| Contributors |
|
xxiii | |
| Introduction |
|
xli | |
|
Access Control Systems and Methodology |
|
|
1 | (196) |
|
Access Control Techniques |
|
|
|
Enhancing Security through Biometric Technology |
|
|
5 | (16) |
|
|
|
|
|
21 | (6) |
|
|
|
Controlling FTP: Providing Secured Data Transfers |
|
|
27 | (18) |
|
|
|
Access Control Administration |
|
|
|
Privacy in the Healthcare Industry |
|
|
45 | (10) |
|
|
|
|
|
55 | (6) |
|
|
|
Identification and Authentication Techniques |
|
|
|
|
|
61 | (16) |
|
|
|
Single Sign-On for the Enterprise |
|
|
77 | (20) |
|
|
|
Access Control Methodologies and Implementation |
|
|
|
Centralized Authentication Services (Radius, Tacacs, Diameter) |
|
|
97 | (12) |
|
|
|
An Introduction to Secure Remote Access |
|
|
109 | (12) |
|
|
|
|
|
|
Hacker Tools and Techniques |
|
|
121 | (14) |
|
|
|
A New Breed of Hacker Tools and Defenses |
|
|
135 | (12) |
|
|
|
Social Engineering: The Forgotten Risk |
|
|
147 | (8) |
|
|
|
|
|
Breaking News: The Latest Hacker Attacks and Defenses |
|
|
155 | (10) |
|
|
|
Counter-Economic Espionage |
|
|
165 | (14) |
|
|
|
Monitoring and Penetration Testing |
|
|
|
|
|
179 | (12) |
|
|
|
|
|
191 | (6) |
|
|
|
Telecommunications, Network, and Internet Security |
|
|
197 | (470) |
|
Communications and Network Security |
|
|
|
|
|
203 | (14) |
|
|
|
Packet Sniffers and Network Monitors |
|
|
217 | (18) |
|
|
|
|
|
Secured Connections to External Networks |
|
|
235 | (14) |
|
|
|
Security and Network Technologies |
|
|
249 | (20) |
|
|
|
Wired and Wireless Physical Layer Security Issues |
|
|
269 | (8) |
|
|
|
|
|
277 | (10) |
|
|
|
What's Not So Simple about SNMP? |
|
|
287 | (10) |
|
|
|
Network and Telecommunications Media: Security from the Ground Up |
|
|
297 | (14) |
|
|
|
Security and the Physical Network Layer |
|
|
311 | (8) |
|
|
|
Security of Wireless Local Area Networks |
|
|
319 | (10) |
|
|
|
Securing Wireless Networks |
|
|
329 | (10) |
|
|
|
Wireless Security Mayhem: Restraining the Insanity of Convenience |
|
|
339 | (10) |
|
|
|
Wireless LAN Security Challenge |
|
|
349 | (14) |
|
|
|
|
|
ISO/OSI Layers and Characteristics |
|
|
363 | (10) |
|
|
|
Internet/Intranet/Extranet |
|
|
|
Enclaves: The Enterprise as an Extranet |
|
|
373 | (10) |
|
|
|
IPSec Virtual Private Networks |
|
|
383 | (24) |
|
|
|
Firewalls: An Effective Solution for Internet Security |
|
|
407 | (6) |
|
|
|
Internet Security: Securing the Perimeter |
|
|
413 | (10) |
|
|
|
Extranet Access Control Issues |
|
|
423 | (12) |
|
|
|
Application-Layer Security Protocols for Networks |
|
|
435 | (12) |
|
|
|
Application Layer: Next Level of Security |
|
|
447 | (10) |
|
|
|
Security of Communication Protocols and Services |
|
|
457 | (10) |
|
|
|
|
|
467 | (8) |
|
|
|
VPN Deployment and Evaluation Strategy |
|
|
475 | (18) |
|
|
|
How to Perform a Security Review of a Checkpoint Firewall |
|
|
493 | (20) |
|
|
|
Comparing Firewall Technologies |
|
|
513 | (10) |
|
|
|
The (In) Security of Virtual Private Networks |
|
|
523 | (16) |
|
|
|
|
|
539 | (10) |
|
|
|
|
|
|
|
Leveraging Virtual Private Networks |
|
|
549 | (12) |
