• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel och pussel

Skapa nya rutiner – hälsoböcker upp till 50% →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Security Operations Center

    Building, Operating, and Maintaining your SOC

    AvJoseph Muniz,Gary McIntyre

    Häftad, Engelska, 2015

    377 kr

    Beställningsvara. Skickas inom 7-10 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Security Operations Center

    Building, Operating, and Maintaining Your SOC

     

    The complete, practical guide to planning, building, and operating an effective Security Operations Center (SOC)


    Security Operations Center is the complete guide to building, operating, and managing Security Operations Centers in any environment. Drawing on experience with hundreds of customers ranging from Fortune 500 enterprises to large military organizations, three leading experts thoroughly review each SOC model, including virtual SOCs. You’ll learn how to select the right strategic option for your organization, and then plan and execute the strategy you’ve chosen.


    Security Operations Center walks you through every phase required to establish and run an effective SOC, including all significant people, process, and technology capabilities. The authors assess SOC technologies, strategy, infrastructure, governance, planning, implementation, and more. They take a holistic approach considering various commercial and open-source tools found in modern SOCs.


    This best-practice guide is written for anybody interested in learning how to develop, manage, or improve a SOC. A background in network security, management, and operations will be helpful but is not required. It is also an indispensable resource for anyone preparing for the Cisco SCYBER exam.

     

    ·         Review high-level issues, such as vulnerability and risk management, threat intelligence, digital investigation, and data collection/analysis

    ·         Understand the technical components of a modern SOC

    ·         Assess the current state of your SOC and identify areas of improvement

    ·         Plan SOC strategy, mission, functions, and services

    ·         Design and build out SOC infrastructure, from facilities and networks to systems, storage, and physical security

    ·         Collect and successfully analyze security data

    ·         Establish an effective vulnerability management practice

    ·         Organize incident response teams and measure their performance

    ·         Define an optimal governance and staffing model

    ·         Develop a practical SOC handbook that people can actually use

    ·         Prepare SOC to go live, with comprehensive transition plans

    ·         React quickly and collaboratively to security incidents

    ·         Implement best practice security operations, including continuous enhancement and improvement

      

    Produktinformation

    • Utgivningsdatum:2015-11-19
    • Mått:190 x 230 x 20 mm
    • Vikt:756 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:448
    • Upplaga:1
    • Förlag:Pearson Education
    • ISBN:9780134052014

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT

    Mer om författaren

    Joseph Muniz is a consultant at Cisco Systems and security researcher. Joseph started his career in software development and later managed networks as a contracted technical resource. Joseph moved into consulting and found a passion for security while meeting with a variety of customers. He has been involved with the design and implementation of multiple projects, ranging from Fortune 500 corporations to large federal networks. Joseph is the author of and contributor to several books and is a speaker for popular security conferences. Check out his blog, http://www.thesecurityblogger.com, which showcases the latest security events, research, and technologies.  Gary McIntyre is a seasoned information security professional focusing on the development and operation of large-scale information security programs. As an architect, manager, and consultant, he has worked with a wide range of public and private sector organizations around the world to design, build, and maintain small to large security operations teams. He currently holds a Masters degree from the University of Toronto and has also been a long-time (ISC)2 instructor.  Dr. Nadhem AlFardan has more than 15 years of experience in the area of information security and holds a Ph.D. in Information Security from Royal Holloway, University of London. Nadhem is a senior security solution architect working for Cisco Systems. Before joining Cisco, he worked for Schlumbeger and HSBC. Nadhem is CISSP certified and is an ISO 27001 lead auditor. He is also CCIE Security certified. In his Ph.D. research, Nadhem published a number of papers in prestige conferences, such as IEEE S&P and USENIX Security, mainly around cryptoanalysis topics. His work involved him working with organizations such as Google, Microsoft, Cisco, Mozilla, OpenSSL, and many others, mainly to help them assess and fix major findings in the Transport Layer Security/Secure Sockets Layer (TLS/SSL) protocol. His work is referenced in a number of IETF standards.

