Been awhile since I've done any book reviews or the like on this blog. Am a little behind on my series looking at the "20 Books".
I'd thought I should bring to peoples attention a pair of books that came out a few years ago. No so much technical security works as more philosophical: Beautiful Security and The Myths of Security. Both are from O'Reilly and came out in 2009. And both share an author (kind of).
Showing posts with label book reviews. Show all posts
Showing posts with label book reviews. Show all posts
Wednesday, April 27, 2016
Friday, April 24, 2015
"The Frugal CISO" by Kerry Anderson
Currently I am reading thru Kerry Ann Anderson's The Frugal CISO (CRC Press, 2014).
I am always on the lookout for good infosec books, and one area that I think is under served are those that are aimed at the top-level security professional on how to implement a good information security program.
This one I had discovered thanks to a related article the author had in a recent issue of the ISACA Journal on information security maturity models ("From Here to Maturity—Managing the
Information Security Life Cycle" v6, 2014). She makes use of the Nolan Model, which I wasn't familiar with (being more familiar with the CMM/CMMI based models). The article was interesting, and I wanted to know more on the idea and she spends a chapter on this concept, which is good. I think this would be a better maturity model for infosec groups to use then a CMM-based one.
I am currently reading thru the book, basically jumping around based on my interests. What I see is pretty good. She has stuff on hiring and building an infosec team, policies, controls, and more. Her main theme overall is being frugal, being smart with you are spending money on, an important concept in today's cost-cutting attitude.
This is not a full review of the book. I will probably post something like that later on.
I am always on the lookout for good infosec books, and one area that I think is under served are those that are aimed at the top-level security professional on how to implement a good information security program.
This one I had discovered thanks to a related article the author had in a recent issue of the ISACA Journal on information security maturity models ("From Here to Maturity—Managing the
Information Security Life Cycle" v6, 2014). She makes use of the Nolan Model, which I wasn't familiar with (being more familiar with the CMM/CMMI based models). The article was interesting, and I wanted to know more on the idea and she spends a chapter on this concept, which is good. I think this would be a better maturity model for infosec groups to use then a CMM-based one.
I am currently reading thru the book, basically jumping around based on my interests. What I see is pretty good. She has stuff on hiring and building an infosec team, policies, controls, and more. Her main theme overall is being frugal, being smart with you are spending money on, an important concept in today's cost-cutting attitude.
This is not a full review of the book. I will probably post something like that later on.
Wednesday, April 23, 2014
Currently Reading: Schneier on Security
A book that I am currently reading is Schneier on Security (2008) by Bruce Schneier.
I would hope that most security professionals out there are familiar with Bruce. He has written several books and numerous articles. His blog, Schneier on Security, is well known as is his monthly e-newsletter Crypto-Gram (go to his blog to read and subscribe).
For myself, I've read many of his materials and seldom disagree with his views. I think mainly where I think he may not have all the info, I disagree with his conclusions. Frankly, I find that too many other security experts of his caliber are sadly a bit stuck in their ways and the views are too off.
Schneier is known for actually criticizing many of the so-called "security" measures put into place for really failing to make us more secure. He called this "security theater". So while some so-called experts push for new IDs or more surveillance, Schneier points out that all this stuff doesn't do what it claims, and may, in fact, make us less secure. You have to wonder what the real reason some people push these methods?
Schneier on Security is a collection of essays written between 2002 and 2008 that have appeared in various magazines, newspapers, websites and Crypto-Gram. A few he updated at the time of the publication of the book (2008), and all cite the original publication. Sadly, being over 5 years old, some of the statements are now a little dated, but if you overlook that, there are many interesting items here.
The book is organized into a dozen chapters:
<updated 5/1/2014>
I would hope that most security professionals out there are familiar with Bruce. He has written several books and numerous articles. His blog, Schneier on Security, is well known as is his monthly e-newsletter Crypto-Gram (go to his blog to read and subscribe).
For myself, I've read many of his materials and seldom disagree with his views. I think mainly where I think he may not have all the info, I disagree with his conclusions. Frankly, I find that too many other security experts of his caliber are sadly a bit stuck in their ways and the views are too off.
Schneier is known for actually criticizing many of the so-called "security" measures put into place for really failing to make us more secure. He called this "security theater". So while some so-called experts push for new IDs or more surveillance, Schneier points out that all this stuff doesn't do what it claims, and may, in fact, make us less secure. You have to wonder what the real reason some people push these methods?