|
|
|
|
|
561 | (6) |
|
|
|
Security for Broadband Internet Access Users |
|
|
567 | (8) |
|
|
|
|
|
575 | (6) |
|
|
|
An Examination of Firewall Architectures |
|
|
581 | (20) |
|
|
|
|
|
|
Instant Messaging Security Issues |
|
|
601 | (16) |
|
|
|
Secure Voice Communications |
|
|
|
|
|
617 | (10) |
|
|
|
Secure Voice Communications (VoI) |
|
|
627 | (12) |
|
|
|
Network Attacks and Countermeasures |
|
|
|
Packet Sniffers: Use and Misuse |
|
|
639 | (10) |
|
|
|
ISPs and Denial-of-Service Attacks |
|
|
649 | (18) |
|
|
|
Information Security Management |
|
|
667 | (406) |
|
Security Management Concepts and Principles |
|
|
|
The Human Side of Information Security |
|
|
663 | (14) |
|
|
|
|
|
677 | (8) |
|
|
|
Measuring ROI on Security |
|
|
685 | (4) |
|
|
|
Security Patch Management |
|
|
689 | (8) |
|
|
|
Change Control Management |
|
|
|
Configuration Management: Charting the Course for the Organization |
|
|
697 | (18) |
|
|
|
|
|
|
|
|
Information Classification: A Corporate Implementation Guide |
|
|
715 | (12) |
|
|
|
|
|
|
|
|
727 | (14) |
|
|
|
Trust Governance in a Web Services World |
|
|
741 | (10) |
|
|
|
Risk Management and Analysis |
|
|
751 | (8) |
|
|
|
New Trends in Information Risk Management |
|
|
759 | (8) |
|
|
|
Information Security in the Enterprise |
|
|
767 | (12) |
|
|
|
Managing Enterprise Security Information |
|
|
779 | (16) |
|
|
|
|
|
Risk Analysis and Assessment |
|
|
795 | (26) |
|
|
|
|
|
821 | (8) |
|
|
|
Cyber-Risk Management: Technical and Insurance Controls for Enterprise-Level Security |
|
|
829 | (16) |
|
|
|
|
|
|
|
Employment Policies and Practices |
|
|
|
A Progress Report on the CVE Initiative |
|
|
845 | (20) |
|
|
|
|
|
|
|
Roles and Responsibilities of the Information Systems Security Officer |
|
|
865 | (6) |
|
|
|
Information Protection: Organization, Roles, and Separation of Duties |
|
|
871 | (16) |
|
|
|
Organizing for Success: Some Human Resources Issues in Information Security |
|
|
887 | (12) |
|
|
|
|
|
Ownership and Custody of Data |
|
|
899 | (8) |
|
|
|
Hiring Ex-Criminal Hackers |
|
|
907 | (10) |
|
|
|
|
|
|
Information Security Policies from the Ground Up |
|
|
917 | (8) |
|
|
|
|
|
925 | (20) |
|
|
|
Toward Enforcing Security Policy: Encouraging Personal Accountability for Corporate Information Security Policy |
|
|
945 | (8) |
|
|
|
The Common Criteria for IT Security Evaluation |
|
|
953 | (16) |
|
|
|
A Look at the Common Criteria |
|
|
969 | (10) |
|
|
|
The Security Policy Life Cycle: Functions and Responsibilities |
|
|
979 | (10) |
|
|
|
Security Awareness Training |
|
|
|
Maintaining Management's Commitment |
|
|
989 | (10) |
|
|
|
Making Security Awareness Happen |
|
|
999 | (12) |
|
|
|
Making Security Awareness Happen: Appendices |
|
|
1011 | (12) |
|
|
|
Security Management Planning |
|
|
|
Maintaining Information Security during Downsizing |
|
|
1023 | (6) |
|
|
|
The Business Case for Information Security: Selling Management on the Protection of Vital Secrets and Products |
|
|
1029 | (6) |
|
|
|
How to Work with a Managed Security Service Provider |
|
|
1035 | (12) |
|
|
|
