256
people found this helpful, as of 2023
ranked #110,096 most helpful
out of 571,544,897 reviews
★☆☆☆☆
DO NOT BUY THIS BOOK IT NEEDS TO BE RECALLED AND FIXED
This very boring book is more for a security professional to have on his or her desk as a reference rather than a study tool for the CISSP exam. There is a LOT of material in it that you don't need to know for the exam. For example, DR is gone over in painstaking detail. That's fine, but the CISSP exam is a mile wide/inch deep, so you will end up wasting a lot of studying time. Also there is a lot of redundancy throughout the book so more wasted studying time.
My main beef with the book is that it's unnecessarily wordy and highbrow. Here's an example.
"Specifically, what the security architect needs to accomplish through the investment of this time is to gain a better understanding of the usage scenarios that each stakeholder brings to the system in question and what the intricacies of those scenarios are in order to perform a risk analysis against them, and as a result, he or she will gain a better understanding of the powerful threats and vulnerabilities to be addressed as part of any defenses that may be planned and implemented".
Good gawd, I almost fell asleep while typing that out. That sentence could easily be cut in half.
Here's another example.
"Several common methods of cryptography exist including stream-based and block ciphers. The information security professional must have a basic understanding of both to ensure further understanding of encryption implementations."
The second sentence is unnecessary. It just adds weight to the book.There are a ton of sentences like that all throughout the book.
One more.
"Computers are inherently designed for predictability not randomness. Computers are so thoroughly deterministic that they have a hard time generating high-quality randomness. Therefore, special purpose built hardware and software called "random number generators," or RNG's, are needed for cryptography applications. The U.S. federal government provides recommendations on deterministic random number generators through the NIST. An international standard for random number generation suitable for cryptographic systems is sponsored by the International Organization for Standardization as ISO 18031. A rigorous statistical analysis of the output is often needed to have confidence in such RNG algorithms. A random number generator based solely on deterministic computation done solely by a computer cannot be regarded as a true random number generator sufficient in lack of predictability for cryptographic applications because its output is inherently predictable."
The last sentence is totally unnecessary. That was already stated in the first two sentences. I could give you many, many more examples but you get the picture.
The publisher must have wanted to get this book out quickly to capitalize on the new CISSP exam so they opted to skip proofreading.
Here's some proof for you.
"Iris scanning is the most accurate biometric technology."
"Retina scan devices are probably the most accurate biometric available today".
That's 4 points down the drain if I get a question on the exam about the most accurate biometric.
I especially love this one.
"Some areas to consider are actions such as planning for delivery of office supplies to the alternate site, setting up a package delivery account for the alternate site like UPS or Airborne...."
Airborne hasn't been around since 2003 when it got acquired by DHL.
Go with the latest Shon Harris book, she does a much better job of explaining the material. Although it doesn't reflect the new 8 domains, it still has everything you need to know to pass the latest CISSP exam, and you won't be bored to death.
May 2015 · Books · verified purchase