Stay Safe! | A Basic Guide to Information Technology Security
Language: English
Published by Abbott Press, 2016
- Softcover
- New

Seller: preigu, Osnabrück, Germanypreigu
AbeBooks seller since August 5, 2024
Condition: New
US$ 25.91
Quantity: 5 available
Add to basketItem description from seller
Stay Safe! | A Basic Guide to Information Technology Security | Abdul B. Subhani | Taschenbuch | Kartoniert / Broschiert | Englisch | 2016 | Abbott Press | EAN 9781458220271 | Verantwortliche Person für die EU: Libri GmbH, Europaallee 1, 36244 Bad Hersfeld, gpsr[at]libri[dot]de | Anbieter: preigu Print on Demand.
Seller Inventory # 103446352
- Title
- Stay Safe! | A Basic Guide to Information Technology Security
- Author
- Abdul B. Subhani
- Publisher
- Abbott Press
- Publication year
- 2016
- Condition
- Neu
- Binding
- Taschenbuch
- Language
- English
- ISBN 10
- 1458220273
- ISBN 13
- 9781458220271
- Item weight
- 273 grams
- Dimensions
- 229 x 152 x 10 mm
- Seller catalogs
- Bücher
Information security is vital to the health of today's businesses, but designing, managing, and implementing IT security applications and answering fundamental IT security questions can seem like a daunting task--especially to those who are not the most tech savvy. What is security? And how can business leaders ensure that their virtual networks, business assets, and intellectual property are secure from the threat of viruses, malware, and malicious users?
Stay Safe! A Basic Guide to Information Technology Security provides an overview of the fundamental aspects of computer and network security. Examine how information security applies to applications, the Internet, and other networks, cloud computing, mobile devices, and more. Become familiar with different types of information security protection, including access control, antivirus software, cryptography, firewalls, intrusion detection and prevention systems, data backup and recovery, and biometrics. Understand different information technology threats, such as malware and social engineering.
Because network and computer security is critical for today's businesses, it is important for management to be informed and able to discuss intricate information-security issues with technical experts. This guide will explain security concepts and help business leaders be more confident in their decisions regarding information security infrastructure.
"Synopsis" may belong to another edition of this title.
Excerpt. © Reprinted by permission. All rights reserved.
Stay Safe!
A Basic Guide to Information Technology Security
By Abdul B. Subhani, Christopher WaltonAbbott Press
All rights reserved.
Contents
Chapter 1 Introduction to Security, 1,
Chapter 2 Introduction to Computer Security, 7,
Chapter 3 Access Control, 14,
Chapter 4 Application and Web Security, 21,
Chapter 5 Malware, 31,
Chapter 6 Antivirus Software, 43,
Chapter 7 Cryptography, 52,
Chapter 8 Understanding Networks and Network Security, 63,
Chapter 9 Firewalls, 75,
Chapter 10 Intrusion Detection and Prevention Systems, 83,
Chapter 11 Virtual Private Networks, 95,
Chapter 12 Data Backup and Recovery, 105,
Chapter 13 Cloud Computing, 115,
Chapter 14 Physical Security and Biometrics, 124,
Chapter 15 Social Engineering, 136,
Chapter 16 Mobile Security, 148,
Chapter 17 Current Trends in Information Security, 158,
Conclusion, 169,
About the Author, 170,
CHAPTER 1
Introduction to Security
Defining Security
What is security?
Is it a state of well-being for systems, organizations, or people? Can it be achieved through safety from criminal activity, such as terrorism, theft, or espionage? Does it include procedures followed or measures taken to ensure feelings of safety, stability, and freedom from fear or anxiety?
Security is all of these things and more. Specifically, in computer systems, security is expressed as the system's degree of resistance to, or protection from, harm.
Foundations of Security
Security is built on the following foundations:
Authentication
Put simply, authentication is the process of verifying the identity of a person or thing. It might involve confirming the identity of a person by validating identity documents, verifying the validity of a website with a digital certificate, tracing the age of an artifact by carbon dating, or ensuring that a product is what its packaging and labeling claim it is. Authentication often involves verifying the validity of at least one form of identification.
