• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod: NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. IT-säkerhet

    Effective Vulnerability Management

    Managing Risk in the Vulnerable Digital Ecosystem

    AvChris Hughes,Nikki Robinson

    Häftad, Engelska, 2024

    259 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Infuse efficiency into risk mitigation practices by optimizing resource use with the latest best practices in vulnerability management Organizations spend tremendous time and resources addressing vulnerabilities to their technology, software, and organizations. But are those time and resources well spent? Often, the answer is no, because we rely on outdated practices and inefficient, scattershot approaches. Effective Vulnerability Management takes a fresh look at a core component of cybersecurity, revealing the practices, processes, and tools that can enable today's organizations to mitigate risk efficiently and expediently in the era of Cloud, DevSecOps and Zero Trust. Every organization now relies on third-party software and services, ever-changing cloud technologies, and business practices that introduce tremendous potential for risk, requiring constant vigilance. It's more crucial than ever for organizations to successfully minimize the risk to the rest of the organization's success. This book describes the assessment, planning, monitoring, and resource allocation tasks each company must undertake for successful vulnerability management. And it enables readers to do away with unnecessary steps, streamlining the process of securing organizational data and operations. It also covers key emerging domains such as software supply chain security and human factors in cybersecurity. Learn the important difference between asset management, patch management, and vulnerability management and how they need to function cohesivelyBuild a real-time understanding of risk through secure configuration and continuous monitoringImplement best practices like vulnerability scoring, prioritization and design interactions to reduce risks from human psychology and behaviorsDiscover new types of attacks like vulnerability chaining, and find out how to secure your assets against themEffective Vulnerability Management is a new and essential volume for executives, risk program leaders, engineers, systems administrators, and anyone involved in managing systems and software in our modern digitally-driven society.

    Produktinformation

    • Utgivningsdatum:2024-04-22
    • Mått:152 x 226 x 20 mm
    • Vikt:318 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:288
    • Förlag:John Wiley & Sons Inc
    • Medarbetare:Ron Gula
    • ISBN:9781394221202

    Utforska kategorier

    • IT-säkerhet inom Data och IT

    Mer om författaren

    CHRIS HUGHES, M.S., MBA, currently serves as the Co-Founder and President at Aquia and has 20 years of IT/Cybersecurity experience in the public and private sectors. He is also an adjunct professor for M.S. Cybersecurity programs. Chris co-hosts the Resilient Cyber Podcast and also serves as a Cyber Innovation Fellow at CISA. NIKKI ROBINSON, DSc, PhD, is a Security Architect and Professor of Practice at Capitol Technology University. She holds a DSc in Cybersecurity and a PhD in Human Factors.

