Cybersecurity First Principles: A Reboot of Strategy and Tactics
- 5h 43m
- Rick Howard
- John Wiley & Sons (US)
- 2023
The first expert discussion of the foundations of cybersecurity
In Cybersecurity First Principles, Rick Howard, the Chief Security Officer, Chief Analyst, and Senior fellow at The Cyberwire, challenges the conventional wisdom of current cybersecurity best practices, strategy, and tactics and makes the case that the profession needs to get back to first principles. The author convincingly lays out the arguments for the absolute cybersecurity first principle and then discusses the strategies and tactics required to achieve it.
In the book, you'll explore:
- Infosec history from the 1960s until the early 2020s and why it has largely failed
- What the infosec community should be trying to achieve instead
- The arguments for the absolute and atomic cybersecurity first principle
- The strategies and tactics to adopt that will have the greatest impact in pursuing the ultimate first principle
- Case studies through a first principle lens of the 2015 OPM hack, the 2016 DNC Hack, the 2019 Colonial Pipeline hack, and the Netflix Chaos Monkey resilience program
- A top to bottom explanation of how to calculate cyber risk for two different kinds of companies
This book is perfect for cybersecurity professionals at all levels: business executives and senior security professionals, mid-level practitioner veterans, newbies coming out of school as well as career-changers seeking better career opportunities, teachers, and students.
About the Author
RICK HOWARD is the Chief Analyst and Senior Fellow at The CyberWire, the world’s largest cybersecurity podcast network, and the CSO of N2K (The CyberWire’s parent company). He’s been a CSO for Palo Alto Networks, TASC, and a former Commander for the U.S. Army’s Computer Emergency Response Team. He helped found the Cyber Threat Alliance (an ISAO for security vendors) and the Cybersecurity Canon Project (a Rock & Roll Hall of Fame for cybersecurity books).
In this Book
-
Who We are
-
Introduction
-
First Principles
-
Strategies
-
Zero Trust
-
Intrusion Kill Chain Prevention
-
Resilience
-
Risk Forecasting
-
Automation
-
Summation