Authorization
Authorization is the function of specifying access rights to resources. More formally, to authorize is to define an access policy based on roles and permissions.
It is easy to confuse authentication with authorization. The two are frequently used interchangeably in conversation and are often tightly associated as key pieces of a secure system. But the two are very different concepts. Authentication is the process by which an individual's identity is confirmed. Authorization is the association of that identity with rights and permissions.
Auditing
Auditing is normally used as a finance-related term. However, in the realm of security, auditing is an unbiased examination and evaluation of an organization's security goals. It can be done internally (by employees of the organization) or externally (by an outside firm).
Confidentiality
Confidentiality involves a set of rules or a promise that limits access or places restrictions on certain types of information. In day-to-day life, people do not share all of their personal information with every person around. Information is shared on a need-to-know basis or it is protected, according to the requirements of its holder. All of this falls under the foundation of confidentiality.
Integrity
The commonly understood meaning of integrity is the quality of being honest, having strong moral principles, and sometimes, the state of being whole and undivided. In security, integrity is further defined as the state of a system performing its intended functions without being degraded or impaired by changes or disruptions in its internal or external environments.
Availability
In secure systems, availability is the degree to which a secured system resource, such as a system, a subsystem, or equipment, is in a specified operational and accessible state at the start of a task, when the task is called for at an unknown or random time.
Availability is linked to other security foundations as well. The availability of a resource to those accessing it should be according to their roles, permissions, and authorization.
Accountability
One goal of computer security is that anyone with access to a secured system should be held accountable for his or her actions within the system. For example, if a document has been amended by person X, and if later X denies having amended it, the system should be able to hold X accountable by showing evidence that the document was amended by X.
Security Terminology
When discussing security, it is important to be aware of these frequently used terms:
• Assurance: A guarantee or level of guarantee that a secure system will behave as expected when put to use.
• Risk: A possibility that something may go wrong. While working to make a system secure, one must consider the risks to the security.
• Threat: A method of triggering risk. Any action needed to make a system secure is based on preventing the threats posed to the system.
• Vulnerability: A weakness in a system that can be exploited by a security threat.
• Countermeasures: Ways and means to stop a threat from triggering a risk.
• Exploits: Vulnerabilities that have been triggered by a threat.
Different Kinds of Security
After becoming familiar with basic security terminology, the next stage is to understand the different types of computer security.
Internet security
Internet security is a set of rules and actions meant to protect against online attacks. The Internet has become part of our daily lives — a basic need for individuals, organizations, and systems. Internet security works to ensure confidentiality by protecting access to authorized resources and services. One example is an online system that prevents credit card details from being stolen on a shopping website.
Information security
Information security means defending information from attempts by unauthorized entities to use, disclose, disrupt, modify, peruse, inspect, record, or destroy a system. Information is a generic term for any form of data, whether physical or electronic.
Mobile security
Mobile security, as the name suggests, is the security of mobile devices like smartphones, tablets, laptops, and other portable computing devices. Because this type of security also includes securing the networks that mobile devices use to operate, it is sometimes referred to as wireless security.
Network security
Network security is a specialized field involving securing a computer or mobile network infrastructure against threats. Network security includes the policies and procedures implemented by a network administrator or manager to avoid and keep track of unauthorized access, modification, exploitation, or denial of the network and network resources.
CHAPTER 2Introduction to Computer Security
What is Computer Security?
Computer security is designed to protect computer systems from theft or damage to the software, the hardware, and the information on them, as well as from disruption or usurpation of the services they provide.
Computer security has the following three major security objectives, based on several of the previously discussed security foundations:
• Confidentiality: Disclosure of information is on a need-to-know basis or per roles and permissions.
• Integrity: Data can be altered in authorized ways by authorized users only.
• Availability: Data should be accessible to those authorized to access it.
Why is Computer Security Important?
Prevention against data theft is essential. So much data, such as personal information, credit card information, bank account numbers, passwords, and work-related documents, is stored in computers used by people on a daily basis. Not securing a computer against breaches can lead to data becoming compromised by unauthorized and malicious parties.
