CITATION

Rhodes-Ousley, Mark. Information Security The Complete Reference, Second Edition. US: McGraw-Hill Osborne Media, 2013.

Information Security The Complete Reference, Second Edition

Published:  April 2013

eISBN: 9780071784368 0071784365 | ISBN: 9780071784351

Book description:

Develop and implement an effective end-to-end security program

Today’s complex world of mobile platforms, cloud computing, and ubiquitous data access puts new security demands on every IT professional. Information Security: The Complete Reference, Second Edition (previously titled Network Security: The Complete Reference) is the only comprehensive book that offers vendor-neutral details on all aspects of information protection, with an eye toward the evolving threat landscape. Thoroughly revised and expanded to cover all aspects of modern information security—from concepts to details—this edition provides a one-stop reference equally applicable to the beginner and the seasoned professional.

Find out how to build a holistic security program based on proven methodology, risk analysis, compliance, and business needs. You’ll learn how to successfully protect data, networks, computers, and applications. In-depth chapters cover data protection, encryption, information rights management, network security, intrusion detection and prevention, Unix and Windows security, virtual and cloud security, secure application development, disaster recovery, forensics, and real-world attacks and countermeasures. Included is an extensive security glossary, as well as standards-based references. This is a great resource for professionals and students alike.

  • Understand security concepts and building blocks

  • Identify vulnerabilities and mitigate risk

  • Optimize authentication and authorization

  • Use IRM and encryption to protect unstructured data

  • Defend storage devices, databases, and software

  • Protect network routers, switches, and firewalls

  • Secure VPN, wireless, VoIP, and PBX infrastructure

  • Design intrusion detection and prevention systems

  • Develop secure Windows, Java, and mobile applications

  • Perform incident response and forensic analysis

Mark Rhodes-Ousley has 20 years of experience with every aspect of security, from program management to technology. That experience includes risk management, security policies, security management, technology implementation and operations, physical security, disaster recovery, and business continuity planning. He holds two core beliefs: that business processes are just as important as technology because security relies on people; and that security should be a business enabler with a goal of enhancing the customer experience. Mark is CISSP, CISM, and MCSE certified.

Keywords: NETWORK SECURITY COMPLETE REFERENCE, INFORMATION SECURITY COMPLETE REFERENCE, MARK RHODES OUSLEY, NETWORK SECURITY, SECURE NETWORK, PLAN SECURE NETWORK, IMPLEMENT SECURE NETWORK, PROTECT CONFIDENTIAL INFORMATION, SECURITY PRACTITIONERS, SECURITY STANDARDS, SECURITY REGULATIONS, ISO 27001, COBIT, SAS 70, LEGAL REGULATIONS, SARBANES-OXLEY, SOX, SB 1386, SB 1841, FFIEC, GRAMM-LEACH BLILEY, GLB, HIPAA, SECURITY INDUSTRY, VOIP SECURITY, APPLICATION BEHAVIOR, OPERATIONAL SECURITY, SYSTEM SECURITY, PLANNING AND RESPONSE, STANDARDS COMPLIANCE, NETWORK SECURITY FOUNDATIONS, DEFENSE MODELS, SECURITY POLICIES, SECURITY ORGANIZATION, ACCESS CONTROL, SECURITY MANAGEMENT, DATA SECURITY, FIREWALLS, VIRTUAL PRIVATE NETWORKS, WIRELESS SECURITY, UNIX, LINUX, WINDOWS SECURITY, APPLICATION SECURITY, J2EE, WINDOWS .NET, DATABASE SECURITY, WRITING SECURE SOFTWARE, DISASTER RECOVERY, ATTACKS AND COUNTERMEASURES, INCIDENT RESPONSE, LEGAL COMPLIANCE, STANDARDS COMPLIANCE, REGULATORY COMPLIANCE, INFORMATION SECURITY MANAGERS, NETWORK ADMINISTRATORS, SECURITY SOFTWARE SOLUTIONS, IT MANAGEMENT, ADVANCED PRACTITIONER, SECURE WINDOWS, VPN, VIRTUAL PRIVATE NETWORKS, SOFTWARE DEVELOPMENT, AUTHENTICATION MODELS, AUTHORIZATION METHODS, BUSINESS CONTINUITY, FORENSIC ANALYSIS, VOICE OVER IP, ROLE BASED SECURITY, INTRUSION DETECTION SYSTEMS, WIRELESS NETWORK SECURITY, NETWORK DEVICE SECURITY, NETWORK DESIGN CONSIDERATIONS, DATA SECURITY, PHYSICAL SECURITY, RISK ANALYSIS, NETWORK SECURITY BEGINNER'S GUIDE, ERIC MAIWALD, HACKING EXPOSED 6 NETWORK SECURITY SECRETS AND SOLUTIONS, STUART MCCLURE, JOEL SCAMBRAY, GEORGE KURTZ, NETWORK SECURITY HACKS, NETWORK SECURITY FOR DUMMIES, NETWORK SECURITY PRIVATE COMM, TAO OF NETWORK SECURITY, NETWORK SECURITY ASSESSMENT, NETWORK SECURITY BIBLE SECOND EDITION, NETWORK SECURITY BIBLE FIRST EDITION, HACKING EXPOSED, HACKING EXPOSED WEB 2.0, HACKING EXPOSED VOIP, HACKING EXPOSED WINDOWS, HACKING EXPOSED WEB APPLICATIONS, HACKING EXPOSED CISCO NETWORKS, GRAY HAT HACKING, HACKING EXPOSED WIRELESS, HACKING EXPOSED COMPUTER FORENSICS, 19 DEADLY SINS OF SOFTWARE SECURITY, 24 DEADLY SINS OF SOFTWARE SECURITY, CCNA CISCO CERTIFIED NETWORK ASSOCIATE STUDY GUIDE, CCENT CISCO CERTIFIED ENTRY NETWORKING TECHNICIAN STUDY GUIDE, CCNA CISCO CERTIFIED NETWORK ASSOCIATE WIRELESS STUDY GUIDE, CISSP ALL-IN-ONE EXAM GUIDE, MOBILE APPLICATION SECURITY, HACKING EXPOSED MALWARE AND ROOTKITS, HACKING EXPOSED COMPUTER FORENSICS, HACKING EXPOSED VIRTUALIZATION & CLOUD COMPUTING, IT SECURITY METRICS, SECURITY INFORMATION AND EVENT MANAGEMENT (SIEM) IMPLEMENTATION, IT AUDITING, CISSP BOXED SET, CISA CERTIFIED INFORMATION SYSTEMS AUDITOR ALL-IN-ONE EXAM GUIDE, MIKE MEYERS' COMPTIA SECURITY+ CERTIFICATION PASSPORT, SECURITY+ ALL-IN-ONE EXAM GUIDE, COMPTIA A+ CERTIFICATION ALL-IN-ONE EXAM GUIDE, CCNA CISCO CERTIFIED NETWORK ASSOCIATE SECURITY STUDY GUIDE, CWSP CERTIFIED WIRELESS SECURITY PROFESSIONAL OFFICIAL STUDY GUIDE, CWNA CERTIFIED WIRELESS NETWORK ADMINISTRATOR & CWSP CERTIFIED WIRELESS SECURITY PROFESSIONAL ALL-IN-ONE EXAM GUIDE, CTS CERTIFIED TECHNOLOGY SPECIALIST EXAM GUIDE, PRINCIPLES OF COMPUTER SECURITY COMPTIA SECURITY+ AND BEYOND LAB MANUAL, PRINCIPLES OF COMPUTER SECURITY, COMPTIA SECURITY+ AND BEYOND, COMPTIA A+ CERTIFICATION BOXED SET, COMPTIA SECURITY+ CERTIFICATION STUDY GUIDE, COMPTIA SECURITY+ CERTIFICATION PRACTICE EXAMS, COMPTIA SECURITY+ ALL-IN-ONE EXAM GUIDE, COMPTIA SECURITY+ CERTIFICATION BOXED SET, SECURITY METRICS A BEGINNER'S GUIDE, WIRELESS NETWORK SECURITY A BEGINNER'S GUIDE, COMPUTER FORENSICS A BEGINNER'S GUIDE, SECURING THE CLICKS, NETWORK SECURITY IN THE AGE OF SOCIAL MEDIA, CEH CERTIFIED ETHICAL HACKER ALL-IN-ONE EXAM GUIDE, SSCP SYSTEMS SECURITY CERTIFIED PRACTITIONER ALL-IN-ONE EXAM GUIDE