Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Information Security Management Handbook, Sixth Edition, Volume 2 Review

Information Security Management Handbook, Sixth Edition, Volume 2
Average Reviews:

(More customer reviews)
Are you looking to buy Information Security Management Handbook, Sixth Edition, Volume 2? Here is the right place to find the great deals. we can offer discounts of up to 90% on Information Security Management Handbook, Sixth Edition, Volume 2. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Information Security Management Handbook, Sixth Edition, Volume 2 ReviewThe book has a particularly good summary of phishing. Explaining the main attack methods used by phishers to trick users into divulging sensitive financial data about themselves.
It also goes into how phishers use compromised computers to inject their messages into the net. The reader should note that in most cases, these computers are not the targets of the bad phishing links inside the messages. So one lesson is that we must expect that phishers will always be able to disseminate messages.
The countermeasures are given. For a far more extensive discussion, check out Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. However, neither book has made the conceptual leap to using Partner Lists and custom tags inside real messages from banks.Information Security Management Handbook, Sixth Edition, Volume 2 OverviewA compilation of the fundamental knowledge, skills, techniques, and tools require by all security professionals, Information Security Handbook, Sixth Edition sets the standard on which all IT security programs and certifications are based. Considered the gold-standard reference of Information Security, Volume 2 includes coverage of each domain of the Common Body of Knowledge, the standard of knowledge required by IT security professionals worldwide. In step with the lightening-quick, increasingly fast pace of change in the technology field, this book is updated annually, keeping IT professionals updated and current in their field and on the job.

Want to learn more information about Information Security Management Handbook, Sixth Edition, Volume 2?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Sarbanes-Oxley Guide for Finance and Information Technology Professionals Review

Sarbanes-Oxley Guide for Finance and Information Technology Professionals
Average Reviews:

(More customer reviews)
Are you looking to buy Sarbanes-Oxley Guide for Finance and Information Technology Professionals? Here is the right place to find the great deals. we can offer discounts of up to 90% on Sarbanes-Oxley Guide for Finance and Information Technology Professionals. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Sarbanes-Oxley Guide for Finance and Information Technology Professionals ReviewThis comprehensive guide provides a complete methodology for achieving Sarbanes-Oxley compliancy, namely the Sarbanes-Oxley Compliant Key Enterprise Technology (SOCKET) framework. The author is one of the world's leading regulatory compliance experts and Chairperson of the SOX Institute.
In terms of getting things done (and why it needs to be done) this is an excellent book. The SOCKET framework is laid out very clearly and you will find material and PowerPoint friendly bulleted lists covering every aspect of a SOX project (or, more accurately, a process).
Compared to the Manager's Guide to Compliance, the chapters constitute a more coherent narrative with more emphasis on organisational and IT issues. Compared to The Joy of SOX, it provides a generally more detailed coverage (but it is less entertaining). To give an example, the book contains a brilliant mapping between Sections of the Sarbanes-Oxley Act, business processes and affected technologies. Of course, it is not rocket science, but it is great value for money. For the IT professional, it goes beyond the presentation of the usual suspects COSO and COBIT by covering e.g. the ISO 1335 and 17799 standards.
Yet, despite the level of detail, the author manages to keep the momentum as he takes the reader through all the steps of a SOX compliance process in terms of the SOCKET framework. This implies that some important topics have been moved to the Appendices (that includes about 35 pages on COBIT 3 and 4).
One could wish for more examples and templates, but it is apparently easier said than done. (Another book from the same publisher that should provide templates, key processes, and checklists has been postponed until February 2007.) Apparently, Sanjay Anand is currently working on another book Essentials of Sarbanes-Oxley that will include "Tips and Techniques" and "In the Real World" features with realistic advice on compliance. At least until then, the Sarbanes-Oxley Guide is the book to buy.
Sarbanes-Oxley Guide for Finance and Information Technology Professionals OverviewPraise for Sarbanes-Oxley Guide for Finance and Information Technology Professionals
"Effective SOX programs enlist the entire organization to build and monitor a compliant control environment. However, even the best SOX programs are inefficient at best, ineffective at worst, if there is a lack of informed, competent finance and IT personnel to support the effort. This book provides these important professionals a needed resource for and road map toward successfully implementing their SOX initiative."—Scott Green Chief Administrative Officer, Weil, Gotshal & Manges LLP and author, Sarbanes-Oxley and the Board of Directors
"As a former CFO and CIO, I found this book to be an excellent synopsis of SOX, with impressive implementation summaries and checklists."—Michael P. Cangemi CISA, Editor in Chief, Information Systems Control Journal and author, Managing the Audit Function
"An excellent introduction to the Sarbanes-Oxley Act from the perspective of the financial and IT professionals that are on the front lines of establishing compliance in their organizations. The author walks through many areas by asking 'what can go wrong' types of questions, and then outlines actions that should be taken as well as the consequences of noncompliance. This is a good book to add to one's professional library!"—Robert R. Moeller Author, Sarbanes-Oxley and the New Internal Auditing Rules
"Mr. Anand has compiled a solid overview of the control systems needed for not only accounting systems, but also the information technologies that support those systems. Among the Sarbanes books on the market, his coverage of both topics is unique."—Steven M. Bragg Author, Accounting Best Practices
"An excellent overview of the compliance process. A must-read for anyone who needs to get up to speed quickly with Sarbanes-Oxley."—Jack Martin Publisher, Sarbanes-Oxley Compliance Journal

