Skip to Content
97 Things Every Information Security Professional Should Know
book

97 Things Every Information Security Professional Should Know

by Christina Morillo
September 2021
Beginner
264 pages
7h 48m
English
O'Reilly Media, Inc.
Content preview from 97 Things Every Information Security Professional Should Know

Chapter 95. The Security Practitioner

Wayne A. Howell Jr.

The threat landscape for security practitioners changes on a daily basis. It is critical that security professionals have an understanding of key focus areas and best practices to help organizations manage their risk. When building a new security program, practitioners should incorporate the fundamental principle of, What is the risk to the business? Every company should have a risk management plan that captures what the business should focus on, and it is our job to ensure that the business understands the risks associated with it. Risks can come from various areas such as compliance risk, business risk, open source risk, supplier risk, etc. Every business understands the cost of doing business and should have a defined place within our security program. This allows organizations to be given the guidance when needed to navigate the ever-changing security landscape.

As security practitioners, it is our duty to drive organizations to incorporate the use of security tools throughout the software development life cycle. It is critical that the risk management plan is supported by security tooling. This allows development teams to identify, classify, and remediate weaknesses found during automated analysis. Security practitioners should incorporate the use of software composition analysis (SCA), static application security ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Information Security Handbook

Information Security Handbook

Darren Death
Zero Trust Security: An Enterprise Guide

Zero Trust Security: An Enterprise Guide

Jason Garbis, Jerry W. Chapman

Publisher Resources

ISBN: 9781098101381Errata Page