IT Security Metrics: A Practical Framework for Measuring Security & Protecting Data

June 8, 2010



IT Security MetricIT Security Metrics: A Practical Framework for Measuring Security & Protecting Data

Author: Hayden, Lance
ISBN-13: 978-0-07-171340-5
ISBN-10: 0071713409
©2011 | 1st Edition | 400 pages , Softcover
Pub Date: July 2010
Price: US$ 49.99

Learn More

Implement an effective security metrics project or program

IT Security Metrics: A Practical Framework for Measuring Security & Protecting Data proposes new ways of examining security activities that focus on observation, measurement, and a more structured way of looking at security problems. These methods encourage empirical inquiry and scientific analysis over subjective judgment and opinion when driving security decision-making. The book offers concrete strategies for putting a variety of research tools and metrics into active use on everyday projects.

This definitive guide first describes the history and theory behind empirical analysis and scientific methods, and shows how traditional security practices often do not stand up to rigorous standards of research and analysis. The book then presents new security methods that improve decisions, increase security, and save time and money. The book advises how to choose effective methods and metrics for security projects and provide better information to security stakeholders, reducing uncertainty about the effectiveness of their programs.

  • Define security metrics as a manageable amount of usable data
  • Design effective security metrics
  • Understand quantitative and qualitative data, data sources, and collection and normalization methods
  • Implement a programmatic approach to security using the Security Process Management Framework.
  • Analyze security metrics data using quantitative and qualitative methods
  • Design a security measurement project for operational analysis of security metrics
  • Measure security operations, compliance, cost and value, and people, organizations, and culture
  • Manage groups of security measurement projects using the Security Improvement Program
  • Apply organizational learning methods to security metrics


Endorsement

“Disperses myths while illuminating truths, pointing towards better ways for IT to conceptualize, implement, and articulate the value proposition of security activities and investments….Clearly grounded in foundational concepts of risk management, decision support, and basic economics….Abounds with practical examples, anecdotes, metaphors, crisp descriptions of difficult concepts, comparisons with other industries, and a just plain entertaining writing style that won’t strain your attention span….The relevance, information density, and readability of this book is top-notch….I strongly recommend it to anyone who is passionate and serious about protecting digital assets with better precision and effectiveness.”

Joel Scambray, Co-Author, Hacking Exposed, and CEO of Consciere


About the Author

Lance Hayden, Ph.D. (Austin, TX) works for Cisco Systems, developing and managing security consulting services and contributing to new security product initiatives. He previously worked for the CIA where he conducted sensitive intelligence operations on behalf of the U.S. government. Lance has spoken at technology and security conferences such as RSA, FIRST, ToorCon, and Cisco Live.

Read the rest of this entry »


Virtualization, A Beginner’s Guide

April 6, 2010

   

Virtualization

Virtualization: A Beginner’s Guide  

Authors: Ruest, Nelson; Ruest, Danielle
ISBN-13: 978-0-07-161401-6
ISBN-10: 007161401X
©2009 | 1st Edition | 464 pages , Softcover
February: February 2009
Price: US$ 39.99 


Migrate to a dynamic, on-demand data delivery platform
  

“If you’re looking to hit the ground running with any virtualization project, large or small, this book is going to give you the start you need, and along the way will offer you some cautionary tales that will even take some seasoned virtualization veterans by surprise.” –From the foreword by Chris Wolf, Senior Analyst, Burton Group  

Transform your IT infrastructure into a leaner, greener datacenter with expert guidance from a pair of industry professionals. Through clear explanations, examples, and a five-step deployment plan, Virtualization: A Beginner’s Guide shows you how to maximize the latest technologies from Citrix, Microsoft, and VMware. Consolidate your servers, set up virtual machines and applications, and manage virtual desktop environments. You’ll also learn how to implement reliable security, monitoring, and backup procedures.  

  • Select a virtualization platform and develop rollout plans
  • Perform pre-deployment network and workstation tests
  • Configure virtual machines, storage devices, and workloads
  • Set up and secure a fully virtualized and highly available server environment
  • Manage a centralized, on-demand application delivery framework
  • Handle volatile and persistent desktop virtualization
  • Use hypervisors to facilitate workload delivery
  • Implement failsafe system backup and recovery strategies

   

About the Authors  

Danielle Ruest is a senior enterprise workflow architect and consultant, and a Microsoft Most Valuable Professional for the Virtual Machine product line.  

Nelson Ruest is a senior enterprise IT architect and a Microsoft Most Valuable Professional for the Windows Server product line. Together, they are the coauthors of Microsoft Windows Server 2008: The Complete Reference and other titles.

 

Virtualization expert Nelson Ruest, author of Virtualization: A Beginner’s Guide, on the evolution and history of virtualization technology 

 

  

Sample Chapter 01  |  Sample Chapter 06  Learn More  

   

   

   

   

 


Follow

Get every new post delivered to your Inbox.