    Innehållsförteckning

    • Introduction xxPart I SOC BasicsChapter 1 Introduction to Security Operations and the SOC 1Cybersecurity Challenges 1Threat Landscape 4Business Challenges 7The Cloud 8Compliance 9Privacy and Data Protection 9Introduction to Information Assurance 10Introduction to Risk Management 11Information Security Incident Response 14Incident Detection 15Incident Triage 16Incident Categories 17Incident Severity 17Incident Resolution 18Incident Closure 19Post-Incident 20SOC Generations 21First-Generation SOC 22Second-Generation SOC 22Third-Generation SOC 23Fourth-Generation SOC 24Characteristics of an Effective SOC 24Introduction to Maturity Models 27Applying Maturity Models to SOC 29Phases of Building a SOC 31Challenges and Obstacles 32Summary 32References 33Chapter 2 Overview of SOC Technologies 35Data Collection and Analysis 35Data Sources 37Data Collection 38The Syslog Protocol 39Telemetry Data: Network Flows 45Telemetry Data: Packet Capture 48Parsing and Normalization 49Security Analysis 52Alternatives to Rule-Based Correlation 55Data Enrichment 56Big Data Platforms for Security 57Vulnerability Management 58Vulnerability Announcements 60Threat Intelligence 62Compliance 64Ticketing and Case Management 64Collaboration 65SOC Conceptual Architecture 66Summary 67References 67Part II: The Plan PhaseChapter 3 Assessing Security Operations Capabilities 69Assessment Methodology 69Step 1: Identify Business and IT Goals 71Step 2: Assessing Capabilities 73Assessing IT Processes 75Step 3: Collect Information 82Step 4: Analyze Maturity Levels 84Step 5: Formalize Findings 87The Organization’s Vision and Strategy 87The Department’s Vision and Strategy 87External and Internal Compliance Requirements 87Organization’s Threat Landscape 88History of Previous Information Security Incidents 88SOC Sponsorship 89Allocated Budget 89Presenting Data 89Closing 90Summary 90References 90Chapter 4 SOC Strategy 91Strategy Elements 91Who Is Involved? 92SOC Mission 92SOC Scope 93Example 1: A Military Organization 94Mission Statement 94SOC Scope Statement 95Example 2: A Financial Organization 95Mission Statement 95SOC Scope Statement 95SOC Model of Operation 95In-House and Virtual SOC 96SOC Services 98SOC Capabilities Roadmap 99Summary 101Part III: The Design PhaseChapter 5 The SOC Infrastructure 103Design Considerations 103Model of Operation 104Facilities 105SOC Internal Layout 106Lighting 107Acoustics 107Physical Security 108Video Wall 108SOC Analyst Services 109Active Infrastructure 110Network 111Access to Systems 112Security 112Compute 115Dedicated Versus Virtualized Environment 116Choice of Operating Systems 118Storage 118Capacity Planning 119Collaboration 119Ticketing 120Summary 120References 120Chapter 6 Security Event Generation and Collection 123Data Collection 123Calculating EPS 124Ubuntu Syslog Server 124Network Time Protocol 129Deploying NTP 130Data-Collection Tools 134Company 135Product Options and Architecture 136Installation and Maintenance 136User Interface and Experience 136Compliance Requirements 137Firewalls 137Stateless/Stateful Firewalls 137Cisco Adaptive Security Appliance ASA 138Application Firewalls 142Cisco FirePOWER Services 142Cloud Security 152Cisco Meraki 153Exporting Logs from Meraki 154Virtual Firewalls 155Cisco Virtual Firewalls 156Host Firewalls 157Intrusion Detection and Prevention Systems 157Cisco FirePOWER IPS 160Meraki IPS 161Snort 162Host-Based Intrusion Prevention 162Routers and Switches 163Host Systems 166Mobile Devices 167Breach Detection 168Cisco Advanced Malware Prevention 168Web Proxies 169Cisco Web Security Appliance 170Cloud Proxies 172Cisco Cloud Web Security 172DNS Servers 173Exporting DNS 174Network Telemetry with Network Flow Monitoring 174NetFlow Tools 175StealthWatch 177Exporting Data from StealthWatch 179NetFlow from Routers and Switches 182NetFlow from Security Products 184NetFlow in the Data Center 186Summary 187References 188Chapter 7 Vulnerability Management 189Identifying Vulnerabilities 190Security Services 191Vulnerability Tools 193Handling Vulnerabilities 195OWASP Risk Rating Methodology 197Threat Agent Factors 198Vulnerability Factors 198Technical Impact Factors 200Business Impact Factors 200The Vulnerability Management Lifecycle 202Automating Vulnerability Management 205Inventory Assessment Tools 205Information Management Tools 206Risk-Assessment Tools 206Vulnerability-Assessment Tools 206Report and Remediate Tools 206Responding Tools 207Threat Intelligence 208Attack Signatures 209Threat Feeds 210Other Threat Intelligence Sources 211Summary 213References 214Chapter 8 People and Processes 215Key Challenges 215Wanted: Rock Stars, Leaders, and Grunts 216The Weight of Process 216The Upper and Lower Bounds of Technology 217Designing and Building the SOC Team 