The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice
Book information
Description
As part of the Syngress Basics series, The Basics of Information Security provides you with fundamental knowledge of information security in both theoretical and practical aspects. Author Jason Andress gives you the basic knowledge needed to understand the key concepts of confidentiality, integrity, and availability, and then dives into practical applications of these ideas in the areas of operational, physical, network, application, and operating system security. The Basics of Information Security gives you clear non technical explanations of how infosec works and how to apply these principles whether you're in the IT field or want to understand how it affects your career and business. The new Second Edition has been updated for the latest trends and threats, including new material on many infosec subjects. Learn about information security without wading through a huge textbookCovers both theoretical and practical aspects of information securityProvides a broad view of the information security field in a concise mannerAll new Second Edition updated for the latest information security trends and threats, including material on incident response, social engineering, security awareness, risk management, and legal/regulatory issues Front Cover The Basics of Information Security Copyright Page Dedication Contents Author Biography Introduction Book overview and key learning points Book audience How this book is organized Chapter 1: What is information security? Chapter 2: Identification and authentication Chapter 3: Authorization and access control Chapter 4: Auditing and accountability Chapter 5: Cryptography Chapter 6: Laws and regulations Chapter 7: Operations security Chapter 8: Human element security Chapter 9: Physical security Chapter 10: Network security Chapter 11: Operating system security Chapter 12: Application security Conclusion 1 What is Information Security? Introduction What is security? When are we secure? Alert! Models for discussing security The confidentiality, integrity, and availability triad More advanced Confidentiality Integrity Availability Relating the CIA triad to security The Parkerian hexad Alert! Confidentiality, integrity, and availability Possession or control Authenticity Utility Attacks Types of attack payloads Interception Interruption Modification Fabrication Threats, vulnerabilities, and risk Threats Vulnerabilities Risk Impact Risk management Identify assets Identify threats Assess vulnerabilities Assess risks Mitigating risks Physical Logical and technical controls Administrative Incident response Preparation Detection and analysis Containment, eradication, and recovery Post incident activity Defense in depth Layers Information security in the real world Summary Exercises References 2 Identification and Authentication Introduction Identification Who we claim to be Identity verification Falsifying identification Authentication Factors Multifactor authentication Mutual authentication Passwords More advanced Biometrics Additional resources Characteristics Measuring performance Issues Hardware tokens Alert! Identification and authentication in the real world Summary Exercises References 3 Authorization and Access Control Introduction Authorization Principle of least privilege Access control More advanced Access control lists File system ACLs More advanced Network ACLs Alert! More advanced Capabilities Confused deputy problem Alert! Access control methodologies Access control models Discretionary access control Mandatory access control More advanced Role-based access control Attribute-based access control Multilevel access control Physical access controls Authorization and access control in the real world Summary Exercises References 4 Auditing and Accountability Introduction Accountability More advanced Security benefits of accountability Nonrepudiation Deterrence More advanced Intrusion detection and prevention Admissibility of records How we accomplish accountability Auditing What do we audit? Alert! Logging Monitoring Assessments Accountability and auditing in the real world More advanced Summary Exercises References 5 Cryptography Introduction History Caesar cipher Cryptographic machines More advanced Additional resources Kerckhoffs’ principle Modern cryptographic tools Symmetric versus asymmetric cryptography Symmetric cryptography Block versus stream ciphers Symmetric key algorithms Asymmetric cryptography Asymmetric key algorithms More advanced Hash functions Digital signatures Certificates Protecting data at rest, in motion, and in use Protecting data at rest Data security Physical security Alert! Protecting data in motion Protecting the data itself Protecting the connection Protecting data in use Cryptography in the real world Summary Exercises References 6 Laws and Regulations Introduction Laws and regulations US laws applicable to computing Laws outside of the United States Compliance Regulatory compliance Industry compliance Privacy The concept of privacy Privacy rights 2013, the year of global surveillance issues Privacy and business Summary Questions References 7 Operations Security Introduction Alert! Origins of operations security Sun Tzu Additional resources George Washington Vietnam War Business Interagency OPSEC support staff The operations security process Identification of critical information Analysis of threats Analysis of vulnerabilities Assessment of risks Application of countermeasures Haas’ Laws of operations security First law More advanced Second law Third law Operations security in our personal lives Alert! Operations security in the real world Summary Exercises References 8 Human Element Security Introduction Humans: the weak link Security awareness Protecting data Passwords Social engineering Pretexting Phishing Tailgating Network usage Malware Personal equipment Clean desk Policy and regulatory knowledge The security awareness and training program Effectively reaching users Summary Exercises References 9 Physical Security Introduction Alert! Additional resources Physical security controls Deterrent Detective Preventive How we use physical access controls Protecting people Physical concerns for people Safety Evacuation Where How Who Practice Administrative controls Protecting data Physical concerns for data Availability Residual data Backups More advanced Protecting equipment Physical concerns for equipment Note Site selection Securing access Environmental conditions Physical security in the real world Summary Exercises References 10 Network Security Introduction Protecting networks Security in network design Firewalls Packet filtering Stateful packet inspection Deep packet inspection Proxy servers DMZs Network intrusion detection systems IDS detection methods Protecting network traffic The impact of intercepted data Wireless exposure Virtual private networks Wireless network security Secure protocols Mobile device security What is a mobile device? Mobile device management Bring your own device Network security tools More advanced Wireless Port scanners Packet sniffers Alert! Honeypots Additional resources Firewall tools Network security in the real world Summary Exercises References 11 Operating System Security Introduction Operating system hardening Remove all unnecessary software Alert! Remove all unessential services Alter default accounts Apply the principle of least privilege Perform updates Turn on logging and auditing Protecting against malware Additional resources Anti-malware tools Executable space protection More advanced Software firewalls and host intrusion detection Software firewalls Host intrusion detection Operating system security tools Scanners Alert! Vulnerability assessment tools Exploit frameworks Operating system security in the real world Summary Exercises References 12 Application Security Introduction The TJX breach Software development vulnerabilities Additional resources Buffer overflows Race conditions Input validation attacks Authentication attacks Authorization attacks Cryptographic attacks Web security Client-side attacks Cross-site scripting Alert! Cross-site request forgery Clickjacking More advanced Server-side attacks Lack of input validation Improper or inadequate permissions Extraneous files Database security Protocol issues Unauthenticated access Arbitrary code execution Privilege escalation Additional resources Application security tools Sniffers Web application analysis tools Nikto and Wikto Alert! Burp Suite Fuzzers More advanced Application security in the real world Summary Exercises References Index
Similar books
Building a Practical Information Security Program
EPUB
Foundations of Information Security: A Straightforward Introduction
2019 · PDF
The Basics of Cyber Warfare: Understanding the Fundamentals of Cyber Warfare in Theory and Practice
2012 · PDF
Foundations of Information Security: A Straightforward Introduction
2019 · MOBI
Foundations of Information Security: A Straightforward Introduction
2019 · PDF
Coding for Penetration Testers
2016 · PDF
Foundations of Information Security: A Straightforward Introduction
2019 · EPUB
Building a Practical Information Security Program
2017 · PDF