Considerations for Outsourcing Security |
|
|
1047 | (14) |
|
|
|
|
|
1061 | (12) |
|
|
|
Application Program Security |
|
|
1073 | (222) |
|
|
|
|
Security Models for Object-Oriented Databases |
|
|
1077 | (6) |
|
|
|
|
|
1083 | (10) |
|
|
|
Security for XML and Other Metadata Languages |
|
|
1093 | (8) |
|
|
|
XML and Information Security |
|
|
1101 | (8) |
|
|
|
|
|
1109 | (6) |
|
|
|
|
|
1115 | (8) |
|
|
|
Security as a Value Enhancer in Application Systems Development |
|
|
1123 | (16) |
|
|
|
Open Source versus Closed Source |
|
|
1139 | (18) |
|
|
|
Databases and Data Warehousing |
|
|
|
Reflections on Database Integrity |
|
|
1157 | (8) |
|
|
|
Digital Signatures in Relational Database Applications |
|
|
1165 | (10) |
|
|
|
Security and Privacy for Data Warehouses: Opportunity or Threat? |
|
|
1175 | (18) |
|
|
|
|
|
|
|
Systems Development Controls |
|
|
|
Enterprise Security Architecture |
|
|
1193 | (12) |
|
|
|
Certification and Accreditation Methodology |
|
|
1205 | (16) |
|
|
|
|
|
System Development Security Methodology |
|
|
1221 | (14) |
|
|
|
|
|
A Security-Oriented Extension of the Object Model for the Development of an Information System |
|
|
1235 | (16) |
|
|
|
|
|
|
|
|
|
|
|
|
1251 | (6) |
|
|
|
Malware and Computer Viruses |
|
|
1257 | (30) |
|
|
|
|
|
|
Methods of Auditing Applications |
|
|
1287 | (8) |
|
|
|
|
|
|
|
1295 | (170) |
|
|
|
|
Three New Models for the Application of Cryptography |
|
|
1299 | (10) |
|
|
|
Auditing Cryptography: Assessing System Security |
|
|
1309 | (4) |
|
|
|
Cryptographic Concepts, Methodologies, and Practices |
|
|
|
|
|
1313 | (14) |
|
|
|
Steganography: The Art of Hiding Messages |
|
|
1327 | (6) |
|
|
|
An Introduction to Cryptography |
|
|
1333 | (16) |
|
|
|
Hash Algorithms: From Message Digests to Signatures |
|
|
1349 | (8) |
|
|
|
A Look at the Advanced Encryption Standard (AES) |
|
|
1357 | (8) |
|
|
|
|
|
|
Principles and Applications of Cryptographic Key Management |
|
|
1365 | (14) |
|
|
|
Public Key Infrastructure (PKI) |
|
|
|
Preserving Public Key Hierarchy |
|
|
1379 | (6) |
|
|
|
|
|
1385 | (12) |
|
|
|
System Architecture for Implementing Cryptographic Functions |
|
|
|
Implementing Kerberos in Distributed Systems |
|
|
1397 | (50) |
|
|
|
|
|
|
|
|
Methods of Attacking and Defending Cryptosystems |
|
|
1447 | (18) |
|
|
|
Enterprise Security Architecture |
|
|
1465 | (90) |
|
Principles of Computer and Network Organizations, Architectures, and Designs |
|
|
|
Security Infrastructure: Basics of Intrusion Detection Systems |
|
|
1465 | (10) |
|
|
|
Firewalls, 10 Percent of the Solution: A Security Architecture Primer |
|
|
1475 | (14) |
|
|
|
The Reality of Virtual Computing |
|
|
1489 | (18) |
|
|
|
Overcoming Wireless LAN Security Vulnerabilities |
|
|
1507 | (6) |
|
|
|
Principles of Security Models, Architectures and Evaluation Criteria |
|
|
|
Formulating an Enterprise Information Security Architecture |
|
|
1513 | (18) |
|
|
|
|
|
Security Architecture and Models |
|
|
1531 | (16) |
|
|
|
Kellina M. Craig-Henderson |
|
|
Common Flaws and Security Issues --- System Architecture and Design |
