Showing posts with label it. Show all posts
Showing posts with label it. Show all posts

Security 2020: Reduce Security Risks This Decade Review

Security 2020: Reduce Security Risks This Decade
Average Reviews:

(More customer reviews)
Disclaimer: I worked for Doug for a few years, and I know a number of the other contributing authors.
I liked this book, and I think it is a useful review of where InfoSec is coming from and a useful guide to how things are likely to go in the next years.
It strikes a good balance between technical details and executive management readability, which is good for a couple of reasons.
First, it will be useful to a wider audience, and broader awareness of these issues is a good thing.
Second, given that broad appeal, it can provide some common ground for the tactical folks in the trenches (like me), and the strategic folks in management. Making sure everyone is aware of the risks and getting everyone on the same page isn't always easy, and Security 2020 can help bridge the gap.
This is not "InfoSec 101" nor is it intended to be, though the writing is approachable enough that anyone will get something out of it. But for anyone in InfoSec directly, in a related role such as systems or network administration, or considering such a role, there's a lot of good stuff here. (Some might argue that systems or network administration are InfoSec roles, and I agree but depending on how your organization is structured you can end up with separate "silos"... Regardless--being on the same page is a Good Thing.)
If you've been around a while, the early chapters will be a good review, otherwise they'll help explain how we got where we are. Then it jumps to a blend of current threats and issues, where we're likely to go, and how we'll get there. My favorite section was the various scenarios in chapter 9, though the conclusions in chapter 10 are very interesting too.
Bottom line: if you have any role or interest in Information Security at all, this is good food for thought.

Click Here to see more reviews about: Security 2020: Reduce Security Risks This Decade

Identify real security risks and skip the hype
After years of focusing on IT security, we find that hackers are as active and effective as ever. This book gives application developers, networking and security professionals, those that create standards, and CIOs a straightforward look at the reality of today's IT security and a sobering forecast of what to expect in the next decade. It debunks the media hype and unnecessary concerns while focusing on the knowledge you need to combat and prioritize the actual risks of today and beyond.
IT security needs are constantly evolving; this guide examines what history has taught us and predicts future concerns
Points out the differences between artificial concerns and solutions and the very real threats to new technology, with startling real-world scenarios
Provides knowledge needed to cope with emerging dangers and offers opinions and input from more than 20 noteworthy CIOs and business executives
Gives you insight to not only what these industry experts believe, but also what over 20 of their peers believe and predict as well

With a foreword by security expert Bruce Schneier, Security 2020: Reduce Security Risks This Decade supplies a roadmap to real IT security for the coming decade and beyond.

Buy Now

Click here for more information about Security 2020: Reduce Security Risks This Decade

Read More...

Blind Men and the Elephant: Demystifying the Global IT Services Industry Review

Blind Men and the Elephant: Demystifying the Global IT Services Industry
Average Reviews:

(More customer reviews)
A very clear, concise, and easy-to-read book that lays out the origins, current state and the challenges facing Global IT services. This book is a must read for people who buy IT services, sell IT services, deliver IT services and also for those who have more than a passing interest in Global IT. The authors present an unbiased view of the industry, how the different parties involved have created the successes (some accidental), the challenges, and some future scenarios (four-seeable futures), without introducing the reader to new jargon. In the process the authors pepper the book with industry trivia, some more welcome (origin of IBM) than others (full name of FIAT, the auto company). They do a great job of presenting the realized value and the larger unrealized potential of IT services transforming businesses. The authors certainly deliver what they set to achieve (as outlined in "About this book"). There are many takeaways from this book that some may call "common sense." And, that would be a shame because it is not that common.
I wish the authors had spent a little more time on how the different parties involved in Global IT services have contributed to the challenges and the unrealized potential. I also think it would have been better if the authors had expanded/ shown preference for at least one or two of the four future scenarios they layout even though they clearly say they are not out to predict the future. In addition, areas like software-as-service and vertical specific products could have benefited from more discussion.
Overall, `Blind Men and the Elephant: Demystifying the Global IT Services Industry' is a great introduction for anyone interested in Global IT services or entering it as a participant and a good summary for all those who are in it.

