• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel och pussel

Pocketfynda! Hundratals böcker för 49 kr/st →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Information Security

    Principles and Practices

    AvMark Merkow,Jim Breithaupt

    Häftad, Engelska, 2014

    942 kr

    Beställningsvara. Skickas inom 7-10 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Information Security: Principles and Practices, Second Edition

    Everything You Need to Know About Modern Computer Security, in One Book

    Clearly explains all facets of information security in all 10 domains of the latest Information Security Common Body of Knowledge [(ISC)2 CBK].

    Thoroughly updated for today’s challenges, technologies, procedures, and best practices.

    The perfect resource for anyone pursuing an IT security career.

    Fully updated for the newest technologies and best practices, Information Security: Principles and Practices, Second Edition thoroughly covers all 10 domains of today’s Information Security Common Body of Knowledge.

    Two highly experienced security practitioners have brought together all the foundational knowledge you need to succeed in today’s IT and business environments. They offer easy-to-understand, practical coverage of topics ranging from security management and physical security to cryptography and application development security.

    This edition fully addresses new trends that are transforming security, from cloud services to mobile applications, “Bring Your Own Device” (BYOD) strategies to today’s increasingly rigorous compliance requirements. Throughout, you’ll find updated case studies, review questions, and exercises–all designed to reveal today’s real-world IT security challenges and help you overcome them.

    Learn how to

    -- Recognize the evolving role of IT security

    -- Identify the best new opportunities in the field

    -- Discover today’s core information security principles of success

    -- Understand certification programs and the CBK

    -- Master today’s best practices for governance and risk management

    -- Architect and design systems to maximize security

    -- Plan for business continuity

    -- Understand the legal, investigatory, and ethical requirements associated with IT security

    -- Improve physical and operational security

    -- Implement effective access control systems

    -- Effectively utilize cryptography

    -- Improve network and Internet security

    -- Build more secure software

    -- Define more effective security policies and standards

    -- Preview the future of information security

    Produktinformation

    • Utgivningsdatum:2014-06-26
    • Mått:180 x 230 x 22 mm
    • Vikt:640 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:368
    • Upplaga:2
    • Förlag:Pearson Education
    • ISBN:9780789753250

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT

    Mer om författaren

    Mark Merkow, CISSP, CISM, CSSLP, is a technical director for a Fortune 100 financial services firm, where he works on implementing and operating a software security practice for the enterprise. He has more than 35 years of IT experience, including 20 years in IT security. Mark has worked in a variety of roles, including applications development, systems analysis and design, security engineering, and security management. Mark holds a master’s degree in decision and info systems from Arizona State University (ASU), a master’s of education in Distance Learning from ASU, and a bachelor’s degree in Computer Info Systems from ASU.Jim Breithaupt is a data integrity manager for a major bank, where he manages risk for a large data mart. He has more than 30 years of data processing experience and has co-authored several other books on information systems and information security, along with Mark Merkow.