|
|
|
Common System Design Flaws and Security Issues |
|
|
1547 | (8) |
|
|
|
|
|
1555 | (86) |
|
|
|
|
Operations: The Center of Support and Control |
|
|
1559 | (6) |
|
|
|
Why Today's Security Technologies Are So Inadequate: History, Implications, and New Approaches |
|
|
1565 | (4) |
|
|
|
Resource Protection Requirements |
|
|
|
|
|
1569 | (16) |
|
|
|
|
|
|
Auditing the Electronic Commerce Environment |
|
|
1585 | (16) |
|
|
|
|
|
|
Improving Network-Level Security through Real-Time Monitoring and Intrusion Detection |
|
|
1601 | (18) |
|
|
|
Intelligent Intrusion Analysis: How Thinking Machines Can Recognize Computer Intrusions |
|
|
1619 | (14) |
|
|
|
|
|
|
|
|
1633 | (8) |
|
|
|
Business Continuity Planning |
|
|
1641 | (84) |
|
Business Continuity Planning |
|
|
|
Reengineering the Business Continuity Planning Process |
|
|
1645 | (12) |
|
|
|
The Changing Face of Continuity Planning |
|
|
1657 | (10) |
|
|
|
The Role of Continuity Planning in the Enterprise Risk Management Structure |
|
|
1667 | (12) |
|
|
|
Disaster Recovery Planning |
|
|
|
Restoration Component of Business Continuity Planning |
|
|
1679 | (10) |
|
|
|
|
|
Business Resumption Planning and Disaster Recovery: A Case History |
|
|
1689 | (10) |
|
|
|
Business Continuity Planning: A Collaborative Approach |
|
|
1699 | (10) |
|
|
|
Elements of Business Continuity Planning |
|
|
|
The Business Impact Assessment Process |
|
|
1709 | (16) |
|
|
|
Law, Investigation, and Ethics |
|
|
1725 | (196) |
|
|
|
|
Jurisdictional Issues in Global Transmissions |
|
|
1729 | (8) |
|
|
|
Liability for Lax Computer Security in DDoS Attacks |
|
|
1737 | (6) |
|
|
|
The Final HIPAA Security Rule Is Here! Now What? |
|
|
1743 | (16) |
|
|
|
HIPAA 201: A Framework Approach to HIPAA Security Readiness |
|
|
1759 | (12) |
|
|
|
|
|
|
|
|
|
|
Computer Crime Investigations: Managing a Process without Any Golden Rules |
|
|
1771 | (14) |
|
|
|
Computer Crime Investigation and Computer Forensics |
|
|
1785 | (28) |
|
|
|
|
|
1813 | (6) |
|
|
|
|
|
1819 | (4) |
|
|
|
Major Categories of Computer Crime |
|
|
|
The International Dimensions of Cybercrime |
|
|
1823 | (18) |
|
|
|
|
|
|
|
|
1841 | (6) |
|
|
|
CIRT: Responding to Attack |
|
|
1847 | (14) |
|
|
|
Incident Response Management |
|
|
1861 | (10) |
|
|
|
Managing the Response to a Computer Security Incident |
|
|
1871 | (10) |
|
|
|
Cyber Crime: Response, Investigation, and Prosecution |
|
|
1881 | (6) |
|
|
|
Incident Response Exercises |
|
|
1887 | (10) |
|
|
|
|
|
|
|
1897 | (14) |
|
|
|
|
|
|
|
|
1911 | (10) |
|
|
|
|
|
1921 | (76) |
|
|
|
|
Physical Security: A Foundation for Information Security |
|
|
1925 | (10) |
|
|
|
Physical Security: Controlled Access and Layered Defense |
|
|
1935 | (12) |
|
|
|
Computing Facility Physical Security |
|
|
1947 | (10) |
|
|
|
Closed Circuit Television and Video Surveillance |
|
|
1957 | (8) |
|
|
|
|
|
|
Types of Information Security Controls |
|
|
1965 | (10) |
|
|
|
Environment and Life Safety |
|
|
|
Physical Security: The Threat after September 11th |
|
|
1975 | (22) |
|
|
| Index |
|
1997 | |