You do not need me to vouchsafe the value of this book ( and the CD) to prepare for the CISSP exam. If Shon is not the best known author, she is certainly in the top two or three in this category. But, I believe this book has another equally important role. It is perfect for the CxO that wants to understand what security is, what they need to know about it. I understand the knee jerk response to that is, "you cannot ask a CEO to read 1100 pages". Actually, the successful senior executives in the world are generally quite good at reading a LOT of information in a SHORT period of time. Shon is accurate, the writing is excellent, the diagrams help with "knowledge compression", a CFO interested in security can zip through this like a zero turn mower on a two acre MacMansion.
Nitpicks, sigh, I wish ISC2 had settled on the standard approach to incident handling instead of creating their own broken one. The Quantum Cryptography section is actually Quantum Key Exchange, but hey! That is a nitpick, no reader of this book actually needs to know the difference. And critics will be overjoyed because Shon seems to have threat, risk, and vulnerability in the right pidgeon holes. The most serious flaw in the book is in chapter 12, Hack and Attack Methods, some of that stuff I know cold and I got a bit confused reading that section, but it is the end of the book and my guess is that folks were getting tired. A few network traces would go a long way towards bringing that section to life. And you know what? The book remains 5 stars. Even if that section was spot on, even if the thirty weak pages out of the 1070 strong pages were perfect, the book is not designed to prepare the reader to be an IPS analyst. The overall message is clear and compelling, the bad guys do evil things with packets; I get the message so will the reader, let's move on.
The bottom line, if you think you know security and want to test your knowledge, buy the book, fire up the CD, install the test software and give yourself a run. Shon is a great author, but she has also compiled an awesome set of questions. Yes, they will prepare you for the CISSP exam, but they will also help you test your knowledge of security and your ability to think critically.If you have further questions about the book, or you disagree with my review, drop me a line and let's talk about it, stephen@sans.edu.
Click Here to see more reviews about: CISSP Certification All-in-One Exam Guide, Fourth Edition (Hardcover)
Hi, probably our entry may be off topic but anyways, I have been surfing around your blog and it looks very professional.
ReplyDeleteIt’s obvious you know your topic and you appear fervent about it. I’m developing a fresh blog plus I’m struggling to make it
look good, as well as offer the best quality content. I have learned much at your web site and also I anticipate alot more
articles and will be coming back soon. Thanks you.
CISSP Certification