Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
40 used & new from $0.80

Have one to sell? Sell yours here
 
   
The Process of Network Security: Designing and Managing a Safe Network
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

The Process of Network Security: Designing and Managing a Safe Network (Paperback)

by Thomas A. Wadlow (Author)
4.2 out of 5 stars See all reviews (8 customer reviews)

List Price: $39.99
Price: $39.99 & this item ships for FREE with Super Saver Shipping. Details
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Only 2 left in stock--order soon (more on the way).

Want it delivered Wednesday, July 15? Choose One-Day Shipping at checkout. Details
21 new from $15.79 19 used from $0.80

Frequently Bought Together

Customers buy this book with Secrets and Lies: Digital Security in a Networked World by Bruce Schneier

The Process of Network Security: Designing and Managing a Safe Network + Secrets and Lies: Digital Security in a Networked World
  • This item: The Process of Network Security: Designing and Managing a Safe Network by Thomas A. Wadlow

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Secrets and Lies: Digital Security in a Networked World by Bruce Schneier

    In Stock.
    Ships from and sold by Amazon.com.
    Eligible for FREE Super Saver Shipping on orders over $25. Details


Customers Who Bought This Item Also Bought

Secrets and Lies: Digital Security in a Networked World

Secrets and Lies: Digital Security in a Networked World

by Bruce Schneier
4.4 out of 5 stars (127)  $12.21
Writing Information Security Policies (Landmark)

Writing Information Security Policies (Landmark)

by Scott Barman
4.5 out of 5 stars (11)  $34.99
Explore similar items

Editorial Reviews

Product Description
Reveals the approaches, techniques, and best practices that effectively secure the modern workplace. Discusses the issues involved and the specific steps of setting up a secure system, focusing on standard operating procedures and dayto-day operations and maintenance. Softcover. DLC: Computer networks--Security measures.

From the Inside Flap

A friend of mine said to me the other day that he wanted his old Internet back again. Things worked as well as they needed to. Everyone was nice. You could send mail to people you'd never met, and you'd typically get a nice reply. People gained access to different machines all around the world, which was given more or less freely, so you could log into those machines and see what they'd accomplished this month or just chat with friends. If something needed to be done, a bunch of smart people got together and did it, without too much fuss or bother. It was a nice place, for the most part.

He really wasn't serious, this friend of mine. He makes his living using the Internet we have today and by speaking about the Internet we'll have tomorrow. He gets most of his news from CNN's Web site, and the computer industry-specific sites such as Slashdot and Freshmeat. I can't remember the last time he traveled without a laptop; you can send him e-mail anywhere he travels, and (if you get past his filtering software) he'll answer it from Tokyo or Singapore or Paris. The Internet is probably the most complicated thing created by the human race, and yet it is (relatively speaking, of course) easy to use and just about everywhere you'd want it to be.

But I understand his point. The Internet isn't the friendly place it used to be. What was once a small town, where neighbors were friendly and you could leave your door unlocked, is now the largest (virtual) community in the world, and it's growing bigger every day. There are bad parts of town, and there are muggers and thieves and con men, just as in every other city on Earth. You can't get beaten up, but you can be robbed of your time and in some cases of your money.

For all that, the Internet is probably the safest community of its size ever in existence. But that isn't something to take much comfort in. The reason I say this is that I and other members of my profession are called on to look at the security of sites on the Internet from time to time. I know the Internet is mostly safe, because the doors to most places are still unlocked and yet major catastrophes have not happened. Reasoning from that, it appears that most of the people on the Internet are not Bad Guys. Not yet, anyway.

Of course, this can change at any time. And it has begun to. The 1990s saw an ever-growing number of people systematically trolling for computer weaknesses. These people are not trying to attack a specific site; rather, they are just fishing to see what they can catch. The late 1990s saw the beginning of Internet attacks for political reasons. As this book was written, the news media referred to the conflict in Kosovo as the "First Internet War" because of several hostile incidents that occurred and also because much of the unofficial communication between sides was taking place over the Internet.

The Internet is becoming a dangerous place. But it is important to see this in perspective. Any large community has its bad neighborhoods, robberies, muggings and trouble spots, but that doesn't mean it is impossible to live and work there safely. The trick is to keep your eyes open, take reasonable precautions, and not act foolishly. The same rules apply to the Internet.

But computer security means far more these days than the ability of one person to protect himself or herself from the dangers that can arise on the Internet. It's one thing to protect yourself. It's a very different thing indeed to protect a hundred computers, or a thousand, or ten thousand.

This book is intended for the people facing that formidable challenge and the people who will assist in such an endeavour. It is not a tutorial on how to become a hacker. Nor is it a technical manual on how to run a large computer network. Many other sources cover those subjects, for better or worse. My goal here is to give a person charged with the responsibility of running the network security for a large organization a tool for understanding the language and practices of network and computer security, and to provide some hints along the way to save some time and some scraped knuckles. As with any large project, there are many ways to approach these issues. I don't claim that this book is an exhaustive survey of all possible ways. It is, however, a collection of good methodology and tips and tricks, with some warning signs at the rough spots, that have worked for me.

So who am I? Well, I am an electrical engineer by training, but I was swept up into computer science in my high school and college years. My first experience with the Internet was in the late 1970s, when I discovered that I could connect from Carnegie-Mellon University, where I went to school, to a machine in London, England, over something called the ARPANET, which was just appearing on the scene at that time. Like many others at CMU, I worked in the university Computer Center. Unlike many of my colleagues there, I've kept much the same job ever since, running larger and larger collections of computers and their networks at Lawrence Livermore Laboratory, Schlumberger's Palo Alto Research Center, Xerox's Palo Alto Research Center, ParcPlace Systems, and Sun Microsystems Laboratories. Along the way, I've learned a few things about keeping large collections of machines happy and healthy and about keeping the Bad Guys out and the Good Guys working. Now I find myself as the Chief Technology Officer and Vice President of Security for Pilot Network Services, Inc., a company I helped to found and whose function is to handle Internet security for our customers, a diverse collection of some of the most dynamic and interesting (as well as the largest) companies on Earth. The principles we use to run our business safely can be found in this book. That may strike you as odd, creating a book that says how we do our business, because it enables people to compete against us, using our own principles. Well, read on. If you still think it's easy, give it a shot. We welcome the competition. Acknowledgments

A great many people helped me with the production of this book, directly or indirectly, but I'd like to thank several specifically:

Dr. Martine Droulers and Dr. Celine Broggio, wonderful friends who fed me delicious food and gave me the use of their French seaside attic to finish the book. Fromage! Eileen Keremitsis, who put up with my grumbling, made sure that I wasn't working too hard, and was ready with an invitation to dinner whenever I needed one. Dennis Allison, who tempted me back into the book-writing business after a long absence, and Karen Gettman and Mary Hart of Addison-Wesley, who made sure that I stayed the course. Steve Riley, Joseph Balsama, Steve Rader, John Stewart, and Clifford Neuman, who read the entire manuscript and whose numerous and insightful comments I found very helpful. And of course, the people at Pilot Network Services, who are the hardest working and nicest bunch of security folks I've ever met.

Tom Wadlow
San Francisco, California, USA
Le Crotoy, Picardie, France, 2000 0201433176P04062001

See all Editorial Reviews


Product Details

  • Paperback: 304 pages
  • Publisher: Addison-Wesley Professional (March 12, 2000)
  • Language: English
  • ISBN-10: 0201433176
  • ISBN-13: 978-0201433173
  • Product Dimensions: 9.2 x 7.3 x 0.8 inches
  • Shipping Weight: 1.3 pounds (View shipping rates and policies)
  • Average Customer Review: 4.2 out of 5 stars See all reviews (8 customer reviews)
  • Amazon.com Sales Rank: #1,356,868 in Books (See Bestsellers in Books)

Look Inside This Book


Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

8 Reviews
5 star:
 (5)
4 star:
 (2)
3 star:    (0)
2 star:    (0)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
4.2 out of 5 stars (8 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
10 of 10 people found the following review helpful:
4.0 out of 5 stars A really good starting point for network security, October 30, 2000
The problem with most introductory books is that they are written in an overly simplistic and long-winded style. The Process of Network Security is different in that respect, and it is indeed an effective introduction to the world of network security.

What differentiates this book from other introductory texts is that author Thomas Wadlow treats information systems security not as a set of different technologies, but rather as an integrated process. By viewing security as an evolving process, a network manager can create a security methodology that can develop into a strong foundation for the company's information security program.

The book is written for network managers and systems administrators who have been give different security responsibilities within their organizations and provides them with a comprehensive overview of the critical aspects involved with information systems security. While it is, of course, impossible to build security systems that are absolutely secure, the book demonstrates that a thorough process incorporating good designs can isolate security so that problems in one specific area aren't catastrophic to the entire system.

Wadlow is an industry veteran, and his experience shines throughout the book. The work covers all the major aspects of information security, including security team building, network monitoring, intrusion detection, and damage control. For those wanting a taste of what information security is all about, in a book written in a real-world format for an intelligent reader, this book is an excellent choice.

