Big Breaches: Cybersecurity Lessons for Everyone
暫譯: 重大資安漏洞:人人都應學習的資安教訓

Daswani, Neil, Elbayadi, Moudy

  • 出版商: Apress
  • 出版日期: 2021-02-25
  • 售價: $1,370
  • 貴賓價: 9.5$1,302
  • 語言: 英文
  • 頁數: 427
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1484266544
  • ISBN-13: 9781484266540
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

The cybersecurity industry has seen an investment of over $45 billion in the past 15 years. Hundreds of thousands of jobs in the field remain unfilled amid breach after breach, and the problem has come to a head. It is time for everyone--not just techies--to become informed and empowered on the subject of cybersecurity.

In engaging and exciting fashion, Big Breaches covers some of the largest security breaches and the technical topics behind them such as phishing, malware, third-party compromise, software vulnerabilities, unencrypted data, and more. Cybersecurity affects daily life for all of us, and the area has never been more accessible than with this book.

You will obtain a confident grasp on industry insider knowledge such as effective prevention and detection countermeasures, the meta-level causes of breaches, the seven crucial habits for optimal security in your organization, and much more. These valuable lessons are applied to real-world cases, helping you deduce just how high-profile mega-breaches at Target, JPMorgan Chase, Equifax, Marriott, and more were able to occur.

Whether you are seeking to implement a stronger foundation of cybersecurity within your organization or you are an individual who wants to learn the basics, Big Breaches ensures that everybody comes away with essential knowledge to move forward successfully. Arm yourself with this book's expert insights and be prepared for the future of cybersecurity.



Who This Book Is For

Those interested in understanding what cybersecurity is all about, the failures have taken place in the field to date, and how they could have been avoided. For existing leadership and management in enterprises and government organizations, existing professionals in the field, and for those who are considering entering the field, this book covers everything from how to create a culture of security to the technologies and processes you can employ to achieve security based on lessons that can be learned from past breaches.

商品描述(中文翻譯)

網路安全產業在過去15年中已經吸引了超過450億美元的投資。在一連串的資料外洩事件中,該領域的數十萬個職位仍然無法填補,這個問題已經達到臨界點。是時候讓每個人——不僅僅是技術人員——對網路安全這個主題變得知情並具備能力。

在引人入勝且令人興奮的方式中,Big Breaches 涵蓋了一些最大的安全漏洞及其背後的技術主題,例如釣魚攻擊、惡意軟體、第三方妥協、軟體漏洞、未加密的數據等等。網路安全影響著我們所有人的日常生活,而這本書使這個領域變得前所未有的易於接觸。

您將自信地掌握行業內部知識,例如有效的預防和檢測對策、漏洞的元層原因、組織中最佳安全的七個關鍵習慣,以及更多內容。這些寶貴的教訓應用於現實案例,幫助您推斷出像 Target、JPMorgan Chase、Equifax、Marriott 等高調的重大資料外洩事件是如何發生的。

無論您是希望在組織內部建立更強的網路安全基礎,還是想學習基礎知識的個人,Big Breaches 確保每個人都能獲得成功前進所需的基本知識。用這本書的專家見解武裝自己,為網路安全的未來做好準備。



本書適合誰閱讀

對於那些希望了解網路安全的本質、迄今為止在該領域發生的失敗以及如何避免這些失敗的人來說,這本書是非常合適的。對於企業和政府組織中的現有領導層和管理層、該領域的現有專業人士,以及考慮進入該領域的人士,本書涵蓋了從如何創建安全文化到您可以採用的技術和流程,以根據過去漏洞中可以學到的教訓來實現安全的所有內容。

