The Best Damn Firewall Book Period

In an age where our society relies so heavily on electronic communication, the need for information security is constantly increasing. Given the value and confidential nature of the information that exists on today's networks, CIOs are finding that an investment in security is extremely beneficial. Without security, a company can suffer from theft or alteration of data, legal ramifications, and other issues that all result in monetary losses.
In this chapter, we look at the big picture: what we mean by network security in general and Internet security in particular; why it's necessary and how we can create a comprehensive security policy to protect our networks from unauthorized access.
Network security is a hot topic and is growing into a high-profile (and often highly-paid) IT specialty area. Security-related Web sites such as Net-Security (www.net-security.org), SecurityFocus (www.securityfocus.com), and Packetstorm Security (www.packetstormsecurity.org) are tremendously popular with savvy Internet users. Esoteric security measures such as biometric identification and authentication formerly the province of science fiction writers and perhaps a few ultrasecretive government agencies have become almost commonplace in corporate America.
Yet with all this focus on security, many organizations implement security measures in an almost haphazard way, with no well-considered plan for making all the parts fit together. Computer security involves many aspects of safekeeping, from protection of the physical equipment to protection of the electronic bits...