Book description
Information security is broken. Users and customers continually entrust companies with vital information, and companies continually fail to maintain that trust. Year after year, the same attacks are successful. But the impact has become greater. Those who build, operate, and defend systems need to acknowledge that failure will happen. People will click on the wrong thing. The security implications of code changes won't be clear. Things will break.
In this report, Aaron Rinehart and Kelly Shortridge explain how engineers can navigate security in this new frontier. You'll learn the guiding principles of security chaos engineering for harnessing experimentation and failure as tools for empowerment--and you'll understand how to transform security from a gatekeeper to a valued advisor. Case studies from Capital One and Cardinal Health are included.
- Apply chaos engineering and resilience engineering to securely deliver software and services
- Transform security into an innovative and collaborative engine for enhancing operational speed and stability
- Anticipate and identify security failure before it turns into an incident, outage, or breach
- Harness failure to continuously improve your security strategy
- Learn your systems' ability to handle security-relevant failures such as system exploitation and server failures
- Apply a series of controlled experiments in engineering testing processes
Table of contents
- The Case for Security Chaos Engineering
- 1. Experimenting with Failure
- 2. Decision Trees—Making Attacker Math Work for You
- 3. SCE versus Security Theater—Getting Drama out of Security
- 4. Democratizing Security
- 5. Build Security in SCE
- 6. Production Security in SCE
- 7. The Journey into SCE
- 8. Case Studies
- Conclusion
- Acknowledgments
- About the Authors
Product information
- Title: Security Chaos Engineering
- Author(s):
- Release date: December 2020
- Publisher(s): O'Reilly Media, Inc.
- ISBN: 9781492080343
You might also like
book
Security Chaos Engineering
Cybersecurity is broken. Year after year, attackers remain unchallenged and undeterred, while engineering teams feel pressure …
book
Security Engineering, 3rd Edition
Now that there’s software in everything, how can you make anything secure? Understand how to engineer …
audiobook
(ISC)2 CISSP Certified Information Systems Security Professional Official Study Guide 9th Edition
(ISC)2 Certified Information Systems Security Professional (CISSP) Official Study Guide, 9th Edition has been completely updated …
book
ISC2 CISSP Certified Information Systems Security Professional Official Study Guide, 10th Edition
CISSP Study Guide - fully updated for the 2024 CISSP Body of Knowledge ISC2 Certified Information …