Scott's Recommended Reading List for Information Security Managers

[In association with Amazon.com] All the books on this page may be purchased from Amazon.com. The commission from all books bought from this list using the links on this page will be donated to cancer research!

[Understanding Information Security]   [Managing Information Security]
[Understanding The Risk]   [Incident Response and Management]
[Cryptography]   [Security Certification]
[Search Amazon.com]


Understanding Information Security

Writing Information Security Policies
by Scott Barman
New Riders Publishing, November 2001
ISBN 157870264X

"This is one of those books that should be in the back pocket of any manager who really wants to cover that part of their anatomy."
-Amazon.com reviewer Charles Ashbacher
Computer Security Basics
by Deborah F. Russell, G.T. Gangemi
O'Reilly & Associates, February 1991
ISBN 0937175714

A classic that still contains great principles that still apply which are explained in a manner that everyone could understand.
Hackers Beware
by Eric Cole
New Riders Publishing, August 2001
ISBN 0735710090

It is a good idea to understand computer security from the hacker's point of view. Hackers Beware gives the reader the big picture from all apects of computer security. A must read for everyone, including the seasoned professional.
Know Your Enemy: Revealing the Security Tools, Tactics, and Motives of the Blackhat Community
by The Honeynet Project, Foreword by Bruce Schneier, Preface by Lance Spitzner
Addison-Wesley, August 2001, ISBN 0201746131

A great companion to Hackers Beware is this compilation from The Honeynet Project, a project that set out to study the "Black Hat" community.
Top of the page...

Managing Information Security

Secrets and Lies: Digital Security in a Networked World
by Bruce Schneier
John Wiley & Sons, August 2000
ISBN 0471253111

If you are going to be an InfoSec manager, this book better be on your shelf for reference, after you memorize it! Schneier has a unique perspective on information security that every manager should pay attention to. It is based in common sense, which can be rare for an InfoSec book.
Defending Your Digital Assets Against Hackers, Crackers, Spies, and Thieves
by Randall K. Nichols, Julie J. Ryan, with Forewords by William E. Baugh and Arthur W. Coviello
McGraw-Hill Professional Publishing, January 2000
ISBN 0072122854

This book delves deep into the nuts and bolts of managing InfoSec and puts it clearly in context of the business process you InfoSec program should be designed to protect.
Top of the page...

Understanding The Risk

Information Security Risk Analysis
by Thomas R. Peltier
Auerbach Publications, January 2001
ISBN 0849308801

The best book on understanding information security risk assessments and how it can be used to set policies.
Maximum Security (4th Edition)
by Anonymous
Sams, December 2002
ISBN 0672324598

The next step to understanding information security risks to to understand security from a hacker's point of view. Sams rounded up the stories and suggestions from many hackers and put them into a book that should be required reading for everyone in this industry
Top of the page...

Incident Response and Management

Incident Response: A Strategic Guide to Handling System and Network Security Breaches
by E. Eugene Schultz and Russell Shumway
New Riders Publishing, December 2001
ISBN 1578702569

According to the publisher's catalog, "Incident Response advances the notion that without effective management, incident response cannot succeed."
CERT Guide to System and Network Security Practices
by Julia H. Allen
Addison Wesley Longman, June 2001
ISBN 020173723X

What better way to learn about information security than from The CERT Coordination Center, the people who has watched and reported on Internet incidents since 1988.
Firewalls and Internet Security: Repelling the Wily Hacker, 2nd Edition
by William R. Cheswick, Steven M. Bellovin, and Aviel D. Rubin
Addison Wesley, February 2003
ISBN 020163466X

Security is more than a firewall. And despite the book's title, the noted authors follow-up their breakthrough original book with a thoughtful, well written discussion on the mechanisms of Internet security.
Network Intrusion Detection: An Analyst's Handbook, 3rd Edition
by Stephen Northcutt and Judy Novak
New Riders Publishing, August 2002
ISBN 0735712654

You cannot find a better or more comprehensive book on intrusion detection.
Top of the page...

Cryptography

Applied Cryptography: Protocols, Algorithms, and Source Code in C, 2nd Edition
by Bruce Schneier
John Wiley & Sons, October 1995, ISBN 0471117099

If you have any questions about cryptography, this is the reference to use to answer them. If you buy one book on cryptography, this is the book to own.
Cryptography and Network Security: Principles and Practice (3rd Edition)
by William Stallings
Prentice Hall, August 2002
ISBN l0138690170

After you finish Schneier's book, Stallings bridges the gap between what cryptography is and how it applies to network security. The updated 3rd Edition is really an improvement over previous editions.
PGP: Pretty Good Privacy
by Simson Garfinkel
O'Reilly & Associates, October 1995
ISBN 1565920988

One application of cryptography is PGP. This book is an excellent reference into how to use PGP in your network environment.
SSH, The Secure Shell: The Definitive Guide
by Daniel J. Barrett, Richard Silverman
O'Reilly & Associates, February 2001
ISBN 0596000111

Another popular application is SSH, which everyone should look at for securing internal communications, including file transfers.
Top of the page...

Security Certification

CISSP Training Guide
by Roberta Bragg
Que Publishing, November 2002
ISBN 078972801X

This is an excellent book. It not only covers the ten domains but contains a CD-ROM with a lot of practice questions. Scott Barman is a contributor of Chapter 3 to this book.

Eric Cole, Matthew Newfield, John M. Millican, and Stephen Northcutt
Que Publishing, October 2002
ISBN 0789727749

The Global Information Assurance Certification (GIAC) is an up and coming certification exam that many will accept as much as the CISSP. However, if you read this study guide, you will think that the GIAC is superior to all others. This book is well crafted for all levels of understanding information security.
Top of the page...

 

In Association with Amazon.com Search:
Keywords:
Writing Information Security Policy's Home Page...
Scott's Home Page...

All questions, comments, and corrections may be mailed to the author at wisp@barman.ws Last update: August 17, 2003