Want to learn more information about Sarbanes-Oxley Guide for Finance and Information Technology Professionals?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server) Review

Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server)
Average Reviews:

(More customer reviews)
Are you looking to buy Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server) ReviewShort Summary:
Pro T-SQL 2008 Programmer's Guide examines SQL Server 2008 T-SQL from a developer's perspective. This information-rich book covers a wide array of developer-specific topics in SQL Server 2008. In addition, it provides in-depth knowledge of various newly introduced topics. This book is written as a practical guide to help database developers who mainly deal with T-SQL. It has really hit the spot with appropriate .NET code at a few places where required. The book assumes a basic knowledge of SQL, but it is very easy to understand for novice developers, while for advanced developers it is a great source to enhance their knowledge.
Detailed Summary:
Pro T-SQL 2008 Programmer's Guide is a well-written and well-structured book with a good depth and breadth of quality content presented in a reader friendly way. The book is structured into chapters where latest and comprehensive information have been backed with numerous examples to facilitate understanding of all levels of developers. What I really liked about this book is that it can either be read from cover to cover, or can be used as a reference guide for finding information topic-wise. A well-organized index aids in finding the topics very quickly.
Apart from valuable knowledge, each chapter of the book contains excellent advice and is filled with sample code (available online). It primarily revolves around SQL Server 2008 and innovative ways to code T-SQL, new functions and commands. It addresses many details and comparisons with T-SQL in a very organized manner. All the examples have been carefully selected and are accurate, useful and sufficient for the targeted topics. In addition, this book addresses a number of real-world issues with examples, discussions and solutions.
SQLCMD and SQL Server Management Studio are advanced tools to explore SQL Server 2008 that have been covered in depth in the beginning of the book. I would like to discuss Chapter 2 in detail. This chapter dives right into the new features of T-SQL on SQL Server 2008, with discussion on productivity-enhancing features, the new MERGE statement, new data types like geometry and hierarchyid, and grouping sets. Chapter 13 introduces SQL Server 2008 catalog views, which are the preferred tools for retrieving database and database object metadata. This chapter also hashes out dynamic management views and functions, which provide access to server and database state information.
Chapters that cover Common Table Expressions (CTEs), new data types, operators, keywords, functions, and control of flows are very interesting and contain necessary explanation. Readers of my blog are very well aware of my interests in Error handling and Debugging. Interesting enough for me, there is one whole chapter dedicated to these areas. Some of the regular T-SQL concepts such as Stored Procedure, Triggers and Dynamic SQL, which I write a lot about, have also been covered in this book and each have a chapter dedicated to them. The last three chapters of the book on SQLCLR, .NET Client Programming and HTTP Endpoints necessitate Microsoft .NET FrameWork 2.0, as they contain some codes that are written in VB and C#.
One demerit with other run-of-the-mill T-SQL books is that they do not include in-depth information on XML, XQuery and XPath, while these topic have been discussed in good detail in this book, and their importance has been appropriately explained. Yet another attractive feature of this book is that all the chapters contain exercise with Appendix A having answers to all the questions asked. Appendix D comprises quick reference to SQLCMD command-line tool, which I have been using myself.
Some excerpts from the book that demonstrate how complex subjects have been explained in a lucid way and present the visionary attitude of the author.
"How do you pass parameters to triggers? The short answer is you can't. Because they are automatically fired in response to events, SQL Server triggers provide no means to pass in parameters."
"When used with an aggregate function like SUM, COUNT, or AVG, or a user-defined aggregate, the OVER clause can only take a PARTITION BY clause-not an ORDER BY clause. This is a serious shortcoming in the SQL Server implementation of OVER for aggregate functions. ORDER BY in the OVER clause for aggregate functions allows you to easily perform single-statement running sum-type calculations. Running sum calculations without this feature require extensive joins, causing many people to fall back on cursors. ORDER BY for the aggregate OVER clause, and other features related to windowing functions, has been submitted as a feature request to Microsoft. Hopefully, we'll see it implemented at some point in the near future."
One thing that I have always liked in any database book is the use of sample database AdventureWorks. I strongly believe that the all the examples should be independent of the previous examples and should use default database. If you have not installed default database AdventureWorks, you can get its latest location by searching in my blog SQLAuthority.com. All the scripts of examples are easily available and can be downloaded online. No book is free from errors and the website for this book has errata list, which is surprisingly very small.
Rating: 5 Stars
To sum up, Pro T-SQL 2008 Programmer's Guide is a must-read book for every developer who wants to take full advantage of the power of T-SQL on SQL Server 2008. This book by Author Michel Coles it meant to facilitate developers - they can now spend less time worrying about how things get done and instead think about what they actually want to get done.
Pinal Dave
Founder - (blog.SQLAuthority.com)Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server) OverviewSkill with the Transact-SQL language is key to any developer making use of Microsoft SQL Server. Written especially for developers, the Pro T-SQL 2008 Programmer's Guide shows developers the full range of what's possible using the language. Readers become fully-grounded in the language, in the key features that SQL Server has to offer, and they are introduced to best-practices that will help ensure their success.

