The Experts below are selected from a list of 41703 Experts worldwide ranked by ideXlab platform

Gerry Kovacich - One of the best experts on this subject based on the ideXlab platform.

  • information warfare and the information systems Security Professional
    Information Systems Security, 1997
    Co-Authors: Gerry Kovacich
    Abstract:

    (1997). Information Warfare and the Information Systems Security Professional. Information Systems Security: Vol. 6, No. 2, pp. 45-55.

  • special feature information warfare and the information systems Security Professional
    Computers & Security, 1997
    Co-Authors: Gerry Kovacich
    Abstract:

    When a government agency or business computer system is attacked, the response to such an attack will be based on the attacker. Will the attacker be a hacker, phreaker, cracker, just someone breaking in for fun? Will the attacker be an employee of a business competitor, in the case of an attack on a business system, or will it be a terrorist, or a government agency-sponsored attack for economic reasons? Will the attacker be a foreign soldier attacking the system as a prelude to war? These questions require serious consideration when information systems are being attacked, because it dictates the response. Would you attack a country because of what a terrorist or economic spy did to a business or government system? To complicate the matter, what if the terrorist was in a third country but only made it look like he/she was coming from your potential adversary? How do you know? The key to the future is in information systems Security for defence and information warfare weapons. As with nuclear weapons used as a form of deterrent, in the future, information weapons systems will be the basis of the information warfare deterrent. Each nation must begin now to prepare for 21st Century warfare by establishing a programme to ensure the protection of information assets in the 21st Century. Remember, it is bad enough being attacked, but it is worse to be attacked and not know it until it is too late!

Derek Atkins - One of the best experts on this subject based on the ideXlab platform.

  • Internet Security: Professional Reference with Cdrom
    1997
    Co-Authors: Joel Snyder, Chris Hare, Derek Atkins
    Abstract:

    From the Publisher: Internet Security Professional Reference, Second Edition takes you through planning, implementing, and administering a secure Internet connection - from understanding UUCP and auditing to encryption and firewalls to understanding viruses - this book has everything you need. A comprehensive resource for Security and network Professionals alike, Internet Security Professional Reference, Second Edition will show you how to use and implement the latest technologies in the most secure fashion, including Java, CGI, and Windows NT.

  • internet Security Professional reference
    1996
    Co-Authors: Derek Atkins
    Abstract:

    This complete reference shows how Internet and network Security is implemented and details ways to keep it from being violated. Inadequacies in current Security products and set-ups are pointed out and strategies to overcome them are detailed step by step.

Mike Chapple - One of the best experts on this subject based on the ideXlab platform.

  • isc 2 cissp certified information systems Security Professional official study guide
    2018
    Co-Authors: Mike Chapple, James Michael Stewart, Darril Gibson
    Abstract:

    CISSP Study Guide - fully updated for the 2018 CISSP Body of Knowledge CISSP (ISC)2 Certified Information Systems Security Professional Official Study Guide, 8th Editionhas been completely updated for the latest 2018 CISSP Body of Knowledge. This bestselling Sybex study guide covers 100% of all exam objectives. You'll prepare for the exam smarter and faster with Sybex thanks to expert content, real-world examples, advice on passing each section of the exam, access to the Sybex online interactive learning environment, and much more. Reinforce what you've learned with key topic exam essentials and chapter review questions. Along with the book, you also get access to Sybex's superior online interactive learning environment that includes: Six unique 150 question practice exams to help you identify where you need to study more. Get more than 90 percent of the answers correct, and you're ready to take the certification exam. More than 1400 Electronic Flashcards to reinforce your learning and give you last-minute test prep before the exam A searchable glossary in PDF to give you instant access to the key terms you need to know for the exam Coverage of all of the exam topics in the book means you'll be ready for: Security and Risk Management Asset Security Security Engineering Communication and Network Security Identity and Access Management Security Assessment and Testing Security Operations Software Development Security

  • cissp certified information systems Security Professional study guide
    2003
    Co-Authors: James Michael Stewart, Ed Tittel, Mike Chapple
    Abstract:

    Totally updated for 2011, here's the ultimate study guide for the CISSP examConsidered the most desired certification for IT Security Professionals, the Certified Information Systems Security Professional designation is also a career-booster. This comprehensive study guide covers every aspect of the 2011 exam and the latest revision of the CISSP body of knowledge. It offers advice on how to pass each section of the exam and features expanded coverage of biometrics, auditing and accountability, software Security testing, and other key topics. Included is a CD with two full-length, 250-question sample exams to test your progress.CISSP certification identifies the ultimate IT Security Professional; this complete study guide is fully updated to cover all the objectives of the 2011 CISSP examProvides in-depth knowledge of access control, application development Security, business continuity and disaster recovery planning, cryptography, Information Security governance and risk management, operations Security, physical (environmental) Security, Security architecture and design, and telecommunications and network SecurityAlso covers legal and regulatory investigation and complianceIncludes two practice exams and challenging review questions on the CDProfessionals seeking the CISSP certification will boost their chances of success with CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition.

Alireza Tamjidyamcholo - One of the best experts on this subject based on the ideXlab platform.

  • Evaluation model for knowledge sharing in information Security Professional virtual community
    Computers & Security, 2014
    Co-Authors: Alireza Tamjidyamcholo, Mohd Sapiyan Bin Baba, Nor Liyana Mohd Shuib, Vala Ali Rohani
    Abstract:

    Knowledge sharing has been proven to have affirmative effects on both the education and business sectors. Nevertheless, many Professional virtual communities (PVC) have failed due to reasons, such as the low willingness of members to share knowledge with other members. In addition, it is not explicitly evident whether knowledge sharing in information Security is able to reduce risk. To date, there have been relatively few empirical studies concerning the effects of knowledge sharing and its capability to reduce risk in information Security communities. This paper proposes a model that is composed of two main parts. The first part is the Triandis theory, which is adapted to understand and foster the determinants of knowledge sharing behavior in PVCs. The second part explores the quantitative relationship between knowledge sharing and Security risk reduction expectation. One hundred and forty-two members from the LinkedIn information Security groups participated in this study. PLS analysis shows that perceived consequences, affect, and facilitating conditions have significant effects on knowledge sharing behavior. In contrast, social factors have shown insignificant effects on knowledge sharing behavior in information Security communities. The results of the study demonstrate that there is a positive and strong relationship between knowledge sharing behavior and information Security risk reduction expectation.

  • information Security Professional perceptions of knowledge sharing intention under self efficacy trust reciprocity and shared language
    Computer Education, 2013
    Co-Authors: Alireza Tamjidyamcholo, Mohd Sapiyan Baba, Hamed Tamjid, Rahmatollah Gholipour
    Abstract:

    Knowledge sharing is an important component of knowledge management systems. Security knowledge sharing substantially reduces risk and investment in information Security. Despite the importance of information Security, little research based on knowledge sharing has focused on the Security profession. Therefore, this study analyses key factors, containing attitude, self-efficacy, trust, norm of reciprocity, and shared language, in respect of the information Security workers intention to share knowledge. Information Security Professionals in virtual communities, including the Information Security Professional Association (ISPA), Information Systems Security Association (ISSA), Society of Information Risk Analysts (SIRA), and LinkedIn Security groups, were surveyed to test the proposed research model. Confirmatory factor analysis (CFA) and the structural equation modelling (SEM) technique were used to analyse the data and evaluate the research model. The results showed that the research model fit the data well and the structural model suggests a strong relationship between attitude, trust, and norms of reciprocity to knowledge sharing intention. Hypotheses regarding the influence of self-efficacy and reciprocity, to knowledge sharing attitude were upheld. Shared language did not influence either the attitude or intention to share knowledge. We model six factors which influence Security workers knowledge sharing intention.Effect of attitude, trust, reciprocity to knowledge sharing intention were upheld.Self-efficacy and reciprocity had influence on knowledge sharing attitude.Shared language affected neither intention nor attitude to share knowledge.

  • Information Security Professional perceptions of knowledge-sharing intention in virtual communities under social cognitive theory
    2013 International Conference on Research and Innovation in Information Systems (ICRIIS), 2013
    Co-Authors: Alireza Tamjidyamcholo, Rahmatollah Gholipour, Mohd Sapiyan Bin Baba, Hamed Tamjid Yamchello
    Abstract:

    Knowledge sharing is an important component of knowledge management systems. Security knowledge sharing substantially reduces risk and investment in information Security. Despite the importance of information Security, little research based on knowledge sharing has focused on the Security profession. Therefore, this study analyses key factors, containing attitude, self-efficacy, personal outcome expectation, and facilitating condition, in respect of the information Security workers intention to share knowledge. Information Security Professionals in virtual communities, including the Information Security Professional Association (ISPA), Information Systems Security Association (ISSA), Society of Information Risk Analysts (SIRA), and LinkedIn Security groups, were surveyed to test the proposed research model. Confirmatory factor analysis (CFA) and the structural equation modelling (SEM) technique were used to analyse the data and evaluate the research model. The results showed that the research model fit the data well and the structural model suggests a strong relationship between attitude and knowledge sharing intention. Hypotheses regarding the influence of self-efficacy and personal outcome expectation, to knowledge sharing attitude were upheld. Facilitating condition showed significant influences on moderating between attitude and intention.

Shayan Zamanirad - One of the best experts on this subject based on the ideXlab platform.

  • Security Professional skills representation in bug bounty programs and processes
    International Conference on Service Oriented Computing, 2020
    Co-Authors: Sara Mumtaz, Carlos Rodriguez, Shayan Zamanirad
    Abstract:

    The ever-increasing amount of Security vulnerabilities discovered and reported in recent years are significantly raising the concerns of organizations and businesses regarding the potential risks of data breaches and attacks that may affect their assets (e.g. the cases of Yahoo and Equifax). Consequently, organizations, particularly those suffering from these attacks are relying on the job of Security Professionals. Unfortunately, due to a wide range of cyber-attacks, the identification of such skilled Security Professional is a challenging task. One such reason is the “skill gap” problem, a mismatch between the Security Professionals’ skills and the skills required for the job (vulnerability discovery in our case). In this work, we focus on platforms and processes for crowdsourced Security vulnerability discovery (bug bounty programs) and present a framework for the representation of Security Professional skills. More specifically, we propose an embedding-based clustering approach that exploits multiple and rich information available across the web (e.g. job postings, vulnerability discovery reports) to translate the Security Professional skills into a set of relevant skills using clustering information in a semantic vector space. The effectiveness of this approach is demonstrated through experiments, and the results show that our approach works better than baseline solutions in selecting the appropriate Security Professionals.