Click Here to see more reviews about: Blind Men and the Elephant: Demystifying the Global IT Services Industry

In just a few decades since its birth, the global IT industry has grown to a trillion dollars. It continues to transform society and business, as perhaps no other industry has, and yet remains one of the least understood industries in the world. Behind the facade of geekiness and technophobia lies a set of organizations that are routinely given the power to fundamentally reshape many facets of our lives, and in the process create lucrative sources of financial rewards for those investing in it. This book explains what consultants and IT Services firms do. It examines the industry s surprisingly captivating history, and in doing so, explains why the industry does things the way it does and what motivates the different players within it. The book tries to answers basic questions such as: Why is it that those fundamentally affected by the industry have little idea about how this industry has managed to have such a hard-hitting impact globally? How has this industry managed to reach the unique statues it enjoys around the world today, with literally millions from all corners of the world aspiring to enter it? What is it about this industry that has caused it to evolve so differently as compared to other fields? Perhaps most importantly, where could it, and the rest of us, go next? Drawing vivid comparisons from everyday life and other industries, this book makes complex concepts accessible to the general reader, giving them for the first time an in-depth insight into the IT industry, how it works, how it affects all of us, and where it is likely to catapult us in this century. Written in a lucid style by renowned IT professionals, this book is a must read not only for management and engineering students, IT professionals, managers, and technocrats, but also for anyone keen to have the mysteries of the computer age unraveled.

Buy Now

Click here for more information about Blind Men and the Elephant: Demystifying the Global IT Services Industry

Read More...

Moodle Security Review

Moodle Security
Average Reviews:

(More customer reviews)
I have been asked on several occasions to tech review Packt Moodle books as they are being drafted. It's a privilege and I tend to say yes -usually because the topic is one I feel is in my area - pedagogically- so I can be of assistance to the author. Sometimes however, I am asked to review a book in a different field from my own. As long as I know the other reviewer is a technical expert I am happy to continue, restricting my comments to style, layout and readability. Such was it with Moodle Security. Before I read the book I only knew the bare minimum a Moodle admin needs to know so I almost turned down the offer of reviewing it. On Packt's assurance that their other reviewer was highly knowledgeable about security issues (so nobody can blame me if they get hacked!!), I agreed to read it and am very glad I did so. I found it enlightening and invaluable.
Written by Moodler Darko Miletic, it takes you through, chapter by chapter, the steps you need to ensure your Moodle is secure from initial installation to site backup -with user and file management in between. Moodlers are well aware that alongside all the great publicity this Open Source LMS/VLE generates, it has had a bad press in the past because of quite large security loopholes. Some have argued this has been the fault of inadequately trained admins -who've left the user profiles open to Google or put their moodledata folder (the one with all the "stuff") in an easily accessible directory because they didn't read the warnings. Others have made the point that Moodle should not allow such mistakes to be made in the first place -particularly as Moodle admins might not always be your techie types, but a regular teacher like me just doing the job for their school. So a book like this must be a welcome addition to any Moodle admin. The first couple of chapters deal with securing your Linux or Windows server. However, even if you don't host Moodle yourself, it is worth reading on because Darko then talks about authentication and roles and permissions. Vital if you want to avoid such dangerous pitfalls as - allowing email based self authentication with no Captcha! or email restrictions (spammers' paradise) or - setting permissions wrongly and allowing someone to create an account and subsequently edit your front page (as I was able to do on a local Moodle a couple of years ago) You can read Chapter 4 on authentication on Packt's site - as a free taster. The book is based on Moodle 1.9 although much of it is still relevant to Moodle 2.0 However, some of the potential security problems with Moodle (such as site wide roles) have been addressed in Moodle 2.0. Chapter 6 handles protection against bots while Chapter 7 deals with securing user files. Moodle 2.0 handles files differently from 1.9 (subject of much controversy!) so some of this will currently not apply - but many users will remain with Moodle 1.9 for a year or so yet, so the information remains valuable. Chapter 9 deals with protecting user and course information, leading up to monitoring user activity in Chapter 10.
Despite being a non-technical Moodle admin I found the book easy to digest and I learned a lot about keeping Moodles secure. If you are a Moodle administrator responsible for a large number of users (or even a small primary school!) it would be well worth investing in Moodle Security, if only so you don't wake up one morning to find the Russian Federation have taken over your site...


Click Here to see more reviews about: Moodle Security

Moodle Security is packed with practical examples, which guide you through optimizing the protection of your Moodle site. Each chapter covers a different security threat and how to secure your site against it. You will also find recommendations for what is best for your particular system and usage. If you are in charge of Moodle - whether you are an administrator or lead teacher - then securing it is one of the most important things that you can do. You need to know the basics of working with Moodle, but no previous experience of system administration is required.

Buy Now

Click here for more information about Moodle Security

Read More...