Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - REVIEW: "The GSEC Prep Guide", Mike Chapple

 
Thread Tools Search this Thread
Old 11-10-2003, 03:39 PM   #1
Default REVIEW: "The GSEC Prep Guide", Mike Chapple


BKGSECPG.RVW 20030918

"The GSEC Prep Guide", Mike Chapple, 2003, 0-7645-3932-9,
U$60.00/C$90.99/UK#41.95
%A Mike Chapple
%C 5353 Dundas Street West, 4th Floor, Etobicoke, ON M9B 6H8
%D 2003
%G 0-7645-3932-9
%I John Wiley & Sons, Inc.
%O U$60.00/C$90.99/UK#41.95 416-236-4433 fax: 416-236-4448
%O http://www.amazon.com/exec/obidos/AS...bsladesinterne
http://www.amazon.co.uk/exec/obidos/...bsladesinte-21
%O http://www.amazon.ca/exec/obidos/ASI...bsladesin03-20
%P 448 p. + CD-ROM
%T "The GSEC Prep Guide: Mastering SANS GIAC Security Essentials"

The SANS (System administrators, Audit, Network, Security) Institute
GIAC (Global Information Assurance Certification) Security Essentials
Certification (GSEC) is supposed to be the "core" program for the
various GIAC courses and exams.

Chapter one covers some basic, but random, security concepts and
topics. A list of sample questions, intended to help the
student/candidate prepare for the GSEC exam, is given at the end of
every chapter. If these truly represent the level and type of
questions on the exam then getting the GSEC is a snap: quick, which
type of situation is worse, one that has low threat and low
vulnerability or high threat and high vulnerability? (On the other
hand, you may have to know the party line: one question insists that
you credit SANS with the concept of defence in depth, and there is a
concept of "separation of privilege" that seems to be what everyone
else refers to as separation of duties.) Security policies are
discussed in a verbose but almost "content-free" manner in chapter
two. Virtually nothing is said about the policy process and different
functional types of policies. Again, there is a demand for
idiosyncratic jargon: high level policies are "program" policies,
whereas detailed policies (mostly procedural, given the list
discussed) are "issue-specific." One term that might be worth
adopting is "system-specific policy": those who deal with policies
know that it is difficult to have exceptions documented. Using this
term for deviations, as SANS does, may reduce the resistance to noting
the irregularities. There are some basic ideas about risk assessment
and management in chapter three, but most of the text reviews network
scanning tools. Chapter four contains network nomenclature, Cisco
equipment filtering command arguments, and miscellaneous IP (Internet
Protocol) protocols in varying depth. There are a brief list of the
titular "Incident Handling" factors contained in chapter five, as well
as random legal terms. The discussion of cryptography in chapter six
is reasonable up to the point of symmetric block ciphers, but
subsequent material has errors (keystream data should *not* repeat
during the course of a message), confusing diagrams, and unhelpful
mathematics. There is no deliberation about the usage of public key
cryptography, hashes, and digests until chapter seven, which, despite
the title, has absolutely nothing to say about "Applications
Security." Chapter eight provides a simple overview of firewalls and
intrusion detection systems (IDSs) but is not overly detailed: no
distinction is made between application and circuit-level proxies, and
some of the statements made are clearly incorrect for circuit devices.
There is a grab bag of malware, cryptanalysis, attack methods and more
in chapter nine. The content on operations security is limited to
assorted aspects and tools of Windows and UNIX that might be related
to secure processing, in chapters ten and eleven respectively.
Chapter twelve is a practice exam. It's pretty easy.

The GSEC is sometimes said to be adequate preparation for the CISSP
(Certified Information Systems Security Professional) exam, but there
are significant gaps in GSEC's coverage of the security topic.
Although risk assessment and policy are discussed, management issues
and access controls get limited substance in GSEC. Security
architecture, applications security, physical security, and business
continuity are all missing, while operations are restricted to Windows
and UNIX.

This book does provide some useful direction in regard to information
systems security, but readers should be warned that the missing pieces
will probably be very important at some point.

copyright Robert M. Slade, 2003 BKGSECPG.RVW 20030918

--
======================

"If you do buy a computer, don't turn it on." - Richards' 2nd Law
============= for back issues:
[Base URL] site http://victoria.tc.ca/techrev/
or mirror http://sun.soci.niu.edu/~rslade/
CISSP refs: [Base URL]mnbksccd.htm
Security Dict.: [Base URL]secgloss.htm
Security Educ.: [Base URL]comseced.htm
Book reviews: [Base URL]mnbk.htm
[Base URL]review.htm
Partial/recent: http://groups.yahoo.com/group/techbooks/
Security Educ.: http://groups.yahoo.com/group/comseced/
Review mailing list: send mail to techbooks-



Rob Slade, doting grandpa of Ryan and Trevor
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
How much storage for 30 mins of TV program? Jon D DVD Video 3 08-26-2005 01:42 AM
NEC 3500 E.F. DVD Video 3 12-23-2004 12:00 AM
TheDigitalReview: BABE SPECIAL EDITION - DVD REVIEW (User Review) Mike McGee DVD Video 0 12-04-2003 04:52 AM
TheDigitalReview: HUD - DVD REVIEW Mike McGee DVD Video 0 11-22-2003 10:34 AM
TheDigitalReview: THE JAMIE KENNEDY EXPERIMENT - COMPLETE FIRST SEASON - DVD REVIEW Mike McGee DVD Video 0 11-21-2003 12:07 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46