<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Allen Pomeroy &#187; books</title>
	<atom:link href="http://www.networkforensics.us/tag/books/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.us</link>
	<description>Blog of an IT security specialist  .: beta :.</description>
	<lastBuildDate>Tue, 08 Jun 2010 16:59:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=9285</generator>
		<item>
		<title>Info Sec and IT Sec books and articles of interest</title>
		<link>http://www.networkforensics.us/2009/05/info-sec-and-it-sec-books-and-articles-of-interest/</link>
		<comments>http://www.networkforensics.us/2009/05/info-sec-and-it-sec-books-and-articles-of-interest/#comments</comments>
		<pubDate>Mon, 18 May 2009 17:33:41 +0000</pubDate>
		<dc:creator>edhacker</dc:creator>
				<category><![CDATA[notes]]></category>
		<category><![CDATA[books]]></category>

		<guid isPermaLink="false">http://blog.networkforensics.us/?p=63</guid>
		<description><![CDATA[Start of my InfoSec article journal and book list Not really blog worthy, but I decided to start a journal of interesting information security articles or books that I&#8217;ve found to be particularly valuable. Not all of them are publicly available, but where I can, I&#8217;ll add some links. Really this is just a list [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Start of my InfoSec article journal and book list </strong></p>
<p>Not really blog worthy, but I decided to start a journal of interesting information security articles or books that I&#8217;ve found to be particularly valuable.  Not all of them are publicly available, but where I can, I&#8217;ll add some links.  Really this is just a list of my dog-eared books in no particular order.  (-:</p>
<p><strong>Articles</strong></p>
<p>Security Controls That Work; Information Systems Control Journal; Volume 4, 2007</p>
<p>Information Security Standards Foucs on the Existence of Process, Not Its Content; Communications of the ACM; August 2006, Volume 49, Number 8</p>
<p>FrankenSOA; Network Computing; 06/25/07; Page 41</p>
<p><strong>Books</strong></p>
<p>Chris McNab, <span style="text-decoration: underline;">Network Security Assessment</span>, Sebastapol, CA: O&#8217;Reilly Media, Inc., 2004 &#8211; Describes a technical assessment methodology which can be used to understand the &#8220;threats, vulnerabilities, and exposures modern public networks face.&#8221;</p>
<p>Andrew Jaquith, <span style="text-decoration: underline;">Security Metrics: Replacing Fear, Uncertainty, and Doubt</span>, Upper Saddle River, NJ: Addison-Wesley, 2007 &#8211; Information security has been largely justified by fear over the last many years. This book is the single best book I have seen yet which provides a pragmatic guide to using effective metrics in infosec programs and communication with stakeholders.  I think that organizations which adopt this type of approach will fare well when infosec spending starts to level off or dry up.</p>
<p>Stephen Northcut, Lenny Zeltser, Scott Winters, Karen Kent &amp; Ronald Ritchey, <span style="text-decoration: underline;">Inside Network Perimeter Security</span>, Indianapolis, Indiana: Sams Publishing, 2005 &#8211; excellent multi-layer book which describes appropriate techniques to layer differing strategies together to provide stronger perimeter defense<br />
.  &#8220;Defense in depth is a primary focus of this book, and the concept is quite<br />
simple: Make it harder to attack at chokepoint after chokepoint.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.networkforensics.us/2009/05/info-sec-and-it-sec-books-and-articles-of-interest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
