Posts

Showing posts with the label Book

Book review: The CISO Playbook

Image
The CISO Playbook by Andres Andreu ISBN:  978-1032762074 US $48 from Amazon (softback) GH rating: 70% Summary The CISO Playbook  is a valuable resource for cybersecurity specialists seeking to build on their technical competencies and progress, or for mid-level IT professionals looking to deepen and extend their understanding of cybersecurity technologies. However, aspiring or newly promoted or appointed CISOs seeking practical advice on the leadership and management challenges of a true C-suite role are out of luck.  The book  leans towards technical details rather than leadership and management topics, core parts of the CISO role.   While the technical coverage is commendable, the book would benefit from a broader perspective that encompasses the full scope of a CISO's senior management responsibilities.  Frankly, and despite the title, t he approach described is, I feel, better suited to Cybersecurity or Information Security Managers, heads of department...

Cognitive Hack - book review

Image
Title: Cognitive Hack - The New Battleground in Cybersecurity... The Human Mind Author: James Bone Part of the Internal Audit  and IT Audit series edited by Dan Swanson Publisher: CRC Press/Auerbach (2017) ISBN: 978-1-4987-4981-7 Price: US $100 ( hardback ) US $53 ( paperback ) GH rating: 50% Summary The author's core thesis is that we are expecting IT users and managers to make rational, risk-averse decisions and take appropriate actions in response to complex threats. The 'cognitive load' is such that people are bound to make mistakes. Therefore we  should be simplifying things ( e.g. by automating cybersecurity controls), thereby reducing the number of choices and hence taxing decisions we're asking people to make.

Book review: Permanent Record by Ed Snowden

Image
Title: Permanent Record Author: Edward Snowden ISBN: 978-1-250-23723-1 Price: US$18 from Amazon GH rating: 90% Summary Until I read this book, I considered my personal integrity a fundamental strength, core to my very being. It pales in comparison to Ed's extreme courage and intense determination to expose the shocking truth about the NSA's mass surveillance programme and the way it was concealed from Congress.

Book review: Thinking Fast and Slow

Image
Title: Thinking, Fast and Slow Author:  Daniel Kahneman ISBN: 978-0-374-53355-7 Price: $18 from Amazon GH rating: 60% Summary Didn't match up to the high expectations, for me. Wading through numerous examples with tedious explanations of subtle choices presented to experimental subjects made it a slog.

Hyperglossary published!

Image
Having declared it officially 'done', the SecAware information security hyperglossary is finally self-published as an eBook in PDF format. More than three thousand terms-of-art are defined in the areas of: Information risk  Information security  Cybersecurity (IT/Internet security) ICS/SCADA/OT security Artificial Intelligence Privacy, data protection, personal information Governance Conformity and compliance Incidents  Business continuity and more.  It has taken me three decades so far to compile the glossary, initially just as a reference for my personal use, then for our security awareness clients, and now for anyone with a little cash to spare and an interest in the field.

Hyper-glossary nearing completion (?)

Image
My next book will be a 'hyper-glossary' of terms relating to information security, including closely related aspects such as information risk management, governance, compliance ... and more ... and there's the rub: I'm struggling to catch up/keep up with developments in the field, not least because of the rate at which novel concepts are introduced and new terms are coined. Here's an example of a definition originally added a couple of years ago and most recently amended today: There I've defined "Deep fake", one of several terms washed up in the AI tsunami. The underlined terms are hyperlinked to their definitions ... and so on forming an extensive web within the document.

Book review: The Consultant's Handbook

Image
Title: The Consultant's Handbook : How to use your expertise to deliver client success and run a profitable business Author: Andrew Sheves ISBN: 978-1-7345116-7-3 Price: $15 from Amazon GH rating: 85% Summary Straightforward, straight-talking guidance for busy consultants looking to establish and grow their practice.  

