Secrets of a Cyber Security Architect
Book information
Description
This book is filled with techniques, tips, and tricks that secure software architects and developers can apply directly. From assessing the sensitivity of data in a system through actually getting requirements implemented, this book offers readers practical, how-to advice in small, focused and directly applicable gems of insight, knowledge, and wisdom from secure software principal architect Brook S.E. Schoenfield. The book is organized by applicability of topics that include getting security architecture started, helping architects be effective, working with partner teams, assessing systems, driving security requirements to completion, and programmatic hints. Cover Half Title Title Page Copyright Page Contents Author Note/Trademarks Covered in This Book Dedication List of Figures and Tables Foreword Preface Acknowledgments About the Author Chapter 1 The Context of Security Architecture 1.1 Omnipresent Cyber War 1.2 Know the Threat Actors 1.2.1 Useful Exploits Don’t Die 1.3 Everything Can Become a Target 1.4 Warlords and Pirates 1.5 What Is the Scope of a Security Architect? 1.5.1 Are There Really Two Distinct Roles? 1.6 Essential Technique 1.6.1 Threat Modeling: An Essential Craft 1.6.2 Architecture Is Primary 1.7 Aiming Design Toward Security 1.7.1 What Is Secure Software? 1.7.2 Secure Design Primer 1.8 Summary Chapter 2 What Is Security Architecture, and Why Should I Care? 2.1 Define Security Architecture 2.1.1 Software Security 2.1.2 Security Architecture Practices 2.2 Relevant Knowledge Domains 2.3 More About Architecture 2.4 Architectures of Security 2.5 Architecture as a Part of Cyber Security 2.6 Security Architecture in Software Development 2.7 Generally, Experience Is a Teacher 2.8 Introducing Attack Methods 2.9 Speaking of Defense 2.10 More Precise Definition 2.11 Summary Chapter 3 Architecture, Attacks, and Defenses 3.1 Yes, Exploit Details, But 3.2 Security Architects Must... 3.3 Understanding Categories of Attacks 3.4 Attack Knowledge for Defense 3.5 Example: Heartbleed Analysis 3.5.1 Heartbleed Technical Analysis 3.6 Analyze to Defend 3.7 Turn Off TLS? 3.8 Security Architecture Analyses 3.8.1 Some Cheap Risk Concepts 3.8.2 JGERR Risk Rating 3.8.3 At Base: Threat Model 3.9 Threat Modeling Definition 3.9.1 Alternate Definition 3.9.2 When Is My Threat Model Done? 3.10 Summary Chapter 4 Culture Hacking 4.1 Team Tourism 4.1.1 Build and Maintain Trust 4.1.2 Don’t Squander Influence 4.2 Threat Modeling: Just Do It 4.2.1 “Trust Developers?” 4.2.2 Threat Model Training Is for Everyone 4.3 More Culture Hacks 4.3.1 Nimble Governance 4.3.2 Build Skills by Sharing 4.3.3 What to Do About “It Depends” 4.3.4 Is the Threat Model Finished? 4.3.5 Create a Security Contract 4.3.6 Threat Models Are Not Additive! 4.3.7 Audit and Security Are Not the Same Thing 4.4 From Program to Transformation 4.4.1 Pro-Social Modeling 4.4.2 Leaders Must Get Challenged 4.4.3 Hack All Levels 4.4.4 Coding Is Fraught with Error 4.4.5 Effective Secure Coding Training 4.4.6 Make Validation Easy 4.5 Summary 4.5.1 We All Can Use Some Feedback Chapter 5 Learning the Trade 5.1 Attack Knowledge 5.2 Which Defenses for What System? 5.3 Threat Modeling: The Learning Method 5.3.1 How to Escalate for Management Decision 5.4 To Accelerate: Cross Pollinate 5.5 Build a Community of Practice 5.6 Support Learners’ Errors 5.7 Facilitate as Much as Lead 5.8 Summary Chapter 6 Problem Areas You Will Encounter 6.1 What Does a Mature Practice Look Like? 6.1.1 Do We Add Value? 6.1.2 The War Is Over 6.1.3 Optimum Tool Use 6.1.4 You Know That You’re Maturing When 6.1.5 “Nothing Proves Architecture Like Nothing” 6.1.6 Get It in Writing! 6.2 Typical Problems Programs Encounter 6.2.1 Scale 6.2.2 Assessments Take Too Long 6.2.3 Late Engagement 6.2.4 Skill Churn 6.2.5 Exceptions 6.2.6 Fostering Innovation 6.3 Dealing with Chaotic Elements 6.3.1 There Are Differences 6.3.2 Translate and Generalize 6.4 Summary Appendix A: Heartbleed Exposure, What Is It Really? Appendix B: Developer-Centric Security Appendix C: Don’t Substitute CVSS for Risk: Scoring System Inflates Importance of CVE-2017-3735 Appendix D: Security Architecture Smart Guide Appendix E: Threat Modeling’s Definition of Done References Index
Similar books
Securing Systems: Applied Security Architecture and Threat Models
2015 · PDF
Securing Systems Applied Security Architecture and Threat Models
2015 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF