New School of Information Security, The and over 360,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
50 used & new from $15.78

Have one to sell? Sell yours here
 
   
Express Checkout with PayPhrase
What's this? | Create PayPhrase
Sorry!
The New School of Information Security
 
 
Start reading New School of Information Security, The on your Kindle in under a minute.

Don’t have a Kindle? Get your Kindle here.
 
  
4.4 out of 5 stars  See all reviews (15 customer reviews)

List Price: $29.99
Price: $19.79 & eligible for FREE Super Saver Shipping on orders over $25. Details
You Save: $10.20 (34%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Tuesday, November 10? Choose One-Day Shipping at checkout. Details
36 new from $15.78 14 used from $17.60

Formats

Amazon Price New from Used from
  Kindle Edition $14.39 -- --
  Hardcover $19.79 $15.78 $17.60

Frequently Bought Together

The New School of Information Security + Security Metrics: Replacing Fear, Uncertainty, and Doubt + Applied Security Visualization
Price For All Three: $81.96

Show availability and shipping details

  • This item: The New School of Information Security by Adam Shostack

    In Stock.
    Ships from and sold by Amazon.com.
    Eligible for FREE Super Saver Shipping on orders over $25. Details

  • Security Metrics: Replacing Fear, Uncertainty, and Doubt by Andrew Jaquith

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Applied Security Visualization by Raffael Marty

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought

Security Engineering: A Guide to Building Dependable Distributed Systems

Security Engineering: A Guide to Building Dependable Distributed Systems

by Ross J. Anderson
4.7 out of 5 stars (32)  $56.00
Applied Security Visualization

Applied Security Visualization

by Raffael Marty
4.8 out of 5 stars (8)  $30.68
Schneier on Security

Schneier on Security

by Bruce Schneier
4.5 out of 5 stars (6)  $19.79
Beautiful Security

Beautiful Security

by Andy Oram
5.0 out of 5 stars (8)  $34.61
Geekonomics: The Real Cost of Insecure Software

Geekonomics: The Real Cost of Insecure Software

by David Rice
4.4 out of 5 stars (9)  $21.89
Explore similar items

Editorial Reviews

Product Description

<>“It is about time that a book like The New School came along. The age of security as pure technology is long past, and modern practitioners need to understand the social and cognitive aspects of security if they are to be successful. Shostack and Stewart teach readers exactly what they need to know--I just wish I could have had it when I first started out.”

--David Mortman, CSO-in-Residence Echelon One, former CSO Siebel Systems

 

Why is information security so dysfunctional? Are you wasting the money you spend on security? This book shows how to spend it more effectively. How can you make more effective security decisions? This book explains why professionals have taken to studying economics, not cryptography--and why you should, too. And why security breach notices are the best thing to ever happen to information security. It’s about time someone asked the biggest, toughest questions about information security. Security experts Adam Shostack and Andrew Stewart don’t just answer those questions--they offer honest, deeply troubling answers. They explain why these critical problems exist and how to solve them. Drawing on powerful lessons from economics and other disciplines, Shostack and Stewart offer a new way forward. In clear and engaging prose, they shed new light on the critical challenges that are faced by the security field. Whether you’re a CIO, IT manager, or security specialist, this book will open your eyes to new ways of thinking about--and overcoming--your most pressing security challenges. The New School enables you to take control, while others struggle with non-stop crises.

  • Better evidence for better decision-making
    Why the security data you have doesn’t support effective decision-making--and what to do about it
  • Beyond security “silos”: getting the job done together
    Why it’s so hard to improve security in isolation--and how the entire industry can make it happen and evolve
  • Amateurs study cryptography; professionals study economics
    What IT security leaders can and must learn from other scientific fields
  • A bigger bang for every buck
    How to re-allocate your scarce resources where they’ll do the most good


About the Author

Adam Shostack is part of Microsoft’s Security Development Lifecycle strategy team, where he is responsible for security design analysis techniques. Before Microsoft, Adam was involved in a number of successful start-ups focused on vulnerability scanning, privacy, and program analysis. He helped found the CVE, International Financial Cryptography association, and the Privacy Enhancing Technologies workshop. He has been a technical advisor to companies including Counterpane Internet Security and Debix.

 

Andrew Stewart is a Vice President at a US-based investment bank. His work on information security topics has been published in journals such as Computers & Security and Information Security Bulletin. His homepage is homepage.mac.com/andrew_j_stewart


Product Details

  • Hardcover: 288 pages
  • Publisher: Addison-Wesley Professional; 1 edition (April 5, 2008)
  • Language: English
  • ISBN-10: 0321502787
  • ISBN-13: 978-0321502780
  • Product Dimensions: 9 x 6.1 x 1.3 inches
  • Shipping Weight: 1.3 pounds (View shipping rates and policies)
  • Average Customer Review: 4.4 out of 5 stars  See all reviews (15 customer reviews)
  • Amazon.com Sales Rank: #166,001 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #67 in  Books > Computers & Internet > Certification Central > Exams > Security+
    #94 in  Books > Computers & Internet > Web Development > Security & Encryption > Encryption

More About the Author

Adam Shostack
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's Adam Shostack Page

Inside This Book (learn more)

What Do Customers Ultimately Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 
(4)
(2)

Your tags: Add your first tag
 

 

Customer Reviews

15 Reviews
5 star:
 (7)
4 star:
 (7)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.4 out of 5 stars (15 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
19 of 21 people found the following review helpful:
5.0 out of 5 stars Book review I wrote for ITToolbox , April 24, 2008
If you want to read a book that will have an influence on your information security career, or if you just want to read something that points out that we do need to do information security differently, then you need to go pick up a copy of "The new school of information security" by Adam Shostack and Andrew Stewart.

The book reads like this blog, everything from Noam Epple and the "Security Absurdity" with the response article Noam Eppel Follow up to Security Absurdity and Security Absurdity - Is information security "Broken". All the way through some of the latest hacks from Two weeks, two security breaches in web 2.0 applications to Tom's excellent article on Even Oracle is not without security problems. There are some short sharp jabs in the side for information security people and managers that think they are safe behind their firewalls.

If anything is going to serve as the cup of coffee after Noam Epple's wake up call, it has to be this book. Which means you have to go buy it to get where we are going as an industry.

The New School of Information Security asks a lot of questions, that as a security community we need to answer. Everything from the value of the CISSP (is it just showing you can take a test, or does it really imply that the person knows something?), in a debate here that even people in the industry who love what we do can not answer. The idea of the CISSP is good, but the book speaks heresy, reliance on the CISSP is dangerous, dangerous to a company, it narrows the confines of the box when information security people need to be everywhere helping out.

The book also talks about issues within the company as simple as the firewall, to how programmers got around firewall blocks by routing programs over port 80, to the untrusted and trusted insider, to the fundamental bedrock of how we make decisions, the flawed and often meaningless statistics that come from research labs.

The whole industry is broken, and while we bask in our unregulated age, HIPAA, SOX, and other rules like PCI are just the shot across the bow on regulation, and more will be coming.

Programmers do not get it, neither do security folks. From requesting a 6 million dollar solution for a 30 minute test, to saying "no" to watching businesses move their IT requirements to Amazon EC2 or AWS, to dumping the traditional attitude - we are a group of people in trouble, and we need to read this book.

We need to shake up our communities, and the way that we work, not smarter, not harder, but working within the confines of realistic information security for the company that we are in. Best practices are just that, generic, you must tailor them for the risks that you have in your industry. To rely on Best Practices, NIST 800, ITIL, and other standards is to court disaster because no one is taking the specifics or unique issues of your particular industry.

They also talk about security appliances, vendors, trusted sites that have the branding truste and hacker safe, with some interesting comments on how those systems and certifications provide a false sense of security not just to the people running the site, but to the customers who visit them as well.

Much to ponder, some of it has shown up with the writers here at ITtoolbox as well, which is very nice, we have been talking about these very same issues for the last 2 years if you read this site. The book is a nice digest of what has been here, and available to folks who visit here or read via syndication or RSS.

Otherwise, we really will not need a "security industry" per say, we will just get rolled up into something else, and loose our unique and distinct culture.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
18 of 20 people found the following review helpful:
4.0 out of 5 stars Amateurs Study Cryptography; Professionals Study Economics, April 28, 2008
What a delightful chapter title in Adam Shostack's and Andrew Stewart's new book, The New School of Information Security. They have produced a readable, compact tour of the information security field as it stands today - or perhaps as it lies in its crib. What we know intuitively the authors bring forward thoughtfully in their analysis of the information security industry: it is struggling to keep up with the defects in online communication, data storage, and business processes.

Shostack and Stewart helpfully review the stable of plagues on computing, communication, and remote commerce: spam, phishing, viruses, identity theft, and such. Likewise, they introduce the cast of characters in the security field, all of whom seem to be feeling along in the dark together.

Why are the lights off? Lack of data, they argue. Most information security decisions are taken in the absence of good information. The authors perceptively describe the substitutes for good information, like following trends, clinging to established brands, or chasing after studies produced by or for security vendors.

The authors revel in the breach data that has been made available to them thanks to disclosure laws like California's SB 1386. A purist must quibble with mandated disclosure when common law can drive consumer protection more elegantly. But good data is good data, and the happenstance of its availability in the breach area is welcome.

In the most delightful chapter in the book (I've used it as the title of this review), Shostack and Stewart go through the some of the most interesting problems in information security. Technical problems are what they are. Economics, sociology, psychology, and the like are the disciplines that will actually frame the solutions for information security problems.