Want to learn more information about Pro T-SQL 2008 Programmer's Guide (Expert's Voice in SQL Server)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security+ Guide to Network Security Fundamentals Review

Security+ Guide to Network Security Fundamentals
Average Reviews:

(More customer reviews)
Are you looking to buy Security+ Guide to Network Security Fundamentals? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security+ Guide to Network Security Fundamentals. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security+ Guide to Network Security Fundamentals ReviewI bought this book for two reasons: first I needed it for a security class this summer, second I needed a book with good testing software to prepare for the CompTIA Security+ exam. It served its purpose and I passed the exam easily.
The practice exam software is good, but I have used this exam engine from Certblaster before and the question text size they use is too small, which is very irratiting especially since there is plenty of room to use a larger text size. Unlike other books that use the same Certblaster software (usually a Course Technology publication), this one does not use the other functions that the test software offers, like providing the explanations to the questions, so you can actually learn as you go. Someone got lazy. Also the end of chapter question drills, which ask up to 20 questions, provide neither the answer OR the explanation key so you can check yourself; you have to dig through the text. End of chapter quizzes are really good learning tools, but these ones make you work too hard, and waste your time by making you hunt down the correct answers in a chapter you just read. They could at least give the answers, even if they are too lazy to provide the explanations. So, as an exam prep book, this one really falls down on its face in that area. I hate to criticize this fine book, but for almost 100.00 these overpriced Course Technology books should be doing better than this.
It is a good book as far as the text and layout go, very readable and enjoyable. But unless you need it for a class (as is often the case with Course Technology books), save your money and get the Sybex book, or Sybex+something else like the ExamCram and STILL pay less than half what this book costs.
I give it 3 stars. I would have given 5 except for the inexcusable lack of answers/explanations to the end of chapter review questions, the lack of answers/explanations to the Certblaster practice exams, and the insane price.Security+ Guide to Network Security Fundamentals OverviewNow in its third edition, the best-selling SECURITY+ GUIDE TO NETWORK SECURITY FUNDAMENTALS provides the most up-to-date industry information, reflecting the changes in security that have occurred since the most recent CompTIA Security+ objectives were created. The book covers all of the new CompTIA Security+ 2008 exam objectives and maps to the new Security+ 2008 exam. This updated edition features many all-new topics, including topics new to the CompTIA exams like cross site scripting, SQL injection, rootkits, and virtualization, as well as topics of increasing importance in the industry as a whole, like the latest breeds of attackers, Wi-Fi Protected Access 2, and Microsoft Windows Vista security.