218Starting with the Mission 218Focusing on Services 219Security Monitoring Service Example 220Determining the Required SOC Roles 223Leadership Roles 224Analyst Roles 224Engineering Roles 224Operations Roles 224Other Support Roles 224Working with HR 225Job Role Analysis 225Market Analysis 225Organizational Structure 226Calculating Team Numbers 227Deciding on Your Resourcing Strategy 228Building Your Own: The Art of Recruiting SOC Personnel 229Working with Contractors and Service Bureaus 229Working with Outsourcing and Managed Service Providers 230Working with Processes and Procedures 231Processes Versus Procedures 231Working with Enterprise Service Management Processes 232Event Management 232Incident Management 233Problem Management 233Vulnerability Management 233Other IT Management Processes 233The Positives and Perils of Process 234Examples of SOC Processes and Procedures 236Security Service Management 236Security Service Engineering 237Security Service Operations 238Security Monitoring 239Security Incident Investigation and Response 239Security Log Management 240Security Vulnerability Management 241Security Intelligence 241Security Analytics and Reporting 242Breach Discovery and Remediation 242Summary 243Part IV: The Build PhaseChapter 9 The Technology 245In-House Versus Virtual SOC 245Network 246Segmentation 247VPN 251High Availability 253Support Contracts 254Security 255Network Access Control 255Authentication 257On-Network Security 258Encryption 259Systems 260Operating Systems 261Hardening Endpoints 262Endpoint Breach Detection 263Mobile Devices 264Servers 264Storage 265Data-Loss Protection 266Cloud Storage 270Collaboration 271Collaboration for Pandemic Events 272Technologies to Consider During SOC Design 273Firewalls 273Firewall Modes 273Firewall Clustering 276Firewall High Availability 276Firewall Architecture 277Routers and Switches 279Securing Network Devices 280Hardening Network Devices 280Network Access Control 281Deploying NAC 282NAC Posture 284Architecting NAC 285Web Proxies 290Reputation Security 290Proxy Architecture 292Intrusion Detection/Prevention 295IDS IPS Architecture 295Evaluating IDS IPS Technology 296Tuning IDS/IPS 298Breach Detection 300Honeypots 301Sandboxes 302Endpoint Breach Detection 303Network Telemetry 306Enabling NetFlow 308Architecting Network Telemetry Solutions 310Network Forensics 312Digital Forensics Tools 313Final SOC Architecture 314Summary 317References 318Chapter 10 Preparing to Operate 319Key Challenges 319People Challenges 319Process Challenges 320Technology Challenges 321Managing Challenges Through a Well-Managed Transition 321Elements of an Effective Service Transition Plan 322Determining Success Criteria and Managing to Success 322Deploying Against Attainable Service Levels 323Focusing on Defined Use Cases 325Managing Project Resources Effectively 328Marching to Clear and Attainable Requirements 329Staffing Requirements for Go-Live 329Process Requirements for Go-Live 330Technology Requirements for Go-Live 331Using Simple Checks to Verify That the SOC Is Ready 332People Checks 332Process Checks 336Technology Checks 340Summary 346Part V: The Operate PhaseChapter 11 Reacting to Events and Incidents 347A Word About Events 348Event Intake, Enrichment, Monitoring, and Handling 348Events in the SIEM 349Events in the Security Log Management Solution 350Events in Their Original Habitats 350Events Through Communications and Collaboration Platforms 350Working with Events: The Malware Scenario 351Handling and Investigating the Incident Report 353Creating and Managing Cases 354Working as a Team 355Working with Other Parts of the Organization 357Working with Third Parties 359Closing and Reporting on the Case 362Summary 363Chapter 12 Maintain, Review, and Improve 365Reviewing and Assessing the SOC 366Determining Scope 366Examining the Services 367Personnel/Staffing 369Processes, Procedures, and Other Operational Documentation 371Technology 372Scheduled and Ad Hoc Reviews 373Internal Versus External Assessments 374Internal Assessments 374External Assessments 374Assessment Methodologies 375Maturity Model Approaches 375Services-Oriented Approaches 376Post-Incident Reviews 378Maintaining and Improving the SOC 381Maintaining and Improving Services 381Maintain and Improving Your Team 383Improving Staff Recruitment 383Improving Team Training and Development 384Improving Team Retention 386Maintaining and Improving the SOC Technology Stack 387Improving Threat, Anomaly, and Breach-Detection Systems 388Improving Case and Investigation Management Systems 391Improving Analytics and Reporting 392Improving Technology Integration 392Improving Security Testing and Simulation Systems 393Improving Automated Remediation 394Conclusions 395    9780134052014    TOC    10/12/2015
    Hoppa över listan

