Security Assessment and over 360,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

Buy New
 

or
Sign in to turn on 1-Click ordering.
 
 
Buy Used
Used - Good See details
$16.22 & eligible for FREE Super Saver Shipping on orders over $25. Details

or
Sign in to turn on 1-Click ordering.
 
   
Express Checkout with PayPhrase
What's this? | Create PayPhrase
More Buying Choices
43 used & new from $6.49

Have one to sell? Sell yours here
 
   
Security Assessment: Case Studies for Implementing the NSA IAM
 
 
Start reading Security Assessment on your Kindle in under a minute.

Don’t have a Kindle? Get your Kindle here.
 
  

Security Assessment: Case Studies for Implementing the NSA IAM (Paperback)

~ Russ Rogers (Author), Greg Miles (Author), Ed Fuller (Author), Ted Dykstra (Author) "The National Security Agency (NSA) Information Security (INFOSEC) Assessment Methodology (IAM) is a detailed and systematic method for examining security vulnerabilities from an organizational perspective..." (more)
Key Phrases: critical information types, onsite phase, criticality matrices, Frequently Asked Questions, Medical Management, Ask the Author (more...)
3.8 out of 5 stars  See all reviews (5 customer reviews)

List Price: $69.95
Price: $50.95 & this item ships for FREE with Super Saver Shipping. Details
You Save: $19.00 (27%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Upgrade this book for $13.99 more, and you can read, search, and annotate every page online. See details
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Only 5 left in stock--order soon (more on the way).

Want it delivered Thursday, December 10? Choose One-Day Shipping at checkout. Details
Ordering for Christmas? To ensure delivery by December 24, choose FREE Super Saver Shipping at checkout. Read more about holiday shipping.

21 new from $14.99 22 used from $6.49

Formats

Amazon Price New from Used from
  Kindle Edition, January 16, 2004 $40.76 -- --
  Paperback, December 31, 2003 $50.95 $14.99 $6.49

Frequently Bought Together

Security Assessment: Case Studies for Implementing the NSA IAM + Network Security Evaluation Using the NSA IEM + FISMA Certification & Accreditation Handbook
Price For All Three: $157.66

Show availability and shipping details

  • This item: Security Assessment: Case Studies for Implementing the NSA IAM by Russ Rogers

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Network Security Evaluation Using the NSA IEM by Russ Rogers

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • FISMA Certification & Accreditation Handbook by L. Taylor

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought

Network Security Evaluation Using the NSA IEM

Network Security Evaluation Using the NSA IEM

by Russ Rogers
4.5 out of 5 stars (2)  $43.76
FISMA Certification & Accreditation Handbook

FISMA Certification & Accreditation Handbook

by L. Taylor
3.8 out of 5 stars (6)  $62.95
Network Security Assessment

Network Security Assessment

by Chris McNab
4.3 out of 5 stars (21)  $29.19
The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments

The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments

by Douglas J. Landoll
5.0 out of 5 stars (4)  $56.66
Security Metrics: Replacing Fear, Uncertainty, and Doubt

Security Metrics: Replacing Fear, Uncertainty, and Doubt

by Andrew Jaquith
4.6 out of 5 stars (20)  $34.64
Explore similar items

Editorial Reviews

Review

In 1998, the National Security Agency (NSA) Information Assurance Methodology (IAM) was developed to meet the demand for information security (INFOSEC) assessments-a demand that was increasing due to Presidential Decision Directive 63 (PDD-63) while at the same time NSA was downsizing. NSA sought a way to maximize its resources to assist as many customers as possible and so they created a list of organizations that could perform the same service as the NSA. NSA quickly realized that this system would not only provide valuable information to consumers-it would also provide a vehicle for standardization of INFOSEC assessments.

Define What Composes an Assessment
Learn about the NSA's three-phases: Assessment,
Evaluation, and Red teaming

Understand Industry Concerns for the Assessment Site
Review the items that affect your client: Health Insurance Portability and Accounting Act of 1996 (HIPAA), Sarbanes-Oxley, Financial Management and Accountability (FMA) Act, Family Education Rights and Privacy Act (FERPA), and others.

Create the Organizational Information Criticality Matrix (OICM)
Create the OICM, which provides a basis for everything else in the methodology and clarifies the intentions and goals of the assessment process for the customer.

Handle Documentation Identification and Collection
Work with the client to gather and define documents such as policy, guidelines, plans, SOPs, user documentation and see what happens when no documentation exists.

Understand the Technical Assessment Plan (TAP)
Use the TAP to define all dates and scheduling, personnel involvement, understood boundaries, deliverables, priority concerns, and priority constraints.