Malicious intent can pose a vital threat to the security of a computer. An intruder can alter program source codes and use personal pictures or email accounts to create derogatory content, such as pornographic images or fake, misleading, and offensive social media accounts. Vengeful people might crash computer systems to cause data loss. Intruders may hack other computers, websites, or networks and then use them in denial-of-service or similar attacks to prevent access to other websites and servers.
It is important to keep data safe, secure, and confidential. This is only possible by understanding the threats to our computer systems, being aware of possible countermeasures, and paying necessary attention to the subject of computer security.
Types of Computer Security Threats
The computer security life cycle begins with ascertaining the threat environment. One can correctly guard systems only against known threats. Therefore, it is important to take note of the different types of threats posed to computer systems.
Malware
Malware is any malicious program or software designed to perform harmful or unwanted actions on a computer system. Some malware attacks computer applications and data, while other malware steal confidential data from systems. It is important to note that malicious intent is a requirement in deeming a code malware. Unintentional flaws, such as bugs or run-time errors, cannot be defined as malware. Typical types of malware include computer viruses, worms, Trojan horses, spyware, rootkits, and backdoors.
Grayware
It is important to talk about grayware while describing computer security threats. Grayware is a term coined for applications that are unwanted, annoying, and troublesome but cannot be termed malware. Grayware may degrade a system, but not as much as malware. It includes adware, fraudulent dialers, hoaxes, software bundlers, browser modifiers, some types of spyware, and more. Typical grayware activities include capturing keystrokes, bombarding a system with ads, stealing data, installing unwanted software, playing pranks or false warnings, modifying system settings, and modifying functionality.
Computer Security Best Practices
With so many different types of malware and grayware, computer systems require specific security measures to combat the dangerous threat environment. Although this book aims to explain all threats, vulnerabilities, and related defensive mechanisms and practices, this section looks at the best practices for computer security.
Use an antivirus program
In today's threat environment, use of an antivirus program is vital for protecting a computer's normal functioning capabilities. A good antivirus is usually bundled with Internet security, anti-spyware, and anti-adware features. Antivirus vendors keep making protection mechanisms for upcoming malware; therefore, antivirus programs must always be updated with new virus definitions.
Keep software updated
In addition to the operating system's core system software, which performs the computer system's primary tasks, computers use a host of application software for routine tasks, such as documentation, programming, watching movies, and web surfing. A system can be compromised through a vulnerability in any of the software, whether it is the system software or the application software.
Many times, software vendors identify a vulnerability in their software and then create and release patches in the form of software updates. These updates are offered through notifications to the clients who are already using the software. This aspect becomes much more important when the software is an antivirus program. Antivirus updates are new virus definitions. If an antivirus program is not updated with the new definitions, it will not be able to guard against the latest known malware.
When a vulnerability has been identified and an update has been released, the vulnerability becomes public. It is not very hard for attackers to exploit such known vulnerabilities, since half of their job — identifying the vulnerability — has already been done. Therefore, all users who do not update their software immediately after release of a patch are highly vulnerable to attacks. In summary, computer users should never delay in installing a security update.
Take care in installing new software
First and foremost, only install software when it is absolutely necessary. When there is a need to install new software, either through external media, like disks, or directly downloaded from Internet, make sure that the software is from a trusted source. If the software is downloaded directly, it should be obtained from the official website of that software.
Avoid pirated and cracked software at all costs. It is not very difficult to get allegedly free software (freeware) from peer-to-peer sites, but money saved in this way will very likely be wasted — along with much more money spent fixing the system later. Never underestimate the cost of hassle and trouble of losing data.
Utilize user account controls
Current operating systems provide elaborate user account controls for better system management. This feature is also useful in securing a system efficiently. There should not be any default accounts without a password. No one should be using the root or superuser account routinely. Routine and normal working users should not have permissions to install/uninstall software or change system settings. That creates less chance of compromising the system accidentally by a naïve user installing harmful software.
Use firewall software
Firewall software protects the system against unauthorized connections and traffic. This keeps the system protected from malware exploits unknowingly installed by harmful sites and software. Basic firewall software is typically bundled with the operating system. It is often easy to configure and works reasonably well in default configuration.