Want to learn more information about Security+ Guide to Network Security Fundamentals?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Managing Security with Snort and IDS Tools Review

Managing Security with Snort and IDS Tools
Average Reviews:

(More customer reviews)
Are you looking to buy Managing Security with Snort and IDS Tools? Here is the right place to find the great deals. we can offer discounts of up to 90% on Managing Security with Snort and IDS Tools. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Managing Security with Snort and IDS Tools ReviewThis is basically a book about intrusion detection using all open source tools. It starts with an introductory chapter that explains the problem of defining an intrusion and why it is becoming more and more of a problem. It follows up with a chapter on network traffic analysis including packet sniffing and using tcpdump and ethereal. Then comes the meat of the text - installing Snort. Of course to really understand how to use Snort you have to understand how attacks occur and the common methods used. The authors provide a really nice chapter on this subject. After that come five chapters on configuring, deploying, and managing Snort rules, intrusion prevention strategies, and tuning. Once Snort is up and running the authors examine the use of ACID and SnortCenter as Snort IDS management consoles. Either of these products drastically decreases the burden of analyzing what has happened and is happening on the intrusion detection forefront. The book ends with additional tools for Snort IDS management and implementation strategies for high-bandwidth situations.
There are other very good books on Snort but one of the things that makes this one particularly valuable is that it also looks at other open source tools and provides a good basic background on intrusion detection theory. Managing Security with Snort and IDS Tools is highly recommended for those in charge of intrusion detection and prevention in a network environment and planning to implement a system their self.Managing Security with Snort and IDS Tools Overview
Intrusion detection is not for the faint at heart. But, if you are a network administrator chances are you're under increasing pressure to ensure that mission-critical systems are safe--in fact impenetrable--from malicious code, buffer overflows, stealth port scans, SMB probes, OS fingerprinting attempts, CGI attacks, and other network intruders.

Designing a reliable way to detect intruders before they get in is a vital but daunting challenge. Because of this, a plethora of complex, sophisticated, and pricy software solutions are now available. In terms of raw power and features, SNORT, the most commonly used Open Source Intrusion Detection System, (IDS) has begun to eclipse many expensive proprietary IDSes. In terms of documentation or ease of use, however, SNORT can seem overwhelming. Which output plugin to use?How do you to email alerts to yourself? Most importantly, how do you sort through the immense amount of information Snort makes available to you?

Many intrusion detection books are long on theory but short on specifics and practical examples. Not Managing Security with Snort and IDS Tools.This new book is a thorough, exceptionally practical guide to managing network security using Snort 2.1 (the latest release) and dozens of other high-quality open source other open source intrusion detection programs.

Managing Security with Snort and IDS Tools covers reliable methods for detecting network intruders, from using simple packet sniffers to more sophisticated IDS (Intrusion Detection Systems) applications and the GUI interfaces for managing them. A comprehensive but concise guide for monitoring illegal entry attempts, this invaluable new book explains how to shut down and secure workstations, servers, firewalls, routers, sensors and other network devices.

Step-by-step instructions are provided to quickly get up and running with Snort. Each chapter includes links for the programs discussed, and additional links at the end of the book give administrators access to numerous web sites for additional information and instructional material that will satisfy even the most serious security enthusiasts.

Managing Security with Snort and IDS Tools maps out a proactive--and effective--approach to keeping your systems safe from attack.


Want to learn more information about Managing Security with Snort and IDS Tools?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...