Review the 18 NSA INFOSEC Baseline Classes and Categories
Use these 18 categories to address the customer's security posture and determine what questions should be asked during the interview process.

Create a Recommendation Road Map
Provide the customer with a road map to the best way to address or implement the corrective measures for negative findings.

Understand the Findings
Assess the overall risk to a customer by looking at the threats, vulnerabilities, and asset value and analyze both negative and positive findings to create a true picture of the customer's security posture.

Register for Your 1 Year Upgrade
The Syngress Solutions upgrade plan protects you from content obsolescence and provides monthly mailings, whitepapers, and more!


Book Description

Everything you need to know to conduct a security audit of your organisation --This text refers to the Digital edition.

Product Details

  • Paperback: 448 pages
  • Publisher: Syngress; 1st edition (January 1, 2004)
  • Language: English
  • ISBN-10: 1932266968
  • ISBN-13: 978-1932266962
  • Product Dimensions: 9.3 x 6.8 x 0.9 inches
  • Shipping Weight: 1.9 pounds (View shipping rates and policies)
  • Average Customer Review: 3.8 out of 5 stars  See all reviews (5 customer reviews)
  • Amazon.com Sales Rank: #816,370 in Books (See Bestsellers in Books)

Inside This Book (learn more)
First Sentence:
The National Security Agency (NSA) Information Security (INFOSEC) Assessment Methodology (IAM) is a detailed and systematic method for examining security vulnerabilities from an organizational perspective as opposed to a only a technical perspective. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
critical information types, onsite phase, criticality matrices, information criticality, onsite portion, closeout meeting, customer followup, criticality matrix, followup process, current security posture, various information types, assessment team leader, impact attributes, overall security posture, questions about this chapter, sensitive customer information, assessment team members, ized access, scope drift, measure your understanding, customer team member, customer constraints, customer documentation, system criticality, warning banners
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Frequently Asked Questions, Medical Management, Ask the Author, Security Horizon, Source Rating Consequence, Planning Survey, Paper Justin Phun, Organizational Information Criticality Matrix, Finding Action, Finding Threat Impact Vulnerability, National Security Agency, Vulnerability Recommendation Target Date Responsibility, Digital Cole Ishin, Red Rover University, Weeks Pre-Assessment Visit, Assessment Methodology, Continued Interview, High Attacker, Mobile Phone, Weeks Weeks, High There, Maintenance System, Mapping Findings, Redundant Redundancy, Solutions Fast Track
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:


Books on Related Topics (learn more)
 
 

What Do Customers Ultimately Buy After Viewing This Item?

Security Assessment: Case Studies for Implementing the NSA IAM
85% buy the item featured on this page:
Security Assessment: Case Studies for Implementing the NSA IAM 3.8 out of 5 stars (5)
$50.95
FISMA Certification & Accreditation Handbook
7% buy
FISMA Certification & Accreditation Handbook 3.8 out of 5 stars (6)
$62.95
Network Security Evaluation Using the NSA IEM
5% buy
Network Security Evaluation Using the NSA IEM 4.5 out of 5 stars (2)
$43.76
IT Auditing: Using Controls to Protect Information Assets
2% buy
IT Auditing: Using Controls to Protect Information Assets 4.7 out of 5 stars (6)
$37.79

Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(7)

Your tags: Add your first tag
 

 

Customer Reviews

5 Reviews
5 star:
 (2)
4 star:
 (1)
3 star:
 (1)
2 star:
 (1)
1 star:    (0)
 
 
 
 
 
Average Customer Review
3.8 out of 5 stars (5 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
6 of 8 people found the following review helpful:
5.0 out of 5 stars Security Assessment a MUST have, February 10, 2004
By Travis Schack (Denver, CO) - See all my reviews
Whether you are an experienced security professional or just starting out in security, this book is a MUST for anyone serious about security. Although I have taken the NSA IAM training in the past, this book is a great compliment to the training.

The authors have combined their professional experience using the IAM with feedback and experiences from class participants and customers, and applied them to real world, practical, case studies. It demonstrates how the IAM, a thorough hands-off security assessment methodology, can be applied to both government and commercial entities. The book guides you through the entire IAM process, with highlighted tips and caveats that you will not get from any other source.

After you complete this insightful book, you will be armed with information that will be valuable to you, your company, and your customers in performing a thorough hands-off security assessment. This book will be a great reference for the IEM.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
1 of 1 people found the following review helpful:
3.0 out of 5 stars Good Resource For Implementing NSA IAM, November 7, 2004
The authors' have a wealth of experience in information security and with the IAM framework. They convey this experience through case studies derived from real-world scenarios to provide examples that illustrate the IAM in action.