Be extremely cautious in giving out personal information
In the modern-day threat environment, one has to be careful about giving out personal information. Phishing and social engineering attacks are common ways of getting or stealing personal information from people around the world.
Use password protection
The importance of password protection cannot be overemphasized. Weak passwords, reusing passwords, custody/security of passwords, password leakage, etc. are part of the big issue of password protection.
People tend to use simple passwords that they can remember easily. Sometimes, with the same intentions, people reuse passwords with different websites and systems. But a reused password only makes the person more vulnerable. Attackers can use an email or username at one site along with the associated password from another site or system to gain access to both.
Best password practices include:
• Not reusing passwords for multiple websites and systems
• Keeping complex passwords with a variety of alphanumeric characters
• Not sharing passwords
• Not writing passwords down in obvious places
Minimize storage of sensitive data
A good way to remain secure is to not store any passwords. If that is not possible, minimize the location and the amount of sensitive data that is stored to make it easier to store in a safe place. If storing sensitive data electronically, use a removable media or tertiary storage; if writing it down in a journal or other book, make sure the document hidden from plain view while at the computer system.
Remember physical security
Last, but not least, on the list of best practices is physical security. Other security measures are rendered useless if the hardware is stolen. Physical security is less important for desktop computers and large servers, but it is more important for portable hardware like laptops, mobiles, removable media, etc. Keep electronic devices all under lock and key or with you while traveling or moving around.
CHAPTER 3Access Centre!
What is Access Control?
Access control is the set of legitimate procedures to access a system. A person, a device, or a service, such as an application program or a web service, may want access to a system to use a service, read or write data, or utilize a resource. Simply put, access control can be understood as mechanisms for guarding entry to a system, similar to people implementing security in the form of guards, a photo ID verification system, keys, etc. to grant access to their property.
A good access control system should deny entry to unauthorized and malicious parties while allowing admission to legitimate users. It should have elaborate methods for adding to and excluding members from a list of allowed users. Its administrative procedures should be concise and comprehensive to avoid mistakes and ambiguity.
Subject and object in access control
Understanding the details of access control requires understanding the distinction between subject and object. The subject wants access to some information, resource, service, or application. The object is the information, resource, service, or application being accessed.
For example, if a user tries to open a file, then the user is the subject and file is an object. Whether the user will be allowed to open the file is a question of access rights. The entity or system with the power to grant access has the access control of that particular file.
Classification of Access Control
In the computer security world, access control is classified based on the controlling authority that decides the access permission of an object. There are four basic classifications of access control:
• Mandatory Access Control (MAC)
• Discretionary Access Control (DAC)
• Originator Controlled Access Control (ORCON or ORGCON)
• Role Based Access Control (RBAC)
Mandatory access control (MAC)
Mandatory access control (MAC) is when access to a system is controlled by the system's own mechanisms/tools. As the emphasis is on the rules and regulations of the system, which are not easily changed by the user, mandatory access control is also called Rule Based Access Control.
The access control mechanisms built into operating systems are examples of MAC; neither the subject accessing the system nor the objects being accessed by that subject have any role in determining grant of access. Usually, the operating system's routines themselves grant access based on the attributes associated with the subject needing access and the object being accessed.
Discretionary access control (DAC)
Discretionary access control (DAC) is when an individual user can set the access control rights and permissions of an object. As this type of access control is linked to the identity of individual users, it is also called Identity Based Access Control (IBAC).
(Continues...)
Excerpted from Stay Safe! by Abdul B. Subhani, Christopher Walton. Copyright © 2016 Abdul B. Subhani. Excerpted by permission of Abbott Press.
All rights reserved. No part of this excerpt may be reproduced or reprinted without permission in writing from the publisher.
Excerpts are provided by Dial-A-Book Inc. solely for the personal use of visitors to this web site.
"About the title" may belong to another edition of this title.
