CertCities.com -- The Ultimate Site for Certified IT Professionals
Post Your Mind in the CertCities.com Forums Share share | bookmark | e-mail
  Microsoft®
  Cisco®
  Security
  Oracle®
  A+/Network+"
  Linux/Unix
  More Certs
  Newsletters
  Salary Surveys
  Forums
  News
  Exam Reviews
  Tips
  Columns
  Features
  PopQuiz
  RSS Feeds
  Press Releases
  Contributors
  About Us
  Search
 

Advanced Search
  Free Newsletter
  Sign-up for the #1 Weekly IT
Certification News
and Advice.
Subscribe to CertCities.com Free Weekly E-mail Newsletter
CertCities.com

See What's New on
Redmondmag.com!

Cover Story: IE8: Behind the 8 Ball

Tech-Ed: Let's (Third) Party!

A Secure Leap into the Cloud

Windows Mobile's New Moves

SQL Speed Secrets


CertCities.com
Let us know what you
think! E-mail us at:



 
 
...Home ... Editorial ... Columns ..Column Story Saturday: April 5, 2014


 Dulaney on Certs  
Emmett Dulaney
Emmett Dulaney


 Security Title Roundup
A great many new titles on system and network security have hit the book shelves recently, with three standing out among the masses.
by Emmett Dulaney  
1/11/2012 -- A great many new titles on system and network security have hit the book shelves recently, with three standing out among the masses. While none of these titles are study guides, these books can still be used as resources if you are studying for a security certification or just to round out the knowledge you need to keep one step ahead of the malware and miscreants. We'll take a look at each of the three and what makes each one worthy of note.

Web Application Security: A Beginner's Guide
Don't let the "Beginner's Guide" throw you for too much of a loop. The feature that makes this book stand out from the pack is the team of authors. Bryan Sullivan used to be the security program manager at Microsoft and is currently the senior security researcher at Adobe. His coauthor, Vincent Liu, led the Attack & Penetration and Reverse Engineering teams for Honeywell and was an analyst for the National Security Agency. To say this is a strong team of authors hardly scratches the surface.

There are three parts to the book and nine chapters:

  • Welcome to the Wide World of Web Application Security
  • Security Fundamentals
  • Authentication
  • Authorization
  • Browser Security Principles: The Same-Origin Policy
  • Browser Security Principles: Cross-Site Scripting and Cross-Site Request Forgery
  • Database Security Principles
  • File Security Principles
  • Secure Development Methodologies

In my opinion, the chapter on Cross-Site Scripting/Request Forgery is worth the cost of the book alone. This is a problem/vulnerability that seems to be becoming more exploited every day and there are few good sources on it.  

Security Metrics: A Beginner's Guide
One of the biggest issues with security is justifying the costs associated with it. When IT budgets are being trimmed and slashed, it can be hard to explain why security should be exempt from such actions and obtain shareholder buy-in.  That is where this book from Caroline Wong comes in. Wong is the former chief of staff for the Global Information Security Team at eBay and helped build their metrics from the start.

The 17 chapters are divided among eight parts, and the titles of the parts pinpoint the material covered quite well:

  • Why Security Metrics?
  • Essential Components of an Effective Security Metrics Practitioner
  • Decide What to Measure
  • Get Started
  • Toolkit
  • Creating the Best Environment for Healthy Metrics
  • Secret Sauce: Lessons Learned from an Enterprise Practitioner
  • Looking Forward

The chapter worth special recognition in this book, in my opinion, is "Falling beneath the Toolkit." Technologies are discussed first, and then you're given a scenario for Acme Corporation -- a large, public, multinational pharmaceutical company -- and you walk through their issues with lessons that are learned given at the end.

Securing the Clicks: Network Security in the Age of Social Media
Leaving the "Beginner's Guide" series, Gary Bahadur, Jason Inasi, and Alex de Carvalho have written a guidebook for analyzing risk and formulating solutions. The focus on social media is both timely and indispensable in today's environment. The 18 chapters are divided into five parts:

  • Assessing Social Media Security
  • Assessing Social Media Threats
  • Operations, Policies, & Processes
  • Monitoring & Reporting
  • Social Media 3.0

Each chapter begins with a case study intended to illustrate the need for the discussion and those alone are worth the read. They run the gamut from "Expensive Paperweight Gets Fired" to "Domino's Reputation Attack." The book is insightful, illuminating and recommended for security administrators at all levels.


Emmett Dulaney is the author of several books on Linux, Unix and certification. He can be reached at .

 


More articles by Emmett Dulaney:

-- advertisement --


There are 29 CertCities.com user Comments for “Security Title Roundup”
Page 1 of 3
7/4/13: guccioutletstore-online.com from [email protected] says: ths guccioutletstore-online.com http://www.guccioutletstore-online.com
7/5/13: louboutin outlet from [email protected] says: good share. louboutin outlet http://www.christianlouboutinoutleta.com
7/25/13: cheap sunglasses online from [email protected] says: thank you for share! cheap sunglasses online http://www.cheap-sunglass.net/
8/8/13: Fake Oakleys from [email protected] says: Getting Traffic Technique That's In fact Helping sunglass-industry professionals Growing Fake Oakleys http://www.fakeoakleysglasses.com
8/18/13: OakleySunglassesForS from [email protected] says: Obtain a sunglass Without the need for Paying A Single Nickle Oakley Sunglasses For Sale http://www.replica-oakleysunglassesusa.com
9/5/13: moncler outlet from [email protected] says: nice articles moncler outlet http://www.monclereoutletonline.net
9/5/13: cheap nfl jerseys authentic from [email protected] says: thanks for share! cheap nfl jerseys authentic http://www.cheapauthenticnfljerseyss.com
9/8/13: ugg outlet store from [email protected] says: thank you for share! ugg outlet store http://www.ggsestore.com
9/11/13: jordan pas cher from [email protected] says: good share. jordan pas cher http://www.ntsy.com/engs/jordan-tuschak.html
10/2/13: classicshortboots1.com from [email protected] says: nice articles classicshortboots1.com http://classicshortboots1.com
First Page   Next Page   Last Page
Your comment about: “Security Title Roundup”
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comment:
   

-- advertisement (story continued below) --

top