or
Sign in to turn on 1-Click ordering.
 
 
Express Checkout with PayPhrase
What's this? | Create PayPhrase
More Buying Choices
24 used & new from $116.35

Have one to sell? Sell yours here
 
   
Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here.
 
  

Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans (Hardcover)

~ (Author) "What drives revenue and profit in today's economy is undoubtedly the mix of hardware, software, and services..." (more)
Key Phrases: discussion with the network administrator, physical access privileges, concurrent device sessions, Server Operators, Category Control Objectives Risk, Choose Policies (more...)
1.0 out of 5 stars  See all reviews (2 customer reviews)

Price: $150.00 & this item ships for FREE with Super Saver Shipping. Details
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

14 new from $130.99 10 used from $116.35

Editorial Reviews

Product Description

A complete and definitive guide to auditing the security of IT systems for managers, CIOs, controllers, and auditors

This up-to-date resource provides all the tools you need to perform practical security audits on the entire spectrum of a company’s IT platforms–from the mainframe to the individual PC–as well as the networks that connect them to each other and to the global marketplace. Auditing and Security: AS/400, NT, Unix, Networks, and Disaster Recovery Plans is the first book on IT security written specifically for the auditor, detailing what controls are necessary to ensure a secure system regardless of the specific hardware, software, or architecture a company runs. The author uses helpful checklists and diagrams and a practical, rather than theoretical, method to understanding and auditing a company’s IT security systems and their requirements. This comprehensive volume covers the full range of issues relating to security audits, including:

  • Hardware and software
  • Operating systems
  • Network connections
  • The cooperation of logical and physical security systems
  • Disaster recovery planning

From the Inside Flap

According to law enforcement figures, American corporations lose billions of dollars a year due to IT security breaches. Auditing and Security: AS/400, NT, Unix, Networks, and Disaster Recovery Plans provides the tools that an auditor needs to ensure that a company’s platforms and networks are adequately protected.

Auditing information systems for security requires knowledge across a wide range of disciplines beyond computer science, including management science, information security, accounting, finance, business, and human resources. This book supplies the vital information across these divergent fields that auditors, IT managers, controllers, and CIOs need to measure the security of their systems. This comprehensive volume covers the full range of issues relating to security audits–hardware, operating systems, network connections, the cooperation of logical and physical security measures, and disaster recovery planning.

The author begins with an overview of the structure of information systems and their security requirements and then shows you how physical and logical security systems work together to create a safe corporate information structure. Comprehensive treatment of the different structures and security needs of AS/400, Microsoft NT, and Unix allows you to understand security requirements regardless of which computer architecture a company runs. Auditing and Security also uses helpful checklists and diagrams and a practical, rather than theoretical, method for understanding hardware, operating systems, and the networks that enable the interconnection of platforms and applications. Another important topic this volume covers is disaster recovery planning to help you ensure that IT systems and the information they safeguard are recoverable in the event of a major disruption in service or intentional destruction of data.

This up-to-date resource provides all the tools you need to perform practical security audits on the entire spectrum of a company’s various IT platforms–from the mainframe to the individual PC–as well as the networks that connect them to each other and to the global marketplace. Auditing and Security: AS/400, NT, Unix, Networks, and Disaster Recovery Plans is the first book on IT security written specifically for the auditor, detailing what controls are necessary to ensure a secure system regardless of the specific hardware, software, or architecture a company runs.


Product Details

  • Hardcover: 552 pages
  • Publisher: Wiley; 1 edition (February 21, 2001)
  • Language: English
  • ISBN-10: 0471383716
  • ISBN-13: 978-0471383710
  • Product Dimensions: 10.2 x 7.3 x 1.3 inches
  • Shipping Weight: 2.8 pounds (View shipping rates and policies)
  • Average Customer Review: 1.0 out of 5 stars  See all reviews (2 customer reviews)
  • Amazon.com Sales Rank: #2,080,695 in Books (See Bestsellers in Books)

    Popular in this category: (What's this?)

