Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Amanda Berlin, Lee Brotherston, William F. Reyor III

Rating No ratings yet

Despite the increase of high-profile hacks, record-breaking data leaks, and ransomware attacks, many organizations don't have the budget for an information security (InfoSec) program. If you're forced to protect yourself by improvising on the job, this pragmatic guide provides a security-101 handbook with steps, tools, processes, and ideas to help you drive maximum-security improvement at little or no cost. Each chapter in this book provides step-by-step instructions for dealing with issues such as breaches and disasters, compliance, network infrastructure, password management, vulnerability scanning, penetration testing, and more. Network engineers, system administrators, and security professionals will learn how to use frameworks, tools, and techniques to build and improve their cybersecurity programs.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A pragmatic, budget-conscious security-101 handbook for network engineers, system administrators, and IT professionals who must build or improve an InfoSec program without dedicated funding, offering step-by-step processes, tools, and frameworks for defending infrastructure. 【Book Arc】 - **Opening (~0%–10%)**: Lays the groundwork for creating a security program, covering team establishment, baseline posture assessment, risk/threat identification, and prioritization. It introduces the core risk management cycle (assess, mitigate, monitor, govern) and emphasizes the need for continuous improvement. - **Early (~10%–23%)**: Moves into asset management and documentation, stressing the need for a "single source of truth" and treating inventory as an ongoing process. It also covers network infrastructure hardening, including device configuration, patching, and segmentation, with a cautionary note on IPv6. - **Early (~23%–32%)**: Delves into practical exercises like tabletops and drills for testing incident response, and expands on asset management with detailed schemas for hardware, software, and user inventories. It highlights the role of IAM systems and tools like osquery for visibility. - **Middle (~39%–48%)**: Focuses on data classification and user education, using examples like a university's fundraising department to illustrate tailored classification systems. It also introduces standards and procedures as the "what" and "how" that support policy "why," and discusses the shift toward user-level security awareness. - **Middle (~48%–52%)**: Continues with standards/procedures documentation hierarchy and emphasizes the importance of user training with metrics to demonstrate change. The book's later sections (not fully covered in excerpts) likely address compliance, vulnerability scanning, and penetration testing. 【Key Takeaways】 - **Risk management is a continuous cycle** (Early): Assess threats, mitigate, monitor via quarterly reviews, and govern with senior management involvement. A risk register helps track scenarios and controls over time. - **Asset management is foundational and ongoing** (Early): You cannot protect unknown assets; maintain a single source of truth and treat inventory as a cycle, not a one-time project. This is critical for incident response, like validating encryption on a stolen device. - **Tabletops and drills reveal weaknesses before incidents** (Early): Tabletop exercises are low-stress walkthroughs with a moderator and diverse participants (finance, HR, legal), while drills test specific controls like backup restoration. Both are essential for finding gaps. - **Documentation hierarchy clarifies policy** (Middle): Policies are the "why," while standards and procedures are the "what" and "how." Organizing documentation into this hierarchy brings policies to life and supports consistent implementation. - **User education is shifting to user-level security** (Middle): Move beyond perimeter defenses (VPNs, WAFs) to train users as a line of defense. Use metrics to demonstrate successful change and start with universal attack vectors before spending on threat intel. - **Data classification requires collaboration** (Middle): Work with business units to classify data (e.g., public, private, internal) tailored to their needs, fostering shared responsibility. A university fundraising example shows how to identify data types and build a simple system. - **IAM systems streamline user inventory** (Middle): Track user access rights, MFA status, and account details via IAM solutions (e.g., Active Directory). Scheduled reports help monitor new accounts and foil social engineering attacks on help desks. 【Reading Tips】 - **Deep-read Chapters 1–2** for the foundational risk management cycle and asset management schemas; these are the backbone of the book and apply to any organization size. - **Skim the network hardening sections** (Chapter 16) if you're not a network engineer, but note the IPv6 cautionary note—it's a common oversight. - **Focus on the tabletop and drill guidance** (Chapter 1) if you need immediate, low-cost ways to test your incident response; the participant list and moderator tips are directly actionable. - **Use the data classification example** (Chapter 2) as a template for your own department; it's a concrete, repeatable process. - **Take away the documentation hierarchy concept** (Chapter 4) even if you skip the details; it will help you structure any security documentation you create. 【Coverage Limits】 This guide synthesizes the opening through middle sections (~0–52%) of the book, covering security program creation, asset management, network hardening, and user education. Later chapters on compliance, vulnerability scanning, and penetration testing are not covered in the provided excerpts.
Excerpt 1
3 Assessing Threats and Risks 4 Identify Scope, Assets, and Threa...
View in text
Page 19
d assets to the best of our abilities. There will always be cases where you will walk into an environment that is a metaphorical train wreck with so many fir...
View in text
Excerpt 3
e it, or even provide its serial number to law enforcement. And for the last scenario, the architecture of HR systems can be complex, especially in larger or...
View in text
Excerpt 4
administrator at a midsized company, and you’ve been tasked with auditing the software installed on employees’ workstations to ensure compliance with licensi...
View in text
Excerpt 5
edicated DR facility or secondary office, located somewhere where the appropriate connectivity is available, and the servers can begin operating right away.
View in text
Excerpt 6
ce a clear desk policy, utilizing locking document storage. Access to network jacks, telephony jacks, and other potentially sensitive connectors should be re...
View in text
Excerpt 7
protection from unwanted connections. Manage File Integrity File integrity management tools monitor key files on the filesystem and alert the administrator i...
View in text
Excerpt 8
stem while performing their tasks. The issue is that at the same time they are fixing issues, they are themselves running additional code on a host that can,...
View in text
Tags
AI categories
CybersecurityBackendTechnology
information security
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 363
File Format: PDF
File Size: 8.9 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…