Computer Security Handbook

Seymour Bosworth, Michel E. Kabay

  • 出版商: Wiley
  • 出版日期: 2002-04-11
  • 售價: $1,600
  • 貴賓價: 9.8$1,568
  • 語言: 英文
  • 頁數: 1224
  • 裝訂: Paperback
  • ISBN: 0471412589
  • ISBN-13: 9780471412588
  • 相關分類: 資訊安全
  • 下單後立即進貨 (約5~7天)

買這商品的人也買了...

商品描述

The definitive formula for computer security, from power outages to theft and sabotage

Whether you are in charge of many computers, or even one important one, there are immediate steps you can take to safeguard your company’s computer system and its contents. The Computer Security Handbook provides a readable and comprehensive resource for protecting computer mainframe systems and PC networks. This Fourth Edition continues a long tradition of maintaining highly regarded industry guidelines for detecting virtually every possible threat to your system and prescribes specific actions you can take to eliminate them.

The collected chapters are written by renowned industry professionals. Requiring minimal technical knowledge to understand, covered topics include: foundations of computer security, threats and vulnerabilities, prevention (technical defenses and human factors), detection, remediation, management’s role, and other considerations such as using encryption internationally, anonymity and identity in cyberspace, and censorship.

Protect the information and networks that are vital to your organization with Computer Security Handbook, Fourth Edition.

Table of Contents

PART ONE: FOUNDATIONS OF COMPUTER SECURITY.

Brief History and Mission of Information System Security (S. Bosworth & R. Jacobson).

Cyberspace Law and Computer Forensics (R. Heverly & M. Wright).

Using a "Common Language" for Computer Security Incident Information (J. Howard & P. Meunier).

Studies and Surveys of Computer Crime (M. Kabay).

Toward a New Framework for Information Security (D. Parker).

PART TWO: THREATS AND VULNERABILITIES.

The Psychology of Computer Criminals (Q. Campbell & D. Kennedy).

Information Warfare (S. Bosworth).

Penetrating Computer Systems and Networks (C. Cobb, et al.).

Malicious Code (R. Thompson).

Mobile Code (R. Gezelter).

Denial of Service Attacks (D. Levine & G. Kessler).

The Legal Framework for Protecting Intellectual Property in the Field of Computing and Computer Software (W. Zucker & S. Nathan).

E-Commerce Vulnerabilities (A. Ghosh).

Physical Threats to the Information Infrastructure (F. Platt).

PART THREE: PREVENTION: TECHNICAL DEFENSES.

Protecting the Information Infrastructure (F. Platt).

Identification and Authentication (R. Sandhu).

Operating System Security (W. Stallings).

Local Area Networks (G. Kessler & N. Pritsky).

E-Commerce Safeguards (J. Ritter & M. Money).

Firewalls and Proxy Servers (D. Brussin).

Protecting Internet-Visible Systems (R. Gezelter).

Protecting Web Sites (R. Gezelter).

Public Key Infrastructures and Certificate Authorities (S. Chokhani).

Antivirus Technology (C. Cobb).

Software Development and Quality Assurance (D. Levine).

Piracy and Antipiracy Techniques (D. Levine).

PART FOUR: PREVENTION: HUMAN FACTORS.

Standards for Security Products (P. Brusil & N. Zakin).

Security Policy Guidelines (M. Kabay).

Security Awareness (K. Rudolph, et al.).

Ethical Decision Making and High Technology (J. Linderman).

Employment Practices and Policies (M. Kabay).

Operations Security and Production Controls (M. Walsh & M. Kabay).

E-Mail and Internet Use Policies (M. Kabay).

Working with Law Enforcement (M. Wright).

Using Social Psychology to Implement Security Policies (M. Kabay).

Auditing Computer Security (D. Levine).

PART FIVE: DETECTION.

Vulnerability Assessment and Intrusion Detection Systems (R. Bace).

Monitoring and Control Systems (D. Levine).

Application Controls (M. Walsh).

PART SIX: REMEDIATION.

Computer Emergency Quick-Response Teams (B. Cowens & M. Miora).

Data Backups and Archives (M. Kabay).

Business Continuity Planning (M. Miora).

Disaster Recovery (M. Miora).

Insurance Relief (R. Parisi, Jr.).

PART SEVEN: MANAGEMENT'S ROLE.

Management Responsibilities and Liabilities (C. Hallberg, et al.).

Developing Security Policies (M. Kabay).

Risk Assessment and Risk Management (R. Jacobson).

Y2K: Lessons Learned for Computer Security (T. Braithwaite).

PART EIGHT: OTHER CONSIDERATIONS.

Medical Records Security (P. Brusil & D. Harley).

Using Encryption Internationally (D. Levine).

Censorship and Content Filtering (L. Tien & S. Finkelstein).

Privacy in Cyberspace (B. Hayes, et al.).

Anoymity and Identity in Cyberspace (M. Kabay).

The Future of Information Security (P. Tippett).

Index.

商品描述(中文翻譯)

從停電到竊盜和破壞,電腦安全的明確公式
無論您負責多台電腦,甚至只有一台重要的電腦,您都可以立即採取措施來保護公司的電腦系統和內容。《電腦安全手冊》提供了一個易讀且全面的資源,用於保護電腦主機系統和個人電腦網絡。這本第四版延續了長期以來維護高度受尊敬的行業指南的傳統,用於檢測幾乎所有可能對您的系統構成威脅的方法,並提供具體的行動來消除這些威脅。

這些章節由知名的行業專業人士撰寫,只需要最少的技術知識即可理解,涵蓋的主題包括:電腦安全基礎、威脅和漏洞、預防(技術防禦和人為因素)、檢測、修復、管理角色以及其他考慮因素,如在國際上使用加密、網絡空間中的匿名和身份以及審查制度。

使用《電腦安全手冊》第四版來保護對您的組織至關重要的信息和網絡。

目錄:
第一部分:電腦安全基礎
- 信息系統安全的簡要歷史和使命
- 網絡空間法律和電腦取證
- 使用“共同語言”來傳遞電腦安全事件信息
- 電腦犯罪的研究和調查
- 通往信息安全新框架的道路

第二部分:威脅和漏洞
- 電腦罪犯的心理學
- 信息戰爭
- 入侵電腦系統和網絡
- 惡意代碼
- 移動代碼
- 拒絕服務攻擊
- 在計算和計算軟件領域保護知識產權的法律框架
- 電子商務的漏洞
- 對信息基礎設施的物理威脅

第三部分:預防:技術防禦
- 保護信息基礎設施
- 識別和驗證
- 操作系統安全
- 局域網
- 電子商務保障
- 防火牆和代理服務器
- 保護互聯網可見系統
- 保護網站
- 公鑰基礎設施和證書機構
- 防病毒技術
- 軟件開發和質量保證
- 盜版和反盜版技術

第四部分:預防:人為因素
- 安全產品的標準
- 安全政策指南
- 安全意識
- 道德決策和高科技
- 就業實踐和政策
- 運營安全和生產控制
- 電子郵件和互聯網使用政策
- 與執法機構合作
- 使用社會心理學來實施安全政策
- 電腦安全審計

第五部分:檢測
- 漏洞評估和入侵檢測系統
- 監控和控制系統
- 應用程序控制

第六部分:修復
- 電腦緊急快速響應團隊