Book description
Develop and implement an effective end-to-end security program
Today’s complex world of mobile platforms, cloud computing, and ubiquitous data access puts new security demands on every IT professional. Information Security: The Complete Reference, Second Edition (previously titled Network Security: The Complete Reference) is the only comprehensive book that offers vendor-neutral details on all aspects of information protection, with an eye toward the evolving threat landscape. Thoroughly revised and expanded to cover all aspects of modern information security—from concepts to details—this edition provides a one-stop reference equally applicable to the beginner and the seasoned professional.
Find out how to build a holistic security program based on proven methodology, risk analysis, compliance, and business needs. You’ll learn how to successfully protect data, networks, computers, and applications. In-depth chapters cover data protection, encryption, information rights management, network security, intrusion detection and prevention, Unix and Windows security, virtual and cloud security, secure application development, disaster recovery, forensics, and real-world attacks and countermeasures. Included is an extensive security glossary, as well as standards-based references. This is a great resource for professionals and students alike.
- Understand security concepts and building blocks
- Identify vulnerabilities and mitigate risk
- Optimize authentication and authorization
- Use IRM and encryption to protect unstructured data
- Defend storage devices, databases, and software
- Protect network routers, switches, and firewalls
- Secure VPN, wireless, VoIP, and PBX infrastructure
- Design intrusion detection and prevention systems
- Develop secure Windows, Java, and mobile applications
- Perform incident response and forensic analysis
Table of contents
- Cover
- About the Author
- Title Page
- Copyright Page
- Contents at a Glance
- Contents
- Preface
- Acknowledgments
- Introduction
-
Part I: Foundations
- Chapter 1: Information Security Overview
- Chapter 2: Risk Analysis
- Chapter 3: Compliance with Standards, Regulations, and Laws
-
Chapter 4: Secure Design Principles
- The CIA Triad and Other Models
- Defense Models
- Zones of Trust
-
Best Practices for Network Defense
- Secure the Physical Environment
- Harden the Operating System
- Keep Patches Updated
- Use an Antivirus Scanner (with Real-Time Scanning)
- Use Firewall Software
- Secure Network Share Permissions
- Use Encryption
- Secure Applications
- Back Up the System
- Implement ARP Poisoning Defenses
- Create a Computer Security Defense Plan
- Summary
- References
-
Chapter 5: Security Policies, Standards, Procedures, and Guidelines
-
Security Policies
- Security Policy Development
- Security Policy Contributors
- Security Policy Audience
- Policy Categories
- Frameworks
- Security Awareness
- Importance of Security Awareness
- Objectives of an Awareness Program
- Increasing Effectiveness
- Implementing the Awareness Program
- Enforcement
- Policy Enforcement for Vendors
- Policy Enforcement for Employees
- Software-Based Enforcement
- Example Security Policy Topics
- Acceptable Use Policies
- Computer Policies
- Network Policies
- Data Privacy Policies
- Data Integrity Policies
- Personnel Management Policies
- Security Management Policies
- Physical Security Policies
- Security Standards
- Security Procedures
- Security Guidelines
- Ongoing Maintenance
- Summary
- References
-
Security Policies
- Chapter 6: Security Organization
- Chapter 7: Authentication and Authorization
-
Part II: Data Security
- Chapter 8: Securing Unstructured Data
- Chapter 9: Information Rights Management
- Chapter 10: Encryption
- Chapter 11: Storage Security
- Chapter 12: Database Security
-
Part III: Network Security
- Chapter 13: Secure Network Design
- Chapter 14: Network Device Security
- Chapter 15: Firewalls
- Chapter 16: Virtual Private Networks
-
Chapter 17: Wireless Network Security
- Radio Frequency Security Basics
- Data-Link Layer Wireless Security Features, Flaws, and Threats
- Wireless Vulnerabilities and Mitigations
- Wireless Network Hardening Practices and Recommendations
- Wireless Intrusion Detection and Prevention
- Wireless Network Positioning and Secure Gateways
- Summary
- References
- Chapter 18: Intrusion Detection and Prevention Systems
- Chapter 19: Voice over IP (VoIP) and PBX Security
-
Part IV: Computer Security
- Chapter 20: Operating System Security Models
- Chapter 21: Unix Security
-
Chapter 22: Windows Security
-
Securing Windows Systems
- Disable Windows Services and Remove Software
- Securely Configure Remaining Software
- Use Group Policy to Manage Settings
- Computer Policies
- User Policies
- Security Configuration and Analysis
- Group Policy
- Install Security Software
- Application Whitelisting
- Patch Systems Regularly
- Segment the Network into Zones of Trust
- Blocking and Filtering Access to Services
- Mitigating the Effect of Spoofed Ports
- Strengthen Authentication Processes
- Require, Promote, and Train Users in Using Strong Passwords
- Use Alternatives to Passwords
- Apply Technology and Physical Controls to Protect Access Points
- Modify Defaults for Windows Authentication Systems
- Limit the Number of Administrators and Limit the Privileges of Administrators
- Applications that Require Admin Access to Files and the Registry
- Elevated Privileges Are Required
- Programmers as Administrators
- Requiring Administrators to Use runas
- Active Directory Domain Architecture
- Compliance with Standards
- Summary
- References
-
Securing Windows Systems
- Chapter 23: Securing Infrastructure Services
- Chapter 24: Virtual Machines and Cloud Computing
- Chapter 25: Securing Mobile Devices
-
Part V: Application Security
- Chapter 26: Secure Application Design
- Chapter 27: Writing Secure Software
- Chapter 28: J2EE Security
- Chapter 29: Windows .NET Security
- Chapter 30: Controlling Application Behavior
-
Part VI: Security Operations
- Chapter 31: Security Operations Management
- Chapter 32: Disaster Recovery, Business Continuity, Backups, and High Availability
- Chapter 33: Incident Response and Forensic Analysis
- Part VII: Physical Security
- Glossary
- Index
Product information
- Title: Information Security: The Complete Reference, Second Edition, 2nd Edition
- Author(s):
- Release date: April 2013
- Publisher(s): McGraw-Hill
- ISBN: 9780071784368
You might also like
book
Information Security Fundamentals, 2nd Edition
Following in the footsteps of its bestselling predecessor, Information Security Fundamentals, Second Edition provides information security …
book
Computer and Information Security Handbook, 3rd Edition
Computer and Information Security Handbook, Third Edition, provides the most current and complete reference on computer …
book
Computer and Information Security Handbook, 2nd Edition
The second edition of this comprehensive handbook of computer and information security provides the most complete …
book
Practical Internet of Things Security - Second Edition
A practical, indispensable security guide that will navigate you through the complex realm of securely building …