    Innehållsförteckning

    • PrefaceChapter 1: Why Study Information Security?IntroductionThe Growing Importance of IT Security and New Career OpportunitiesAn Increase in Demand by Government and Private IndustryBecoming an Information Security SpecialistSchools Are Responding to DemandsThe Importance of a Multidisciplinary ApproachContextualizing Information SecurityInformation Security Careers Meet the Needs of BusinessSummaryChapter 2: Information Security Principles of SuccessIntroductionPrinciple 1: There Is No Such Thing As Absolute SecurityPrinciple 2: The Three Security Goals Are Confidentiality, Integrity, and AvailabilityIntegrity ModelsAvailability ModelsPrinciple 3: Defense in Depth as StrategyPrinciple 4: When Left on Their Own, People Tend to Make the Worst Security DecisionsPrinciple 5: Computer Security Depends on Two Types of Requirements: Functional and AssurancePrinciple 6: Security Through Obscurity Is Not an AnswerPrinciple 7: Security = Risk ManagementPrinciple 8: The Three Types of Security Controls Are Preventative, Detective, and ResponsivePrinciple 9: Complexity Is the Enemy of SecurityPrinciple 10: Fear, Uncertainty, and Doubt Do Not Work in Selling SecurityPrinciple 11: People, Process, and Technology Are All Needed to Adequately Secure a System or FacilityPrinciple 12: Open Disclosure of Vulnerabilities Is Good for Security!SummaryChapter 3: Certification Programs and the Common Body of KnowledgeIntroductionCertification and Information SecurityInternational Information Systems Security Certifications Consortium (ISC)2The Information Security Common Body of KnowledgeInformation Security Governance and Risk ManagementSecurity Architecture and DesignBusiness Continuity and Disaster Recovery PlanningLegal Regulations, Investigations, and CompliancePhysical (Environmental) SecurityOperations SecurityAccess ControlCryptographyTelecommunications and Network SecuritySoftware Development SecurityOther Certificate Programs in the IT Security IndustryCertified Information Systems AuditorCertified Information Security ManagerCertified in Risk and Information Systems ControlGlobal Information Assurance Certifications(ISC)2 Specialization CertificatesCCFP: Certified Cyber Forensics ProfessionalHCISPP: HealthCare Information Security and Privacy PractitionerVendor-Specific and Other Certification ProgramsSummaryChapter 4: Governance and Risk ManagementIntroductionSecurity Policies Set the Stage for SuccessUnderstanding the Four Types of PoliciesProgramme-Level PoliciesProgramme-Framework PoliciesIssue-Specific PoliciesSystem-Specific PoliciesDeveloping and Managing Security PoliciesSecurity ObjectivesOperational SecurityPolicy ImplementationProviding Policy Support DocumentsRegulationsStandards and BaselinesGuidelinesProceduresSuggested Standards TaxonomyAsset and Data ClassificationSeparation of DutiesEmployment Hiring PracticesRisk Analysis and ManagementEducation, Training, and AwarenessWho Is Responsible for Security?SummaryChapter 5: Security Architecture and DesignIntroductionDefining the Trusted Computing BaseRings of TrustProtection Mechanisms in a TCBSystem Security Assurance ConceptsGoals of Security TestingFormal Security Testing ModelsThe Trusted Computer Security Evaluation CriteriaDivision D: Minimal ProtectionDivision C: Discretionary ProtectionDivision B: Mandatory ProtectionDivision A: Verified ProtectionThe Trusted Network Interpretation of the TCSECThe Information Technology Security Evaluation CriteriaComparing ITSEC to TCSECITSEC Assurance ClassesThe Canadian Trusted Computer Product Evaluation CriteriaThe Federal Criteria for Information Technology SecurityThe Common CriteriaProtection Profile OrganizationSecurity Functional RequirementsEvaluation Assurance LevelsThe Common Evaluation MethodologyConfidentiality and Integrity ModelsBell-LaPadula ModelBiba Integrity ModelAdvanced ModelsSummaryChapter 6: Business Continuity Planning and Disaster Recovery PlanningIntroductionOverview of the Business Continuity Plan and Disaster Recovery PlanWhy the BCP Is So ImportantTypes of Disruptive EventsDefining the Scope of the BCPCreating the Business Impact AnalysisDisaster Recovery PlanningIdentifying Recovery StrategiesUnderstanding Shared-Site AgreementsUsing