2. Foundations and Principles of Security

This chapter discusses some of the basic principles and theories of security. Some of you are probably very familiar with the methodologies discussed in this chapter and if that is so, let this serve as a quick review. Others may be looking for a complete, holistic approach to understanding risk assessment. If so, this chapter will serve as a good basis. In the end, security is not one item, technology, or tool. It is an ongoing process that includes assessing risk, building good policies, implementing protections for key informational assets, training employees, and designing true defense in depth.

By the time you finish reading this chapter, you will understand these basic components and how they contribute ...

Get Inside Network Security Assessment: Guarding Your IT Infrastructure now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.