Book description
The first expert discussion of the foundations of cybersecurity
In Cybersecurity First Principles, Rick Howard, the Chief Security Officer, Chief Analyst, and Senior fellow at The Cyberwire, challenges the conventional wisdom of current cybersecurity best practices, strategy, and tactics and makes the case that the profession needs to get back to first principles. The author convincingly lays out the arguments for the absolute cybersecurity first principle and then discusses the strategies and tactics required to achieve it.
In the book, you'll explore:
- Infosec history from the 1960s until the early 2020s and why it has largely failed
- What the infosec community should be trying to achieve instead
- The arguments for the absolute and atomic cybersecurity first principle
- The strategies and tactics to adopt that will have the greatest impact in pursuing the ultimate first principle
- Case studies through a first principle lens of the 2015 OPM hack, the 2016 DNC Hack, the 2019 Colonial Pipeline hack, and the Netflix Chaos Monkey resilience program
- A top to bottom explanation of how to calculate cyber risk for two different kinds of companies
This book is perfect for cybersecurity professionals at all levels: business executives and senior security professionals, mid-level practitioner veterans, newbies coming out of school as well as career-changers seeking better career opportunities, teachers, and students.
Table of contents
- Cover
- Title Page
- Who We Are
- Introduction
- 1 First Principles
-
2 Strategies
- Overview
- Strategies vs. Tactics
- What Are the Essential Strategies Required for a First Principle Infosec Program?
- Zero Trust Strategy Overview
- Intrusion Kill Chain Prevention Strategy Overview
- Resilience Strategy Overview
- Risk Forecasting Strategy Overview
- Automation Strategy Overview
- Conclusion
- Notes
-
3 Zero Trust
- Overview
- The Use Case for Zero Trust: Edward Snowden
- Zero Trust: Overhyped in the Market but…
- Cyber Hygiene, Defense in Depth, and Perimeter Defense: Zero Trust Before We Had Zero Trust
- Zero Trust Is Born
- Zero Trust Is a Philosophy, Not a Product
- Meat‐and‐Potatoes Zero Trust
- Logical and Micro Segmentation
- Vulnerability Management: A Zero Trust Tactic
- Software Bill of Materials: A Zero Trust Tactic
- Identity Management: A Tactic for Zero Trust
- Single Sign‐On: A Zero Trust Tactic
- Two‐Factor Authentication: A Tactic for Zero Trust
- Software‐Defined Perimeter: A Tactic for Zero Trust
- Why Zero Trust Projects Fail
- Conclusion
- Notes
-
4 Intrusion Kill Chain Prevention
- Overview
- The Beginnings of a New Idea
- The Lockheed Martin Kill Chain Paper
- Kill Chain Models
- Cyber Threat Intelligence Operations As a Journey
- Red/Blue/Purple Team Operations: A Tactic for Intrusion Kill Chain Prevention
- Intelligence Sharing: A Tactic for Intrusion Kill Chain Prevention
- Conclusion
- Notes
- 5 Resilience
- 6 Risk Forecasting
- 7 Automation
- 8 Summation
- Index
- Copyright
- Dedication
- About the Authors
- About the Technical Editors
- Acknowledgments
- End User License Agreement
Product information
- Title: Cybersecurity First Principles: A Reboot of Strategy and Tactics
- Author(s):
- Release date: April 2023
- Publisher(s): Wiley
- ISBN: 9781394173082
You might also like
book
ISC2 CISSP Certified Information Systems Security Professional Official Study Guide, 10th Edition
CISSP Study Guide - fully updated for the 2024 CISSP Body of Knowledge ISC2 Certified Information …
audiobook
(ISC)2 CISSP Certified Information Systems Security Professional Official Study Guide 9th Edition
(ISC)2 Certified Information Systems Security Professional (CISSP) Official Study Guide, 9th Edition has been completely updated …
video
CISSP, 3rd Edition
27+ Hours of Video Instruction Overview: CISSP Complete Video Course, 3rd Edition, is your full study …
book
Principles of Computer Security: CompTIA Security+ and Beyond, Sixth Edition (Exam SY0-601), 6th Edition
Fully updated computer security essentials—mapped to the CompTIA Security+ SY0-601 exam Save 10% on any CompTIA …