Shipping rates from Germany to U.S.A.
| Item | 60 to 60 business days | 60 to 60 business days |
|---|---|---|
| First item | US$ 81.15 | US$ 81.15 |
Payment methods
- Paypal
Store description
preigu betreibt einen Onlineversandhandel mit über 1 Mio. Produkten in verschiedenen Sortimenten. Das Kernsortiment besteht aus Büchern, Medien und Spielwaren. Ein gelungenes Einkaufserlebnis ist das Ziel einer jeden Bestellung bei preigu, denn der Kunde und seine Zufriedenheit stehen an erster Stelle. preigu setzt daher auf einen kompetenten Kundenservice, funktionierende Prozesse und schnelle Reaktion.
Specialty
Bücher, SpielwarenSeller's business information
preigu GmbH & Co. KG
Lengericher Landstraße 19
Osnabrück, Germany 49078
Terms of sale
Standard Business Terms and customer information
I. Standard business terms
§ 1 Basic provisions
(1) The following terms and conditions of business apply for all contracts concluded with us as the supplier (preigu GmbH & Co. KG) via the websites AbeBooks and/or ZVAB. Unless otherwise agreed, the inclusion of your own terms and conditions is explicitly rejected.
(2) A ‘consumer' in the sense of the following regulations is every natural person who concludes a legal transaction which, to an overwhelming extent, cannot be attributed to either his commercial or independent professional activities. The term ‘businessman' refers to every natural person, legal person or legally responsible partnership that concludes a legal transaction in pursuance of his/its independent professional or commercial activity.
§ 2 Conclusion of the contract
(1) The subject-matter of the contract is the selling of products .
(2) If an article is placed by us with AbeBooks or ZVAB, the activation of the page on AbeBooks or ZVAB shall involve the binding offer to conclude a contract under the terms and conditions contained in the article page.
(3) The contract shall become effective via the online shopping cart system as follows:
The products intended for purchase are moved to the "shopping cart". You can select the "Shopping Cart" using the appropriate buttons on the navigation bar and make changes there at any time.
After calling up the "Checkout" page and entering the required personal data and payment and shipping conditions, all order information is then displayed again on the order summary page.
Before submitting the order, you have the ability once more to review or change any information here (you may also use the "back" button on the Internet browser), or to cancel the purchase.
By clicking the "Buy now" button to submit the order, you declare your legally binding acceptance of the order which makes the contract effective.
(4) The execution of the order and the sending of all the details necessitated by the conclusion of the contract take place via e-mail, in a partially-automated manner. Consequently, you have to ensure that the e-mail address that you have deposited with us is the correct one, and that the receipt of the respective e-mails is guaranteed. In particular, you have to ensure that the respective e-mails are not blocked by a SPAM filter.
§ 3 Right of retention, reservation of proprietary rights
(1) You can only exercise a right of retention if the situation in question involves claims arising from the same contractual relationship.
(2) The goods remain our property until the purchase price is paid in full.
§ 4 Warranty
(1) The statutory warranty rights are applicable.
(2) As a consumer, you are requested to promptly check the product for completeness, visible defects and transport damage as soon as it is delivered, and promptly disclose your complaints to us and the shipping company in writing. Even if you do not comply with this request, it shall have no effect on your legal warranty claims.
(3) If a characteristic of the goods deviates from the objective requirements, the deviation shall only be deemed to be agreed if you were informed of the same by us before submitting the contractual declaration and the deviation was expressly and separately agreed between the contracting parties.
§ 5 Choice of law, place of fulfilment, jurisdiction
(1) German law shall apply. This choice of law only applies to customers if it does not result in the revocation of the protection guaranteed by the mandatory provisions of the law of the country in which the respective customer's usual place of residence is located (benefit-of-the-doubt principle).
(2) If you are not a consumer, but a businessman, a legal entity under public law or an institutional fund governed by public law, our place of business is the place of jurisdiction as well as the place of fulfilment for all services that follow from the business relationships that exist with us. The same condition applies to situations in which you are not associated with a general place of jurisdiction in Germany or the EU, as well as situations in which the place of residence or the usual place of residence is not known at the time of commencement of proceedings. This has no bearing on the capacity to call upon the court associated with another place of jurisdiction.
(3) The provisions of the UN Convention on Contracts for the International Sale of Goods are explicitly inapplicable.
