Customer Reviews


51 Reviews
5 star:
 (25)
4 star:
 (13)
3 star:
 (7)
2 star:
 (4)
1 star:
 (2)
 
 
 
 
 
Average Customer Review
Share your thoughts with other customers
Create your own review
 
 
Only search this product's reviews

The most helpful favorable review
The most helpful critical review


42 of 45 people found the following review helpful:
5.0 out of 5 stars King of the hill for Security Tome
I have exchanged email with the author and we have had a few phone calls, but I cannot say that I know Shon Harris well. However, after reading the 4th edition of her very successful book, I feel I know her better. I love the humor in the italics at the beginning of sections and - warning - sometimes in line with the technical material. I appreciate the plain, clear, as...
Published on December 24, 2007 by Stephen Northcutt

versus
66 of 71 people found the following review helpful:
2.0 out of 5 stars Bigger books, less knowledge
Not sure why this book is so highly rated. Having taken (and passed) the CISSP several years ago, I need to retake this exam and bought three books for review and study purposes. I have a previous version of the Harris book and it is ~900 pages. This new version is 1100+ pages, but seems to be filled more with fluff and some of the actually useful knowledge has been...
Published on July 19, 2008 by vaaesthete


‹ Previous | 1 26| Next ›
Most Helpful First | Newest First

66 of 71 people found the following review helpful:
2.0 out of 5 stars Bigger books, less knowledge, July 19, 2008
By 
Amazon Verified Purchase(What's this?)
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
Not sure why this book is so highly rated. Having taken (and passed) the CISSP several years ago, I need to retake this exam and bought three books for review and study purposes. I have a previous version of the Harris book and it is ~900 pages. This new version is 1100+ pages, but seems to be filled more with fluff and some of the actually useful knowledge has been removed! One example which stands out is the removal of the effectiveness and acceptance charts for biometrics methods. This is an important concept and it is entirely ignored in this version. Other things have been changed to no real benefit. The CIA triad (as is the de-facto acronym, even in her previous book) has been renamed to the ICA triad. There is no reason for this.
Finally, the entire book is written in a dumbed-down, cutesy fashion in an attempt (I believe) to make the book more approachable. All it has done, IMO, has increased the number of pages, possibly forcing out relevant materials.
I will pass this test, but it won't be because of this book. Buy the ISC book and the Krutz book (and/or a previous version of the Harris book) - you will not be disappointed.

UPDATE: ok, took the test in Sept and passed. I won't turn this into a test review as this is about the book, but when you buy a certification book, your primary requirement is that the book will be timely and relevant to the test material. The 4th Edition Harris book does just that. ISC has made significant changes to both the content and nature of the test (in large part to keep its test current on security trends and to satisfy a larger target audience) and Shon has captured those changes very well. So, having said all that, it is my revised opinion that this book is more than adequate for passing the test (although it is still filled with fluff.) If I could change the review, I would probably give it 4 stars at this point. The ISC book and the Krutz book are both excellent references to actually apply the knowledge in a meaningful way, however if you just want to pass the test, the Harris book will serve you well.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


42 of 45 people found the following review helpful:
5.0 out of 5 stars King of the hill for Security Tome, December 24, 2007
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
I have exchanged email with the author and we have had a few phone calls, but I cannot say that I know Shon Harris well. However, after reading the 4th edition of her very successful book, I feel I know her better. I love the humor in the italics at the beginning of sections and - warning - sometimes in line with the technical material. I appreciate the plain, clear, as simple as possible, way the information is presented. It would be easy to make these concepts sound hard, Shon does not do that, not ever; thank you! The charts and graphics on the main do a fantastic job of making the information clear. She does an extraordinary job of moving between well written prose and bullet points in a style reminiscent of Dorothy Denning. At three inches thick and running over 1100 pages, one certainly cannot fault her for leaving critical information out. This is on par with the Matt Bishop book of being the Information Security Tome. I can't say that I learned that much reading the book since I do security all day, every day and have done so for years, but I never got bored and I went cover to cover ( not counting the detailed index in the back and the "so you want to be a CISSP in the front) and I was astounded by the author's craft, she tells the story of security as well as anyone ever has.

