The Art of Deception: Controlling the Human Element of Security
by Kevin D. MitnickMitnick's insights into social engineering highlight the critical human factors in security, essential for comprehensive audits.
Security Engineering: A Guide to Building Dependable Distributed Systems
by Ross J. AndersonAnderson's classic provides foundational knowledge on security principles, vital for understanding multi-tier applications.
Threat Modeling: Designing for Security
by Adam ShostackThis book offers a practical approach to threat modeling, crucial for identifying vulnerabilities in complex systems.
Risk Management Framework: A Lab-Based Approach to Securing Information Systems
by James BroadBroad's framework integrates risk assessment methodologies, enhancing your ability to conduct thorough audits.
The Security Risk Assessment Handbook
by Douglas J. LandollLandoll’s comprehensive guide to risk assessments will refine your skills in evaluating and prioritizing risks.
The Checklist Manifesto: How to Get Things Right
by Atul GawandeGawande's principles on checklists can streamline your audit processes and ensure thoroughness in evaluations.
Enterprise Security Architecture: A Business-Driven Approach
by Scott L. D. McKenzieThis book connects security frameworks with business needs, crucial for compliance and stakeholder communication.
Cybersecurity and Cyberwar: What Everyone Needs to Know
by P.W. Singer and Allan FriedmanSinger and Friedman provide insights into the broader cybersecurity landscape, enhancing your contextual understanding.