Schneier on Security is a collection of essays written between 2002 and 2008 that have appeared in various magazines, newspapers, websites and Crypto-Gram. A few he updated at the time of the publication of the book (2008), and all cite the original publication. Sadly, being over 5 years old, some of the statements are now a little dated, but if you overlook that, there are many interesting items here.
The book is organized into a dozen chapters:
- Terrorism and Security
- National Security Policy
- Airline Travel
- Privacy and Surveillance
- ID Cards and Security
- Election Security
- Security and Disasters
- Economics of Security
- Psychology of Security
- Business of Security
- Cybercrime and Cyberwar
- Computer and Information Security
Because each essay is fairly short (2-3 pages max), and most are just gathered into each chapter by common topic, one can jump around and read what sparks your interest. In fact, that's what I have been doing.
As some of the topics go beyond just technical information security that many of us in the infosec world focus on, I think its good that we have a better understanding of security outside of IT, as well as the impact of what we do affects other areas.
So check it out. And if you like what you see, check out his other works as well. His latest book, Carry On, is actually a "sequel" to this work, collecting articles from 2008-2013. I don't have it yet, but plan on getting it soon.
<updated 5/1/2014>
Wednesday, April 9, 2014
20 Books Cybersecurity Professionals Should Read Now
At the recent RSA Conference, Rick Howard, CSO for Palo Alto Networks, gave a popular talk where he gave a recommended list of works he felt cybersecurity professionals should read.
Some are technical, some fiction, and others non-fiction for the general reader.
I have read several, a few I have on my "to read" list, and a few I wasn't aware of. But with that in mind, I plan on reading and reviewing these works over the next few months as possible.
The List? Here it is in alphabetical order.
For those wanting to obtain them:
Some are technical, some fiction, and others non-fiction for the general reader.
I have read several, a few I have on my "to read" list, and a few I wasn't aware of. But with that in mind, I plan on reading and reviewing these works over the next few months as possible.
The List? Here it is in alphabetical order.
- The Blue Nowhere, Jeffery Deaver (2001)
- Breakpoint, Richard A. Clarke (2007)
- The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud), Dawn M. Cappelli, Andrew P. Moore, and Randall F. Trzeciak (2012)
- Confront and Conceal: Obama’s Secret Wars and Surprising Use of American Power, David Sanger (2013)
- Cryptonomicon, Neal Stephenson (1999)
- The Cuckoo’s Egg: Tracking a Spy Through the Maze of Computer Espionage, Clifford Stoll (1989)
- Cyber War: The Next Threat to National Security and What to Do about It, Richard Clarke and Robert Knake (2010)
- Daemon (2006) and Freedom™ (2010), Daniel Suarez
- Fatal System Error: The Hunt for the New Crime Lords Who Are Bringing Down the Internet, Joseph Menn (2010)
- The Girl with the Dragon Tattoo, Stieg Larssen (2011)
- Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground, Kevin Poulsen (2011)
- Neuromancer, William Gibson (1986)
- Reamde, Neil Stephenson (2011)
- Security Metrics: Replacing Fear, Uncertainty, and Doubt, Andrew Jacquith (2007)
- Snow Crash, Neal Stephenson (1992)
- We Are Anonymous: Inside the Hacker World of LulzSec, Anonymous and the Global Cyber Insurgency, Parmy Olson (2012)
- Worm: The First Digital World War, Mark Bowden (2011)
- Zero Day (2011) and Trojan Horse (2012), Mark Russinovich
For those wanting to obtain them:
Friday, November 1, 2013
Currently reading: Android Application Security Essentials
I wouldn't ordinarily do this, but I am currently reading Android Application Security Essentials by Pragati Ogal Rai and published by PackT Publishing.
(you can check out the book here: http://bit.ly/15mnEus)
Seeing as how more and more people are moving the mobile devices (smartphone and tablets) not just as a secondary device but sometimes a primary device, security applications on these devices becomes more and more important. This book aims to address it. I am still reading it, but what I've read it pretty good. Even if your focus is not application development, this will help your understanding of Android security.
Once complete, I hope to do a full review here. In the meantime, check out the publishers other works. I've seen several that have caught my eye.
(you can check out the book here: http://bit.ly/15mnEus)
Seeing as how more and more people are moving the mobile devices (smartphone and tablets) not just as a secondary device but sometimes a primary device, security applications on these devices becomes more and more important. This book aims to address it. I am still reading it, but what I've read it pretty good. Even if your focus is not application development, this will help your understanding of Android security.
Once complete, I hope to do a full review here. In the meantime, check out the publishers other works. I've seen several that have caught my eye.
Subscribe to:
Posts (Atom)