You do not need me to vouchsafe the value of this book ( and the CD) to prepare for the CISSP exam. If Shon is not the best known author, she is certainly in the top two or three in this category. But, I believe this book has another equally important role. It is perfect for the CxO that wants to understand what security is, what they need to know about it. I understand the knee jerk response to that is, "you cannot ask a CEO to read 1100 pages". Actually, the successful senior executives in the world are generally quite good at reading a LOT of information in a SHORT period of time. Shon is accurate, the writing is excellent, the diagrams help with "knowledge compression", a CFO interested in security can zip through this like a zero turn mower on a two acre MacMansion.

Nitpicks, sigh, I wish ISC2 had settled on the standard approach to incident handling instead of creating their own broken one. The Quantum Cryptography section is actually Quantum Key Exchange, but hey! That is a nitpick, no reader of this book actually needs to know the difference. And critics will be overjoyed because Shon seems to have threat, risk, and vulnerability in the right pidgeon holes. The most serious flaw in the book is in chapter 12, Hack and Attack Methods, some of that stuff I know cold and I got a bit confused reading that section, but it is the end of the book and my guess is that folks were getting tired. A few network traces would go a long way towards bringing that section to life. And you know what? The book remains 5 stars. Even if that section was spot on, even if the thirty weak pages out of the 1070 strong pages were perfect, the book is not designed to prepare the reader to be an IPS analyst. The overall message is clear and compelling, the bad guys do evil things with packets; I get the message so will the reader, let's move on.

The bottom line, if you think you know security and want to test your knowledge, buy the book, fire up the CD, install the test software and give yourself a run. Shon is a great author, but she has also compiled an awesome set of questions. Yes, they will prepare you for the CISSP exam, but they will also help you test your knowledge of security and your ability to think critically. If you have further questions about the book, or you disagree with my review, drop me a line and let's talk about it, stephen@sans.edu.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


13 of 13 people found the following review helpful:
5.0 out of 5 stars Highly recommended, June 9, 2008
By 
V. Jin "Y. Jin" (Orange County, CA USA) - See all my reviews
(REAL NAME)   
Amazon Verified Purchase(What's this?)
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
I passed the test using this book. I did not use any other methods for the preparation. This book explains all of the aspect of the CISSP exam in detail explanations. It took me about 2 months to finish the whole contents. This is the only easy to understand IT book I've ever used.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


8 of 8 people found the following review helpful:
4.0 out of 5 stars A Good Baseline for Exam Review, July 24, 2008
By 
Curtis W. Diblin (Moreno Valley, CA United States) - See all my reviews
(REAL NAME)   
Amazon Verified Purchase(What's this?)
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
I just passed the CISSP exam using, almost exclusively, the Shon Harris, 4th ed., 'All in ONE, CISSP Exam Guide' - supplementing Harris with some additional materials on networking and encryption. It took me about 7 weeks to study the materials before taking the exam despite a busy work schedule (my background is operations). The book is an excellent resource for most of the 10 knowledge domains with special mention to LAW, and Physical Security. However, the Networking and Encryption Domains were not nearly adequate - not enough information and presented at a level below that of the actual exam. Use the questions at the end of each chapter as review but be WARNED, most of the chapter review questions are much to simple. Seek out other text books for more representative exam questions(combining knowledge with logic and practical scenarios). Also, do not waste your time on the questions found on the CD - way, way to simple. I found the book a little verbose for my taste but the many tables, diagrams, summary areas, and the quite excellent Quick Tips section at the end of each chapter more than made up for this minor flaw.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


