Defense in Depth: An Impractical Strategy for a Cyber-World

Nonfiction, Computers, Networking & Communications, Computer Security, Operating Systems, Application Software
Cover of the book Defense in Depth: An Impractical Strategy for a Cyber-World by Prescott Small, Prescott Small
View on Amazon View on AbeBooks View on Kobo View on B.Depository View on eBay View on Walmart
Author: Prescott Small ISBN: 9781465791894
Publisher: Prescott Small Publication: January 31, 2012
Imprint: Smashwords Edition Language: English
Author: Prescott Small
ISBN: 9781465791894
Publisher: Prescott Small
Publication: January 31, 2012
Imprint: Smashwords Edition
Language: English

Businesses and Information Technology Security Professionals have spent a tremendous amount of time, money and resources to deploy a Defense in Depth approach to Information Technology Security. Yet successful attacks against RSA, HB Gary, Booz, Allen & Hamilton, the United States Military, and many others are examples of how Defense in Depth, as practiced, is unsustainable and the examples show that the enemy cannot be eliminated permanently. A closer look at how Defense in Depth evolved and how it was made to fit within Information Technology is important to help better understand the trends seen today. Knowing that Defense in Depth, as practiced, actually renders the organization more vulnerable is vital to understanding that there must be a shift in attitudes and thinking to better address the risks faced in a more effective manner. Based on examples in this paper, a change is proposed in the current security and risk management models from the Defense in Depth model to Sustained Cyber-Siege Defense. The implications for this are significant in that there have to be transitions in thinking as well as how People, Process and Technology are implemented to better defend against a never ending siege by a limitless number and variety of attackers that cannot be eliminated. The suggestions proposed are not a drastic change in operations as much as how defenses area aligned, achieve vendor collaboration by applying market pressures and openly sharing information with each other as well as with federal and state agencies. By more accurately describing the problems, corporations and IT Security Professionals will be better equipped to address the challenges faced together.

View on Amazon View on AbeBooks View on Kobo View on B.Depository View on eBay View on Walmart

Businesses and Information Technology Security Professionals have spent a tremendous amount of time, money and resources to deploy a Defense in Depth approach to Information Technology Security. Yet successful attacks against RSA, HB Gary, Booz, Allen & Hamilton, the United States Military, and many others are examples of how Defense in Depth, as practiced, is unsustainable and the examples show that the enemy cannot be eliminated permanently. A closer look at how Defense in Depth evolved and how it was made to fit within Information Technology is important to help better understand the trends seen today. Knowing that Defense in Depth, as practiced, actually renders the organization more vulnerable is vital to understanding that there must be a shift in attitudes and thinking to better address the risks faced in a more effective manner. Based on examples in this paper, a change is proposed in the current security and risk management models from the Defense in Depth model to Sustained Cyber-Siege Defense. The implications for this are significant in that there have to be transitions in thinking as well as how People, Process and Technology are implemented to better defend against a never ending siege by a limitless number and variety of attackers that cannot be eliminated. The suggestions proposed are not a drastic change in operations as much as how defenses area aligned, achieve vendor collaboration by applying market pressures and openly sharing information with each other as well as with federal and state agencies. By more accurately describing the problems, corporations and IT Security Professionals will be better equipped to address the challenges faced together.

More books from Application Software

Cover of the book OneNote For Beginners by Prescott Small
Cover of the book Mercurial: The Definitive Guide by Prescott Small
Cover of the book Genetic Algorithms for Pattern Recognition by Prescott Small
Cover of the book Delivering Exceptional Project Results by Prescott Small
Cover of the book Handbook of Research on Network Forensics and Analysis Techniques by Prescott Small
Cover of the book Computer Building Made Simple by Prescott Small
Cover of the book Certified Ethical Hacker (CEH) Foundation Guide by Prescott Small
Cover of the book Oracle Business Intelligence Enterprise Edition 12c - Second Edition by Prescott Small
Cover of the book Radio Frequency Identification and IoT Security by Prescott Small
Cover of the book NoSQL for Mere Mortals by Prescott Small
Cover of the book Interactivity, Collaboration, and Authoring in Social Media by Prescott Small
Cover of the book Algebraic and Computational Aspects of Real Tensor Ranks by Prescott Small
Cover of the book Building an Intelligence-Led Security Program by Prescott Small
Cover of the book Outsourcing and Offshoring Business Services by Prescott Small
Cover of the book Applications of ATILA FEM Software to Smart Materials by Prescott Small
We use our own "cookies" and third party cookies to improve services and to see statistical information. By using this website, you agree to our Privacy Policy