    #16 in  Books > Computers & Internet > Security & Encryption > Unix Security

More About the Author

Yusufali F. Musaji
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's Yusufali F. Musaji Page

Inside This Book (learn more)
First Sentence:
What drives revenue and profit in today's economy is undoubtedly the mix of hardware, software, and services. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
discussion with the network administrator, physical access privileges, concurrent device sessions, user profile level, corporate security standards, trusted system components, verify that all users, primary log file, user profile parameter, privileged account passwords, system distribution directory, setgid programs, dedicated service tools, replicator account, default account policies, default public authority, user environment profiles, vital business processes, auditing status, audit log file, portable storage media, access control list entries, select success, firmware environment variables, setuid programs
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Server Operators, Category Control Objectives Risk, Choose Policies, Authority Holders, Full Control System, Print Operators, Security Administration Activities, System Key Lock, Full Control Everyone, Click Cancel, Account Operators, Audit Test, Click the Permissions, Recommended Permissions, Unix Reference Manual, Choose Select Domain, System Policy Editor, Control Techniques Restrict, Ensure the Rudit These Events, Network File System, Password Management, Audit Objective Users, Confirm Password, Creator Owner, Data Authorities
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:




What Do Customers Ultimately Buy After Viewing This Item?

Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans
65% buy the item featured on this page:
Auditing and Security: AS/400, NT, UNIX, Networks, and Disaster Recovery Plans 1.0 out of 5 stars (2)
$150.00
IT Auditing: Using Controls to Protect Information Assets
35% buy
IT Auditing: Using Controls to Protect Information Assets 4.4 out of 5 stars (7)
$37.79

Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

2 Reviews
5 star:    (0)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:
 (2)
 
 
 
 
 
Average Customer Review
1.0 out of 5 stars (2 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
3 of 4 people found the following review helpful:
1.0 out of 5 stars Not a good source for recent AS/400 info, April 15, 2003
By John Earl (Gig Harbor, WA United States) - See all my reviews
Because the book was published in 2001, and it used the AS/400 name in it's title, I expected it to be a good source on recent developments in security on the AS/400 (AKA the IBM iSeries). I am dissapointed. While the information that is included in the book seems generally accurate (I have a few quibbles in areas like QSECURITY, Adopted Authority, CHGSYSLIBL, and CRTAUT to name a few), the big problem is that there are huge chunks of current technologies that are not even addressed in this audit standard.

Some examples include, the entire IFS (Integrated File System), Operations Navigator, NetServer and other network servers like SMTP, HTTP, FTP, etc. No reference to exit programs beyond the ancient PCSACC and DDMACC network attirbutes, spotty acknowledgement of System Values added after V3R1 (1995?) and a general lack of understanding of what the potential security exposures might be in areas that were audited. It's one thing to say that you should "discuss with management" the existance on a workstation entry in subsystem QDSNX, but what is an auditor to discuss if the author hasn't explained the potential security exposure?

It may be a rally good book with respect ot the other OS's that it purports to cover, but from an OS/400 perspective it is not current enough to be very effective on modern versions.

Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No


 
1.0 out of 5 stars Not intended for auditors, September 18, 2009
By Dave (New York, NY) - See all my reviews
As an experienced Technology Auditor, I picked up this book to brush up on some of the considerations involved in auditing UNIX systems. After reading through most of the section on UNIX, I couldnt help but think that this book was written without considering the intended audience. Generally speaking, an IT Auditor has to be a jack-of-all-trades when it comes to systems, because it is extremely difficult to find a company that uses ONLY Unix, or ONLY Windows, or ONLY Linux. As a result, the IT Auditor has to know enough about each system to navigate through, but is not necessarily an expert in any of them.

This book seems to be written for a security administrator, assuming that the reader knows the details of every command the system has to offer and offering little or no explanation as to what the command does. Convincing a system administrator to run a command that you, as the auditor, do not understand is potentially disasterous.

Beyond that, typos and spelling errors within the commands (ex: using "is -1" instead of "ls -l" or "chcl" instead of "chacl"), are simply inexcusable for what they are charging for this book.
Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Discussion Replies Latest Post
Sketchy textbook transaction on Marketplace 18 14 hours ago
textbook scam 129 2 days ago
Search Customer Discussions
Search all Amazon discussions
   


Listmania!


Create a Listmania! list

So You'd Like to...


Create a guide

Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.