Despite the increase of high-profile hacks, record-breaking data leaks, and ransomware attacks, many organizations don't have the budget for an information security (InfoSec) program. If you're forced to protect yourself by improvising on the job, this pragmatic guide provides a security-101 handbook with steps, tools, processes, and ideas to help you drive maximum-security improvement at little or no cost.
Each chapter in this book provides step-by-step instructions for dealing with issues such as breaches and disasters, compliance, network infrastructure, password management, vulnerability scanning, penetration testing, and more. Network engineers, system administrators, and security professionals will learn how to use frameworks, tools, and techniques to build and improve their cybersecurity programs.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A pragmatic, budget-conscious security-101 handbook for network engineers, system administrators, and IT professionals who must build or improve an InfoSec program without dedicated funding, offering step-by-step processes, tools, and frameworks for defending infrastructure.
【Book Arc】
- **Opening (~0%–10%)**: Lays the groundwork for creating a security program, covering team establishment, baseline posture assessment, risk/threat identification, and prioritization. It introduces the core risk management cycle (assess, mitigate, monitor, govern) and emphasizes the need for continuous improvement.
- **Early (~10%–23%)**: Moves into asset management and documentation, stressing the need for a "single source of truth" and treating inventory as an ongoing process. It also covers network infrastructure hardening, including device configuration, patching, and segmentation, with a cautionary note on IPv6.
- **Early (~23%–32%)**: Delves into practical exercises like tabletops and drills for testing incident response, and expands on asset management with detailed schemas for hardware, software, and user inventories. It highlights the role of IAM systems and tools like osquery for visibility.
- **Middle (~39%–48%)**: Focuses on data classification and user education, using examples like a university's fundraising department to illustrate tailored classification systems. It also introduces standards and procedures as the "what" and "how" that support policy "why," and discusses the shift toward user-level security awareness.
- **Middle (~48%–52%)**: Continues with standards/procedures documentation hierarchy and emphasizes the importance of user training with metrics to demonstrate change. The book's later sections (not fully covered in excerpts) likely address compliance, vulnerability scanning, and penetration testing.
【Key Takeaways】
- **Risk management is a continuous cycle** (Early): Assess threats, mitigate, monitor via quarterly reviews, and govern with senior management involvement. A risk register helps track scenarios and controls over time.
- **Asset management is foundational and ongoing** (Early): You cannot protect unknown assets; maintain a single source of truth and treat inventory as a cycle, not a one-time project. This is critical for incident response, like validating encryption on a stolen device.
- **Tabletops and drills reveal weaknesses before incidents** (Early): Tabletop exercises are low-stress walkthroughs with a moderator and diverse participants (finance, HR, legal), while drills test specific controls like backup restoration. Both are essential for finding gaps.
- **Documentation hierarchy clarifies policy** (Middle): Policies are the "why," while standards and procedures are the "what" and "how." Organizing documentation into this hierarchy brings policies to life and supports consistent implementation.
- **User education is shifting to user-level security** (Middle): Move beyond perimeter defenses (VPNs, WAFs) to train users as a line of defense. Use metrics to demonstrate successful change and start with universal attack vectors before spending on threat intel.
- **Data classification requires collaboration** (Middle): Work with business units to classify data (e.g., public, private, internal) tailored to their needs, fostering shared responsibility. A university fundraising example shows how to identify data types and build a simple system.
- **IAM systems streamline user inventory** (Middle): Track user access rights, MFA status, and account details via IAM solutions (e.g., Active Directory). Scheduled reports help monitor new accounts and foil social engineering attacks on help desks.
【Reading Tips】
- **Deep-read Chapters 1–2** for the foundational risk management cycle and asset management schemas; these are the backbone of the book and apply to any organization size.
- **Skim the network hardening sections** (Chapter 16) if you're not a network engineer, but note the IPv6 cautionary note—it's a common oversight.
- **Focus on the tabletop and drill guidance** (Chapter 1) if you need immediate, low-cost ways to test your incident response; the participant list and moderator tips are directly actionable.
- **Use the data classification example** (Chapter 2) as a template for your own department; it's a concrete, repeatable process.
- **Take away the documentation hierarchy concept** (Chapter 4) even if you skip the details; it will help you structure any security documentation you create.
【Coverage Limits】
This guide synthesizes the opening through middle sections (~0–52%) of the book, covering security program creation, asset management, network hardening, and user education. Later chapters on compliance, vulnerability scanning, and penetration testing are not covered in the provided excerpts.
Excerpt 1
3 Assessing Threats and Risks 4 Identify Scope, Assets, and Threa...
d assets to the best of our abilities. There will always be cases where you will walk into an environment that is a metaphorical train wreck with so many fir...
e it, or even provide its serial number to law enforcement. And for the last scenario, the architecture of HR systems can be complex, especially in larger or...
administrator at a midsized company, and you’ve been tasked with auditing the software installed on employees’ workstations to ensure compliance with licensi...
edicated DR facility or secondary office, located somewhere where the appropriate connectivity is available, and the servers can begin operating right away.
ce a clear desk policy, utilizing locking document storage. Access to network jacks, telephony jacks, and other potentially sensitive connectors should be re...
protection from unwanted connections. Manage File Integrity File integrity management tools monitor key files on the filesystem and alert the administrator i...
stem while performing their tasks. The issue is that at the same time they are fixing issues, they are themselves running additional code on a host that can,...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Defensive Security Handbook Best Practices for Securing Infrastructure - Second Edition (Amanda Berlin, Lee Brotherston etc.)(Z-Library) (1)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Defensive Security Handbook Best Practices for Securing Infrastructure - Second Edition (Amanda Berlin, Lee Brotherston etc.)(Z-Library) (1)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment