Skip to main content

Books in Security

This collection covers national security, cybersecurity, and crime prevention. Supporting security professionals, policymakers, and researchers, it features threat analysis, policy development, and technological solutions that strengthen safety and resilience.

  • Eleventh Hour CISSP

    Study Guide
    • 1st Edition
    • Eric Conrad + 2 more
    • English
    Eleventh Hour CISSP Study Guide serves as a guide for those who want to be information security professionals. The main job of an information security professional is to evaluate the risks involved in securing assets and to find ways to mitigate those risks. Information security jobs include firewall engineers, penetration testers, auditors, and the like. The book is composed of 10 domains of the Common Body of Knowledge. In each section, it defines each domain. The first domain provides information about risk analysis and mitigation, and it discusses security governance. The second domain discusses techniques of access control, which is the basis for all security disciplines. The third domain explains the concepts behind cryptography, which is a secure way of communicating that is understood only by certain recipients. Domain 5 discusses security system design, which is fundamental in operating the system and software security components. Domain 6 is one of the critical domains in the Common Body of Knowledge, the Business Continuity Planning and Disaster Recovery Planning. It is the final control against extreme events such as injury, loss of life, or failure of an organization. Domain 7, Domain 8 and Domain 9 discuss telecommunications and network security, application development security, and the operations domain, respectively. Domain 10 focuses on the major legal systems that provide a framework for determining laws about information system.
  • Contemporary Security Management

    • 3rd Edition
    • John Fay
    • English
    Contemporary Security Management, Third Edition teaches security professionals how to operate an efficient security department and how to integrate smoothly with other groups inside and outside their own organizations. Fay demonstrates the specifics of security management: how to organize, plan, develop and manage a security operation. how to identify vulnerabilities. how to determine the protective resources required to offset threats. how to implement all necessary physical and IT security measures. Security professionals share the responsibility for mitigating damage, serving as a resource to an Emergency Tactical Center, assisting the return of business continuity, and liaising with local response agencies such as police and fire departments, emergency medical responders, and emergency warning centers. At the organizational level, the book addresses budgeting, employee performance, counseling, hiring and termination, employee theft and other misconduct, and offers sound advice on building constructive relationships with organizational peers and company management.
  • Managed Code Rootkits

    Hooking into Runtime Environments
    • 1st Edition
    • Erez Metula
    • English
    Managed Code Rootkits is the first book to cover application-level rootkits and other types of malware inside the application VM, which runs a platform-independent programming environment for processes. The book, divided into four parts, points out high-level attacks, which are developed in intermediate language. The initial part of the book offers an overview of managed code rootkits. It explores environment models of managed code and the relationship of managed code to rootkits by studying how they use application VMs. It also discusses attackers of managed code rootkits and various attack scenarios. The second part of the book covers the development of managed code rootkits, starting with the tools used in producing managed code rootkits through their deployment. The next part focuses on countermeasures that can possibly be used against managed code rootkits, including technical solutions, prevention, detection, and response tactics. The book concludes by presenting techniques that are somehow similar to managed code rootkits, which can be used in solving problems.
  • Citrix XenDesktop Implementation

    A Practical Guide for IT Professionals
    • 1st Edition
    • Gareth R. James
    • English
    Citrix XenDesktop Implementation explores the implementation of Citrix XenDesktop, a virtual desktop infrastructure solution. After introducing the desktop virtualization, the book discusses the installation of a desktop delivery controller through advanced XenDesktop Client Settings. This book briefly discusses the work of desktop delivery controller mechanisms followed by its installation process, integration process of XenDesktop with Microsoft Active Directory, and the configuration of the desktop delivery controller. It then examines the process of installing the virtual desktop onto the server infrastructure, and it follows the installation and integration onto Xen Server, Hyper-V, and VMware hypervisors. Furthermore, it discusses the advanced configuration settings. The book covers the installation of the Citrix Provisioning Server and its fundamental configuration. It also explores the configuration of Citrix XenApp for Application provisioning, the integration of virtual applications, and the implementation of virtual profiles into the virtual desktop. The book concludes by explaining the advanced XenDesktop client settings on audio, video, and peripherals.
  • Ninja Hacking

    Unconventional Penetration Testing Tactics and Techniques
    • 1st Edition
    • Thomas Wilhelm + 1 more
    • English
    Ninja Hacking offers insight on how to conduct unorthodox attacks on computing networks, using disguise, espionage, stealth, and concealment. This book blends the ancient practices of Japanese ninjas, in particular the historical Ninjutsu techniques, with the present hacking methodologies. It looks at the methods used by malicious attackers in real-world situations and details unorthodox penetration testing techniques by getting inside the mind of a ninja. It also expands upon current penetration testing methodologies including new tactics for hardware and physical attacks. This book is organized into 17 chapters. The first two chapters incorporate the historical ninja into the modern hackers. The white-hat hackers are differentiated from the black-hat hackers. The function gaps between them are identified. The next chapters explore strategies and tactics using knowledge acquired from Sun Tzu's The Art of War applied to a ninja hacking project. The use of disguise, impersonation, and infiltration in hacking is then discussed. Other chapters cover stealth, entering methods, espionage using concealment devices, covert listening devices, intelligence gathering and interrogation, surveillance, and sabotage. The book concludes by presenting ways to hide the attack locations and activities. This book will be of great value not only to penetration testers and security professionals, but also to network and system administrators as well as hackers.
  • Security for Microsoft Windows System Administrators

    Introduction to Key Information Security Concepts
    • 1st Edition
    • Derrick Rountree
    • English
    Security for Microsoft Windows System is a handy guide that features security information for Windows beginners and professional admin. It provides information on security basics and tools for advanced protection against network failures and attacks. The text is divided into six chapters that cover details about network attacks, system failures, audits, and social networking. The book introduces general security concepts including the principles of information security, standards, regulation, and compliance; authentication, authorization, and accounting; and access control. It also covers the cryptography and the principles of network, system, and organizational and operational security, including risk analysis and disaster recovery. The last part of the book presents assessments and audits of information security, which involve methods of testing, monitoring, logging, and auditing. This handy guide offers IT practitioners, systems and network administrators, and graduate and undergraduate students in information technology the details they need about security concepts and issues. Non-experts or beginners in Windows systems security will also find this book helpful.
  • Introduction to Emergency Management

    • 4th Edition
    • George Haddow + 2 more
    • English
    Introduction to Emergency Management, Fourth Edition, offers a practical guide to the discipline of emergency management. It focuses on the domestic emergency management system of the United States, highlighting the lessons and emerging trends that are applicable to emergency management systems in other parts of the world. The book begins by tracing the historical development of emergency management from the 1800s to the present world of homeland security. It then discusses the hazards faced by emergency management and the methods of assessing hazard risk; the function of mitigation and the strategies and programs emergency management or other disciplines use to reduce the impact of disasters; and emergency management preparedness. The book also covers the importance of communication in the emergency management of the twenty-first century; the functions and processes of disaster response; government and voluntary programs aimed at helping people and communities rebuild in the aftermath of a disaster; and international emergency management. It also addresses the impact of September 11, 2001 on traditional perceptions of emergency management; and emergency management in the post-9/11, post-Katrina environment.
  • Metrics and Methods for Security Risk Management

    • 1st Edition
    • Carl Young
    • English
    Security problems have evolved in the corporate world because of technological changes, such as using the Internet as a means of communication. With this, the creation, transmission, and storage of information may represent security problem. Metrics and Methods for Security Risk Management is of interest, especially since the 9/11 terror attacks, because it addresses the ways to manage risk security in the corporate world. The book aims to provide information about the fundamentals of security risks and the corresponding components, an analytical approach to risk assessments and mitigation, and quantitative methods to assess the risk components. In addition, it also discusses the physical models, principles, and quantitative methods needed to assess the risk components. The by-products of the methodology used include security standards, audits, risk metrics, and program frameworks. Security professionals, as well as scientists and engineers who are working on technical issues related to security problems will find this book relevant and useful.
  • Microsoft Windows Server 2008 R2 Administrator's Reference

    The Administrator's Essential Reference
    • 1st Edition
    • Dustin Hannifin
    • English
    Microsoft Windows Server 2008 R2: The Administrators Essential Reference introduces the Windows Server 2008 R2, which is Microsofts flagship server operating systems latest release. The book explores its features; describes differences between the available editions; and discusses its deployment. After introducing Windows Server 2008 R2, the book explains its installation and configuration processes followed by its networking. It also examines different features, such as the active directory, internet information services 7.5, Hyper-V, and PowerShell V2. It discusses securing Windows Server 2008 R2 files and its print services, remote desktop services, high-availability and recovery features, and monitoring and troubleshooting; in addition, their delta changes are discussed in the final chapter. The book also explores the features that influence both Windows Server 2008 R2 and Windows 7. These features allow the server operating system to work with Windows 7. One feature is the BranchCache, which offers users who open files across a Wide Area Network a better end-user experience by caching copy in the branch office when a document or intranet Web site is opened for the first time. Another feature is DirectAccess, which is the new remote connectivity solution for Windows networks.
  • Digital Forensics for Network, Internet, and Cloud Computing

    A Forensic Evidence Guide for Moving Targets and Data
    • 1st Edition
    • Clint P Garrison + 2 more
    • English
    Network forensics is an evolution of typical digital forensics, in which evidence is gathered from network traffic in near real time. This book will help security and forensics professionals as well as network administrators build a solid foundation of processes and controls to identify incidents and gather evidence from the network. Forensic scientists and investigators are some of the fastest growing jobs in the United States with over 70,000 individuals employed in 2008. Specifically in the area of cybercrime and digital forensics, the federal government is conducting a talent search for 10,000 qualified specialists. Almost every technology company has developed or is developing a cloud computing strategy. To cut costs, many companies are moving toward network-based applications like SalesForce.com, PeopleSoft, and HR Direct. Every day, we are moving companies’ proprietary data into a cloud, which can be hosted anywhere in the world. These companies need to understand how to identify where their data is going and what they are sending.
  • Dissecting the Hack: The F0rb1dd3n Network, Revised Edition

    • 1st Edition
    • Brian Baskin + 3 more
    • English
    Dissecting the Hack: The F0rb1dd3n Network, Revised Edition, deals with hackers and hacking. The book is divided into two parts. The first part, entitled “The F0rb1dd3n Network,” tells the fictional story of Bob and Leon, two kids caught up in an adventure where they learn the real-world consequence of digital actions. The second part, “Security Threats Are Real” (STAR), focuses on these real-world lessons.The F0rb1dd3n Network can be read as a stand-alone story or as an illustration of the issues described in STAR. Throughout The F0rb1dd3n Network are “Easter eggs”—references, hints, phrases, and more that will lead readers to insights into hacker culture. Drawing on The F0rb1dd3n Network, STAR explains the various aspects of reconnaissance; the scanning phase of an attack; the attacker’s search for network weaknesses and vulnerabilities to exploit; the various angles of attack used by the characters in the story; basic methods of erasing information and obscuring an attacker’s presence on a computer system; and the underlying hacking culture.
  • Seven Deadliest USB Attacks

    • 1st Edition
    • Brian Anderson + 1 more
    • English
    Seven Deadliest USB Attacks provides a comprehensive view of the most serious types of Universal Serial Bus (USB) attacks. While the book focuses on Windows systems, Mac, Linux, and UNIX systems are equally susceptible to similar attacks. If you need to keep up with the latest hacks, attacks, and exploits effecting USB technology, then this book is for you. This book pinpoints the most dangerous hacks and exploits specific to USB, laying out the anatomy of these attacks including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable. The attacks outlined in this book are intended for individuals with moderate Microsoft Windows proficiency. The book provides the tools, tricks, and detailed instructions necessary to reconstruct and mitigate these activities while peering into the risks and future aspects surrounding the respective technologies. There are seven chapters that cover the following: USB Hacksaw; the USB Switchblade; viruses and malicious codes; USB-based heap overflow; the evolution of forensics in computer security; pod slurping; and the human element of security, including the risks, rewards, and controversy surrounding social-engineering engagements. This book was written to target a vast audience including students, technical staff, business leaders, or anyone seeking to understand fully the removable-media risk for Windows systems. It will be a valuable resource for information security professionals of all levels, as well as web application developers and recreational hackers.
  • Seven Deadliest Social Network Attacks

    • 1st Edition
    • Carl Timm + 1 more
    • English
    Seven Deadliest Social Network Attacks describes the seven deadliest social networking attacks and how to defend against them. This book pinpoints the most dangerous hacks and exploits specific to social networks like Facebook, Twitter, and MySpace, and provides a comprehensive view into how such attacks have impacted the livelihood and lives of adults and children. It lays out the anatomy of these attacks, including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable. The book is separated into seven chapters, with each focusing on a specific type of attack that has been furthered with social networking tools and devices. These are: social networking infrastructure attacks; malware attacks; phishing attacks; Evil Twin Attacks; identity theft; cyberbullying; and physical threat. Each chapter takes readers through a detailed overview of a particular attack to demonstrate how it was used, what was accomplished as a result, and the ensuing consequences. In addition to analyzing the anatomy of the attacks, the book offers insights into how to develop mitigation strategies, including forecasts of where these types of attacks are heading. This book can serve as a reference guide to anyone who is or will be involved in oversight roles within the information security field. It will also benefit those involved or interested in providing defense mechanisms surrounding social media as well as information security professionals at all levels, those in the teaching profession, and recreational hackers.
  • Microsoft Windows 7 Administrator's Reference

    Upgrading, Deploying, Managing, and Securing Windows 7
    • 1st Edition
    • Jorge Orchilles
    • English
    Microsoft Windows 7 Administrators Reference covers various aspects of Windows 7 systems, including its general information as well as installation and upgrades. This reference explains how to deploy, use, and manage the operating system. The book is divided into 10 chapters. Chapter 1 introduces the Windows 7 and the rationale of releasing this operating system. The next chapter discusses how an administrator can install and upgrade the old operating system from Windows Vista to Windows 7. The deployment of Windows 7 in an organization or other environment is then explained. It also provides the information needed to deploy Windows 7 easily and quickly for both the administrator and end users. Furthermore, the book provides the features of Windows 7 and the ways to manage it properly. The remaining chapters discuss how to secure Windows 7, as well as how to troubleshoot it. This book will serve as a reference and guide for those who want to utilize Windows 7.
  • Seven Deadliest Unified Communications Attacks

    • 1st Edition
    • Dan York
    • English
    Seven Deadliest Unified Communications Attacks provides a comprehensive coverage of the seven most dangerous hacks and exploits specific to Unified Communications (UC) and lays out the anatomy of these attacks including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable. The book describes the intersection of the various communication technologies that make up UC, including Voice over IP (VoIP), instant message (IM), and other collaboration technologies. There are seven chapters that focus on the following: attacks against the UC ecosystem and UC endpoints; eavesdropping and modification attacks; control channel attacks; attacks on Session Initiation Protocol (SIP) trunks and public switched telephone network (PSTN) interconnection; attacks on identity; and attacks against distributed systems. Each chapter begins with an introduction to the threat along with some examples of the problem. This is followed by discussions of the anatomy, dangers, and future outlook of the threat as well as specific strategies on how to defend systems against the threat. The discussions of each threat are also organized around the themes of confidentiality, integrity, and availability. This book will be of interest to information security professionals of all levels as well as recreational hackers.
  • Seven Deadliest Network Attacks

    • 1st Edition
    • Stacy Prowell + 2 more
    • English
    Seven Deadliest Network Attacks identifies seven classes of network attacks and discusses how the attack works, including tools to accomplish the attack, the risks of the attack, and how to defend against the attack. This book pinpoints the most dangerous hacks and exploits specific to networks, laying out the anatomy of these attacks including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable. The book consists of seven chapters that deal with the following attacks: denial of service; war dialing; penetration testing; protocol tunneling; spanning tree attacks; man-in-the-middle; and password replay. These attacks are not mutually exclusive and were chosen because they help illustrate different aspects of network security. The principles on which they rely are unlikely to vanish any time soon, and they allow for the possibility of gaining something of interest to the attacker, from money to high-value data. This book is intended to provide practical, usable information. However, the world of network security is evolving very rapidly, and the attack that works today may (hopefully) not work tomorrow. It is more important, then, to understand the principles on which the attacks and exploits are based in order to properly plan either a network attack or a network defense. Seven Deadliest Network Attacks will appeal to information security professionals of all levels, network admins, and recreational hackers.
  • Workplace Violence

    Planning for Prevention and Response
    • 1st Edition
    • Kim Kerr
    • English
    Workplace violence in all its forms is becoming more prevalent and pervasive every year. Workplace Violence: Planning for Prevention and Response gives a comprehensive account of the problem using a multi-faceted approach to the issues surrounding workplace violence incidents, addressing how the topic affects victims, witnesses, the workforce, family members, and management. A series of chapters helps organizations to form action and response plans to manage incidents both large and small. The focus also includes organizations that are forced to address violent individuals in settings where law enforcement may not be immediately available. Kerr speaks first-hand about complex issues like corporate liability for violent or threatening acts committed by employees, as well as issues of privacy, and he includes chapters written by experts on legal issues, cyberthreats, and anger in the workplace. This book belongs on the desk of every security manager and HR professional, and offers solid advice to all managers regardless of the size of their organization.
  • Seven Deadliest Wireless Technologies Attacks

    • 1st Edition
    • Brad Haines
    • English
    Seven Deadliest Wireless Technologies Attacks provides a comprehensive view of the seven different attacks against popular wireless protocols and systems. This book pinpoints the most dangerous hacks and exploits specific to wireless technologies, laying out the anatomy of these attacks, including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable. Each chapter includes an example real attack scenario, an analysis of the attack, and methods for mitigating the attack. Common themes will emerge throughout the book, but each wireless technology has its own unique quirks that make it useful to attackers in different ways, making understanding all of them important to overall security as rarely is just one wireless technology in use at a home or office. The book contains seven chapters that cover the following: infrastructure attacks, client attacks, Bluetooth attacks, RFID attacks; and attacks on analog wireless devices, cell phones, PDAs, and other hybrid devices. A chapter deals with the problem of bad encryption. It demonstrates how something that was supposed to protect communications can end up providing less security than advertised. This book is intended for information security professionals of all levels, as well as wireless device developers and recreational hackers.
  • The Professional Protection Officer

    Practical Security Strategies and Emerging Trends
    • 1st Edition
    • IFPO
    • Sandi J. Davies
    • English
    The Professional Protection Officer: Security Strategies, Tactics and Trends, Second Edition, is the definitive reference and instructional text for career oriented security officers in both the private and public sectors. The first edition originated with the birth of the International Foundation for Protection Officers (IFPO) in 1988, which has been using the book as the official text since that time. Each subsequent edition has brought new and enlightened information to the protection professional. The material in this new edition includes all of the subjects essential to training of protection professionals, and has been updated to reflect new strategies, tactics, and trends in this dynamic field.Written by leading security educators, trainers and consultants, this valuable resource has served as the definitive text for both students and professionals worldwide. This new edition adds critical updates and fresh pedagogy, as well as new diagrams, illustrations, and self assessments. The Professional Protection Officer: Security Strategies, Tactics and Trends is tailored to the training and certification needs of today’s protection professionals and proves to be the most exciting and progressive edition yet.
  • Seven Deadliest Microsoft Attacks

    • 1st Edition
    • Rob Kraus + 3 more
    • English
    Seven Deadliest Microsoft Attacks explores some of the deadliest attacks made against Microsoft software and networks and how these attacks can impact the confidentiality, integrity, and availability of the most closely guarded company secrets. If you need to keep up with the latest hacks, attacks, and exploits effecting Microsoft products, this book is for you. It pinpoints the most dangerous hacks and exploits specific to Microsoft applications, laying out the anatomy of these attacks including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable.The book consists of seven chapters that cover the seven deadliest attacks against Microsoft software and networks: attacks against Windows passwords; escalation attacks; stored procedure attacks; mail service attacks; client-side ActiveX and macro attacks; Web service attacks; and multi-tier attacks. Each chapter provides an overview of a single Microsoft software product, how it is used, and some of the core functionality behind the software. Furthermore, each chapter explores the anatomy of attacks against the software, the dangers of an attack, and possible defenses to help prevent the attacks described in the scenarios.This book will be a valuable resource for those responsible for oversight of network security for either small or large organizations. It will also benefit those interested in learning the details behind attacks against Microsoft infrastructure, products, and services; and how to defend against them. Network administrators and integrators will find value in learning how attacks can be executed, and transfer knowledge gained from this book into improving existing deployment and integration practices.
  • Network and System Security

    • 1st Edition
    • John Vacca
    • English
    Network and System Security provides focused coverage of network and system security technologies. It explores practical solutions to a wide range of network and systems security issues. Chapters are authored by leading experts in the field and address the immediate and long-term challenges in the authors’ respective areas of expertise. Coverage includes building a secure organization; cryptography; system intrusion; UNIX and Linux security; Internet security, intranet security; LAN security; wireless network security; cellular network security, RFID security, and more. This compilation of 13 chapters is tightly focused and ideally suited as an essential desk reference in this high-growth subject area.
  • Digital Video Surveillance and Security

    • 1st Edition
    • Anthony C. Caputo
    • English
    Digital Video Surveillance and Security provides a blueprint for the IP-based electronic security system clients need, allowing security professionals to protect their client's place of business or home. The author gives detailed plans on the best camera position, areas of coverage, and hardware and software to select to maximize the effectiveness of newer lower-cost networked technologies. Clear, step-by-step descriptions and detailed illustrations describe the integration of such components as the current or new security system, door and window sensors, or other access controls, offering the capability of instantly launching a video of the area under surveillance on a computer or HDTV. Today's digital video surveillance solutions are networked, digitally archived, offering granular, managed accessibility from anywhere (any office, home, PDA, or smart phone), and providing interoperability and simple scalability. With recent advances in technology, DVS is economically attainable for most businesses. Security consultants can use this information to guide their clients in making budget-friendly choices of design and equipment and assembling the optimal system for their needs. Systems installers can use this step-by-step illustrated guide to master this crucial new technology.
  • Seven Deadliest Web Application Attacks

    • 1st Edition
    • Mike Shema
    • English
    Seven Deadliest Web Application Attacks highlights the vagaries of web security by discussing the seven deadliest vulnerabilities exploited by attackers. This book pinpoints the most dangerous hacks and exploits specific to web applications, laying out the anatomy of these attacks including how to make your system more secure. You will discover the best ways to defend against these vicious hacks with step-by-step instruction and learn techniques to make your computer and network impenetrable. Each chapter presents examples of different attacks conducted against web sites. The methodology behind the attack is explored, showing its potential impact. The chapter then moves on to address possible countermeasures for different aspects of the attack. The book consists of seven chapters that cover the following: the most pervasive and easily exploited vulnerabilities in web sites and web browsers; Structured Query Language (SQL) injection attacks; mistakes of server administrators that expose the web site to attack; brute force attacks; and logic attacks. The ways in which malicious software malware has been growing as a threat on the Web are also considered. This book is intended for information security professionals of all levels, as well as web application developers and recreational hackers.
  • Hospital Emergency Response Teams

    Triage for Optimal Disaster Response
    • 1st Edition
    • Jan Glarum + 2 more
    • English
    Hospital Emergency Response Teams aims to provide authoritative training for hospital personnel in the emergency department, as well community-level medical service personnel, assisting them in times of disaster and emergency. Comprised of six chapters, the book covers various aspects of emergency response. Some of the aspects are the National Incident Management System (NIMS) implementation activities for hospitals and health care systems and the Hospital Incident Command System (HICS) IV missions. The book also explains the implementation issues, requirements, and timelines in establishing an internal HICS IV program. It presents the assessment of likely mass casualty events and potential hospital impact. The book also features appendices for emergency response team checklists, PPE donning and doffing guide, ambulatory and non-ambulatory decontamination setup, ETA exercises, and ETA drills.The book is intended to provide understanding of emergency response to first emergency medicine professionals, first responders, security staff, community-level disaster planners, and public health and disaster management researchers.
  • PCI Compliance

    Understand and Implement Effective PCI Data Security Standard Compliance
    • 2nd Edition
    • Anton Chuvakin + 1 more
    • English
    PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance, Second Edition, discusses not only how to apply PCI in a practical and cost-effective way but more importantly why. The book explains what the Payment Card Industry Data Security Standard (PCI DSS) is and why it is here to stay; how it applies to information technology (IT) and information security professionals and their organization; how to deal with PCI assessors; and how to plan and manage PCI DSS project. It also describes the technologies referenced by PCI DSS and how PCI DSS relates to laws, frameworks, and regulations.This book is for IT managers and company managers who need to understand how PCI DSS applies to their organizations. It is for the small- and medium-size businesses that do not have an IT department to delegate to. It is for large organizations whose PCI DSS project scope is immense. It is also for all organizations that need to grasp the concepts of PCI DSS and how to implement an effective security framework that is also compliant.
  • Eleventh Hour Linux+

    Exam XK0-003 Study Guide
    • 1st Edition
    • Chris Happel + 3 more
    • English
    Eleventh Hour Linux+: Exam XK0-003 Study Guide offers a practical guide for those preparing for the Linux+ certification exam.The book begins with a review of important concepts that are needed for successful operating system installation. These include computer hardware, environment settings, partitions, and network settings. The book presents the strategies for creating filesystems; different types of filesystems; the tools used to create filesystems; and the tools used to administer filesystems. It explains the Linux boot process; how to configure system and user profiles as well as the common environment variables; and how to use BASH command line interpreter.The remaining chapters discuss how to install, configure, support, and remove applications; the configuration of Linux as a workstation and as a server; securing the Linux system; and common tools for managing a system. Each chapter includes information on exam objectives, exam warnings, and the top five toughest questions along with their answers.
  • CompTIA Linux+ Certification Study Guide (2009 Exam)

    Exam XK0-003
    • 1st Edition
    • Chris Happel + 3 more
    • English
    CompTIA Linux+ Certification Study Guide (2009 Exam) offers a practical guide for those interested in pursuing a Linux+ certification. It covers the required content as specified in CompTIAs exam objectives and has been shaped according to the respective exam experiences of the authors. Careful attention has been paid to ensure that each exam objective has been covered and that each term in the list at the end of the objectives has been included in a glossary at the end of the book. The book has been designed in such a way that readers will start with installing Linux and end up with a useable and secure Linux workstation and server that is supported and managed. Key topics discussed include booting Linux; how to use the BASH command-line interpreter (CLI) or BASH shell; and how to install applications to transform the Linux system into a productive tool. The remaining chapters cover the configuration of Linux as a workstation and as a server; security objectives; and the care and feeding of a Linux system. Each chapter ends with 15 exam questions along with a corresponding answer key.
  • Hospital and Healthcare Security

    • 5th Edition
    • Tony W. York + 1 more
    • English
    Hospital and Healthcare Security, Fifth Edition, examines the issues inherent to healthcare and hospital security, including licensing, regulatory requirements, litigation, and accreditation standards. Building on the solid foundation laid down in the first four editions, the book looks at the changes that have occurred in healthcare security since the last edition was published in 2001. It consists of 25 chapters and presents examples from Canada, the UK, and the United States. It first provides an overview of the healthcare environment, including categories of healthcare, types of hospitals, the nonhospital side of healthcare, and the different stakeholders. It then describes basic healthcare security risks/vulnerabilitie... and offers tips on security management planning. The book also discusses security department organization and staffing, management and supervision of the security force, training of security personnel, security force deployment and patrol activities, employee involvement and awareness of security issues, implementation of physical security safeguards, parking control and security, and emergency preparedness. Healthcare security practitioners and hospital administrators will find this book invaluable.
  • Handbook of Digital Forensics and Investigation

    • 1st Edition
    • Eoghan Casey
    • English
    Handbook of Digital Forensics and Investigation builds on the success of the Handbook of Computer Crime Investigation, bringing together renowned experts in all areas of digital forensics and investigation to provide the consummate resource for practitioners in the field. It is also designed as an accompanying text to Digital Evidence and Computer Crime. This unique collection details how to conduct digital investigations in both criminal and civil contexts, and how to locate and utilize digital evidence on computers, networks, and embedded systems. Specifically, the Investigative Methodology section of the Handbook provides expert guidance in the three main areas of practice: Forensic Analysis, Electronic Discovery, and Intrusion Investigation. The Technology section is extended and updated to reflect the state of the art in each area of specialization. The main areas of focus in the Technology section are forensic analysis of Windows, Unix, Macintosh, and embedded systems (including cellular telephones and other mobile devices), and investigations involving networks (including enterprise environments and mobile telecommunications technology). This handbook is an essential technical reference and on-the-job guide that IT professionals, forensic practitioners, law enforcement, and attorneys will rely on when confronted with computer related crime and digital evidence of any kind.
  • Eleventh Hour Security+

    Exam SY0-201 Study Guide
    • 1st Edition
    • Ido Dubrawsky
    • English
    Eleventh Hour Network+: Exam N10-004 Study Guide offers a practical guide for those preparing for the Security+ certification exam. The book's 14 chapters provide in-depth discussions of the following topics: systems security; operating system hardening; application security; virtualization technologies; network security; wireless networks; network access; network authentication; risk assessment and risk mitigation; general cryptographic concepts; public key infrastructure; redundancy planning; environmental controls and implementing disaster recovery and incident response procedures; and legislation and organizational policies. Each chapter includes information on exam objectives, exam warnings, and the top five toughest questions along with their answers.
  • Eleventh Hour Network+

    Exam N10-004 Study Guide
    • 1st Edition
    • Naomi Alpern
    • English
    Eleventh Hour Security+: Exam SY0-201 Study Guide offers a practical guide for those preparing for the CompTIA Network+ exam. The book's 10 chapters provide in-depth discussions of the following topics: network fundamentals; network media; network devices; wireless networking; open systems interconnection (OSI) model and networking protocols; transmission control protocol/internet protocol (TCP/IP) and IP routing; wide area networking; hardware and software security; network management; and network troubleshooting. Each chapter includes information on exam objectives, exam warnings, and the top five toughest questions along with their answers.
  • Configuring and Troubleshooting Networking in Windows Vista

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Upgrading to Windows Vista and Restoring User Settings

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Examing TCP/IP Communications

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Implementing Network Infrastructure Services

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Implementing Network Access Protection in Windows Server 2008

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Implementing Active Directory Identities and Access in Windows Server 2008

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Maintaining and Optimizing Windows Vista

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Recovering Windows Vista and Capturing User Settings

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Configuring and Troubleshooting Windows Vista Security

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Implementing Terminal Services in Windows Server 2008

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • SQL Server 2008 Implementation and Maintenance Practice Exams: Microsoft Exam 70-432

    • 1st Edition
    • Mark Horninger
    • English
    Leave no doubt that you're ready for exam day by using these realistic practice exams closely matched to the Microsoft exam. This Practice Exam includes practice tests with full explanations. Our diagnostic tool identifies strengths and weaknesses and tells you where to focus your preparation.
  • Configuring and Troubleshooting Windows Vista Media Center and Applications

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • SQL Server 2008 Database Development Quick Test: Microsoft Exam 70-433

    • 1st Edition
    • Mark Horninger
    • English
    We know you don't have time to waste. Use the Quick Test to quickly assess what you need to do to pass the 70-433 cert exam. The Quick Test identifies your strengths and weaknesses and gives you a roadmap of where to focus your test prep efforts.
  • Managing Internet Information Services 7.0 and Windows Media Server in Windows Server 2008

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • SQL Server 2008 Implementation and Maintenance Quick Test: Microsoft Exam 70-432

    • 1st Edition
    • Mark Horninger
    • English
    We know you don't have time to waste. Use the Quick Test to quickly assess what you need to do to pass the 70-432 cert exam. The Quick Test identifies your strengths and weaknesses and gives you a roadmap of where to focus your test prep efforts.
  • Administering Active Directory Domain Services in Windows Server 2008

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Implementing High Availability and Virtualization in Windows Server 2008

    Exams: 70-640, 642, 643
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Configuring and Troubleshooting Internet Explorer 7.0

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.
  • Fundamentals of Windows Vista TCP/IP Connectivity

    Exam: 70-620
    • 1st Edition
    • English
    Syngress vLabs let you learn on live systems in a safe, secure staging environment. You will learn more effectively by experiencing real-world situations and getting immediate feedback. You will be more certain to pass your certification exams because you've studied specific scenarios that you'll see on exam day.