The Complete Reference: Information Security, Second Edition

  • 18h 48m
  • Mark Rhodes-Ousley
  • McGraw-Hill/Osborne
  • 2013

Develop and implement an effective end-to-end security program

Today’s complex world of mobile platforms, cloud computing, and ubiquitous data access puts new security demands on every IT professional. Information Security: The Complete Reference, Second Edition (previously titled Network Security: The Complete Reference) is the only comprehensive book that offers vendor-neutral details on all aspects of information protection, with an eye toward the evolving threat landscape. Thoroughly revised and expanded to cover all aspects of modern information security—from concepts to details—this edition provides a one-stop reference equally applicable to the beginner and the seasoned professional.

Find out how to build a holistic security program based on proven methodology, risk analysis, compliance, and business needs. You’ll learn how to successfully protect data, networks, computers, and applications. In-depth chapters cover data protection, encryption, information rights management, network security, intrusion detection and prevention, Unix and Windows security, virtual and cloud security, secure application development, disaster recovery, forensics, and real-world attacks and countermeasures. Included is an extensive security glossary, as well as standards-based references. This is a great resource for professionals and students alike.

  • Understand security concepts and building blocks
  • Identify vulnerabilities and mitigate risk
  • Optimize authentication and authorization
  • Use IRM and encryption to protect unstructured data
  • Defend storage devices, databases, and software
  • Protect network routers, switches, and firewalls
  • Secure VPN, wireless, VoIP, and PBX infrastructure
  • Design intrusion detection and prevention systems
  • Develop secure Windows, Java, and mobile applications
  • Perform incident response and forensic analysis

About the Author

Mark Rhodes-Ousley has 20 years of experience with every aspect of security, from program management to technology. That experience includes risk management, security policies, security management, technology implementation and operations, physical security, disaster recovery, and business continuity planning. He holds two core beliefs: that business processes are just as important as technology because security relies on people; and that security should be a business enabler with a goal of enhancing the customer experience. Mark is CISSP, CISM, and MCSE certified.

In this Book

  • Information Security Overview
  • Risk Analysis
  • Compliance with Standards, Regulations, and Laws
  • Secure Design Principles
  • Security Policies, Standards, Procedures, and Guidelines
  • Security Organization
  • Authentication and Authorization
  • Securing Unstructured Data
  • Information Rights Management
  • Encryption
  • Storage Security
  • Database Security
  • Secure Network Design
  • Network Device Security
  • Firewalls
  • Virtual Private Networks
  • Wireless Network Security
  • Intrusion Detection and Prevention Systems
  • Voice over IP (VoIP) and PBX Security
  • Operating System Security Models
  • Unix Security
  • Windows Security
  • Securing Infrastructure Services
  • Virtual Machines and Cloud Computing
  • Securing Mobile Devices
  • Secure Application Design
  • Writing Secure Software
  • J2EE Security
  • Windows .NET Security
  • Controlling Application Behavior
  • Security Operations Management
  • Disaster Recovery, Business Continuity, Backups, and High Availability
  • Incident Response and Forensic Analysis
  • Physical Security
SHOW MORE
FREE ACCESS

YOU MIGHT ALSO LIKE

Rating 4.6 of 5 users Rating 4.6 of 5 users (5)
Rating 4.7 of 266 users Rating 4.7 of 266 users (266)
Rating 4.4 of 27 users Rating 4.4 of 27 users (27)