REVIEW:

REVIEW: "Enterprise Information Systems Assurance and System Security", Merrill Warkentin/Rayford Vaughn

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
REVIEW: "Enterprise Information Systems Assurance and System Security", Merrill Warkentin/Rayford Vaughn Robert Michael Slade 05-23-2008
Posted by Robert Michael Slade on May 23, 2008, 4:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
BKEISASS.RVW 20080207

"Enterprise Information Systems Assurance and System Security",
Merrill Warkentin/Rayford Vaughn, 2006, 1-59140-912-8, U$74.95
%E Merrill Warkentin mwarkentin@acm.org
%E Rayford Vaughn
%C Suite 200 701 E. Chocolate Ave., Hershey, PA 17033-1117
%D 2006
%G 1-59140-912-8
%I IRM Press/Idea Group/IGI Global
%O U$74.95 800-345-432 717-533-8845 cust@idea-group.com
%O http://www.amazon.com/exec/obidos/ASIN/1591409128/robsladesinterne
http://www.amazon.co.uk/exec/obidos/ASIN/1591409128/robsladesinte-21
%O http://www.amazon.ca/exec/obidos/ASIN/1591409128/robsladesin03-20
%O Audience i- Tech 1 Writing 1 (see revfaq.htm for explanation)
%P 406 p.
%T "Enterprise Information Systems Assurance and System Security"

This book is a collection of papers on various topics in information
security, divided into five subject areas. There are a number of
similar works, such as the highly regarded Information Security
Management Handbook (cf. BKINSCMH.RVW), and the somewhat lower quality
"Computer Security Handbook" (cf. BKCMSCHB.RVW)

The first section of the work is supposedly devoted to security policy
and management. Three of the papers are unstructured (and
surprisingly terse) collections of thoughts on various themes related
to security management (and some stories of work experiences retailed
as "case studies"): one examines malware protection and basically
suggests that you have virus scanning on the desktop, server, and
network gateway. "Security Implications for Business" doesn't sound
like it would be easy to define, other than saying risks are bad, so
the fact that much of the material in the second section is similarly
vague and disorganized is no surprise. What is startling is that we
get some actual details on documents related to the Sarbanes-Oxley
legislation, a review of Web commerce threats, and the recommendation
to use decentralization as a measure to build business continuity.
Security engineering should be more definitive, so the generic nature
of four of the five papers in section three is more disappointing.
The paper on securing wireless networks isn't great, but it is, at
least, useful. Part four takes brief looks at intrusion detection
technologies, honeynets, an even worse than usual view of
steganography, some aspects of database security, and digital
forensics. Of the three papers in the final section, only one
contains a decent overview of the topic of authentication.

Most of the material in this book is vague, generic, undetailed, and
of very questionable value. In addition to those mentioned above,
Anderson's "Security Engineering" (cf. BKSECENG.RVW), Stallings'
"Computer Security: Principles and Practice" (cf. BKCMSCPP.RVW), and
Stamp's "Information Security: Principles and Practice" (cf.
BKINSCPP.RVW) all provide more complete, detailed, accurate, and
useful coverage of security management and assurance.

copyright Robert M. Slade, 2008 BKEISASS.RVW 20080207


--
rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org
Find virus, book info http://victoria.tc.ca/techrev/rms.htm
Review mailing list: send mail to techbooks-subscribe@egroups.com
"Robert Slade's Guide to Computer Viruses" 0-387-94663-2
"Viruses Revealed" 0-07-213090-3
"Software Forensics" 0-07-142804-6

Similar ThreadsPosted
CFP: Artificial Intelligence in Information Assurance and Security April 6, 2006, 8:43 am
New FISMA Information Assurance Tool - xbasics Ulinzi May 16, 2008, 7:07 am
SECURITY SYSTEMS November 22, 2005, 7:59 am
REVIEW: "File System Forensic Analysis", Brian Carrier August 8, 2005, 2:51 pm
REVIEW: "Black Hat Physical Device Security", Drew Miller August 12, 2005, 3:26 pm
REVIEW: "Corporate Computer and Network Security", Raymond R. Panko August 25, 2005, 8:25 pm
USA, VA-Communications Systems Engineer September 12, 2005, 2:50 pm
Call for Papers on Embedded Cryptographic Systems September 7, 2005, 7:18 am
ADVANCED IDENTIFICATION SYSTEMS 2006 AGENDA IS SET: September 5, 2006, 4:41 pm
Biometric access systems for online website authentication? December 19, 2005, 5:00 am

The site map in XML format XML site map

Contact Us | Privacy Policy