Discount Book Store - Rbookshop.comOnline Book StoreBusiness BooksComputer BooksEngineering BooksMathematics BooksScience BooksView All Categoriesnavmap
arrow Search for books at ARC Spider:
arrow Search for books at Powells:
arrow
Buy a Book from Amazon.com
bar
How to buy? - A step-by-step guide

Book Categories


Network Security Evaluation: Using the NSA IEM

Buy Network Security Evaluation: Using the NSA IEM here, one of many DHCP books offered for sale at discount prices here at Rbookshop.com.  We greatly appreciate your patronage at Rbookshop and look forward to offering you great products and prices now and in the future.
You Are Here:  Home > Computer Books > DHCP > Item 534

View Previous Product in our DHCP Store      View Next Product in our DHCP Store

Click here to buy Network Security Evaluation: Using the NSA IEM by  Russ Rogers, Ed Fuller, Greg Miles, and Matthew Hoagberg. Network Security Evaluation: Using the NSA IEM
by Russ Rogers, Ed Fuller, Greg Miles, and Matthew Hoagberg
Sales Rank: 283895
4.5 out of 5 stars
Discount: 30 %
$43.16
At Amazon
on 7-8-2008.
Buy Network Security Evaluation: Using the NSA IEM now! Get Info on Network Security Evaluation: Using the NSA IEM
Features
  • Cover Type: Paperback with 450 pages
  • Published by: Syngress July 1, 2005
  • Written in: English
  • ISBN 10 Number: 1597490350
  • ISBN 13 Number: 978-1597490351
  • Book Dimensions: 9.5 x 6.9 x 1.1 inches
  • Weighs: 1.7 pounds

Book Description
Network Security Evaluation provides a methodology for conducting technical security evaluations of all the critical components of a target network. The book describes how the methodology evolved and how to define the proper scope of an evaluation, including the consideration of legal issues that may arise during the evaluation. More detailed information is given in later chapters about the core technical processes that need to occur to ensure a comprehensive understanding of the networks security posture.

Ten baseline areas for evaluation are covered in detail. The tools and examples detailed within this book include both Freeware and Commercial tools that provide a detailed analysis of security vulnerabilities on the target network. The book ends with guidance on the creation of customer roadmaps to better security and recommendations on the format and delivery of the final report.

* There is no other book currently on the market that covers the National Security Agency's recommended methodology for conducting technical security evaluations
* The authors are well known in the industry for their work in developing and deploying network security evaluations using the NSA IEM
* The authors also developed the NSA's training class on this methodology

About The Author
Russ is a co-founder, CEO, CTO and Principal Security Consultant for Security Horizon, Inc. Russ is a United States Air Force Veteran and has served in military and contract support for the National Security Agency and the Defense Information Systems Agency. Russ is also the editor-in-chief of "The Security Journal." He also serves as the Professor of Network Security at the University of Advancing Technology (uat.edu) in Tempe, AZ. Russ is the author of Hacking a Terror Network: The Silent Threat of Covert Channels (Syngress, ISBN 1-928994-98-9). He has contributed to many books including Stealing the Network: How to Own a Continent (Syngress, ISBN: 1-931836-05-1), Security Assessment: Case Studies for Implementing the NSA IAM (Syngress, ISBN 1-932266-96-8), WarDriving, Drive, Detect, Defend: A Guide to Wireless Security (Syngress, ISBN: 1-931836-03-5) and SSCP Study Guide and DVD Training System (Syngress, ISBN: 1-931846-80-9). He is also a co-founder of the Security Tribe information security research web site at www.securitytribe.com.

