Wir verwenden Cookies und Analyse-Tools, um die Nutzerfreundlichkeit der Internet-Seite zu verbessern und für Marketingzwecke. Wenn Sie fortfahren, diese Seite zu verwenden, nehmen wir an, dass Sie damit einverstanden sind. Zur Datenschutzerklärung.
The Manager's Guide to Web Application Security
Details
The Manager's Guide to Web Application Security is a concise, information-packed guide to application security risks every organization faces, written in plain language, with guidance on how to deal with those issues quickly and effectively. Often, security vulnerabilities are difficult to understand and quantify because they are the result of intricate programming deficiencies and highly technical issues. Author and noted industry expert Ron Lepofsky breaks down the technical barrier and identifies many real-world examples of security vulnerabilities commonly found by IT security auditors, translates them into business risks with identifiable consequences, and provides practical guidance about mitigating them.
The Manager's Guide to Web Application Security describes how to fix and prevent these vulnerabilities in easy-to-understand discussions of vulnerability classes and their remediation. For easy reference, the information is also presented schematically in Excel spreadsheets available to readers for free download from the publisher's digital annex. The book is current, concise, and to the pointwhich is to help managers cut through the technical jargon and make the business decisions required to find, fix, and prevent serious vulnerabilities.
Autorentext
Ron Lepofsky is the president of ERE Information Security Auditors, which he founded in 2000. He holds the CISSP and CISM security certifications and a degree in mechanical engineering from the University of Toronto. He has extensive experience managing the web application security audit process, advising senior management on remediating security weaknesses, and translating the technical findings of his auditor teams into actionable terms for management.
Klappentext
The Manager's Guide to Web Application Security is a concise, information-packed guide to application security risks every organization faces, written in plain language, with guidance on how to deal with those issues quickly and effectively. Often, security vulnerabilities are difficult to understand and quantify because they are the result of intricate programming deficiencies and highly technical issues. Author and noted industry expert Ron Lepofsky breaks down the technical barrier and identifies many real-world examples of security vulnerabilities commonly found by IT security auditors, translates them into business risks with identifiable consequences, and provides practical guidance about mitigating them. The Manager's Guide to Web Application Security describes how to fix and prevent these vulnerabilities in easy-to-understand discussions of vulnerability classes and their remediation. For easy reference, the information is also presented schematically in Excel spreadsheets available to readers for free download from the publisher's digital annex. The book is current, concise, and to the point-which is to help managers cut through the technical jargon and make the business decisions required to find, fix, and prevent serious vulnerabilities.
Inhalt
Understanding IT Security Risks
Types of Web Application Security Testing
Web Application Vulnerabilities and the Damage They Can Cause
Web Application Vulnerabilities and Countermeasures
How to Build Preventative Countermeasures for Web Application Vulnerabilities
How to Manage Security on Applications Written by Third Parties
Integrating Compliance with Web Application Security
How to Create a Business Case Cost for Web Application Security
Parting Thoughts
A. COBIT 5 for Information Security
B. Experian EI3PA Security Audit
C. ISO/IEC 17799:2005 and the ISO/IEC 27000:2014 Series
D. North American Energy Council Security Standard for Critical Infrastructure Protection (NERC CIP)
E. NIST 800 Guidelines
F. Payment Card Industry (PCI) Data Security Standard
G. Sarbanes-Oxley Security Compliance Requirements
H. Sources of Information
Weitere Informationen
- Allgemeine Informationen
- GTIN 09781484201497
- Sprache Englisch
- Auflage 1st edition
- Größe H229mm x B152mm x T13mm
- Jahr 2014
- EAN 9781484201497
- Format Kartonierter Einband
- ISBN 1484201493
- Veröffentlichung 19.12.2014
- Titel The Manager's Guide to Web Application Security
- Autor Ron Lepofsky
- Untertitel A Concise Guide to the Weaker Side of the Web
- Gewicht 343g
- Herausgeber Apress
- Anzahl Seiten 232
- Lesemotiv Verstehen
- Genre Informatik