商品描述
In an era defined by cloud computing, AI disruption, and evolving cyber threats, traditional security models are no longer enough. Foundations of Modern Information Security delivers a vendor-neutral, real-world guide to designing and maintaining secure systems that stand up to today's--and tomorrow's--challenges. This book bridges the gap between legacy infosec thinking and modern enterprise realities. Covering everything from Zero Trust Architecture and post-quantum cryptography to AI governance and secure cloud design, it equips professionals with the tools to build resilient, adaptable security programs. The methodology is process-centric and rooted in practical implementation, not product marketing. Structured around trusted industry frameworks like NIST, MITRE ATT&CK, and CSA, this guide helps readers align security strategy with compliance, business goals, and operational needs. Whether you're protecting identity, preventing data loss, or planning incident response, you'll find actionable insights and examples that translate directly to your environment. Whether you're an experienced security architect or a technology leader seeking clarity in a complex landscape, this book offers the foundational knowledge and strategic guidance needed to elevate your security posture--without vendor bias or unnecessary complexity. YOU WILL - Design and implement vendor-neutral Zero Trust Architectures - Build resilient, privacy-respecting identity and data protection programs - Navigate AI-driven threats with quantum-resistant and governance-aware controls - Apply MITRE, NIST, and TOGAF frameworks to real-world cloud and hybrid environments - Establish forensic readiness and proactive incident response capabilities WHO THIS BOOK IS FOR This book is intended for cybersecurity professionals, IT architects, and technical leaders seeking a vendor-neutral, strategic understanding of modern information security. It's ideal for mid-to-senior level professionals preparing for leadership roles or certifications like CISSP, CCSP, or CISM.
商品描述(中文翻譯)
在一個由雲端運算、人工智慧顛覆和不斷演變的網路威脅所定義的時代,傳統的安全模型已經不再足夠。《現代資訊安全基礎》提供了一本中立於供應商的實用指南,幫助設計和維護能夠應對當前及未來挑戰的安全系統。
本書彌補了傳統資訊安全思維與現代企業現實之間的鴻溝。涵蓋從零信任架構(Zero Trust Architecture)和後量子密碼學(post-quantum cryptography)到人工智慧治理(AI governance)和安全雲端設計(secure cloud design)的各個方面,為專業人士提供建立韌性和適應性安全計畫的工具。其方法論以過程為中心,根植於實際實施,而非產品行銷。
本指南圍繞著可信的行業框架,如NIST、MITRE ATT&CK和CSA,幫助讀者將安全策略與合規性、商業目標和運營需求對齊。無論您是在保護身份、預防數據損失,還是規劃事件響應,您都會找到可行的見解和範例,這些都能直接轉化為您的環境。
無論您是經驗豐富的安全架構師,還是尋求在複雜環境中獲得清晰的技術領導者,本書都提供了提升您安全姿態所需的基礎知識和戰略指導——不帶供應商偏見或不必要的複雜性。
您將會:
- 設計和實施中立於供應商的零信任架構
- 建立韌性且尊重隱私的身份和數據保護計畫
- 以量子抗性和治理意識的控制措施應對人工智慧驅動的威脅
- 將MITRE、NIST和TOGAF框架應用於現實的雲端和混合環境
- 建立取證準備和主動事件響應能力
本書適合對象:
本書旨在為尋求中立於供應商的現代資訊安全戰略理解的網路安全專業人士、IT架構師和技術領導者而設。非常適合準備擔任領導角色或考取CISSP、CCSP或CISM等證照的中高階專業人士。
作者簡介
Ankit Gupta is a cybersecurity leader with over 15 years of experience across enterprise risk, identity governance, and cloud security. Holding a Master's in Cybersecurity from NYU, he has earned top-tier industry certifications including CISSP, CCSP, ISSMP, CISM, CRISC, CISA, and TOGAF. Ankit currently serves as a senior security consultant at a Financial Organization, where he leads AI governance, DLP modernization, and cloud security strategy initiatives. He actively contributes to the cybersecurity community through blog writing, research on AI-driven quantum threats, exam item creation for EC-Council, and participation in judging panels for global security awards. This book distills his cross-domain expertise and field-tested strategies into a neutral, actionable guide for professionals navigating today's complex security landscape. Shilpi Mittal is a cybersecurity professional with extensive experience in application security, cloud security, and modern secrets management. She holds a graduate degree from the University of Utah and is currently pursuing a PhD in Information Science at the University of North Texas, where her work explores advanced areas of cryptography, API security, and emerging technology risks. Her contributions span technical writing, academic research, and community engagement. She actively supports the security field through conference presentations, peer reviews, and mentoring. Her interests include post quantum security, API protection, and the growing impact of artificial intelligence on modern security practices. This book reflects her commitment to making information security clear, accessible, and practical. It is written for readers who want to understand the foundations of modern security in a way that supports real-world decision making and long term professional growth.
作者簡介(中文翻譯)
Ankit Gupta 是一位網路安全領導者,擁有超過 15 年的企業風險、身份治理和雲安全經驗。他持有紐約大學的網路安全碩士學位,並獲得了包括 CISSP、CCSP、ISSMP、CISM、CRISC、CISA 和 TOGAF 在內的頂級行業認證。Ankit 目前擔任一家金融機構的高級安全顧問,負責 AI 治理、DLP 現代化和雲安全策略的倡議。
他通過撰寫部落格、研究 AI 驅動的量子威脅、為 EC-Council 創建考試題目以及參與全球安全獎項的評審小組,積極貢獻於網路安全社群。本書提煉了他跨領域的專業知識和實地驗證的策略,成為專業人士在當今複雜安全環境中導航的中立、可行的指南。
Shilpi Mittal 是一位網路安全專業人士,擁有應用安全、雲安全和現代秘密管理的豐富經驗。她擁有猶他大學的研究生學位,並目前在北德克薩斯大學攻讀資訊科學博士學位,研究內容涵蓋密碼學、高級 API 安全和新興技術風險。她的貢獻包括技術寫作、學術研究和社群參與。她通過會議演講、同行評審和指導積極支持安全領域。她的興趣包括後量子安全、API 保護以及人工智慧對現代安全實踐的日益影響。本書反映了她致力於使資訊安全變得清晰、可及和實用的承諾。它是為希望以支持現實世界決策和長期專業成長的方式理解現代安全基礎的讀者而寫的。