با وجود افزایش حملات سایبری برجسته، نشت دادههای بیسابقه و حملات باجافزاری، بسیاری از سازمانها بودجه کافی برای یک برنامه امنیت اطلاعات (InfoSec) ندارند. اگر مجبورید با بداههپردازی در حین کار از خود محافظت کنید، این راهنمای عملی یک کتابچه راهنمای امنیت-۱۰۱ را با گامها، ابزارها، فرآیندها و ایدههایی ارائه میدهد تا به شما کمک کند حداکثر بهبود امنیتی را با هزینه کم یا بدون هزینه به دست آورید. هر فصل از این کتاب دستورالعملهای گام به گام برای مقابله با مسائلی مانند نقض امنیتی و بلایا، انطباق، زیرساخت شبکه، مدیریت رمز عبور، اسکن آسیبپذیری، تست نفوذ و موارد دیگر را ارائه میدهد. مهندسان شبکه، مدیران سیستم و متخصصان امنیت یاد خواهند گرفت که چگونه از چارچوبها، ابزارها و تکنیکها برای ساخت و بهبود برنامههای امنیت سایبری خود استفاده کنند. این کتاب به شما کمک خواهد کرد: برنامهریزی و طراحی پاسخ به حوادث، بازیابی فاجعه، انطباق و امنیت فیزیکی. یادگیری و به کارگیری مفاهیم پایه تست نفوذ از طریق تیمسازی بنفش (Purple Teaming). انجام مدیریت آسیبپذیری با استفاده از فرآیندها و ابزارهای خودکار. استفاده از IDS، IPS، SOC، ثبت وقایع (Logging) و نظارت. تقویت سیستمهای مایکروسافت و یونیکس، زیرساخت شبکه و مدیریت رمز عبور. استفاده از روشها و طراحیهای تقسیمبندی (Segmentation) برای بخشبندی شبکه شما. کاهش خطاهای قابل بهرهبرداری با توسعه کد به صورت امن.
اشتراکی

با مرور فصلها، ساختار ، محتوای کتاب را به سرعت بشناسید.
با مرور فصلهای این کتاب میتونی خیلی سریع بفهمی هر بخش چی یاد میده، ساختار کلی چطوره و از کجا باید شروع کنی. هر فصل روی یک مفهوم یا مهارت خاص تمرکز داره و موضوعات اصلیش رو میبینی تا انتخابت آگاهانهتر باشه. چه بخوای کل کتاب رو دنبال کنی، چه فقط یک بخش خاص رو دنبال کنی، این نما کمکت میکنه مسیرت رو پیدا کنی.

ایجاد یک برنامه امنیتی
Laying the Groundwork • Establishing Teams • Determining Your Baseline Security Posture • Assessing Threats and Risks • Identify Scope, Assets, and Threats • Assess Risk and Impact • Mitigate • Monitor • Govern • Prioritizing • Creating Milestones • Use Cases, Tabletops, and Drills • Expanding Your Team and Skillsets • Conclusion
درحال تولید...

مدیریت دارایی و مستندسازی
What Is Asset Management? • Documentation • Establishing the Schema • Data Storage Options • Data Classification • Understanding Your Inventory Schema • Asset Management Implementation Steps • Defining the Lifecycle • Information Gathering • Change Tracking • Monitoring and Reporting • Asset Management Guidelines • Automate • Establish a Single Source of Truth • Organize a Company-wide Team • Find Executive Champions • Keep on Top of Software Licensing • Conclusion
درحال تولید...

سیاستها
Language • Document Contents • Topics • Storage and Communication • Conclusion
درحال تولید...

استانداردها و رویهها
Standards • Procedures • Document Contents • Conclusion
درحال تولید...

آموزش کاربر
Broken Processes • Bridging the Gap • Building Your Own Program • Establish Objectives • Establish Baselines • Scope and Create Program Rules and Guidelines • Provide Positive Reinforcement • Define Incident Response Processes • Obtaining Meaningful Metrics • Measurements • Tracking Success Rate and Progress • Important Metrics • Conclusion
درحال تولید...

پاسخ به حوادث
Processes • Pre-Incident Processes • Incident Processes • Post-Incident Processes • Tools and Technology • Log Analysis • EDR/XDR/MDR/All the “Rs” • Disk and File Analysis • Memory Analysis • PCAP Analysis • All-in-One Tools • Conclusion
درحال تولید...

بازیابی فاجعه
Setting Objectives • Recovery Point Objective • Recovery Time Objective • Recovery Strategies • Traditional Physical Backups • Warm Standby • High Availability • Alternate System • System Function Reassignment • Cloud Native Disaster Recovery • Dependencies • Scenarios • Invoking a Failover...and Back • Testing • Security Considerations • Conclusion
درحال تولید...

استانداردها و چارچوبهای انطباق صنعتی
Industry Compliance Standards • Family Educational Rights and Privacy Act (FERPA) • Gramm-Leach-Bliley Act (GLBA) • Health Insurance Portability and Accountability Act (HIPAA) • Payment Card Industry Data Security Standard (PCI DSS) • Sarbanes-Oxley (SOX) Act • Frameworks • Center for Internet Security (CIS) • Cloud Control Matrix (CCM) • The Committee of Sponsoring Organizations of the Treadway Commission (COSO) • Control Objectives for Information and Related Technologies (COBIT) • ISO-27000 Series • MITRE ATT&CK • NIST Cybersecurity Framework (CSF) • Regulated Industries • Financial • Government • Healthcare • Conclusion
درحال تولید...

امنیت فیزیکی
Physical • Restrict Access • Video Surveillance • Authentication Maintenance • Secure Media • Datacenters • Operational Aspects • Identifying Visitors and Contractors • Physical Security Training • Conclusion
درحال تولید...

زیرساخت مایکروسافت ویندوز
Quick Wins • Upgrade • Third-Party Patches • Open Shares • Active Directory Domain Services • Forests • Domains • Domain Controllers • Organizational Units • Groups • Accounts • Group Policy Objects (GPOs) • Conclusion
درحال تولید...

سرورهای کاربردی یونیکس
Keeping Up-to-Date • Third-Party Software Updates • Core Operating System Updates • Hardening a Unix Application Server • Disable Services • Set File Permissions • Use Host-Based Firewalls • Manage File Integrity • Configure Separate Disk Partitions • Use chroot • Set Up Mandatory Access Control • Conclusion
درحال تولید...

نقاط پایانی
Keeping Up-to-Date • Microsoft Windows • macOS • Unix Desktops • Third-Party Updates • Hardening Endpoints • Disable Services • Use Desktop Firewalls • Implement Full-Disk Encryption • Use Endpoint Protection Tools • Mobile Device Management • Endpoint Visibility • Centralization • Conclusion
درحال تولید...

پایگاههای داده
Introduction to Databases and Their Importance in Information Security • Database Implementations • Common Database Management Systems • A Real-World Case Study: The Marriott Breach • Database Security Threats and Vulnerabilities • Unauthorized Access • SQL Injection • Data Leakage • Insider Threats • Defense Evasion • Database Security Best Practices • Data Encryption • Authentication and Authorization Mechanisms • Secure Database Configuration and Hardening • Database Management in the Cloud • Hands-on Exercise: Implementing Encryption in a MySQL Database (Operation Lockdown) • Conclusion
درحال تولید...

زیرساخت ابری
Types of Cloud Services and Their Security Implications • Software as a Service (SaaS) • Platform as a Service (PaaS) • Infrastructure as a Service (IaaS) • The Shared Responsibility Model • Common Cloud Security Mistakes and How to Avoid Them • Misconfigurations • Inadequate Credential and Secrets Management • Overpermissioned Cloud Resources • Poor Security Hygiene • Failing to Understand the Shared Responsibility Model • Cloud Security Best Practices • Start with Secure Architectural Patterns • Properly Manage Secrets • Embrace Well-Architected Frameworks • Continue Following Security Best Practices • Exercise: Gaining Security Visibility into an AWS Environment • Configure an SNS Email Notification • Enable GuardDuty • Set Up EventBridge to Route Alerts to Email • Testing • Conclusion
درحال تولید...

احراز هویت
Identity and Access Management • Passwords • Password Basics • Encryption, Hashing, and Salting • Password Management • Additional Password Security • Common Authentication Protocols • NTLM • Kerberos • LDAP • RADIUS • Differences Between Protocols • Protocol Security • Choosing the Best Protocol for Your Organization • Multi-Factor Authentication • MFA Weaknesses • Where It Should Be Implemented • Conclusion
درحال تولید...

زیرساخت شبکه امن
Device Hardening • Firmware/Software Patching • Services • SNMP • Encrypted Protocols • Management Network • Hardware Devices • Bastion Hosts • Routers • Switches • Wireless Devices • Design • Egress Filtering • IPv6: A Cautionary Note • TACACS+ • Networking Attacks • ARP Cache Poisoning and MAC Spoofing • DDoS Amplification • VPN Attacks • Wireless • Conclusion
درحال تولید...

تقسیمبندی
Network Segmentation • Physical • Logical • Physical and Logical Network Example • Software-Defined Networking • Application Segmentation • Segmentation of Roles and Responsibilities • Conclusion
درحال تولید...

مدیریت آسیبپذیری
Authenticated Versus Unauthenticated Scans • Vulnerability Assessment Tools • Open Source Tools • Vulnerability Management Program • Program Initialization • Business as Usual • Remediation Prioritization • Risk Acceptance • Conclusion
درحال تولید...

توسعه
Language Selection • Assembly • C and C++ • Go • Rust • Python/Ruby/Perl • PHP • Secure Coding Guidelines • Testing • Automated Static Testing • Automated Dynamic Testing • Peer Review • Software Development Lifecycle • Conclusion
درحال تولید...

هوش منبع باز و تیمسازی بنفش
Open Source Intelligence • Types of Information and Access • Modern OSINT Tools • Purple Teaming • A Purple Teaming Example • Conclusion
درحال تولید...

درک IDS و IPS
Role in Information Security • Exploring IDS and IPS Types • Network-Based IDSs • Host-Based IDSs • IPSs • NGFWs • IDSs and IPSs in the Cloud • AWS • Azure • GCP • Working with IDSs and IPSs • Managing False Positives • Writing Your Own Signatures • IDS/IPS Positioning • Encrypted Protocols • Conclusion
درحال تولید...

ثبت وقایع و نظارت
Security Information and Event Management • Why Use a SIEM • Scope of Coverage • Designing the SIEM • Log Analysis and Enrichment • Sysmon • Group Policy • Alert Examples and Log Sources to Focus On • Authentication Systems • Application Logs • Cloud Services • Databases • DNS • Endpoint Protection Solutions • IDSs/IPSs • Operating Systems • Proxy and Firewall Logs • User Accounts, Groups, and Permissions • Testing and Continuing Configuration • Aligning with Detection Frameworks, Compliance Mandates, and Use Cases • MITRE ATT&CK • Sigma • Compliance • Use Case Analysis • Conclusion
درحال تولید...

فراتر از انتظار
Email Servers • DNS Servers • Security Through Obscurity • Useful Resources • Books • Blogs • Podcasts • Websites
درحال تولید...
23 فصل در حال تولید
مدت زمان خوانش
10:52
نوع کتاب
اشتراکی
شرکت کنندگان
0 نفر
تولید کتاب
۳۱ شهریور ۱۴۰۵