Resources used in my lectures - Information Security

Lecture Materials and Legal Resources
Lecture Image 1 The first chapter talks about the fundamentals including the and design principles. The first chapter gives the background to the subject and important terminology.
Lecture Image 2 Very clear explanation of the subject, including a book, lecture slides, simulated Internet, and lab exercises.
Fundamentals Image Lecture notes, code segments, and presentations.
Android Enterprise Security Android security.
Intruder Dashboard An application security testing tool.
MITRE ATT&CK MITRE attack framework.
IoT Security Architecture Threat modeling by Microsoft - Security architecture for IoT solutions.
MITRE Attack Framework for AI MITRE attack framework for AI.
OWASP ASVS Banner OWASP Application Security Verification Standard.
CYBOK Front Banner Cyber Security Body of Knowledge by the UK government.
Linux Foundation Course on Secure Software Development
NIST Cybersecurity Framework NIST Cybersecurity Framework v2.0
Legislations and Related Source
Personal Data Protection Act, No. 9 of 2022
Intellectual Property Act, No. 36 of 2003
ELECTRONIC TRANSACTIONS ACT, No. 19 OF 2006
Computer Crime Act, No. 24 of 2007
Evidence (Special Provisions) Act (No. 14 of 1995)
General Data Protection Regulation
GDPR Enforcement Tracker
University level course on Cyber Crimes by the United Nations Office on Drugs and Crime
Title Key Points
INFORMATION SECURITY POLICIES, PROCEDURES, AND STANDARDS: A Practitioner’s Reference Chapter 1 and 2. Chapter 2 describes the policies, standards, guidelines, and procedures
ISO 27001 controls – A guide to implementing and auditing (Bridget Kenyon) ISO Standard on Information Security
The Art of Cyber Security: A practical guide to winning the war on cyber crime (Gary Hibberd) The importance of having the right mindset

Comments

  1. This comment has been removed by the author.

    ReplyDelete
  2. SAFECode, “Practical security stories and security tasks for agile development
    environments,” SAFECode, Tech. Rep., July 2012. [Online]. Available: http://safecode.org/
    wp-content/uploads/2018/01/SAFECode Agile Dev Security0712.pdf

    ReplyDelete
  3. SAFECode, “Fundamental practices for secure software development: Essential elements
    of a secure development lifecycle program,” SAFECode, Tech. Rep. Third Edition, March
    2018. [Online]. Available: https://safecode.org/wp-content/uploads/2018/03/SAFECode
    Fundamental Practices for Secure Software Development March 2018.pdf

    ReplyDelete
  4. WhiteSource identifies every open source component in your software, including dependencies. It then secures you from vulnerabilities and enforces license policies throughout the software development lifecycle. The result? Faster, smoother development without compromising on security.

    ReplyDelete
  5. Credential Scanner (aka CredScan) is a tool developed and maintained by Microsoft to identify credential leaks such as those in source code and configuration files. Some of the commonly found types of credentials are default passwords, SQL connection strings and Certificates with private keys.

    ReplyDelete
  6. some games - 7https://www.usenix.org/conference/3gse14/summit-program/presentation/shostack
    8https://securitycards.cs.washington.edu/ Protection Poker [30]

    ReplyDelete
  7. Security Quality Requirements Engineering (SQUARE)
    https://insights.sei.cmu.edu/library/security-quality-requirements-engineering-square/

    ReplyDelete
  8. Cloud Computing Law
    Second Edition
    Edited by
    CHRISTOPHER MILLARD

    ReplyDelete
  9. AWS
    All-in-One
    Security Guide
    Design, Build, Monitor, and Manage a
    Fortified Application Ecosystem on AWS

    ReplyDelete
  10. https://portswigger.net/web-security

    ReplyDelete
  11. Free, online web security training from the creators of Burp Suite

    ReplyDelete
  12. https://www.handsonsecurity.net/resources.html

    ReplyDelete
  13. https://trainingportal.linuxfoundation.org/learn/course/developing-secure-software-lfd121

    ReplyDelete
  14. https://portswigger.net/burp/communitydownload

    ReplyDelete
  15. ISO 27001 Controls
    A guide to implementing and auditing

    ReplyDelete
  16. This comment has been removed by the author.

    ReplyDelete
  17. Book - Grokking Web Application Security

    ReplyDelete
  18. https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Defendable-Architectures.pdf and https://www.lockheedmartin.com/

    ReplyDelete
  19. (1) AWS Graviton Memory Encryption
    (2) AWS Nitro instance Memory Encryption

    ReplyDelete
  20. https://www.nirsoft.net/system_tools.html various tools to study the system, recover passwords, etc

    ReplyDelete
  21. A Cuckoo Sandbox is an open-source tool that can be used to automatically analyze malware. Imagine, it’s 2 am in the Security Operations Center (SOC) and an alert has triggered…
    https://www.varonis.com/blog/cuckoo-sandbox

    ReplyDelete
  22. A challenge - https://www.varonis.com/frostbyte

    ReplyDelete

Post a Comment

Popular posts from this blog

Legal issues in the IT field

Recent legal issues