2 of 2 people found the following review helpful
5.0 out of 5 stars
Excellent introduction to information security, Jan 6 2011
By Richard Leickly - Published on Amazon.com
This review is from: CISSP Guide to Security Essentials (Paperback)
Peter Gregory is a prolific author and well-known computer security professional who is also very active in the information security community. Peter wrote this book to address the current situation in information security, which is stated in the Introduction, as "There aren't enough good security professionals to go around". Information security is a broad field with many sub disciplines. Many professionals feel they should know more about security, but don't know where to start. Peter's book is an attempt to change that situation by providing the foundational materials that every security professional needs to know before undertaking advanced or specialized study. The book is suitable for self-study or as a classroom text. Each chapter has a summary, a glossary of key terms, review questions, hands-on projects, and ideas for case projects. For those interested in obtaining the CISSP, they will find this book a good place to start. The strength of this book lies in its organization and clarity. The book's ten chapters map to the ten CISSP Common Body of Knowledge Domains. Each chapter is broken into many subheadings, with an outline-style organization that clarifies each distinct topic. Acronyms are defined in the text and in the glossaries, which are presented in each chapter and at the end of the book. There are two appendices. One appendix provides summary outlines of the ten domains of CISSP security; the other reproduces the code of ethics of CISSP professionals. The Introduction reviews the steps needed to obtain CISSP certification and, together with the code of ethics, gives a good sense of the knowledge, behavior, and attitude necessary to succeed as a security professional. A CD-ROM containing practice questions for the CISSP exam is included. No single book can provide all you need to know to be a CISSP, but this is a good place to start.
1 of 1 people found the following review helpful
3.0 out of 5 stars
Errors that Need Fixing, Jan 25 2012
By Ken - Published on Amazon.com
This review is from: CISSP Guide to Security Essentials (Paperback)
I've been unable to locate an answer key for any of the reviews questions provided at the end of the chapters. This is a slight annoyance as there are one or two questions where the correct answer is not apparent in the text. I suspect that this book is intended to be used in a college course, and in that case the answers are probably in the teacher's edition. For us non-college students, it would be nice to have a way to obtain the answers.
I've also noticed a rather obvious error in chapter five. On page 179 the book states that SHA-1 is "a robust message digest algorithm that has weakened somewhat. Developers considering using a hashing algorithm are advised to use MD5 instead." This statement is contrary to what I know about the popular hashing algorithms, and I believe it is actually the opposite that is true. There have been some demonstrations that have shown it is theoretically possible to cause collisions using MD5, and it is generally recommended that SHA-1 or SHA256 be used instead.
This error is a rather odd one to make, and I'd be interested to know how it made it into the book. Conversely, if this is not an error, then I would be very interested to know the author's reasoning for this statement.
I also noted some portions of the book, such as wording and a few diagrams, are exactly the same as Wikipedia articles. I'm not sure if the author is a Wikipedia contributor, or if material from Wikipedia was used in this book.
Overall, this appears to be a decent review of the material, and I think subsequent editions would easily be able to get four or even five stars out of me. It just needs a little more editing, and maybe a little more depth in some areas.
1 of 1 people found the following review helpful
5.0 out of 5 stars
Clear Concise Textbook and Reference, Jan 4 2011
By J98103 "Janine" - Published on Amazon.com
This review is from: CISSP Guide to Security Essentials (Paperback)
This was an excellent textbook for our University of Washington Professional Certificate Program in Information Systems Security. It clearly and concisely overviews all ten domains on the CISSP exam. The well organized glossary makes it the perfect reference and checklist so InfoSec professionals can apply all ten domains in protecting their systems.
Janine Michelsons
UW Information Systems Security Program Graduate