    Mer från samma författare

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz - Security Operations Center, E-bok

    Security Operations Center

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz

    E-bok
    2015

    594 kr

    Joseph Muniz - Modern Security Operations Center, The, Häftad

    Modern Security Operations Center, The

    Joseph Muniz

    Häftad, 2021

    419 kr

    Joseph Muniz, Steven Chimes, James Risler - CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide, Övrigt

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide

    Joseph Muniz, Steven Chimes, James Risler

    569 kr

    Joseph Muniz, Aamir Lakhani - Investigating the Cyber Breach, Häftad

    Investigating the Cyber Breach

    Joseph Muniz, Aamir Lakhani

    Häftad, 2018

    345 kr

    Omar Santos, Joseph Muniz, Stefano De Crescenzo - CCNA Cyber Ops SECFND #210-250 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECFND #210-250 Official Cert Guide

    Omar Santos, Joseph Muniz, Stefano De Crescenzo

    867 kr

    Omar Santos, Joseph Muniz - CCNA Cyber Ops SECOPS 210-255 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECOPS 210-255 Official Cert Guide

    Omar Santos, Joseph Muniz

    875 kr

    Joseph Muniz, Aamir Lakhani - Web Penetration Testing with Kali Linux, Häftad

    Web Penetration Testing with Kali Linux

    Joseph Muniz, Aamir Lakhani

    Häftad, 2013

    730 kr

    Aamir Lakhani, Joseph Muniz - Penetration Testing with Raspberry Pi, Häftad

    Penetration Testing with Raspberry Pi

    Aamir Lakhani, Joseph Muniz

    Häftad, 2015

    454 kr

    Hoppa över listan

    Du kanske också är intresserad av

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz - Security Operations Center, E-bok

    Security Operations Center

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz

    E-bok
    2015

    594 kr

    Nadhem AlFardan - Cyber Threat Hunting, Inbunden

    Cyber Threat Hunting

    Nadhem AlFardan

    Inbunden, 2025

    428 kr

    Nadhem AlFardan - Cyber Threat Hunting, E-bok

    Cyber Threat Hunting

    Nadhem AlFardan

    E-bok
    2025

    467 kr

    Omar Santos, Joseph Muniz, Stefano De Crescenzo - CCNA Cyber Ops SECFND #210-250 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECFND #210-250 Official Cert Guide

    Omar Santos, Joseph Muniz, Stefano De Crescenzo

    867 kr

    Joseph Muniz, Steven Chimes, James Risler - CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide, Övrigt

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide

    Joseph Muniz, Steven Chimes, James Risler

    569 kr

    Aamir Lakhani, Joseph Muniz - Penetration Testing with Raspberry Pi, Häftad

    Penetration Testing with Raspberry Pi

    Aamir Lakhani, Joseph Muniz

    Häftad, 2015

    454 kr

    Omar Santos, Joseph Muniz - CCNA Cyber Ops SECOPS 210-255 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECOPS 210-255 Official Cert Guide

    Omar Santos, Joseph Muniz

    875 kr

    Joseph Muniz, Aamir Lakhani - Web Penetration Testing with Kali Linux, Häftad

    Web Penetration Testing with Kali Linux

    Joseph Muniz, Aamir Lakhani

    Häftad, 2013

    730 kr

    Joseph Muniz, Aamir Lakhani - Investigating the Cyber Breach, Häftad

    Investigating the Cyber Breach

    Joseph Muniz, Aamir Lakhani

    Häftad, 2018

    345 kr

    Joseph Muniz - Modern Security Operations Center, The, Häftad

    Modern Security Operations Center, The

    Joseph Muniz

    Häftad, 2021

    419 kr