Skip to Content
97 Things Every Information Security Professional Should Know
book

97 Things Every Information Security Professional Should Know

by Christina Morillo
September 2021
Beginner
264 pages
7h 48m
English
O'Reilly Media, Inc.
Content preview from 97 Things Every Information Security Professional Should Know

Chapter 7. Every Information Security Problem Boils Down to One Thing

Ben Smith

It’s the dirty little secret of our industry: just about every challenge that we face in trying to secure our infrastructure from threats ultimately comes down to an asset management problem.

In many organizations, asset management is viewed as pure drudgery and a never-ending stretch to accomplish. Assets residing on your network, not just those dedicated to your employees but perhaps your supporting third parties as well, are not static entities. Today’s asset inventory is almost guaranteed to look a little different than yesterday’s. Much like Sisyphus pushing the boulder almost to the top of the mountain every day, your asset management goal posts can and will change daily.

Yet if you don’t know what is plugged into your network, if you don’t know who is plugged into your network, your visibility will be dangerously limited, along with the ability to do your job in securing your organization.

Further complicating this task: defining exactly what an “asset” is may not be a totally straightforward exercise. In some cases, assets to be protected by you and your team may not be limited to traditional server, endpoint, or network gear. Are we talking about everything with an IP address? Is a digital signing certificate an asset that should be cataloged and protected like a physical device? Should identities ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Foundations of Information Security

Foundations of Information Security

Jason Andress

Publisher Resources

ISBN: 9781098101381Errata Page