作者簡介

Dr. Neil Daswani is Co-Director of the Stanford Advanced Security Certification program, and is President of Daswani Enterprises, his security consulting and training firm. He has served in a variety of research, development, teaching, and executive management roles at Symantec, LifeLock, Twitter, Dasient, Google, Stanford University, NTT DoCoMo USA Labs, Yodlee, and Telcordia Technologies (formerly Bellcore). At Symantec, he was Chief Information Security Officer (CISO) for the Consumer Business Unit, and at LifeLock he was the company-wide CISO. Neil has served as Executive-in-Residence at Trinity Ventures (funders of Auth0, New Relic, Aruba, Starbucks, and Bulletproof). He is an investor in and advisor to several cybersecurity startup companies and venture capital funds, including Benhamou Global Ventures, Firebolt, Gravity Ranch Ventures, Security Leadership Capital, and Swift VC. Neil is also co-author of Foundations of Security: What Every Programmer Needs to Know (Apress).
Neil's DNA is deeply rooted in security research and development. He has dozens of technical articles published in top academic and industry conferences (ACM, IEEE, USENIX, RSA, BlackHat, and OWASP), and he has been granted over a dozen US patents. He frequently gives talks at industry and academic conferences, and has been quoted by publications such as The New York Times, USA Today, and CSO Magazine. He earned PhD and MS degrees in computer science at Stanford University, and he holds a BS in computer science with honors with distinction from Columbia University.
Dr. Moudy Elbayadi has more than 20 years of experience and has worked with a number of high-growth companies and across a variety of industries, including mobile and SaaS consumer services, and security and financial services. Having held C-level positions for leading solution providers, Dr. Elbayadi has a unique 360-degree view of consumer and enterprise SaaS businesses. He has a consistent track record of defining technology and product strategies that accelerate growth.
As CTO of Shutterfly, Dr. Elbayadi oversees all technology functions including product development, cybersecurity, DevOps, and machine learning/AI R&D functions. In this capacity he is leading the technology platform transformation. Prior to Shutterfly, Dr. Elbayadi held the position of SVP, Product & Technology for Brain Corp, a San Diego-based AI company creating transformative core technology for the robotics industry.
As advisor, Dr. Elbayadi has been engaged by CEOs and senior executives of companies ranging from $10M to $2B in revenues. Representative engagements include public cloud strategy, platform integration and M&A strategy. He has advised numerous VC firms on technology and prospective investments.
Dr. Elbayadi earned a doctorate in leadership and change from Antioch University, a master's degree in organizational leadership from Chapman University, and a master's degree in business administration from the University of Redlands.

作者簡介(中文翻譯)

尼爾·達斯瓦尼博士是史丹佛大學進階安全認證計畫的共同主任,也是達斯瓦尼企業的總裁,該公司專注於安全諮詢和培訓。他曾在多家企業擔任研究、開發、教學和高層管理職位,包括Symantec、LifeLock、Twitter、Dasient、Google、史丹佛大學、NTT DoCoMo USA Labs、Yodlee和Telcordia Technologies(前身為Bellcore)。在Symantec,他擔任消費者業務單位的首席資訊安全官(CISO),在LifeLock則是全公司的CISO。尼爾曾擔任Trinity Ventures的駐業執行官(該公司資助了Auth0、New Relic、Aruba、Starbucks和Bulletproof)。他是多家網路安全初創公司和風險投資基金的投資者和顧問,包括Benhamou Global Ventures、Firebolt、Gravity Ranch Ventures、Security Leadership Capital和Swift VC。尼爾也是安全基礎:每位程式設計師需要知道的事(Apress)的共同作者。
尼爾的DNA深深植根於安全研究和開發。他在頂尖學術和行業會議(ACM、IEEE、USENIX、RSA、BlackHat和OWASP)上發表了數十篇技術文章,並獲得了十多項美國專利。他經常在行業和學術會議上發表演講,並被《紐約時報》、《今日美國》和《CSO雜誌》等出版物引用。他在史丹佛大學獲得計算機科學的博士和碩士學位,並在哥倫比亞大學以優異的成績獲得計算機科學學士學位。
穆迪·艾爾巴亞迪博士擁有超過20年的經驗,曾與多家高成長公司合作,並在多個行業工作,包括移動和SaaS消費者服務,以及安全和金融服務。作為領先解決方案提供商的C級高管,艾爾巴亞迪博士對消費者和企業SaaS業務擁有獨特的360度視角。他在定義加速增長的技術和產品策略方面有著穩定的成功記錄。
作為Shutterfly的首席技術官,艾爾巴亞迪博士負責所有技術功能,包括產品開發、網路安全、DevOps和機器學習/人工智慧的研發。在這個角色中,他正在領導技術平台的轉型。在加入Shutterfly之前,艾爾巴亞迪博士擔任位於聖地牙哥的AI公司Brain Corp的產品與技術高級副總裁,該公司為機器人行業創造變革性的核心技術。
作為顧問,艾爾巴亞迪博士曾為年收入從1000萬到20億美元的公司首席執行官和高級管理人員提供服務。代表性的參與包括公共雲策略、平台整合和併購策略。他還為多家風險投資公司提供技術和潛在投資的建議。
艾爾巴亞迪博士在安提歐克大學獲得領導與變革的博士學位,在查普曼大學獲得組織領導的碩士學位,以及在雷德蘭茲大學獲得工商管理碩士學位。