In subsequent chapters, Shostack and Stewart examine security spending and advocate for the "New School" approach to security. I would summarize theirs as a call for rigor, which is lacking today. It's ironic that the world of information lacks for data about its own workings, and thus lacks sound decision-making methods, but there you go.

The book is a little heavy on "New School" talk. If the name doesn't stick, Shostack and Stewart risk looking like they failed to start a trend. But it's a trend that must take hold if information security is going to be a sound discipline and industry. I'm better aware for reading The New School of Information Security that info sec is very much in its infancy. The nurturing Shostack and Stewart recommend will help it grow.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
13 of 14 people found the following review helpful:
5.0 out of 5 stars It is High Time for the New School, July 2, 2008
The New School of Information Security is one of the most timely and radical books on computer and information security that I've ever read. Adam Shostack and Andrew Stewart help to stimulate a significant paradigm shift that has been brewing in the infosec sphere for some time. With solid evidence and well grounded arguments Shostack and Stewart advocate for a new, and much needed, approach to information security: the New School.

Chapter 1 begins with a quick look at some prominent problems in the information security landscape today. By looking at spam, malware, identity theft, and computer breaches the authors provide a rough sketch of the current infosec landscape. Given the apparent failure of current approaches to security in the face of these threats the authors rhetorically pose the question of simply starting over and building a new approach from scratch before providing the opening sketch of their New School. The authors advocate the need for a new approach to computer security, the New School. The New School is described as quantifiable, "putting our ideas and beliefs through tests designed to draw out their flaws and limitations." This concept of metrics and empiricism is a common thread throughout the book.

Chapter 2 describes the "scene," or the state of the computer security industry today. By applying some elementary game theory the authors sketch out some of the dilemmas facing information security today. Then they delve into some of the historic origins of modern computer security. They point out that much of the computer security "conventional wisdom" has grown out of the military's needs for computer security and how that foundation isn't necessarily the best. They also explore the influence of hackers and crackers on the evolution of the industry. Finally they explore the relationship of capitalism and money to the field, including the driving factors of making money and how these have shaped the development of security today. The authors point out that while many good things have come from these various influences, they have also produced some unfortunate side effects that don't necessarily have to be taken for granted. The chapter goes on to examine the economy of the security industry, including the idea of "best practices" (which the authors very roundly decry) as well as turnkey solutions. The authors also point out the difficulty in measuring security products given the lack of objective test data produced in the sector. The chapter concludes with the though that "without proper use of objective data to test our ideas, we can't tell if we are mistaken or misguided in our judgement." They provide further evidence that the industry as a whole isn't often guided by any sort of quantifiable data (thus removing the 'science' from computer science) and that all too often "conventional wisdom" is misguided and sometimes blatantly wrong because it lacks a solid empirical foundation.

Chapter 3 looks at some of the underpinnings of gathering solid scientific evidence with which to test the ideas of the New School. Without good evidence, they point out, it is nearly impossible to make accurate decisions. The authors point out the problems with much of the evidence used to support common claims in computer security, including surveys, and show the bias present in much of the survey data used to justify security decision making. The chapter goes on to lament the lack of an objective trade press in the industry and then delves into the vulnerability discovery lifecycle that drives much of computer security. The authors examine how vulnerabilities are discovered, how vendors often ignore flaws in their products in their rush to market, and the fact that there are sometimes problems with using vulnerability reports as solid metrics for security. The chapter then goes on to examine how data about security can be collected, either by hobbyists or individuals. Ultimately, the authors lament the fact that much of the data collected about security isn't shared with the community and thus it becomes nearly impossible to make better decisions. The lack of objective, available data makes it extremely difficult for us to draw reliable conclusions based on trends or quantify the current state of security.

Chapter 4 looks at security breaches and specifically argues for the benefits of breach notification as one of the best ways to produce quantifiable metrics in security. The authors point out that breach notification rarely has long term consequences to a companies stock price or customer loyalty and the benefit of breach data would be invaluable to researchers. The authors argue that breach notification is a key component to the outlook of the New School. In joining the New School organizations have to learn "to focus on observation and objective measurement." They argue that only by doing so can we move information security from an art to a science. They say that while "it is true that computer security consists of a fog of moving parts...complex problems do get solved. Investigators bring a broad set of analytic techniques ranging from explanatory psychology...to complex economic models." At this point in the book the authors begin to introduce another key component of the New School, that is the need for integration of other fields of study into computer security. The authors argue that by utilizing approaches and theories developed in the fields of psychology, economics, sociology, and other academic areas our understanding of information security can be broadened and greatly enhanced. They always come back to ideas of empiricism, however, stating that "the core aspect of scientific research - the ability to gather objective data against which to test hypotheses - has been largely missing from information security." The authors emphasize that not only does data need to be collected, it must also be shared in order to aid in our understanding of the data.

Chapter 5 begins to draw upon outside fields of academia to enhance the New School. This chapter begins by introducing several economic models and explaining how they influence information security. While economic approaches to security are nothing new (risk mitigation, calculations of value and exposure equaling risk, etc.) the New School argues that "because computers are inevitably employed within a larger world, information security as a discipline must embrace lessons from a far wider field." The authors argue that economic models don't only have to be applied at a macro level to computer security, but can also be applied to more compartmentalized security problems (such as getting users to select good passwords). They also examine the success potential of certain security products based on economic analysis. The chapter goes on to discuss how lessons from psychology can be incorporated into our security decision making and to help us understand computer security more fully. Finally the chapter draws on lessons from sociology and shows how they too can inform our understanding of security.

Chapter 6 focuses on spending. The chapter is devoted to examining how organizations spend their money on information security and why. Like the earlier chapters, this one applies the New School approach to attempt to analyze spending habits and challenges many of the foundational logic that supports common security spending plans. The chapter draws on lessons from economics and psychology to examine the patterns of spending and suggests some ways in which we can improve our spending on security. Ultimately the authors argue that we understand the factors that should influence spending and focus our efforts on the most quantifiably effective expenditures of money.

Chapter 7, or Life in the New School, discusses many of the challenges facing the New School. These range from the lack of quality data to the dearth of a standardized security vocabulary. This chapter mainly points out the challenges that lie ahead and the many ways that a new approach can help overcome them.

Chapter 8 is a blanket call to join the New School along with instructions for how to begin. The authors argue that New School proponents should collect good data, analyze that data and seek new perspectives. They point out that the New School draws from a diverse body of academic knowledge and advocates synthesizing work from other academic area into the New School approach. Ultimately the New School challenges us to change how we think about information security. Not only should we question the "conventional wisdom" we take for granted, but we should also seek out new hypothesis and ways to test them in order to expand our understanding of computer security as a whole.

The book is an easy read and make quite an impression. Shostack and Stewart lead the charge towards a more empirical approach to computer security. The field has matured enough that we should begin treating it seriously, and in order to do so we need to be able to speak authoritatively about issues. The voodoo of conventional wisdom is no longer good enough when making recommendations as experts. We need to be able to point to solid evidence to justify security strategies and implementations. We also need to be able to look at quantifiable data when evaluating new products and tools. Ultimately I see the field moving in this direction and I give kudos to Shostack and Steward for issuing this clarion call to an industry that will hopefully take their message to heart.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars Good information security primer
While much of may read as a primer to an information security professional, there were some very interesting nuggets that could be found throughout this book, such as:... Read more
Published 7 months ago by Don Franke

5.0 out of 5 stars School of Knowledge
It is great to read a security book that is written by people who "Get It", when it comes to sloppy, lazy, "been there & done that" security professionals. Read more
Published 10 months ago by Bob Monroe

3.0 out of 5 stars Get to the point already
A wise man once said to give a great presentation, start with a great opening that catches the audience attention, close with a reminder of the useful tips you have shared and... Read more
Published 12 months ago by Stephen Northcutt

5.0 out of 5 stars Highly Recommended for All
I really enjoyed this book. Should you buy it and read it? Yes. I think there's no better evidence for your purchase than the fact that many smart people have already provided... Read more
Published 14 months ago by Alexander Hutton

4.0 out of 5 stars Should read if ...
Nutshell review - This book should be read if you are in any kind of management position related to information security. Read more
Published 15 months ago by Jos Pols

4.0 out of 5 stars Not much "new school" in The New School of Information Security
The previous reviews have adequately discussed the contents of The New School of Information Security (The New School). Read more
Published 15 months ago by R. Lewis

4.0 out of 5 stars A wake-up call for some, but not many answers
If you don't "get" Allan Schiffman's 2004 phrase "amateurs study cryptography; professionals study economics," if you don't know who Prof. Read more
Published 15 months ago by Richard Bejtlich

5.0 out of 5 stars Kicking Down Institutional Walls
This book commands attention! The authors bring to light current security practices, methods and decision analysis and their many shortcomings. Read more
Published 17 months ago by Jeffrey W. Bennett

4.0 out of 5 stars Recommended reading for information security practitioners
As an information security professional, I enjoyed reading this book. The authors present a somewhat compelling case for a scientific approach to information security that... Read more
Published 17 months ago by Jacob Gajek

4.0 out of 5 stars New School better than Old School
I think Adam and Andrew did some good work on the book. I just finished The New School of Information Security the other day. Read more
Published 17 months ago by Nathaniel Husted

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Discussion Replies Latest Post
About Taxes for the Nanny State 0 7 days ago
A Reversible Money Pump is in Sight 0 16 days ago
Search Customer Discussions
Search all Amazon discussions
   



So You'd Like to...


Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.