7 of 7 people found the following review helpful:
5.0 out of 5 stars Pleased with content...., January 13, 2008
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
I am still in the midst of reading the CISSP All-in-one guide, and so far, I am very impressed with the content, and my ease of understanding subject matter presented. This is a much easier read than the "Official ISC2 Guide to the CISSP Exam". I also purchased "CISSP for Dummies". Of the three...CISSP all-in-one has the best of both worlds...in-depth content, similar to "Official ISC2 Guide", but also, ease of read, similar to the "For dummies" book. If I had to do it all over again...and just by one text, the CISSP All in one guide would be the one I'd choose, hands down.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
5.0 out of 5 stars Information Security, awesomely reviewed..., January 27, 2008
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
Although a green horn in the information security field, I was amazed at the ease of comprehension portrayed by this book. At first, I imagined it'll be a remix of the previous edition with a little bit extra info here and there; I found out that the information content was as fresh as ever; Currently using it for an introductory course at Walsh College and I must say, in comparism to the 3rd ed. this is a lot better.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
4.0 out of 5 stars Good Read, But..., October 25, 2008
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
Ms. Harris' book is written in a more conversational style than your average technical read, but don't forget you will be tested on the official ISC2 materials. I recommend their book for studying and Ms. Harris' book as a supplement, not a substitute.

Now less than 12 hours away from taking the test, I found many of the post-chapter questions to be not well-formed, though much the same can be said about the ISC2 workbook. It is evident the human factors practioners (those who actually study how to write good questions) have not vetted these.

The CD that comes with Ms. Harris's book is somewhat better. By the way, the 4th Ed. cover has a blue field, not a red one.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
5.0 out of 5 stars Wouldn't have passed without it!, August 9, 2008
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
I can honestly say that if it weren't for this book I probably would not have passed my CISSP exam. Unlike other prep-guides, Shon engages the reader and keeps their attention. Also, this book doesn't read like a "read this book and pass an exam" book. It reads like a security book which just so happens to teach you the contents of the CISSP CBK. Good work and congrats on the 4th edition.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
4.0 out of 5 stars Positive Review, May 21, 2008
By 
V. Schira (Dearborn, MI USA) - See all my reviews
(REAL NAME)   
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
I took the CISSP exam and passed the first time. I read the exam cram book and the ISC official review book, in addition to this book. Everyone I talked to said this was the book to get.

This was by far the easiest to read. The others were horrible reads, so it was hard to take away much from them. But I still felt like there was a lot of info in the book that was not on the exam. Also I think the exam is switching to a more story problem, situation based type question rather than the wrote memorization.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


6 of 7 people found the following review helpful:
3.0 out of 5 stars My Experience Not the same as other reviewers, May 8, 2009
By 
This review is from: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) (Hardcover)
If your background is similar to mine you may be very frustrated with this book. I can imagine writing such a broad survey book is difficult, but it's in its fourth addition now! So clearly a lot of people like it -probably because it has so many pages they think it must be good.

I am a computer professional; I worked in cryptography, computer security, software engineering, RF and network Comms. Although I have a broad background, it is not one obtained from a methodical overview which the CISSP test requires.

The first disappointment is the Index. Once you get into taking practice tests and need to look up information quickly. I guarantee you won't find it in the index.

It also appears that Ms. Harris' background focused on cryptographic systems. Do you really need the detailed procedures to encrypt a message using the 16th century Vigenere cipher? Just for this review, I checked the index. Guess what? Vigenere cipher is not there!

Another frustration is the legal section. Would you not expect the Digital Millennium Copyright Act be discussed? How about the controversial Uniform Computer Information Transactions Act?? Or the Children's Online Privacy Protection Act?

OK, then would you expect computer forensics to be covered in a few pages or more in depth? Oh and look up forensics in the index - not there. You must look up computer forensics. Geeez..

Overall a good editor could get this book down to half its size by removing the chattiness and rambling.

I also have experience with two other CISSP books. One by Ed Tittel called "CISSP: Certified Information Systems Security Professional Study Guide" and the other "CISSP Training Guide" by Roberta Bragg". Don't waste your time on Bragg's book due to the error rate. It comes with test software that is riddled with errors. Titel's book so seems much better but it has its problems. I'll post a review after I finish his book.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


‹ Previous | 1 26| Next ›
Most Helpful First | Newest First

This product

CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)
Used & New from: $3.27
Add to wishlist See buying options