    Innehållsförteckning

    • Foreword xviiIntroduction xix1 Asset Management 1Physical and Mobile Asset Management 3Consumer IoT Assets 4Software Assets 5Cloud Asset Management 6Multicloud Environments 7Hybrid Cloud Environments 7Third-Party Software and Open Source Software (OSS) 9Third-Party Software (and Risk) 10Accounting for Open Source Software 11On-Premises and Cloud Asset Inventories 11On-Premises Data Centers 12Tooling 13Asset Management Tools 13Vulnerability Scanning Tools 14Cloud Inventory Management Tools 15Ephemeral Assets 16Sources of Truth 17Asset Management Risk 18Log4j 18Missing and Unaccounted-for Assets 19Unknown Unknowns 20Patch Management 21Recommendations for Asset Management 22Asset Manager Responsibilities 22Asset Discovery 23Getting the Right Tooling 24Digital Transformation 25Establishing and Decommissioning Standard Operating Procedures 26Summary 272 Patch Management 29Foundations of Patch Management 29Manual Patch Management 30Risks of Manual Patching 31Manual Patching Tooling 32Automated Patch Management 34Benefits of Automated vs Manual Patching 35Combination of Manual and Automated Patching 36Risks of Automated Patching 37Patch Management for Development Environments 38Open Source Patching 38Not All Software Is Equal 39Managing OSS Patches Internally 39Responsibilities of Infrastructure vs Operations Teams 40Who Owns Patch Management? 41Separation of Duties 42Tools and Reporting 43Patching Outdated Systems 43End-of-Life Software 44Unpatched Open Source Software 45Residual Risk 46Common Attacks for Unpatched Systems 47Prioritizing Patching Activities 48Risk Management and Patching 49Building a Patch Management Program 50People 50Process 51Technology 51Summary 523 Secure Configuration 53Regulations, Frameworks, and Laws 53NSA and CISA Top Ten Cybersecurity Misconfigurations 54Default Configurations of Software and Applications 55Improper Separation of User/Administrator Privilege 57Insufficient Internal Network Monitoring 57Lack of Network Segmentation 58Poor Patch Management 58Bypass of System Access Controls 60Weak or Misconfigured Multifactor Authentication Methods 60Lack of Phishing-Resistant MFA 61Insufficient Access Control Lists on Network Shares and Services 61Poor Credential Hygiene 61Unrestricted Code Execution 62Mitigations 62Default Configurations of Software Applications 63Improper Separation of User/Administration Privilege 64Insufficient Network Monitoring 64Poor Patch Management 64Wrapping up the CIS Misconfigurations Guidance 65CIS Benchmarks 65DISA Security Technical Implementation Guides 66Summary 684 Continuous Vulnerability Management 69CIS Control 7—Continuous Vulnerability Management 70Establish and Maintain a Vulnerability Management Process 70Establish and Maintain a Remediation Process 71Perform Automated Operating System Patch Management 71Perform Automated Application Patch Management 72Perform Automated Vulnerability Scans of Internal Enterprise Assets 73Perform Automated Vulnerability Scans of Externally Exposed Enterprise Assets 73Remediate Detected Vulnerabilities 74Continuous Monitoring Practices 74Summary 775 Vulnerability Scoring and Software Identification 79Common Vulnerability Scoring System 79CVSS 4.0 at a Glance 80Base Metrics 84Exploitability Metrics 84Threat Metrics 86Environmental Metrics 88Supplemental Metrics 89Qualitative Severity Rating Scale 91Vector String 92Exploit Prediction Scoring System 92EPSS 3.0—Prioritizing Through Prediction 92Epss 3.0 94Moving Forward 95Stakeholder-Specific Vulnerability Categorization 97CISA SSVC Guide 99Decision Tree Example 106Software Identification Formats 107Common Platform Enumeration 108Package URL 110Software Identification Tags 110Common Weaknesses and Enumerations 112Summary 1146 Vulnerability and Exploit Database Management 115National Vulnerability Database (NVD) 115Sonatype Open Source Software Index 118Open Source Vulnerabilities 119GitHub Advisory Database 120Exploit Databases 121Exploit-DB 122Metasploit 122GitHub 122Summary 1237 Vulnerability Chaining 125Vulnerability Chaining Attacks 125Exploit Chains 127Daisy Chains 128Vendor-Released Chains 129Microsoft Active Directory 129VMware vRealize Products 130iPhone Exploit Chain 130Vulnerability Chaining and Scoring 131Common Vulnerability Scoring System 132EPSS 132Gaps in the Industry 133Vulnerability Chaining Blindness 134Terminology 135Usage in Vulnerability Management Programs 136The Human Aspect of Vulnerability Chaining 138Phishing 138Business Email Compromise 139Social Engineering 140Integration into VMPs 141Leadership Principles 142Security Practitioner Integration 142IT and Development Usage 143Summary 1448 Vulnerability Threat Intelligence 145Why Is Threat Intel Important to VMPs? 145Where to Start 146Technical Threat Intelligence 146Tactical Threat Intelligence 147Strategic Threat Intelligence 148Operational Threat Intelligence 149Threat Hunting 150Integrating Threat Intel into VMPs 151People 151Process 152Technology 153Summary 1549 Cloud, DevSecOps, and Software Supply Chain Security 155Cloud Service Models and Shared Responsibility 156Hybrid and Multicloud Environments 158Containers 159Kubernetes 165Serverless 169DevSecOps 170Open Source Software 174Software-as-a-Service 182Systemic Risks 183Summary 18610 The Human Element in Vulnerability Management 187Human Factors Engineering 189Human Factors Security Engineering 191Context Switching 191Vulnerability Dashboards 193Vulnerability Reports 194Cognition and Metacognition 196Vulnerability Cognition 197The Art of Decision-.Making 197Decision Fatigue 198Alert Fatigue 199Volume of Vulnerabilities Released 199Required Patches and Configurations 200Vulnerability Management Fatigue 201Mental Workload 202Integration of Human Factors into a VMP 202Start Small 203Consider a Consultant 204Summary 20511 Secure-by-Design 207Secure-by-Design/Default 208Secure-by-Design 209Secure-by-Default 210Software Product Security Principles 211Principle 1: Take Ownership of Customer Security Outcomes 211Principle 2: Embrace Radical Transparency and Accountability 214Principle 3: Lead from the Top 216Secure-by-Design Tactics 217Secure-by-Default Tactics 218Hardening vs Loosening Guides 218Recommendations for Customers 219Threat Modeling 220Secure Software Development 222SSDF Details 223Prepare the Organization (PO) 223Protect Software (PS) 225Produce Well-Secured Software (PW) 226Respond to Vulnerabilities (RV) 227Security Chaos Engineering and Resilience 229Summary 23112 Vulnerability Management Maturity Model 233Step 1: Asset Management 234Step 2: Secure Configuration 236Step 3: Continuous Monitoring 238Step 4: Automated Vulnerability Management 240Step 5: Integrating Human Factors 242Step 6: Vulnerability Threat Intelligence 244Summary 245Acknowledgments 247About the Authors 249About the Technical Editor 251Index 253