Incident Response in the Age of Cloud: Techniques and best practices to effectively respond to cybersecurity incidents
暫譯: 雲端時代的事件響應:有效應對網路安全事件的技術與最佳實踐

Ozkaya, Erdal

  • 出版商: Packt Publishing
  • 出版日期: 2021-02-25
  • 售價: $1,830
  • 貴賓價: 9.5$1,739
  • 語言: 英文
  • 頁數: 622
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1800569211
  • ISBN-13: 9781800569218
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Learn to identify a security incident and build a series of best practices to stop an attack before it creates serious consequences


Key Features

  • Discover the entire spectrum of Incident Response (IR), from its evolution to recovery in general as well as in the cloud
  • Understand IR best practices through real-world phishing incident scenarios
  • Explore the current challenges in IR through the perspectives of leading figures in the cybersecurity community


Book Description

Cybercriminals are always in search of new methods and ways to infiltrate systems. Quickly responding to an incident should help an organization minimize its losses, decrease vulnerabilities, and rebuild services and processes. An organization without knowledge of how to effectively implement key IR best practices is highly prone to cyber-attacks.


In the wake of the COVID-19 pandemic, with most organizations gravitating towards remote working and the cloud, this book provides updated IR processes to address the associated security risks.


The book begins by introducing you to the cybersecurity landscape and explaining why IR matters. You will understand the evolution of IR, current challenges, key metrics, and the composition of an IR team, along with an array of methods and tools used in an effective IR process. You will then learn how to apply this conceptual toolkit, with discussions on incident alerting, handling, investigation, recovery, and reporting.


As you progress through the book, you will cover governing IR on multiple platforms and sharing cyber threat intelligence. You will then thoroughly explore the entire spectrum of procedures involved in IR in the cloud - the challenges, opportunities, and how to handle a phishing incident.


Further, you'll learn how to build a proactive incident readiness culture, learn and implement IR best practices, and explore practical case studies using tools from Keepnet Labs and Binalyze. Finally, the book concludes with an "Ask the Experts" section where industry experts have provided their perspective on diverse topics in the IR sphere.


By the end of this book, you should become proficient at building and applying IR strategies pre-emptively and confidently.


What You Will Learn

  • Understand incident response and its significance
  • Organize an incident response team
  • Explore best practices for managing attack situations with your IR team
  • Form, organize, and operate a product security team to deal with product vulnerabilities and assess their severity
  • Organize all the entities involved in product security response
  • Respond to a security vulnerability based on Keepnet Labs processes and practices
  • Adapt all the above learnings for the cloud


Who this Book is for

This book is aimed at first-time incident responders, cybersecurity enthusiasts who want to get into IR, and users who deal with the security of an organization. It will also interest CIOs, CISOs, and members of IR, SOC, and CSIRT teams. However, IR is not just about IT or security teams, and anyone with a legal, HR, media, or other active business role would benefit from this book's discussions on individual and organizational security.

The book assumes you have some admin experience. No prior DFIR experience is required. Some infosec knowledge will be a plus but isn't mandatory.

商品描述(中文翻譯)

學習識別安全事件並建立一系列最佳實踐,以在攻擊造成嚴重後果之前阻止它

主要特點
- 探索事件響應(IR)的整個範疇,從其演變到一般及雲端的恢復
- 通過真實的網絡釣魚事件場景了解IR最佳實踐
- 從網絡安全社群的領導人物的角度探索IR面臨的當前挑戰

書籍描述
網絡犯罪分子總是在尋找新的方法和途徑來滲透系統。快速響應事件應該能幫助組織最小化損失、減少漏洞並重建服務和流程。對於一個不具備有效實施關鍵IR最佳實踐知識的組織來說,極易受到網絡攻擊。

隨著COVID-19疫情的影響,大多數組織轉向遠程工作和雲端,本書提供了更新的IR流程以應對相關的安全風險。

本書首先介紹網絡安全的全景,並解釋為什麼IR很重要。您將了解IR的演變、當前挑戰、關鍵指標以及IR團隊的組成,還有在有效的IR過程中使用的一系列方法和工具。接著,您將學習如何應用這些概念工具包,並討論事件警報、處理、調查、恢復和報告。

隨著您深入閱讀本書,您將涵蓋多平台的IR治理和共享網絡威脅情報。然後,您將徹底探索雲端中IR所涉及的整個程序範疇——挑戰、機會以及如何處理網絡釣魚事件。

此外,您將學習如何建立主動的事件準備文化,學習並實施IR最佳實踐,並使用Keepnet Labs和Binalyze的工具探索實用案例研究。最後,本書以“專家問答”部分結束,行業專家提供了他們對IR領域各種主題的看法。

在本書結束時,您應該能夠熟練地建立和應用IR策略,並充滿信心。

您將學到什麼
- 理解事件響應及其重要性
- 組織事件響應團隊
- 探索與您的IR團隊管理攻擊情況的最佳實踐
- 組建、組織和運營產品安全團隊,以處理產品漏洞並評估其嚴重性
- 組織所有參與產品安全響應的實體
- 根據Keepnet Labs的流程和實踐對安全漏洞作出響應
- 將上述所有學習適應於雲端

本書適合誰
本書針對首次參與事件響應的專業人員、希望進入IR的網絡安全愛好者以及處理組織安全的用戶。它也會吸引CIO、CISO以及IR、SOC和CSIRT團隊的成員。然而,IR不僅僅是IT或安全團隊的事,任何擔任法律、人力資源、媒體或其他活躍商業角色的人都能從本書對個人和組織安全的討論中受益。

本書假設您具備一定的管理經驗。不需要先前的DFIR經驗。一些信息安全知識將是加分項,但不是必需的。