Security Assessment demonstrates how to apply the NSA IAM to commercial and government organizations alike to determine the relative security of their network. The authors' provide tips and advise readers of pitfalls to watch out for as they guide you through performing an IAM security assessment.

The book is both informative and at times entertaining as it walks through sample scenarios. It also provides some templates and sample deliverables that readers can use.

The authors' knowledge and experience is evident throughout, however parts of the book are slightly confusing or hard to follow. Sometimes it seemed as if extra words were added in just to stretch the chapter out without providing any benefit in terms of relaying information. But, overall I think that network or security administrators and particularly those tasked with actually following the NSA IAM will benefit greatly from reading this book.

(...)
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
3 of 4 people found the following review helpful:
4.0 out of 5 stars How To Manage The Security Assessment Process, April 26, 2005
There are two things that are extremely frustrating in working on audits and risk and security assessments. One is that too many people in online discussion fora and ListServs want templates handed to them free so they can resell them or tell their boss about the great work that they did. The second has been the absence of, in the technical book arena, any reference book that focuses more on the business process side of conducting security assessments. Security Assessment - Case Studies for Implementing The NSA IAM (Greg Miles, Russ Rogers et al, Syngress Press, 2004, 429 Pages, US$69.95 List/US$44.07 Amazon) fills both of these holes, but not without incurring a penalty stroke for "grounding the club" in a hazard.

IAM stands for Information Security (INFOSEC) Assessment Methodology and NSA stands for the National Security Agency. These are two things you learn right up front from the authors as the explain how this methodology came to be a the result of the need to do more in a time of budget cuts and its evolution into a broad methodology that can be used by any group in the public or private sector. From this start and background, the authors successfully walk the reader through the "soft skill" side of the security assessment process. What makes this book different than others is that there is little to no discussion of tools used in the assessment. What it does focus on is how to identify assessment needs (for the customer) and opportunities (for the consulting firm). The authors approach security assessments from a holistic project approach, taking the reader through issues and steps with contract preparation/execution, skills identification, team makeup, preplanning, identification of high risk areas, conducting the assessment, delivering the end product, and closing the project out.

For the most part, the authors excel in laying this out in simple terms and provide a number of case studies from their experience. However, as I mentioned at the beginning, I am assessing a penalty stroke in my rating because their discussion of performing security assessment work under government contracts is far too simplistic, is not wholly accurate in their discussion of contract types, and does not even address the issue of all of the additional reporting and cost accounting standards that a vendor will have to accept when doing government work. They also fail to mention how large the universe is of competitors for this work and how difficult it can be to crack this marketplace. They also fail to address legal issues associated with the scope creep in government work, with no discussion of important terms such as "constructive changes", "unauthorized commitments", "change orders", etc. They talk about "colors of money" in the government without even explaining what the term means. Granted, the book could have easily quadrupled in size to address all of this information, but they should have at least included references to sources to provide further insight into these important areas. Oh, and incidentally, the color of money under government contracts is, for the most part, transparent to contractors.

Aside from this penalty stroke, and I am harder on it because I was a Contracting Officer in the Federal Government for a number of years, the book provides an excellent roadmap to groups and/or individuals seeking a security assessment roadmap.

Who Should Read This Book?

Aside from the people who post on the internet looking for solutions to be handed to them, this book would satisfy the needs of a wide variety of users. Practitioners will gain information and insight not provided in typical training classes. Customers would gain a good overview of the process and what to expect as the process goes on. Managers need to read this book so that they do not, as the authors point out often happens, try to turn this methodology into a business process. And finally, Sales staff need to read this book so that they understand what they are trying to sell and that it is not a one size fits all commodity (kudos to the authors for putting this in writing, but it is not enough to recover the penalty stroke).

Scorecard

Birdie on an short par 5 playing downwind (penalty stroke can be a killer).
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars The IAM from a real world perspective
Whether you are currently performing IAM assessments, or if you or your organization wants to begin using the IAM, this book is an excellent reference. Read more
Published on April 28, 2004

2.0 out of 5 stars Disappointed...
This book disappointed me with it's lack of content and diffused focus. Pages of boorish, made up examples with irrelevant details did not provide the necessary information needed... Read more
Published on February 11, 2004 by Ryan M. Ferris

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Discussion Replies Latest Post
Textbooks for Kindle DX? 70 2 hours ago
sure need a ton of protection 0 5 days ago
textbook scam 78 10 days ago
Search Customer Discussions
Search all Amazon discussions
   




Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.