This review of mine originally appears at http://www.securitymanagement.com/library/000905.html

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
9 of 9 people found the following review helpful:
5.0 out of 5 stars What you REALLY need to know about computer security!, January 8, 2001
By Peg Schafer (Harvard University, Cambridge, MA United States) - See all my reviews
I teach computer systems management to students here at Harvard University. Every day someone asks me a question that is answered in Mr. Wadlow's book. Here he explains the way to *_think_* about computer security - before you implement any solution. For anyone who has to design a secure computing infrastructure, Mr. Wadlow's book is the book for you! The art of Computing Security has been made clear by Mr. Wadlow's thoughtful discussions of the trade offs. Every manager of computing professionals should read this book. Mr. Wadlow's writing style is entertaining and informative. Spend a morning with this book and your afternoon will be very productive.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
8 of 8 people found the following review helpful:
5.0 out of 5 stars An approach that goes to the essence of proactive security, April 9, 2001
Mr. Wadlow has written a truly useful book that sorts out the many facets of security and recasts them into a complete and straightforward approach to implementing an effective security organization. The only thing I found wrong with this book is the title because the approach is not confined to network security. This book serves as a model for all IT security, and can be applied to data centers, servers and the other components of a large, complex IT suite.

He starts out with the foundation, writing a security policy, and offers excellent advice on how to go about this important task. Policy writing is an art and a science, and it is apparent that Mr. Wadlow knows his stuff here. An ambiguously worded or unenforceable policy is next to worthless and he shows how to avoid both of those pitfalls.

I liked the chapter titled "Who is Attacking You?" because it forces you to carefully consider threats and exposures, which is the first step towards crafting a plan for dealing with them. I also liked the chapter on the security design process because it is methodical and repeatable. One of the difficulties in developing an encompassing security approach is driving the stake into the ground, and the process given shows just where to drive it and how to proceed from there. This is a good prelude to the chapter on building a security team, which proposes a sensible structure and completely addresses requirements.

The chapters on the technical aspects, such as fortifying network components, physical security, and network monitoring and auditing are true best practices and can be modified to fit other areas of IT (as mentioned at the beginning of this review).

As a consultant I particularly liked the chapter that addresses quantifying the value of security. However, this is not only for consultants - security is expensive and requires both dedication and resources, both of which are costly. This material goes a long way towards building a compelling business case for an effective security posture and for proving its ongoing value to management who might think of it as a necessary evil that sucks up more budget share than it is worth. When faced with the wild world of attackers and the internal bean counters it is sometimes difficult to determine who the real enemy is :-)

The book ends with excellent chapters on preparing for an attack, handling it and analyzing the aftermath for lessons learned and future preventive measures to incorporate. Overall, this section is the life cycle of an incident and should be carefully read.

I obviously like this book a lot. I think it provides a structure and method for designing and implementing a sound and effective security strategy. Moreover, the approach can easily be expanded to encompass off of IT, making this book all the more valuable. I strongly recommend and would give it more than 5 stars if I could.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Nice addition for security library
I got this book and I am happy that I bought it. Read it twice - gives really practical advise on security issues. Read more
Published on September 13, 2002

4.0 out of 5 stars Excellent source for understanding the business of security.
Full disclosure: I was one of the technical reviewers for this book. It was a pleasure to review Wadlow's book because it was the first one I've seen that covers security at the... Read more
Published on August 8, 2000 by Steve M Riley

1.0 out of 5 stars Network Security 101
For the techno-security newbie. Wadlow covers too much territory at such a high level that it almost reads like an outline. Read more
Published on June 11, 2000

5.0 out of 5 stars A clear vision of quality network security
Wadlow's _The Process of Network Security: Designing and Managing a Safe Network_ may set a new standard for presenting information about the policies, procedures and designs... Read more
Published on May 24, 2000 by Steve Rader

5.0 out of 5 stars Deserves to become a classic
Wadlow's new book is full of sage and useful guidance for medium to large organizations that are completely dependent upon the Internet. Read more
Published on April 9, 2000 by J. G. Heiser

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Product Information from the Amapedia Community

Beta (What's this?)

Listmania!



Look for Similar Items by Category


Don't Slip and Slide

HeatTrak Heated Walkway

Keep your walkways safe and clear of snow and ice using the HeatTrak heated walkway.

Shop all HeatTrak heated walkways

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Summer Reading for Kids & Teens

Summer Reading for Kids and Teens
Discover everything from beach reads and board books to teen romance and action-adventure series in Summer Reading for Kids & Teens. And, check off the kids' required reading lists in our Summer School Reading Store.
 

Strengthen Your Joints

Shop for biscuit joiners
With a biscuit joiner you can create joints in a fraction of the time it takes using more traditional woodworking techniques.

Shop for biscuit joiners

 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Glenn Beck's Common Sense
Glenn Beck's Common Sense

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates