logo

CardDev

مسیر یادگیری
logo

CardDev

کتاب راهنمای امنیت دفاعی، ویرایش دوم

0 فلش‌کارت
0 گالری‌کارت
0 صوت
0 پرامپت
0 واژه‌نامه

با وجود افزایش حملات سایبری برجسته، نشت داده‌های بی‌سابقه و حملات باج‌افزاری، بسیاری از سازمان‌ها بودجه کافی برای یک برنامه امنیت اطلاعات (InfoSec) ندارند. اگر مجبورید با بداهه‌پردازی در حین کار از خود محافظت کنید، این راهنمای عملی یک کتابچه راهنمای امنیت-۱۰۱ را با گام‌ها، ابزارها، فرآیندها و ایده‌هایی ارائه می‌دهد تا به شما کمک کند حداکثر بهبود امنیتی را با هزینه کم یا بدون هزینه به دست آورید. هر فصل از این کتاب دستورالعمل‌های گام به گام برای مقابله با مسائلی مانند نقض امنیتی و بلایا، انطباق، زیرساخت شبکه، مدیریت رمز عبور، اسکن آسیب‌پذیری، تست نفوذ و موارد دیگر را ارائه می‌دهد. مهندسان شبکه، مدیران سیستم و متخصصان امنیت یاد خواهند گرفت که چگونه از چارچوب‌ها، ابزارها و تکنیک‌ها برای ساخت و بهبود برنامه‌های امنیت سایبری خود استفاده کنند. این کتاب به شما کمک خواهد کرد: برنامه‌ریزی و طراحی پاسخ به حوادث، بازیابی فاجعه، انطباق و امنیت فیزیکی. یادگیری و به کارگیری مفاهیم پایه تست نفوذ از طریق تیم‌سازی بنفش (Purple Teaming). انجام مدیریت آسیب‌پذیری با استفاده از فرآیندها و ابزارهای خودکار. استفاده از IDS، IPS، SOC، ثبت وقایع (Logging) و نظارت. تقویت سیستم‌های مایکروسافت و یونیکس، زیرساخت شبکه و مدیریت رمز عبور. استفاده از روش‌ها و طراحی‌های تقسیم‌بندی (Segmentation) برای بخش‌بندی شبکه شما. کاهش خطاهای قابل بهره‌برداری با توسعه کد به صورت امن.

اشتراکی

book cover
O’Reilly
0 فلش‌کارت
0 گالری‌کارت
0 صوت
0 پرامپت
0 واژه‌نامه
جزئیاتمقدمهفصل‌هانسخه‌ها

فصل های کتاب

با مرور فصل‌ها، ساختار ، محتوای کتاب را به سرعت بشناسید.

با مرور فصل‌های این کتاب می‌تونی خیلی سریع بفهمی هر بخش چی یاد میده، ساختار کلی چطوره و از کجا باید شروع کنی. هر فصل روی یک مفهوم یا مهارت خاص تمرکز داره و موضوعات اصلیش رو می‌بینی تا انتخابت آگاهانه‌تر باشه. چه بخوای کل کتاب رو دنبال کنی، چه فقط یک بخش خاص رو دنبال کنی، این نما کمکت می‌کنه مسیرت رو پیدا کنی.

book cover

ایجاد یک برنامه امنیتی

Laying the Groundwork • Establishing Teams • Determining Your Baseline Security Posture • Assessing Threats and Risks • Identify Scope, Assets, and Threats • Assess Risk and Impact • Mitigate • Monitor • Govern • Prioritizing • Creating Milestones • Use Cases, Tabletops, and Drills • Expanding Your Team and Skillsets • Conclusion

فصل 1

درحال تولید...

book cover

مدیریت دارایی و مستندسازی

What Is Asset Management? • Documentation • Establishing the Schema • Data Storage Options • Data Classification • Understanding Your Inventory Schema • Asset Management Implementation Steps • Defining the Lifecycle • Information Gathering • Change Tracking • Monitoring and Reporting • Asset Management Guidelines • Automate • Establish a Single Source of Truth • Organize a Company-wide Team • Find Executive Champions • Keep on Top of Software Licensing • Conclusion

فصل 2

درحال تولید...

book cover

سیاست‌ها

Language • Document Contents • Topics • Storage and Communication • Conclusion

فصل 3

درحال تولید...

book cover

استانداردها و رویه‌ها

Standards • Procedures • Document Contents • Conclusion

فصل 4

درحال تولید...

book cover

آموزش کاربر

Broken Processes • Bridging the Gap • Building Your Own Program • Establish Objectives • Establish Baselines • Scope and Create Program Rules and Guidelines • Provide Positive Reinforcement • Define Incident Response Processes • Obtaining Meaningful Metrics • Measurements • Tracking Success Rate and Progress • Important Metrics • Conclusion

فصل 5

درحال تولید...

book cover

پاسخ به حوادث

Processes • Pre-Incident Processes • Incident Processes • Post-Incident Processes • Tools and Technology • Log Analysis • EDR/XDR/MDR/All the “Rs” • Disk and File Analysis • Memory Analysis • PCAP Analysis • All-in-One Tools • Conclusion

فصل 6

درحال تولید...

book cover

بازیابی فاجعه

Setting Objectives • Recovery Point Objective • Recovery Time Objective • Recovery Strategies • Traditional Physical Backups • Warm Standby • High Availability • Alternate System • System Function Reassignment • Cloud Native Disaster Recovery • Dependencies • Scenarios • Invoking a Failover...and Back • Testing • Security Considerations • Conclusion

فصل 7

درحال تولید...

book cover

استانداردها و چارچوب‌های انطباق صنعتی

Industry Compliance Standards • Family Educational Rights and Privacy Act (FERPA) • Gramm-Leach-Bliley Act (GLBA) • Health Insurance Portability and Accountability Act (HIPAA) • Payment Card Industry Data Security Standard (PCI DSS) • Sarbanes-Oxley (SOX) Act • Frameworks • Center for Internet Security (CIS) • Cloud Control Matrix (CCM) • The Committee of Sponsoring Organizations of the Treadway Commission (COSO) • Control Objectives for Information and Related Technologies (COBIT) • ISO-27000 Series • MITRE ATT&CK • NIST Cybersecurity Framework (CSF) • Regulated Industries • Financial • Government • Healthcare • Conclusion

فصل 8

درحال تولید...

book cover

امنیت فیزیکی

Physical • Restrict Access • Video Surveillance • Authentication Maintenance • Secure Media • Datacenters • Operational Aspects • Identifying Visitors and Contractors • Physical Security Training • Conclusion

فصل 9

درحال تولید...

book cover

زیرساخت مایکروسافت ویندوز

Quick Wins • Upgrade • Third-Party Patches • Open Shares • Active Directory Domain Services • Forests • Domains • Domain Controllers • Organizational Units • Groups • Accounts • Group Policy Objects (GPOs) • Conclusion

فصل 10

درحال تولید...

book cover

سرورهای کاربردی یونیکس

Keeping Up-to-Date • Third-Party Software Updates • Core Operating System Updates • Hardening a Unix Application Server • Disable Services • Set File Permissions • Use Host-Based Firewalls • Manage File Integrity • Configure Separate Disk Partitions • Use chroot • Set Up Mandatory Access Control • Conclusion

فصل 11

درحال تولید...

book cover

نقاط پایانی

Keeping Up-to-Date • Microsoft Windows • macOS • Unix Desktops • Third-Party Updates • Hardening Endpoints • Disable Services • Use Desktop Firewalls • Implement Full-Disk Encryption • Use Endpoint Protection Tools • Mobile Device Management • Endpoint Visibility • Centralization • Conclusion

فصل 12

درحال تولید...

book cover

پایگاه‌های داده

Introduction to Databases and Their Importance in Information Security • Database Implementations • Common Database Management Systems • A Real-World Case Study: The Marriott Breach • Database Security Threats and Vulnerabilities • Unauthorized Access • SQL Injection • Data Leakage • Insider Threats • Defense Evasion • Database Security Best Practices • Data Encryption • Authentication and Authorization Mechanisms • Secure Database Configuration and Hardening • Database Management in the Cloud • Hands-on Exercise: Implementing Encryption in a MySQL Database (Operation Lockdown) • Conclusion

فصل 13

درحال تولید...

book cover

زیرساخت ابری

Types of Cloud Services and Their Security Implications • Software as a Service (SaaS) • Platform as a Service (PaaS) • Infrastructure as a Service (IaaS) • The Shared Responsibility Model • Common Cloud Security Mistakes and How to Avoid Them • Misconfigurations • Inadequate Credential and Secrets Management • Overpermissioned Cloud Resources • Poor Security Hygiene • Failing to Understand the Shared Responsibility Model • Cloud Security Best Practices • Start with Secure Architectural Patterns • Properly Manage Secrets • Embrace Well-Architected Frameworks • Continue Following Security Best Practices • Exercise: Gaining Security Visibility into an AWS Environment • Configure an SNS Email Notification • Enable GuardDuty • Set Up EventBridge to Route Alerts to Email • Testing • Conclusion

فصل 14

درحال تولید...

book cover

احراز هویت

Identity and Access Management • Passwords • Password Basics • Encryption, Hashing, and Salting • Password Management • Additional Password Security • Common Authentication Protocols • NTLM • Kerberos • LDAP • RADIUS • Differences Between Protocols • Protocol Security • Choosing the Best Protocol for Your Organization • Multi-Factor Authentication • MFA Weaknesses • Where It Should Be Implemented • Conclusion

فصل 15

درحال تولید...

book cover

زیرساخت شبکه امن

Device Hardening • Firmware/Software Patching • Services • SNMP • Encrypted Protocols • Management Network • Hardware Devices • Bastion Hosts • Routers • Switches • Wireless Devices • Design • Egress Filtering • IPv6: A Cautionary Note • TACACS+ • Networking Attacks • ARP Cache Poisoning and MAC Spoofing • DDoS Amplification • VPN Attacks • Wireless • Conclusion

فصل 16

درحال تولید...

book cover

تقسیم‌بندی

Network Segmentation • Physical • Logical • Physical and Logical Network Example • Software-Defined Networking • Application Segmentation • Segmentation of Roles and Responsibilities • Conclusion

فصل 17

درحال تولید...

book cover

مدیریت آسیب‌پذیری

Authenticated Versus Unauthenticated Scans • Vulnerability Assessment Tools • Open Source Tools • Vulnerability Management Program • Program Initialization • Business as Usual • Remediation Prioritization • Risk Acceptance • Conclusion

فصل 18

درحال تولید...

book cover

توسعه

Language Selection • Assembly • C and C++ • Go • Rust • Python/Ruby/Perl • PHP • Secure Coding Guidelines • Testing • Automated Static Testing • Automated Dynamic Testing • Peer Review • Software Development Lifecycle • Conclusion

فصل 19

درحال تولید...

book cover

هوش منبع باز و تیم‌سازی بنفش

Open Source Intelligence • Types of Information and Access • Modern OSINT Tools • Purple Teaming • A Purple Teaming Example • Conclusion

فصل 20

درحال تولید...

book cover

درک IDS و IPS

Role in Information Security • Exploring IDS and IPS Types • Network-Based IDSs • Host-Based IDSs • IPSs • NGFWs • IDSs and IPSs in the Cloud • AWS • Azure • GCP • Working with IDSs and IPSs • Managing False Positives • Writing Your Own Signatures • IDS/IPS Positioning • Encrypted Protocols • Conclusion

فصل 21

درحال تولید...

book cover

ثبت وقایع و نظارت

Security Information and Event Management • Why Use a SIEM • Scope of Coverage • Designing the SIEM • Log Analysis and Enrichment • Sysmon • Group Policy • Alert Examples and Log Sources to Focus On • Authentication Systems • Application Logs • Cloud Services • Databases • DNS • Endpoint Protection Solutions • IDSs/IPSs • Operating Systems • Proxy and Firewall Logs • User Accounts, Groups, and Permissions • Testing and Continuing Configuration • Aligning with Detection Frameworks, Compliance Mandates, and Use Cases • MITRE ATT&CK • Sigma • Compliance • Use Case Analysis • Conclusion

فصل 22

درحال تولید...

book cover

فراتر از انتظار

Email Servers • DNS Servers • Security Through Obscurity • Useful Resources • Books • Blogs • Podcasts • Websites

فصل 23

درحال تولید...

خانهدسته‌بندیکتابخانهکتاب‌منپروفایل
انتشار کتاب

23 فصل در حال تولید

آخرین بروزرسانی
۳۱ شهریور ۱۴۰۵
امتیاز
5.0
پیش نیاز
ندارد

مدت زمان خوانش

10:52

نوع کتاب

اشتراکی

شرکت کنندگان

0 نفر

تولید کتاب

۳۱ شهریور ۱۴۰۵

درباره ما

قوانین و سوالات

کتاب‌های نرم افزار خوندنش چه نسخه اصلی و چه ترجمه شده میتونه برامون چالش برانگیز و سخت باشه. یا شاید اصلا حوصله نکنی این همه وقت و انرژی بزاری برای کتاب ، ما هستیم تا تو بتونی کتاب های مطرح و مهم دنیای نرم افزار رو بیشتر از پیش و با انگیزه بیشتر و کیفیت بهتر مطاله کنی و یادش بگیری.
CardDev قدمی کوچک برای یک تیم و قدمی بزرگ برای جامعه بزرگ مهندسین نرم‌افزار و برنامه نویسان!

ارتباط با ما

ایمیل

info@aiflashcard.dev

شبکه های اجتماعی

CardDev
CardDev

نصب اپ CardDev

دسترسی سریع‌تر از هوم‌اسکرین

کلیه حقوق مادی و معنوی برای سایت CardDev محفوظ است.

Built pixel by pixel by Khadem

Khadem Al Mahdi

Built pixel by pixel by