II. Customer information
- Identity of the seller
preigu GmbH & Co. KG
Lengericher Landstr. 19
49078 Osnabrück
Germany
Telephone: 0541-580 72 84
E-Mail: mail@preigu.de
We are neither willing nor obliged to participate in dispute resolution proceedings before consumer arbitration boards.
- Information regarding the conclusion of the contract
The technical steps associated with the conclusion of the contract, the contract conclusion itself and the correction options are executed in accordance to the regulations "conclusion of the contract" in our standard business terms (part I.).
- Contractual language, saving the text of the contract
3.1 Contract language shall be English.
3.2 The complete text of the contract is not saved with us. Before the order is sent, the contract data can be printed out or electronically saved using the browser's print function. After the order is received by us, the order data, the legally-mandated details related to distance selling contracts and the standard business terms are re-sent to you via e-mail.
- Main features of the product or service
The key features of the goods and/or services can be found in the respective quote.
- Prices and payment arrangements
5.1 The prices mentioned in the respective offers represent total prices, as do the shipping costs. They include all the price components, including all the incidental taxes.
5.2 The dispatch costs that are incurred are not included in the purchase price. They can be viewed by clicking the appropriate button on our website or in the respective quote, are shown separately over the course of the order transaction and must additionally be borne by you, insofar as free delivery is not confirmed.
5.3 If delivery is made to countries outside of the European Union, we may incur unreasonable additional costs, such as duties, taxes or money transfer fees (transfer or foreign exchange fees charged by the banks), which you must bear.
5.4 You must also bear the costs arising from money transfers in cases in which the delivery is made to an EU Member State, but the payment is initiated outside of the European Union.
5.5 The payment methods that are available to you are shown by clicking the appropriate button on our website or are disclosed in the respective quote.
5.6 Unless otherwise specified for the respective payment methods, the payment claims arising from the contract that has been concluded become payable immediately.
- Delivery conditions
6.1 The delivery conditions, delivery date and existing supply restrictions, if applicable, can be found by clicking the appropriate button on our website or in the respective quote.
Unless a different period is specified in the item description or our delivery conditions, the goods are delivered within 3-5 days after the conclusion of the contract (in case an advance payment has been agreed upon, after the payment authorisation).
6.2 If you are a consumer, the following is statutorily regulated: The risk of the sold item accidentally being destroyed or degraded during shipping only passes over to you when the item in question is delivered, regardless of whether or not the shipping operation is insured. This condition does not apply if you have independently commissioned a transport company that has not been specified by us or a person who has otherwise been appointed to execute the shipping operation.
- Statutory warranty right
Liability for defects is governed by the "Warranty" provisions in our General Terms and Conditions of Business (Part I).
Information on battery disposal
In connection with the sale of batteries or the delivery of devices containing batteries, we are obliged to inform you of the following:
Batteries must not be disposed of with household waste.
You can either return used batteries that we carry or have carried in our range as new batteries to us at your own expense or return them free of charge to our shipping warehouse (shipping address). Alternatively, you can hand in the batteries at your local collection points.
As an end user, you are legally obliged to return used batteries so that they can be recycled or disposed of properly.
Used batteries may contain harmful substances that can damage the environment or your health if not stored or disposed of properly. However, batteries also contain important raw materials such as iron, zinc, manganese or nickel and can be recycled.
The symbols on the batteries have the following meanings:
The symbol of the crossed-out wheelie bin means that the battery must not be disposed of with household waste.
For batteries containing a certain amount of lead, cadmium or mercury, the following additions below the symbol with the crossed-out wheelie bin indicate the respective pollutants:
Pb = Battery contains more than 0.004% lead by weight
Cd = Battery contains more than 0.002% cadmium by weight
Hg = Battery contains more than 0.0005% mercury by weight
Information on the costs involved in accordance with Article 56 (4) of the EU Battery Regulation (Regulation 2023/1542) can be found at the ‘Batterie-Zurück (https://www.batterie-zurueck.de/de/bewirtschaftungvonaltbatterien/)' initiative.
Please pay attention to the above instructions.