Muutke küpsiste eelistusi

New School of Information Security [Kõva köide]

  • Formaat: Hardback, 288 pages, kõrgus x laius x paksus: 156x234x25 mm, kaal: 583 g
  • Ilmumisaeg: 10-Apr-2008
  • Kirjastus: Addison-Wesley Educational Publishers Inc
  • ISBN-10: 0321502787
  • ISBN-13: 9780321502780
Teised raamatud teemal:
  • Kõva köide
  • Hind: 39,69 €*
  • * saadame teile pakkumise kasutatud raamatule, mille hind võib erineda kodulehel olevast hinnast
  • See raamat on trükist otsas, kuid me saadame teile pakkumise kasutatud raamatule.
  • Kogus:
  • Lisa ostukorvi
  • Tasuta tarne
  • Lisa soovinimekirja
  • Formaat: Hardback, 288 pages, kõrgus x laius x paksus: 156x234x25 mm, kaal: 583 g
  • Ilmumisaeg: 10-Apr-2008
  • Kirjastus: Addison-Wesley Educational Publishers Inc
  • ISBN-10: 0321502787
  • ISBN-13: 9780321502780
Teised raamatud teemal:
<>It is about time that a book like The New School came along. The age of security as pure technology is long past, and modern practitioners need to understand the social and cognitive aspects of security if they are to be successful. Shostack and Stewart teach readers exactly what they need to know--I just wish I could have had it when I first started out.

--David Mortman, CSO-in-Residence Echelon One, former CSO Siebel Systems

 

Why is information security so dysfunctional? Are you wasting the money you spend on security? This book shows how to spend it more effectively. How can you make more effective security decisions? This book explains why professionals have taken to studying economics, not cryptography--and why you should, too. And why security breach notices are the best thing to ever happen to information security. Its about time someone asked the biggest, toughest questions about information security. Security experts Adam Shostack and Andrew Stewart dont just answer those questions--they offer honest, deeply troubling answers. They explain why these critical problems exist and how to solve them. Drawing on powerful lessons from economics and other disciplines, Shostack and Stewart offer a new way forward. In clear and engaging prose, they shed new light on the critical challenges that are faced by the security field. Whether youre a CIO, IT manager, or security specialist, this book will open your eyes to new ways of thinking about--and overcoming--your most pressing security challenges. The New School enables you to take control, while others struggle with non-stop crises.





Better evidence for better decision-making Why the security data you have doesnt support effective decision-making--and what to do about it Beyond security silos: getting the job done together Why its so hard to improve security in isolation--and how the entire industry can make it happen and evolve Amateurs study cryptography; professionals study economics What IT security leaders can and must learn from other scientific fields A bigger bang for every buck How to re-allocate your scarce resources where theyll do the most good

Muu info

<>It is about time that a book like The New School came along. The age of security as pure technology is long past, and modern practitioners need to understand the social and cognitive aspects of security if they are to be successful. Shostack and Stewart teach readers exactly what they need to know--I just wish I could have had it when I first started out.

--David Mortman, CSO-in-Residence Echelon One, former CSO Siebel Systems

 

Why is information security so dysfunctional? Are you wasting the money you spend on security? This book shows how to spend it more effectively. How can you make more effective security decisions? This book explains why professionals have taken to studying economics, not cryptography--and why you should, too. And why security breach notices are the best thing to ever happen to information security. Its about time someone asked the biggest, toughest questions about information security. Security experts Adam Shostack and Andrew Stewart dont just answer those questions--they offer honest, deeply troubling answers. They explain why these critical problems exist and how to solve them. Drawing on powerful lessons from economics and other disciplines, Shostack and Stewart offer a new way forward. In clear and engaging prose, they shed new light on the critical challenges that are faced by the security field. Whether youre a CIO, IT manager, or security specialist, this book will open your eyes to new ways of thinking about--and overcoming--your most pressing security challenges. The New School enables you to take control, while others struggle with non-stop crises.





Better evidence for better decision-making Why the security data you have doesnt support effective decision-making--and what to do about it Beyond security silos: getting the job done together Why its so hard to improve security in isolation--and how the entire industry can make it happen and evolve Amateurs study cryptography; professionals study economics What IT security leaders can and must learn from other scientific fields A bigger bang for every buck How to re-allocate your scarce resources where theyll do the most good
Observing the World and Asking Why
Spam, and Other Problems with Email
4(3)
Hostile Code
7(2)
Security Breaches
9(2)
Identity and the Theft of Identity
11(3)
Should We Just Start Over?
14(1)
The Need for a New School
15(4)
The Security Industry
Where the Security Industry Comes From
19(6)
Orientations and Framing
25(2)
What Does the Security Industry Sell?
27(6)
How Security Is Sold
33(13)
On Evidence
The Trouble with Surveys
46(4)
The Trade Press
50(2)
Vulnerabilities
52(2)
Instrumentation on the Internet
54(1)
Organizations and Companies with Data
55(9)
The Rise of the Security Breach
How Do Companies Lose Data?
64(4)
Disclose Breaches
68(2)
Possible Criticisms of Breach Data
70(4)
Moving from Art to Science
74(2)
Get Involved
76(6)
Amateurs Study Cryptography; Professionals Study Economics
The Economics of Information Security
82(13)
Psychology
95(4)
Sociology
99(7)
Spending
Reasons to Spend on Security Today
106(4)
Non-Reasons to Spend on Security
110(2)
Emerging Reasons to Spend
112(4)
How Much Should a Business Spend on Security?
116(6)
The Psychology of Spending
122(4)
On What to Spend
126(6)
Life in the New School
People Are People
132(4)
Breach Data Is Not Actuarial Data
136(1)
Powerful Externalities
137(2)
The Human Computer Interface and Risk Compensation
139(3)
The Use and Abuse of Language
142(2)
Skills Shortages, Organizational Structure, and Collaboration
144(5)
A Call to Action
Join the New School
149(4)
Embrace the New School
153(4)
Make Money from the New School
157(2)
Final Words
159(2)
Endnotes 161(52)
Bibliography 213(16)
Index 229
Adam Shostack is part of Microsofts Security Development Lifecycle strategy team, where he is responsible for security design analysis techniques. Before Microsoft, Adam was involved in a number of successful start-ups focused on vulnerability scanning, privacy, and program analysis. He helped found the CVE, International Financial Cryptography association, and the Privacy Enhancing Technologies workshop. He has been a technical advisor to companies including Counterpane Internet Security and Debix.

 

Andrew Stewart is a Vice President at a US-based investment bank. His work on information security topics has been published in journals such as Computers & Security and Information Security Bulletin. His homepage is homepage.mac.com/andrew_j_stewart