Alternate SitesMaking Additional ArrangementsTesting the DRPSummaryChapter 7: Law, Investigations, and EthicsIntroductionTypes of Computer CrimeHow Cybercriminals Commit CrimesThe Computer and the LawLegislative Branch of the Legal SystemAdministrative Branch of the Legal SystemJudicial Branch of the Legal SystemIntellectual Property LawPatent LawTrademarksTrade SecretsPrivacy and the LawInternational Privacy IssuesPrivacy Laws in the United StatesComputer ForensicsThe Information Security Professional’s Code of EthicsOther Ethics StandardsComputer Ethics InstituteInternet Activities Board: Ethics and the InternetCode of Fair Information PracticesSummaryChapter 8: Physical Security ControlIntroductionUnderstanding the Physical Security DomainPhysical Security ThreatsProviding Physical SecuritySummaryChapter 9: Operations SecurityIntroductionOperations Security PrinciplesOperations Security Process ControlsOperations Security Controls in ActionSoftware SupportConfiguration and Change ManagementBackupsMedia ControlsDocumentationMaintenanceInterdependenciesSummaryChapter 10: Access Control Systems and MethodologyIntroductionTerms and ConceptsIdentificationAuthenticationLeast Privilege (Need to Know)Information OwnerDiscretionary Access ControlAccess Control ListsMandatory Access ControlRole-Based Access ControlPrinciples of AuthenticationThe Problems with PasswordsMultifactor AuthenticationBiometricsSingle Sign-OnKerberosFederated IdentitiesRemote User Access and AuthenticationRemote Access Dial-In User ServiceVirtual Private NetworksSummaryChapter 11: CryptographyIntroductionApplying Cryptography to Information SystemsBasic Terms and ConceptsStrength of CryptosystemsCryptosystems Answer the Needs of Today’s E-CommerceThe Role of Keys in CryptosystemsPutting the Pieces to WorkDigesting DataDigital CertificatesExamining Digital CryptographyHashing FunctionsBlock CiphersImplementations of PPK CryptographySummaryChapter 12: Telecommunications, Network, and Internet SecurityIntroductionAn Overview of Network and Telecommunications SecurityNetwork Security in ContextThe Open Systems Interconnection Reference ModelThe Protocol StackThe OSI Reference Model and TCP/IPThe OSI Model and SecurityData Network TypesLocal Area NetworksWide Area NetworksInternetIntranetExtranetProtecting TCP/IP NetworksBasic Security InfrastructuresRoutersFirewallsIntrusion Detection SystemsIntrusion Prevention SystemsVirtual Private NetworksIPSecEncapsulating Security ProtocolSecurity AssociationInternet Security Association and Key Management ProtocolSecurity PoliciesIPSec Key ManagementApplied VPNsCloud ComputingSummaryChapter 13: Software Development SecurityIntroductionThe Practice of Software EngineeringSoftware Development Life CyclesDon’t Bolt Security On–Build It InCatch Problems Sooner Rather Than LaterRequirements Gathering and AnalysisSystems Design and Detailed DesignDesign ReviewsDevelopment (Coding) PhaseTestingDeploymentSecurity TrainingMeasuring the Secure Development ProgramOpen Software Assurance Maturity Model (OpenSAMM)Building Security in Maturity Model (BSIMM)SummaryChapter 14: Securing the FutureIntroductionOperation Eligible ReceiverCarders, Account Takeover, and Identity TheftSome DefinitionsZeuS Banking TrojanPhishing and Spear PhishingOther Trends in Internet (In)SecurityThe Year (Decade?) of the BreachThe Rosy Future for InfoSec SpecialistsSummaryAppendix A: Common Body of KnowledgeAccess ControlTelecommunications and Network SecurityInformation Security Governance and Risk ManagementSoftware Development SecurityCryptographySecurity Architecture and DesignOperations SecurityBusiness Continuity and Disaster Recovery PlanningLegal Regulations, Investigations, and CompliancePhysical (Environmental) SecurityAppendix B: Security Policy and Standards TaxonomyAppendix C: Sample PoliciesSample Computer Acceptable Use Policy1.0.0 Acceptable Use PolicySample Email Use Policy1.0.0 Email Use PolicySample Password Policy1.0.0 Password PolicySample Wireless (WiFi) Use Policy1.0.0 Wireless Communication PolicyAppendix D: HIPAA Security Rule StandardsHIPAA Security StandardsAdministrative ProceduresPhysical SafeguardsTechnical Security ServicesTechnical Security Mechanisms9780789753250 TOC 5/7/2014