Best way to learn computer security ?

Post by Frank Cusa » Wed, 20 Aug 2003 12:56:19

Become a system administrator first. Make sure you pick up network
admin knowledge. MANDATORY: read these books

Interconnections (Perlman)
"The Red Book" (now, the purple book) (Nemeth)
Practical Unix Security (Garfinkel & Spafford)

Unless you're a comp. sci type (which you're not) you need to become a
sysadmin type. In order to do that, you need to get some real world
experience managing production systems.

Ignore certs for now.


Post by Selle » Fri, 05 Sep 2003 10:49:57


I am not sure I can provide you any insight but I can tell you my progress
so far trying to break into Information Security. I started as a Systems
Administrator and after gaining about 6 years of experience doing that I
decided it was time to start focusing on security. I then took a support
position at a PKI vendor where I am gaining valuable knowledge in Public Key
Infrastructure and X.500 directories. While working in this position I am
also taking the Mentor Led SANS courses along with C++ programming classes
from my local community college because how am I supposed to understand how
to prevent a buffer overflow attack without actually writing code that is
vulnerable to one. Haha. In the upcoming months I will be writing the
certification tests for the SANS GSEC and ISC CISSP certifications just to
make myself more "marketable" and after that the search will be on for a
full time "Security Analyst" position where I hope to focus on Intrusion
Detection and Penetration Testing. Not sure if this helps you at all but
just wanted to share with you the road that I am on.



Post by tornado57 » Fri, 05 Sep 2003 20:03:54

thanks all for ur responses.