Amazon.co.uk Trade-In Store
Did you know you can trade in your old books for an Amazon.co.uk Gift Card to spend on the things you want? Visit the Books Trade-In Store for more details. Special Offer until June 30, 2013: Receive an additional £5 promotional Gift Certificate, when you trade-in at least £10 worth of books. Learn more.
With the growth in social networking and the potential for larger and larger breaches of sensitive data,it is vital for all enterprises to ensure that computer users adhere to corporate policy and project staff design secure systems. Written by a security expert with more than 25 years′ experience, this book examines how fundamental staff awareness is to establishing security and addresses such challenges as containing threats, managing politics, developing programs, and getting a business to buy into a security plan. Illustrated with real–world examples throughout, this is a must–have guide for security and IT professionals.
{"itemData":[{"priceBreaksMAP":null,"buyingPrice":19.19,"ASIN":"0470721995","isPreorder":0},{"priceBreaksMAP":null,"buyingPrice":19.83,"ASIN":"1597496154","isPreorder":0},{"priceBreaksMAP":null,"buyingPrice":12.15,"ASIN":"1597496537","isPreorder":0}],"shippingId":"0470721995::8LFi6TtchUXc0uCOdJnAwYxefv4xUA8CGM9asEpgEAn49xrFNMLRmXUIZxlrZniHpAGv7BxJKwCoo8lnGchamgcd2mw3KGwS,1597496154::xo4oalsIPpMTigvWZc9Vsa%2F%2BFmONJLwPW%2FvNjeILMTy27HjteOxZ6OI48fHumG4gU%2BgUy5qhy4rAiT%2BXUR0CaNx8ep4iMtMJ,1597496537::A1WC3xaSwL%2BvsiVCfRvsMP5vZULi%2BPJLb2Z16tCjgufdTqWjgm3XnU3%2BFcQMzTyKmEmjPq2zNFLgH7sfdJ%2Fqcd%2BJMq7CgEnM","sprites":{"addToWishlist":["wl_one","wl_two","wl_three"],"addToCart":["s_addToCart","s_addBothToCart","s_add3ToCart"],"preorder":["s_preorderThis","s_preorderBoth","s_preorderAll3"]},"currenyCode":"GBP","shippingDetails":{"xz":"same","yz":"same","xy":"same","xyz":"same"},"tags":["x","y","z"],"strings":{"addToWishlist":[null,null,null],"addToCart":["Add to Basket","Add both to Basket","Add all three to Cart"],"showDetailsDefault":"Show availability and delivery details","shippingError":"An error occurred, please try again","hideDetailsDefault":"Hide availability and delivery details","priceLabel":["Price:","Price For Both:","Price For All Three:"],"preorder":["Pre-order this item","Pre-order both items","Pre-order all three items"]}}
"...an engaging read." (Information Age, May 2009) "I found the book enjoyable and easy to read. It is very informative, and gives good references" (Infosecurity, June 2009) ‘For a big book–in size and in ambition– it’s most readable.’ (Professional Security, September 2010).
From the Back Cover
“Computers do not commit crimes. People do.” The biggest threat to information security is the “human factor”, the influence of people. Even the best people will make mistakes, cause breaches and create security weaknesses that enable criminals to steal, corrupt or manipulate systems and data. The explosion in social networking and mobile computing is intensifying this problem. For the first time, this book brings together theories and methods which will help you to change and harness people’s security behaviour. It will help you to: Understand and manage major crises and risk Appreciate the nature of the insider threat Navigate organisation culture and politics Build better awareness programmes Transform user attitudes and behaviour Gain Executive Board buy–in Design management systems that really work Harness the power of your organisation Based on the author’s own personal experience of working with large, complex organisations, such as Shell and Royal Mail, this book is written by an information security insider and makes essential reading for all information security professionals. “We live in am age where social networks, collaborative working and community development are global and commonplace, redefining the role of information security. David takes a dry–as–dust elephant of a subject and expertly serves it up in edible, even tasty, morsels.” JP Rangaswami, Managing Director of BT Design. “A highly entertaining read that will undoubtedly become essential reading for all security professionals.” Professor Fred Piper “I’m really interested in reading this book and, frankly, once it’s published, I’ll be one of the first to buy it.” Dr. Eugene Schultz, High Tower Software
This is an excellent book that deserves to be widely read, not just by information security professionals, but by any one with an interest in understanding the human factors in other 'information' disciplines.
In part this book is a distillation of the author's considerable experience in the field, and for that alone worth reading. In part it is a veritable tapas of food for thought, that moves from hypnosis to the power of networks and systems thinking as applied to information security.
I have one criticism and that is in the discussion of Disaster Recovery the underlying model of 'Command and Control' is presented without a counter. It would have been interesting to see the author discuss the Toyota-Aisin P-valve crisis (as cited in Duncan Watt's Six Degrees).
This is a wide ranging and thought provoking book covering the human factor in information security.
As an out and out techie, I wouldn't normally expect to find this topic very interesting; but in fact it's fascinating. It covers areas such as risk analysis, presentation skills, business cases and network theory.
I strongly recommend it to all information security professionals.
I read this book from cover-to-cover so as not to miss any 'pearls of wisdom' that David has to share with his readers. One could just as naturally use this as a reference book.
Most information security books have a couple of chapters on people and information security, e.g. awareness/training, etc. Do not be deceived into thinking this book is just about 'educating' people about security, although clearly this is covered.
David effectivley turns upsidedown the subject of information security and talks about it in the organisational context that is driven by people. He pulls in organisational dynamics, cultures, politics, everything that can influence your effectiveness in any information security management role/project that you are involved in or driving. He places information security in a full context, i.e. the macro environment.
This book is not written in a theoretical style. It is written as though David Lacey is speaking with you direct, he writes as he speaks. This makes it easy to read.
I recommend this book to all professionals that practice information security management and even managers that are interested in the subject. It will stretch your mind, and answer many questions that you may have never thought to question or ask.