Gutscheinbedingungen

*Gültig bis 21.06.2026 auf (fast) alles. Ausgeschlossen sind Smartboxen, Zeitschriften, Tickets, Lebensmittel, Gaming-Elektroartikel, Tinte/Toner, Gutscheine, Geschenkkarten, Blumen und Abos | Einlösbar in allen Buchhandlungen von Orell Füssli, Barth Bücher, Buchladen Rapunzel, Schuler Orell Füssli, Stauffacher und ZAP unter Vorweisung des Gutscheins, auf www.orellfüssli.ch durch Eingabe des Gutscheincodes. Beim Service „eBooks verschenken“ und bei eBook-Käufen via eReader nicht einlösbar | Mindesteinkaufswert: Fr. 30.- | Nicht mit anderen Rabatten kumulierbar.

Produktbild: Tiller, J: CISO's Guide to Penetration Testing

Tiller, J: CISO's Guide to Penetration Testing A Framework to Plan, Manage, and Maximize Benefits

Fr. 229.00

inkl. gesetzl. MwSt., Versandkostenfrei


Beschreibung

Produktdetails

Einband

Gebundene Ausgabe

Erscheinungsdatum

01.12.2012

Abbildungen

schwarz-weiss Illustrationen, Tabellen, schwarz-weiss

Verlag

Taylor and Francis

Seitenzahl

392

Maße (L/B/H)

24.5/16.5/3.3 cm

Gewicht

830 g

Sprache

Englisch

ISBN

978-1-4398-8027-2

Beschreibung

Produktdetails

Einband

Gebundene Ausgabe

Erscheinungsdatum

01.12.2012

Abbildungen

schwarz-weiss Illustrationen, Tabellen, schwarz-weiss

Verlag

Taylor and Francis

Seitenzahl

392

Maße (L/B/H)

24.5/16.5/3.3 cm

Gewicht

830 g

Sprache

Englisch

ISBN

978-1-4398-8027-2

Kundinnen und Kunden meinen

0 Bewertungen

Informationen zu Bewertungen

Zur Abgabe einer Bewertung ist eine Anmeldung im Konto notwendig. Die Authentizität der Bewertungen wird von uns nicht überprüft. Wir behalten uns vor, Bewertungstexte, die unseren Richtlinien widersprechen, entsprechend zu kürzen oder zu löschen.

Die Bewertungen sind nach Format, Anzahl Sterne und Datum sortiert.

Verfassen Sie die erste Bewertung zu diesem Artikel

Helfen Sie anderen Kund*innen durch Ihre Meinung

Kundinnen und Kunden meinen

0 Bewertungen filtern

  • Produktbild: Tiller, J: CISO's Guide to Penetration Testing
  • Getting Started Audience How to Use This Book Setting the Stage Perspectives of Value Where Does Penetration Testing Fit? What Constitutes a Success? A Quick Look Back Hacking Impacts Resources Information Time Brand and Reputation The Hacker Types of Hackers Script Kiddies Independent Hackers Organized Hackers Sociology Motives The Framework Planning the Test Sound Operations Reconnaissance Enumeration Vulnerability Analysis Exploitation Final Analysis Deliverable Integration The Business Perspective Business Objectives Previous Test Results Building a Roadmap Business Challenges Security Drivers Increasing Network Complexity Ensuring Corporate Value Lower Management Investment Business Consolidation Mobile Workforce Government Regulations and Standards Why Have the Test? Proof of Issue Limited Staffing and Capability Third-Party Perspective It Is All about Perspective Overall Expectations How Deep Is Deep Enough? One-Hole Wonder Today's Hole Planning for a Controlled Attack Inherent Limitations Time Money Determination Legal Restrictions Ethics Imposed Limitations Timing Is Everything Attack Type Source Point Required Knowledge Timing of Information Internet Web Authenticated Application Service Direct Access Multiphased Attacks Parallel Shared Parallel Isolated Series Shared Series Isolated Value of Multiphase Testing Employing Multiphased Tests Teaming and Attack Structure Red Team Vulnerability Explanation Testing Focus Mitigation White Team Piggyback Attacks Reverse Impact Detection Blue Team Incident Response Vulnerability Impact Counterattack Team Communications Engagement Planner The Right Security Consultant Technologists Architects Ethics The Tester Logistics Agreements Downtime Issues System and Data Integrity Get Out of Jail Free Card Intermediates Partners Customers Service Providers Law Enforcement Preparing for a Hack Technical Preparation Attacking System Operating System Tools Data Management and Protection Attacking Network Attacking Network Architecture Managing the Engagement Project Initiation Identify Sponsors Building the Teams Schedule and Milestones Tracking Escalation Customer Approval During the Project Status Reports Scope Management Deliverable Review Concluding the Engagement Reconnaissance Social Engineering E-Mail Value Controlling Depth Help Desk Fraud Value Controlling Depth Prowling and Surfing Internal Relations and Collaboration Corporate Identity Assumption Physical Security Observation Dumpster Diving Theft Internet Reconnaissance General Information Web Sites Social Networking Enumeration Enumeration Techniques Connection Scanning SYN Scanning FIN Scanning Fragment Scanning TCP Reverse IDENT Scanning FTP Bounce Scanning UDP Scanning ACK Scanning Soft Objective Looking Around or Attack? Elements of Enumeration Account Data Architecture Operating Systems Wireless Networks Applications Custom Applications Preparing for the Next Phase Vulnerability Analysis Weighing the Vulnerability Source Points Obtained Data The Internet Vendors Alerts Service Packs Reporting Dilemma Exploitation Intuitive Testing Evasion Threads and Groups Threads Groups Operating Systems Windows UNIX Password Crackers Rootkits Applications Web Applications Distributed Applications Customer Applications Wardialing Network Perimeter Network Nodes Services and Areas of Concern Services Services Started by Default Windows Ports Null Connection Remote Procedure Call (RPC) Simple Network Management Protocol (SNMP) Berkeley Internet Name Domain (BIND) Common Gateway Interface (CGI) Cleartext Services Network File System (NFS) Domain Name Service (DNS) File and Directory Permissions FTP and Telnet Internet Control Message Protocol (ICMP) IMAP and POP Network Architecture The Deliverable Final Analysis Potential Analysis The Document Executive Summary Present Findings Planning and Operations Vulnerability Ranking Process Mapping Recommendations Exceptions and Limitations Final Analysis Conclusion Overall Structure Aligning Findings Technical Measurement Severity Exposure Business Measurement Cost Risk Presentation Remedial Tactical Strategic Integrating the Results Integration Summary Mitigation Test Pilot Implement Validate Defense Planning Architecture Review Architecture Review Structure Awareness Training Awareness Program Incident Management Building a Team People Mission Constituency Organizational Structure Defining Services and Quality CERT Forms Security Policy Data Classification Organizational Security Conclusion Index