Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Amanda Berlin, Lee Brotherston, William F. Reyor III

Rating No ratings yet

Despite the increase of high-profile hacks, record-breaking data leaks, and ransomware attacks, many organizations don't have the budget for an information security (InfoSec) program. If you're forced to protect yourself by improvising on the job, this pragmatic guide provides a security-101 handbook with steps, tools, processes, and ideas to help you drive maximum-security improvement at little or no cost. Each chapter in this book provides step-by-step instructions for dealing with issues such as breaches and disasters, compliance, network infrastructure, password management, vulnerability scanning, penetration testing, and more. Network engineers, system administrators, and security professionals will learn how to use frameworks, tools, and techniques to build and improve their cybersecurity programs. This book will help you: • Plan and design incident response, disaster recovery, compliance, and physical security • Learn and apply basic penetration-testing concepts through purple teaming • Conduct vulnerability management using automated processes and tools • Bolster Microsoft and Unix systems, network infrastructure, and password management • Use segmentation practices and designs to compartmentalize your network • Reduce exploitable errors by developing code securely

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A pragmatic, budget-conscious security-101 handbook for network engineers, system administrators, and IT generalists who must build or improve an InfoSec program without a dedicated security team or large budget—covering incident response, compliance, vulnerability management, and infrastructure hardening with step-by-step guidance. 【Book Arc】 - **Opening (~0%–25%)**: Establishes the book's core premise—most organizations lack dedicated InfoSec budgets, so defenders must improvise. It frames the handbook as a practical, cost-effective guide covering the full spectrum of security operations, from incident response to password management, aimed at practitioners who wear many hats. - **Early (~25%–50%)**: Expands on the foundational program areas: planning and designing incident response, disaster recovery, compliance frameworks, and physical security. This stage emphasizes building a structured security program from scratch using frameworks and processes rather than relying on expensive tools. - **Middle (~50%–75%)**: Moves into hands-on technical defense: conducting vulnerability management with automated processes, using IDS/IPS, SOC operations, logging and monitoring, and applying basic penetration-testing concepts through purple teaming. It also covers hardening Microsoft and Unix systems, network infrastructure, and password management. - **Late (~75%–100%)**: Focuses on network segmentation and secure code development—compartmentalizing networks to limit blast radius and reducing exploitable errors in software. The book closes by positioning itself as a lasting reference for blue team practitioners, endorsed by industry figures for its accessibility and actionable depth. 【Key Takeaways】 - **Security programs can start small and cheap** (Opening): The book's central argument is that meaningful security improvement doesn't require a large budget—it requires process, prioritization, and using free or low-cost tools effectively. This reframes security as an operational discipline rather than a procurement exercise. - **Incident response and disaster recovery are the first pillars** (Early): Before worrying about advanced threats, organizations need clear plans for detecting, responding to, and recovering from breaches and disasters. The book provides step-by-step design guidance for these plans, making them approachable for teams without dedicated security staff. - **Compliance is a security accelerant, not just a checkbox** (Early): Rather than treating compliance as a bureaucratic burden, the authors position it as a framework for building baseline security controls. This helps practitioners prioritize what to implement first when resources are scarce. - **Vulnerability management should be automated and continuous** (Middle): The book advocates for automated scanning and patch processes to keep up with the volume of vulnerabilities, emphasizing that manual, periodic checks are insufficient. It offers practical tooling and workflow suggestions for operationalizing this. - **Purple teaming is the entry point to penetration testing** (Middle): Instead of complex red team operations, the book teaches basic pen-testing concepts through purple teaming—where attackers and defenders collaborate. This makes testing accessible to organizations that can't afford external penetration testers. - **Network segmentation limits damage** (Late): Compartmentalizing the network through segmentation practices is a core defensive technique—it contains breaches and reduces the blast radius of any single compromise. The book provides design patterns for implementing this. - **Secure coding reduces exploitable errors at the source** (Late): The final major theme is that security isn't just an operations concern—developers must write code defensively to prevent vulnerabilities from entering production. This bridges the gap between security and development teams. 【Reading Tips】 - **Skim the praise and front matter** (~0%–25%): The opening chunks are heavy on endorsements and book description; skip ahead to the practical chapters once you understand the book's scope and target audience. - **Deep-read the program design chapters** (Early): The sections on incident response, disaster recovery, and compliance are foundational—read these carefully and take notes, as they form the backbone of the entire security program the book advocates. - **Use the technical chapters as reference, not narrative** (Middle–Late): The vulnerability management, system hardening, and network segmentation chapters are best treated as a manual—dip in when you need specific guidance on a topic rather than reading cover-to-cover. - **Focus on the "how" over the "why"**: The book is explicitly a handbook, so prioritize absorbing the step-by-step processes and tool recommendations over theoretical background. These are the actionable takeaways you'll apply on the job. - **Pair with your existing infrastructure knowledge**: The book assumes you're a network engineer or sysadmin, so it won't teach you basics of Unix or Windows—it will show you how to secure them. Bring your operational experience to the table. 【Coverage Limits】 The excerpts primarily cover the book's front matter, endorsements, and table of contents; detailed chapter content on specific tools, techniques, and step-by-step procedures is not included in the source material. This guide synthesizes the book's stated scope and structure rather than its full technical depth.
Excerpt 1
书名: Defensive Security Handbook Best Practices for Securing Infrastructure Second Edition (Amanda Berlin, Lee Brotherston etc.) (Z Library) 作者: Amanda Berl...
View in text
Page 2
ve the budget for an information security (InfoSec) program. If you’re forced to protect yourself by improvising on the job, this pragmatic guide provides a ...
View in text
Page 2
blue teams across a number of industry verticals. William F. Reyor III, director of security at Modus Create, blends expertise in DevSecOps, AI/LLM security,...
View in text
Page 4
ding blue team concepts in an accessible and actionable way. You will not be disappointed having this book on your shelf and will refer to it for years to co...
View in text
Page 6
d related trade dress are trademarks of O’Reilly Media, Inc. While the publisher and the authors have used good faith efforts to ensure that the information ...
View in text
Tags
AI categories
CybersecurityBackendTechnology
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 363
File Format: PDF
File Size: 8.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…