Building Secure and Reliable Systems: Best Practices for Designing, Implementing, and Maintaining Systems
暫譯: 建立安全可靠的系統:設計、實施和維護系統的最佳實踐

Adkins, Heather, Beyer, Betsy, Blankinship, Paul

買這商品的人也買了...

商品描述

Can a system ever truly be considered reliable if it isn't fundamentally secure? In two previous O'Reilly books, experts from Google showed how reliability is fundamental to service design. Site Reliability Engineering and The Site Reliability Workbook demonstrated how and why a commitment to the entire service lifecycle enables organizations to successfully build, deploy, monitor, and maintain software systems.

Security is also crucial to the design and operation of scalable systems in production, as it plays an important part in product quality, performance, reliability, and availability. In a world where most products are connected to the internet, and with cloud technologies and machine learning becoming more prevalent, enabling security by default is increasingly important.

This book shares best practices to help an organization of any size design scalable and reliable systems that are fundamentally secure. It also offers insights into how teams across an organization can collaborate on security and reliability.

Specifically, you'll learn about:

  • Design Strategies
  • Implementation & Operations
  • Preparing for the Worst: Detection & Response
  • Scaling Security and the Organization

商品描述(中文翻譯)

如果一個系統在根本上不安全,那麼它是否能被真正視為可靠的系統?在之前的兩本 O'Reilly 書籍中,來自 Google 的專家展示了可靠性對服務設計的重要性。網站可靠性工程網站可靠性工作手冊 說明了為什麼對整個服務生命週期的承諾使組織能夠成功地構建、部署、監控和維護軟體系統。

安全性對於可擴展系統在生產中的設計和運作也至關重要,因為它在產品質量、性能、可靠性和可用性中扮演著重要角色。在一個大多數產品都連接到互聯網的世界中,隨著雲技術和機器學習變得越來越普遍,預設啟用安全性變得愈加重要。

本書分享最佳實踐,幫助任何規模的組織設計根本安全的可擴展和可靠系統。它還提供了有關組織內部團隊如何在安全性和可靠性上進行協作的見解。

具體來說,您將學到:


  • 設計策略

  • 實施與運營

  • 為最壞情況做準備:檢測與響應

  • 擴展安全性與組織

作者簡介

Heather Adkins is a 17-year Google veteran and founding member of the Google Security Team. As Sr Director of Information Security, she has built a global team responsible for maintaining the safety and security of Google's networks, systems and applications. She has an extensive background in systems and network administration with an emphasis on practical security, and has worked to build and secure some of the world's largest infrastructure. She now focuses her time primarily on the defense of Google's computing infrastructure and working with industry to tackle some of the greatest security challenges.

Betsy Beyer is a Technical Writer for Google Site Reliability Engineering in NYC, and the editor of Site Reliability Engineering: How Google Runs Production Systems and The Site Reliability Workbook. She has previously written documentation for Google's Data Center and Hardware Operations Teams in Mountain View and across its globally-distributed data centers. Before moving to New York, Betsy was a lecturer on technical writing at Stanford University. En route to her current career, Betsy studied International Relations and English Literature, and holds degrees from Stanford and Tulane.

Paul Blankinship manages the Technical Writing team for Google's Security and Privacy Engineering group. He's previously written documentation for Google Web Designer, and helped develop Google's internal security and privacy policies.

Piotr Lewandowski is a Staff Site Reliability Engineer, responsible for the security of Google's Production infrastructure and ensuring harmonious collaboration between the SRE and the Security organizations. He is also one of the responders for large-scale incidents. In his previous role he led a team responsible for the reliability of Google's critical security infrastructure. Prior to joining Google 8 years ago, he worked at CERT Polska, owned a software company and graduated from Warsaw University of Technology with a degree in Computer Science.

Ana Oprea specializes in Site Reliability Engineering, Security, and planning and strategy for Google's Technical Infrastructure - a role that follows naturally from her previous experience as a Software Developer, Technical Consultant, and Network Admin. After working and studying in Germany, France, and Romania, she accounts for different cultural approaches when facing any challenge.

Adam Stubblefield is a Distinguished Engineer and the Horizontal Lead for Security at Google. Over the past 8 years, he's led teams that have built much of Google's core security infrastructure. Adam has a PhD in Computer Science from Johns Hopkins.

作者簡介(中文翻譯)

Heather Adkins 是一位在 Google 工作了 17 年的資深員工,也是 Google 安全團隊的創始成員。作為資訊安全的高級總監,她建立了一個全球團隊,負責維護 Google 網絡、系統和應用程式的安全性。她在系統和網絡管理方面擁有豐富的背景,特別強調實用安全,並致力於建立和保護一些世界上最大的基礎設施。她現在主要專注於保護 Google 的計算基礎設施,並與業界合作應對一些最大的安全挑戰。

Betsy Beyer 是 Google 網站可靠性工程(Site Reliability Engineering)團隊的技術作家,工作地點在紐約市,也是《網站可靠性工程:Google 如何運行生產系統》和《網站可靠性工作手冊》的編輯。她之前為 Google 的數據中心和硬體運營團隊撰寫文檔,這些團隊位於山景城及其全球分佈的數據中心。在搬到紐約之前,Betsy 是史丹佛大學的技術寫作講師。在她目前的職業生涯之前,Betsy 學習了國際關係和英國文學,並擁有史丹佛大學和杜蘭大學的學位。

Paul Blankinship 管理 Google 安全與隱私工程組的技術寫作團隊。他之前為 Google 網頁設計工具撰寫文檔,並協助制定 Google 的內部安全和隱私政策。

Piotr Lewandowski 是一名資深網站可靠性工程師,負責 Google 生產基礎設施的安全性,並確保 SRE 與安全組織之間的和諧合作。他也是大型事件的應對者之一。在他之前的角色中,他領導了一個負責 Google 關鍵安全基礎設施可靠性的團隊。在 8 年前加入 Google 之前,他曾在 CERT Polska 工作,擁有一家軟體公司,並從華沙科技大學獲得計算機科學學位。

Ana Oprea 專注於網站可靠性工程、安全性以及 Google 技術基礎設施的規劃和策略——這一角色自然延續了她之前作為軟體開發人員、技術顧問和網絡管理員的經驗。在德國、法國和羅馬尼亞工作和學習後,她在面對任何挑戰時考慮到不同的文化方法。

Adam Stubblefield 是 Google 的傑出工程師及安全部門的橫向負責人。在過去的 8 年中,他領導的團隊建立了 Google 大部分核心安全基礎設施。Adam 擁有約翰霍普金斯大學的計算機科學博士學位。