Book review: The Art of Writing Technical Books

Image
Title: The Art of Writing Technical Books Author: Peter H. Gregory ISBN: 978-1-957807-49-2 Price: US$15 *  GH rating: 85% Summary If you are thinking seriously about writing your first book, Peter's plain-talking guidance slices through the bewildering cloud of choices and issues you face.  Working with a literary agent, publisher and assorted experts is an obscure and convoluted process.  Peter explains it well.

Exciting news: extension ladders, stubby snakes!

Image
Having done, seen and learnt a lot in the course of working with the ISO27k standards and precursors since the mid-90's, I'm keen to share my accumulated knowledge with those of you who are relatively new to the field, just setting out and perhaps struggling to get to grips with it all. You needn't learn everything the hard way like I did: I can help you move ahead smartly, avoiding tar pits, finding taller ladders and shorter snakes.

What actually drives information security?

Image
  The 'obvious' driver for information security is information risk: valuable yet vulnerable information must be secured/protected against anything that might compromise its confidentiality, integrity or availability, right? Given an infinite array of possible risks and finite resources to address them, information risk analysis and management techniques help us scan the risk landscape for things that stand out - the peaks - and so we play whack-a-mole, attempting to level the field through mitigating controls, remainingly constantly on the lookout for erupting peaks and those hidden behind the ones we can see or were otherwise transparent. That's 'obvious' from my perspective as an experienced information risk and security professional, anyway. Your perspective probably differs. You may look at things from a slightly or dramatically different angle - and that's fine. I see these as interesting and stimulating complementary approaches, not alternatives. Complian...

Book review: The Resilient Enterprise

Image
Just a brief note today: it's a lovely sunny Saturday morning down here and I have Things To Do . I'm currently enjoying another book by one of my favourite tech authors: Yossi Sheffi's The Resilient Enterprise *. As always, Yossi spins a good yarn, illustrating a strong and convincing argument with interesting, relevant examples leading to sound advice. Specifically, I'm intrigued by the notion that major incidents/disasters leading to severe business disruption may not come "out of the blue". Sometimes (quite often?), there are little warning signs, hints ahead of time about the impending crisis, chances for alert business people to look up from the daily grind and perhaps brace for impact. It ought to be possible to spot fragile supply chains, processes, systems and people, provided we are looking out for them ...    Here in NZ at the moment, we are being treated to a public safety campaign using the analogy of meerkats, encouraging Kiwis to be constantly o...

Book review: Cyber Strategy

Image
Cyber Strategy Risk-driven Security and Resiliency Authors: Carol A. Siegel and Mark Sweeney Publisher: Auerbach/CRC Press ISBN: 978-0-367-45817-1 Price: ~ US$100 + shipping from Amazon Outline This book lays out a systematic process for developing corporate strategy in the area of cyber (meaning IT) security and resilience.   Pros An in-depth exposition on an extremely important topic It emphasises risks to the business, to its information, and to its IT systems and networks, in that order Systematic, well structured and well written, making it readable despite the fairly intense subject matter Lots of diagrams, example reports and checklists to help put the ideas into action Treating strategy development as a discrete project is an intriguing approach Cons Describes a fairly laborious, costly and inflexible approach, if taken literally and followed STEP-by-STEP Implies a large corporate setting, with entire departments of professionals specializing and willing to perfor...

Infosec glossary as an awareness tool

Image
By coincidence, two of the professional groups/discussion forums I frequent have both been discussing terminology today. It takes a particular personality type to enjoy discussing terminology, in depth. It requires both tight focus and a broad appreciation of the field. It helps to be well-read, since terms and concepts generally emerge from study or research that may be obscure. It helps also to be open-minded, since terminology is one of those things that fires-up experienced and knowledgeable colleagues: the passion is almost palpable! I'm not at all worried about being "put straight" by respected gray-beards - we all give as good as we get, part of the cut-n-thrust of professional discussion. Some might consider us anally-retentive.  On the other hand, the information content of language is critically dependent on the meanings, interpretations and implications of the words we use. In relatively new and complex areas such as information security, misunderstandings and ...