Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [CISSP-D] REVIEW: "Information Security Architecture", Jan Killmeyer |
|---|---|
| Date: | Mon, 30 Apr 2007 15:49:16 -0800 |
BKINSEAR.RVW 20070125 "Information Security Architecture", Jan Killmeyer, 2006, 0-8493-1549-2 %A Jan Killmeyer %C 920 Mercer Street, Windsor, ON N9A 7C2 %D 2006 %G 0-8493-1549-2 %I Auerbach Publications %O +1-800-950-1216 auerbach@wgl.com orders@crcpress.com %O http://www.amazon.com/exec/obidos/ASIN/0849315492/robsladesinterne http://www.amazon.co.uk/exec/obidos/ASIN/0849315492/robsladesinte-21 %O http://www.amazon.ca/exec/obidos/ASIN/0849315492/robsladesin03-20 %O Audience i- Tech 1 Writing 1 (see revfaq.htm for explanation) %P 393 p. %T "Information Security Architecture" The preface to the book seems to indicate an intent to provide a taxonomy of security activities under eight (mostly management related) "components": infrastructure, policy, risk assessment, training, compliance, monitoring, incident response, and business continuity. (Those who follow the development of security frameworks will notice a strong correlation to the COSO [Committee of Sponsoring Organizations of the Treadway Commission] structure.) The "Executive Summary" basically does the same thing, at greater length (concentrating on the threats to information), and seems to have been lifted from the first edition of the book with incomplete modifications: the illustrations refer to the original five components, and there is a reference to a now non-existent chapter twelve. Chapter one, on information security architecture, defines it as the mechanism for ensuring that all users know what they are responsible for in terms of protecting resources, which would seem to put it squarely in the "design" camp. (This perspective would seem to be consistent with the statement that an architecture has "components.") The remainder of the material reinforces the idea of a managed plan for implementing security. Infrastructure, in chapter two, is addressed primarily in terms of the roles of people within the enterprise, and a repeat (from chapter one) of several pages of text (and an illustration) outlining the security plan. The elements of a security policy, and pointers to sample constituents listed in the appendices, are given in chapter three. Aspects of risk analysis is mixed with information on random security controls in chapter four. Chapter five says the usual things about security awareness and training programs. Compliance, in chapter six, is primarily concerned with audits. Chapter seven lists some of the problems you may encounter in creating a security program, many of which are related to a lack of management support. A high-level overview of the structures and reports of incident response makes up chapter eight. A final admonition to manage security is given in chapter nine. The book doesn't really talk about information security architecture. There is a general outline of the basic aspects of a security program, although the details have numerous gaps. There are a great many such general security overview texts, and therefore this volume does not address either a specific audience, nor does it contribute anything meaningful to the security literature. copyright Robert M. Slade, 2007 BKINSEAR.RVW 20070125 ====================== (quote inserted randomly by Pegasus Mailer) rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org Charm is a way of getting the answer yes without having asked any clear question. - Albert Camus Dictionary of Information Security www.syngress.com/catalog/?pid=4150 http://victoria.tc.ca/techrev/rms.htm Yahoo! Groups Links <*> To visit your group on the web, go to: http://groups.yahoo.com/group/CISSP-Discuss/ <*> Your email settings: Individual Email | Traditional <*> To change settings online go to: http://groups.yahoo.com/group/CISSP-Discuss/join (Yahoo! ID required) <*> To change settings via email: mailto:CISSP-Discuss-digest@yahoogroups.com mailto:CISSP-Discuss-fullfeatured@yahoogroups.com <*> To unsubscribe from this group, send an email to: CISSP-Discuss-unsubscribe@yahoogroups.com <*> Your use of Yahoo! Groups is subject to: http://docs.yahoo.com/info/terms/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [CISSP-D] REVIEW: "Sarbanes-Oxley for Dummies", Jill Gilbert Welytok, Rob, grandpa of Ryan, Trevor, Devon & Hannah |
|---|---|
| Previous by Thread: | [CISSP-D] REVIEW: "Sarbanes-Oxley for Dummies", Jill Gilbert Welytok, Rob, grandpa of Ryan, Trevor, Devon & Hannah |
| Indexes: | [Date] [Thread] [Top] [All Lists] |