Ten Laws for Security - Practical Guide to Information Security
Ten Laws for Security - Practical Guide to Information Security
Price subject to change. Tap below for current.
Couldn't load pickup availability
In this review of Ten Laws for Security the reviewer finds a compact, experience-driven book aimed at professionals and researchers who need clear, principle-based guidance on protecting information. The single biggest reason to buy is its focus on ten core laws that synthesize practical lessons about attacks, vulnerabilities and threat thinking into accessible guidance; the informal tone plus brief technical introductions makes it useful as a bridge between operational practice and formal concepts in information security.
Key Features
- Ten core laws: Presents a concise framework that helps readers prioritize security decisions and design choices across systems and services.
- Attack and vulnerability focus: Explains common attack patterns and the vulnerabilities they exploit so practitioners can better anticipate and mitigate risks.
- Threat-driven approach: Emphasizes identifying and reasoning about threats, which aids in tailoring defenses to the most relevant risks for a given environment.
- Design guidance: Offers advice on designing security into systems rather than bolting it on, useful for architects and engineers working on new products.
- Practical examples from DRM and video protection: Draws on the authors experience to illustrate concepts with real-world scenarios familiar to media and content protection professionals.
- Introductions to formal ideas: Supplements informal discussion with brief technical introductions to core formal notions, supporting readers who want to deepen their theoretical understanding.
Who It's For
Ten Laws for Security is best for information security professionals, system architects, and researchers who appreciate principle-based thinking and want a compact, experience-backed framework to guide decisions. Those working in media protection, DRM, or related networking and cloud security contexts will find the examples particularly relevant.
Readers seeking a step-by-step how-to handbook, vendor product guidance, or exhaustive protocol specifications should look elsewhere; this book is oriented toward concepts and design laws rather than complete implementation blueprints.
Pros & Cons
Pros
- Provides a clear, memorable set of ten laws that make it easier to reason about security trade-offs.
- Balances practical experience with concise introductions to formal technical ideas, aiding both practitioners and researchers.
- Examples from DRM and video protection ground abstract points in real operational contexts.
Cons
- Not a step-by-step implementation manual, so readers needing detailed configurations will need supplementary resources.
Specifications
| Title | Ten Laws for Security |
| Author | Eric Diehl |
| Focus areas | Attacks, vulnerabilities, threats, design, authentication, social engineering |
| Style | Informal with technical introductions |
| Audience | Professionals and researchers in information security |
| Relevant categories | Books; Network Security; Networking & Cloud Computing |
Our Verdict
Ten Laws for Security is a worthwhile read for security practitioners and researchers who want compact, principle-driven guidance grounded in real experience. Its laws and illustrative examples deliver strong conceptual value and good return for those designing or evaluating protection schemes, though it is best used alongside implementation-focused resources.
Frequently Asked Questions
Does the book cover practical attacks?
The book discusses common attack patterns and the vulnerabilities they exploit, using examples to show how to anticipate and mitigate such attacks.
Is it suitable for beginners?
It is accessible but geared toward readers with some exposure to security concepts; newcomers may need additional introductory material.
Does it include formal technical material?
Yes, the text supplements its informal style with introductions to core formal technical ideas to support deeper understanding.
Editor's Take
Ten Laws for Security is a compact, principle-driven guide ideal for security professionals and researchers; it delivers conceptual value through ten core laws and real-world DRM examples, though it is not a step-by-step implementation manual.

Recently viewed
Recently viewed products will appear here as customers browse the store.