Security without Obscurity: A Guide to Confidentiality, Authentication, and Integrity (Hardcover)
暫譯: 無需模糊的安全性:機密性、身份驗證與完整性的指南(精裝版)
J.J. Stapleton
- 出版商: Auerbach Publication
- 出版日期: 2014-05-02
- 售價: $4,550
- 貴賓價: 9.5 折 $4,323
- 語言: 英文
- 頁數: 355
- 裝訂: Hardcover
- ISBN: 1466592141
- ISBN-13: 9781466592148
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
The traditional view of information security includes the three cornerstones: confidentiality, integrity, and availability; however the author asserts authentication is the third keystone. As the field continues to grow in complexity, novices and professionals need a reliable reference that clearly outlines the essentials. Security without Obscurity: A Guide to Confidentiality, Authentication, and Integrity fills this need.
Rather than focusing on compliance or policies and procedures, this book takes a top-down approach. It shares the author’s knowledge, insights, and observations about information security based on his experience developing dozens of ISO Technical Committee 68 and ANSI accredited X9 standards. Starting with the fundamentals, it provides an understanding of how to approach information security from the bedrock principles of confidentiality, integrity, and authentication.
The text delves beyond the typical cryptographic abstracts of encryption and digital signatures as the fundamental security controls to explain how to implement them into applications, policies, and procedures to meet business and compliance requirements. Providing you with a foundation in cryptography, it keeps things simple regarding symmetric versus asymmetric cryptography, and only refers to algorithms in general, without going too deeply into complex mathematics.
Presenting comprehensive and in-depth coverage of confidentiality, integrity, authentication, non-repudiation, privacy, and key management, this book supplies authoritative insight into the commonalities and differences of various users, providers, and regulators in the U.S. and abroad.
商品描述(中文翻譯)
傳統的信息安全觀點包括三個基石:保密性、完整性和可用性;然而,作者主張身份驗證是第三個基石。隨著該領域的複雜性不斷增長,新手和專業人士需要一個可靠的參考資料,清楚地概述基本要素。《Security without Obscurity: A Guide to Confidentiality, Authentication, and Integrity》正好滿足這一需求。
本書並不專注於合規性或政策和程序,而是採取自上而下的方法。它分享了作者基於其開發數十個ISO技術委員會68和ANSI認證的X9標準的經驗,對信息安全的知識、見解和觀察。從基本原則開始,它提供了如何從保密性、完整性和身份驗證的基石原則來處理信息安全的理解。
本書深入探討了超越典型的加密和數字簽名的加密學摘要,作為基本的安全控制,並解釋如何將它們實施到應用程序、政策和程序中,以滿足業務和合規要求。它為您提供了加密學的基礎,簡單地區分對稱加密和非對稱加密,並僅一般性地提及算法,而不深入複雜的數學。
本書全面而深入地涵蓋了保密性、完整性、身份驗證、不可否認性、隱私和密鑰管理,提供了對美國及國外各種用戶、提供者和監管機構的共性和差異的權威見解。