The fourth edition of Principles of Information Security explores the field of information security and assurance with updated content including new innovations in technology and methodologies. Readers will revel in the comprehensive coverage that includes a historical overview of information security, discussions on risk management and security technology, current certification information, and more. The text builds on internationally recognized standards and bodies of knowledge to provide the knowledge and skills students need for their future roles as business decision-makers. Information security in the modern organization is a management issue which technology alone cannot answer; it is a problem that has important economic consequences for which management will be held accountable. Readers can feel confident that they are using a standards-based, content-driven resource to prepare for their work in the field.
My god, this is the most boring book I've ever read. I had to read it for uni, but gosh, it's been a struggle. It's all 'pie in the sky' security information rather then anything even half way practical. If you don't have to DON'T READ IT
Painfully dry until Chapter 8, Cryptography. The subsequent chapters on Physical Security and Project Management were readable, but the final two returned to the desert.
I quite literally fell asleep while reading this book, so perhaps it might be useful as a cure for insomnia. It was assigned for a course, I don’t hate joy. A necessary primer, I guess, but there’s got to be a more interesting way to glean this information.
Hated every minute of this read. I know it’s probably partly because this is not my field, but, either way, the writing felt very drawn out, too technical, and highly unapproachable.
I will say that I am very proud of myself for finishing this 700+ page textbook in six weeks👏
Note: Physical Book (nothing else was available in this edition😩)
Wow what edition are they on? Way to keep the racket going. Outdated info mixed with as much useless jargon they could find to produce this. Looking forward to the endless red tape people like this will create when info sec becomes standardized by the gov.
As required college overview reading, I guess this book would be OK. Its ivory tower is showing. But the crypto chapter (chapter 8) is pretty bad.
On P350 and P389, they refer to 3DES as a 128-bit cipher. But on P366 they change their minds and write "3DES uses three 64-bit keys for an overall key length of 192 bits". Both were wrong. DES only uses 56 of 64 bits for encrypting/decrypting, so 3DES is 168 bit -- not that it's even close to a 168-bit strength against a brute force attack.
They then say the Vernam Cipher is "also known as the one-time pad". Except that the Vernam cipher's keying material repeats when used up (that's why a one-time pad is not called a two or three time pad).
They also discuss old standards that went no where that no one uses, as if they are legitimate competing alternatives (examples, SESAME and S-HTTP). And their crypto chapter discusses S-HTTP, but doesn't even once mention TLS.
These gripes all pertain to the 4th edition (2011).
Required reading for my class but a good enough read I took the time to add it on. Well written, keeps the info entertaining. A good read if you are newer in the information security scene. Bad thing is it is a textbook so it was $70 or so. Not sure if it is worth that if not needed for class, so you might wait till a bit older or check the first/second edition (not sure how good they are though).
This is an excellent book to read about information technology. It goes into great details about all the security issues we face today involving information. In particular, that internet is a bad neighborhood of its own; yet, many resort to it through daily activities believing that they are safe from harms way.
I read this as recommended reading for my university course. While there were a number of key concepts I picked up, there was also a lot of real estate wasted on excessive detail that I don't think added anything.
Half of the book helped me to sleep, while the other half provided interesting reading.
Required reading for my class and it was great This book gave me a clear view of security components Good for beginners in this field It is not avaliable in many libraries but you could buy it online
Great for history, theory and concepts, but this edition (the third) was a bit behind the times on current standards. Make sure you get the latest edition. As of today, 4th ed from 2012 is the good stuff.
General concepts and dated content. Might have been relevant about 10 years ago. Had to read for school, and even the instructor taking over the class talked about how bad this book is and can't wait to get a new book approved for the next sessions of the course.