Reader Reviews
I am a security consultant in the DC area, so I have heard the NSA IAM and IEM terms bandied about the Beltway. I read Network Security Evaluation Using the NSA IEM (NSE) to get a better understanding of the IEM side of the equation. I found the business process coverage of this book helpful, along with the general understanding of the goals of the IAM and IEM. For these two reasons you may find NSE helpful too. The Prologue, ch 1, ch 2, and Part I (which oddly begins with ch 3 and ends with ch 6) occupies about 40% of the book. None of the material is technical, but it helps the reader understand why the NSA IAM and IEM exist, how the methodologies help clients, and what you as a security consultant owe clients when providing an IEM-centric service. These business issues, which largely sit outside the NSA's purview, are very helpful for those of us trying to provide good services to clients. I found contracting advice in ch 2 to be especially useful. Warnings about scope creep, salespeople over-promising, and setting expectations all rang true. I also liked the legal section (ch 5), but I wished it had avoided trotting out the tiresome links to "cyber terror"; cut pages 100-103 in the second edition! I did learn a critical legal lesson, however: consultants should avoid even the pretense of interpreting laws like SOX or HIPPA when advising clients. This could be misconstrued as "practicing law," which is illegal without a license! Part II discusses "on-site" evaluation issues, which for ch 8-10 means discussing tools to accomplish the ten IEM baseline activities. These tool sections were fairly generic, and anyone with decent security experience will not learn anything new. One exception for me was Ophcrack, a recent password cracker. Ch 9 boasted of getting Unix-centric Nessus to run on Windows using Cygwin, but disappointed by providing no further details. Ch ten mentions network protocol analysis as the tenth IEM baseline activity, but has nothing helpful to say besides mentioning running Ethereal or EtherPeek. If the purpose of protocol analysis is discovering insecure protocols or cleartext passwords, avoid Ethereal -- run a password grabber like dsniff or similar. Part III addresses tasks done in the post-evaluation phase, like report-writing and delivery. Some of the material is superfluous and preachy, e.g. p 316 "Knowledge is individualistic. It is inherent to individuals and is acquired through the natural process of experience and learning." Ch 14 finally displays the 17 IAM (not IEM) categories, which had been alluded to in previous chapters but never explained (which would have been helpful for those unaware of the IAM). The sample Technical Evaluation Plan in Appendix B is a good way to provide concrete examples for IEM beginners. I would like to see a second edition of NSE after an editor reads the entire book, as I just did. That editor should strive to remove as much extra and redundant information as possible. For example, there are sections repeated nearly word-for-word in ch 2 (p 40-43) and ch 4 (p 74-78). The risk triangle appears on p 246 and 383. CVE is introduced in ch 7 and again in ch 13. Calculating ROI is presented in ch 3 and again in the same words in ch 14. These duplications are the result of ten people contributing to a 400 page book. Overall, I still recommend reading NSE. I return to the first 170 pages of the book for its best advice, such as entire chapter on scoping an engagement (ch 4). There are far too few security books that explain how to deliver a valuable service to a client. NSE addresses that issue in great detail, and for that reason I commend the authors. Comment | | (Report this)


Back To Top

View Previous Product in our DHCP Store      View Next Product in our DHCP Store

Network Security Evaluation: Using the NSA IEM
List Price: $59.95
Discount: 30 %
Available from Amazon
Price: $43.16
Updated on 7-8-2008.
Buy Network Security Evaluation: Using the NSA IEM now! Get Info on Network Security Evaluation: Using the NSA IEM




NOTICE: All prices, availability, and specifications
are subject to verification by their respective retailers.




We offer Network Security Evaluation: Using the NSA IEM and other related DHCP Books here at Rbookshop.com. To view more books about DHCP please use the previous and next buttons near the top of this page.




Alternative Med Books | Art Books | Business Books | Comic Books | Computer Books | Cook Books | Engineering Books | History Books | Hobby Books | Law Books | Mathematics Books | Medical Books | Popular Authors | Rare Books | Religion Books | Romance Books | Science Books | Science Fiction Books | Sports Books | Travel Books | Unusual Subjects Books
Discount Book Store
Rbookshop

Copyright © 2007 Rbookshop.com

113808 Computer Books Online and Available as of 7-8-2008.