June 2009

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
Blog powered by TypePad

« Privacy in Germany: Courts Support It | Main | Censorship as Security: GoDaddy Delists Cop Rating Web Site »

March 10, 2008

New School: New Book by Adam Shostack

51jF+BW+JAL._SS500_.jpg Adam Shostack, whose group blog Emergent Chaos I quote frequently in this blog, has a new book coming out with co-author Andrew Stewart: New School of Information Security.
We think there's an emerging way of approaching the world, which we call the New School.

We start with a look at some persistent issues like spam and identity theft. From there, we look at why the information security industry hasn't just fixed them, and some of the data sources which we rely on and how poor they are. We then look at some new source of data, and new ways of interpreting them, and close with some very practical steps that any individual or organization can take to make things better.

The New School of Information Security, Adam Shostack, Emergent Chaos, 10 March 2008

I haven't read the book yet, since it's not published yet, but if it's like the material he posts in his blog, it's a good thing.

One of his commenters doesn't get it:

Spam doesn't represent a threat to an organisation's information assets - it's merely an annoyance to the workforce and a drain on IT resources. Statements like this only perpetuate the muddled line of thinking that confuses Information security with IT Security (hint: they're different!).
Arbitrary lines between job descriptions are part of the problem, especially when people with those different jobs don't coordinate, as is so often the case. As for spam not being a threat to an organization's information assets, that's only so if you define threat in a really narrow manner as for example theft. Spam has caused many people to give up on electronic mail completely, which is a big problem to for example banks that want to be able to communicate with their customers by email. Theft? No. Interference with exchanging information with customers? Yes.

-jsq

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341cb65b53ef00e550f647a98834

Listed below are links to weblogs that reference New School: New Book by Adam Shostack:

Comments

Thanks for posting, John, and you are so right. I think you're going to really enjoy chapter 5. :)

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

My Photo

Risk Reading