Cybersecurity Books: Foundations
The books worth starting with: they give you a threat model, a vocabulary, and the big picture before you open your first tool.
Cybersecurity Books: Foundations
Part one of nine. The books worth starting with: they give you a threat model, a vocabulary, and the big picture before you open your first tool.
Skip this block and jump straight to practice, and you end up with a set of tricks and no understanding of what they are for.
Ross Anderson. Security Engineering (3rd edition, 2020)
The central book of the discipline. Anderson treats security as an engineering problem, using ATMs, electronic locks, medical systems, and elections as examples, not just computer networks. The author has made the full text freely available.
Topics: threat models and adversary models, the economics of security, the psychology of attacks, protocols, access control, physical and hardware protection, how systems fail in real operation.
William Stallings, Lawrie Brown. Computer Security: Principles and Practice
The academic textbook university courses are built on. Dry, but it closes gaps systematically.
Topics: cryptographic primitives, authentication and access management, operating system and database security, malware, network attacks, standards and regulatory requirements.
Bruce Schneier. Secrets and Lies (2000)
A book about why security is a process, and why technology on its own guarantees nothing. Written a quarter of a century ago, and only the examples have aged.
Topics: thinking in terms of risk, mistakes in assumptions, trusted parties, the trade-off between convenience and protection, the limits of cryptography as a solution.
Mike Chapple, David Seidl. CompTIA Security+ Study Guide
Preparation for the entry-level certification and, along the way, the most structured overview of the industry's terminology. Useful even if you never plan to sit the exam.
Topics: types of attacks and controls, architecture and design, identity management, risk management, incident response, the basics of cryptography.
Phillip Wylie, Kim Crawley. The Pentester Blueprint (2020)
On entering the profession: which skills you need at the start, how the roles differ, how to build a path from system administration or development.
Topics: the map of security specialisations, the networking and systems base you need, a lab for practice, certifications and their real weight, finding the first job.
Marcus Carey, Jennifer Jin. Tribe of Hackers (2019)
Seventy interviews with practitioners answering the same set of questions. The value is in the spread of answers: there is less obvious consensus in the industry than it looks from outside.
Topics: career paths, attitudes to certifications, the most overrated defensive measures, working with management, burnout.
Next part: offensive security.
The whole series: