Feeds

Defeating the hacker

Security is for everyone

High performance access to file storage

Book review Who is responsible for security? Everybody is, not just the security officer and his/her team. But it's a technical issue, right? A matter of firewalls, applying patches, installing programs that detect and remove spyware and viruses... Wrong again!

Security is largely (despite the efforts of vendors who want to sell you more "stuff") largely a people and culture thing – a company is more at risk from dissatisfied and unhappy employees misusing the authority they have been given, for example, than from that meeja bogeyman, the external hacker.

A holistic view of security is what makes Robert Schifreen's book Defeating the Hacker, billed as "a non-technical guide to IT security", so useful. Much security good practice is counterintuitive, but everybody working in IT should have a good understanding of security as a whole, not simply of a few pieces of security technology.

However, Schifreen's book isn't technical in the way the Anti-Hacker Toolkit by Mike Shema, Chris Davis, Aaron Philipp, David Cowen (reviewed by Pan Pantziarka here) is.

Actually, the non-technical billing is a bit misleading. Schifreen talks about ISO 17799 (the widely adopted information security standard) and is happy to suggest that you don't broadcast your SSID, and that you do enable WPA rather than WEP encryption when setting up wireless networking. The book is technical enough to be useful, but it isn't just a catalogue of software and hardware products to buy and configure.

Most chapters have five practical "action points" in a checklist at the end, which will help you implement a good security regime in practice. The book starts by recommending basic risk assessment and a review of the laws relating to IT security (such as the UK Data Protection Act) in your place of business. A whole chapter is devoted to information security policies, the lack of which is a key indicator of poor security practice. After all, without an agreed policy, how will you configure all that security hardware you'll no doubt be persuaded to buy?

There are 42 chapters covering everything from server security, firewalls and wireless networking to social engineering, ecommerce fraud, securing your premises and even business continuity planning.

Schifreen has a story to tell (he was the original teenage hacker, back when curiosity was a legitimate excuse) and the whole book is written in an accessible conversational style which makes it readable as well as practical and informative.

For instance, Schifreen writes: "I've seen large multinational companies suffer horrendous virus infections across many thousands of PCs because a board-level director (in one case it was actually the IT director) didn't think that the rules about email attachments should apply to them" – which illustrates the point that senior management buy-in and understanding is vital to security.

This book covers a lot, so the detail it can go into is limited, but it does give readers a very thorough grounding in security as a whole – and doesn't neglect the risk management and people issues as some books do.

You can argue about details, as always, but the content is pretty even-handed (for example, while it recommends automatic patching of Windows systems, which scares me a bit, it does mention the small risk that a patch will cause problems in itself, and describes ways to mitigate this). There is a website for this book, if you want to read a sample chapter.

Defeating the Hacker

Defeating the HackerVerdict: This is a useful book although its billing as a "non-technical guide to IT security"; is a bit misleading. It is technical enough to be useful, but isn't bogged down in technical details and jargon. It would be better described as a practical business-oriented guide to IT security – but it is definitely worth reading.

Author: Robert Schifreen

Publisher: Wiley

ISBN: 0-470-02555-7

Media: Book

Buy this book at Cash 'n' Carrion.

High performance access to file storage

More from The Register

next story
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Windows XP still has 27 per cent market share on its deathbed
Windows 7 making some gains on XP Death Day
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
US taxman blows Win XP deadline, must now spend millions on custom support
Gov't IT likened to 'a Model T with a lot of things on top of it'
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.