• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod: NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. IT-säkerhet

    Information Security and IT Risk Management

    AvManish Agrawal,Alex Campoe

    Häftad, Engelska, 2014

    1 742 kr

    Beställningsvara. Skickas inom 11-20 vardagar. Fri frakt över 249 kr.

    Beskrivning

    This new text provides students the knowledge and skills they will need to compete for and succeed in the information security roles they will encounter straight out of college.  This is accomplished by providing a hands-on immersion in essential system administration, service and application installation and configuration, security tool use, TIG implementation and reporting. It is designed for an introductory course on IS Security offered usually as an elective in IS departments in 2 and 4 year schools.  It is not designed for security certification courses.

    Produktinformation

    • Utgivningsdatum:2014-03-14
    • Mått:185 x 231 x 23 mm
    • Vikt:680 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:432
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781118335895

    Utforska kategorier

    • IT-säkerhet inom Data och IT

    Mer om författaren

    Manish Agrawal recieved his PhD Information Systems from SUNY Buffalo in 2002 and?Bachelor and Master degrees in Electrical Engineering from the Indian Institute of Technology in Kanpur, India. He is an Associate Professor in the?Department of Information Systems and Decision Sciences at the University of South Florida. He currently teaches courses in business data communications, information security and web applications development.?He was the recipient of USF's university-wide award recognizing teaching excellence in 2006 and has published research in academic journals including Management Science, INFORMS Journal on Computing, Journal of Management Information Systems, IEEE Transactions on Software Engineering, Decision Support Systems and the Journal of Organizational Computing and Electronic Commerce. His research and teaching have been funded by the US National Science Foundation, the US Department of Justice, the Indo-US Science and Technology Forum and Sun Microsystems.

    Innehållsförteckning

    • Chapter 1: IntroductionOverviewProfessional utility of information security knowledgeBrief historyDefinition of information securitySummaryExample case – wikileaks, cablegate, and free reign over classified networksChapter review questionsExample case questionsHands-on activity – software inspector, steganographyCritical thinking exercise: identifying CIA area(s) affected by sample real-life hacking incidentsDesign caseChapter 2: System Administration (Part 1)OverviewIntroductionWhat is system administration?System administration and information securityCommon system administration tasksSystem administration utilitiesSummaryExample case - T J MaxxChapter review questionsExample case questionsHands-on Activity – linux system installationCritical thinking exercise – Google executives sentenced toPrison over videoDesign caseChapter 3: System Administration (Part 2)OverviewOperating system structureThe command-line interfaceFiles and DirectoriesMoving around the filesystem – pwd, cdListing files and directoriesShell ExpansionsFile ManagementViewing FilesSearching for fi lesAccess control and user managementAccess control listsFile ownershipEditing fi lesSoftware installation and updatesAccount managementCommand-line user administrationExample case – Northwest Florida State CollegeSummaryChapter review questionsExample case questionsHands-on activity–basic linux system administrationCritical thinking exercise – offensive cyber effects operations (OCEO)Design CaseChapter 4: The basic Information security modelOverviewIntroductionComponents of the basic information security modelCommon vulnerabilities, threats and controlsExample case – ILOVEYOU virusSummaryChapter review questionsExample case questionsHands-on activity–web server securityCritical thinking exercise–the internet, "american values" and securityDesign CaseChapter 5: Asset Identification and CharacterizationOverviewAssets overviewDetermining assets that are important to the organizationAsset TypesAsset CharacterizationIT asset lifecycle and asset identificationSystem profilingAsset ownership and operational responsibilitiesExample case–StuxnetSummaryChapter review questionsExample case questionsHands–on activity–course asset identificationCritical thinking exercise – uses of a hacked PCDesign caseChapter 6: Threats and VulnerabilitiesOverviewIntroductionThreat modelsThreat AgentThreat ActionVulnerabilitiesExample case–GoziSummaryChapter Review QuestionsExample case questionsHands-on activity–Vulnerability scanningCritical thinking exercise–Iraq cyber war plans in 2003Design caseChapter 7: Encryption ControlsOverviewIntroductionEncryption basicsEncryption types overviewEncryption types detailsEncryption in useExample case – Nation technologiesSummaryChapter review questionsExample case questionsHands-on activity–encryptionCritical thinking exercise–encryption keys embed business modelsDesign caseChapter 8: Identity and Access ManagementOverviewIdentity managementAccess ManagementAuthenticationSingle sign-onFederationExample case – markus hessSummaryChapter review questionsExample case questionsHands-on activity – identity match and mergeCritical thinking exercise – feudalism the security solution for the internet?Design caseChapter 9: Hardware and Software ControlsOverviewPassword managementAccess controlFirewallsIntrusion detection/prevention systemsPatch management for operating systems and applicationsEnd point protectionExample case – AirTight NetworksChapter review questionsExample case questionsHands-on activity – host-based IDS (OSSEC)Critical thinking exercise – extra-human security controlsDesign caseChapter 10: Shell ScriptingOverviewIntroductionOutput redirectionText manipulationVariablesConditionalsUser inputLoopsPutting it all togetherExample case–Max ButlerSummaryChapter review questionsExample case questionsHands-on Activity – basic scriptingCritical thinking exercise–script securityDesign caseChapter 11: Incident HandlingIntroductionIncidents overviewIncident handlingThe disasterExample case – on-campus piracySummaryChapter review questionsExample case questionsHands-on activity – incident timeline using OSSECCritical thinking exercise – destruction at the EDADesign caseChapter 12: Incident AnalysisIntroductionLog analysisEvent criticalityGeneral log configuration and maintenanceLive Incident responseTimelinesOther forensics topicsExample case - backup server compromiseChapter review questionsExample case questionsHands-on activity – server log analysisCritical thinking exercise – destruction at the EDA (contd.)Design caseChapter 13: Policies, Standards, and GuidelinesIntroductionGuiding principlesWriting a policyImpact assessment and vettingPolicy reviewComplianceKey Policy IssuesExample case – H B GarySummaryReferenceChapter review questionsExample case questionsHands-on activity – create an AUPCritical thinking exercise – aaron swartzDesign CaseChapter 14: IT risk analysis and risk managementOverviewIntroductionRisk management as a component of organizationalmanagementRisk management frameworkThe NIST 800-39 frameworkRisk assessmentOther risk management frameworksIT general controls for sarbanes-oxley complianceCompliance versus risk managementSelling securityExample case – online marketplace purchasesSummaryChapter review questionsHands-on activity – risk assessment using lsofCritical thinking exercise – risk estimation biasesDesign CaseAppendix A: Password List for the Linux Virtual MachineGlossaryIndex