示了私營企業背後未被講述的故事。它詳細介紹了所使用的工具和產品、典型的行為特徵,以及自九十年代中期以來存在的兩類安全專家——駭客和後來出現的顧問。針對網路滲透測試和雲端計算安全的一些最迫切問題,這本書為您提供了理解和應對當前風險管理問題以及未來挑戰所需的工具。

最後瀏覽商品 (20)