Showing posts with label processes. Show all posts
Showing posts with label processes. Show all posts

Book review: "Own Your Future : How to Think Like an Entrepreneur and Thrive in an Unpredictable Economy" by Paul B. Brown et al. The ALBR process

I came accross this book by Paul B. Brown, Charles F. Kiefer and Leonard A. Schlesinger almost by chance. The title was enticing so I decided to give it a go. You can read it really fast and the structure is very approachable. Having an Information Security mindset, you can apply generic recommendations to our professional field and even try out some entrepreneurial experiments that could lead you to a professional change.

If you are going through a period of time after which you really need a positive? work-related change, reading this book could help you. As always, a little disclaimer: This post does not replace at any time the careful reading of the book and all points expressed here are extracted from the book but by no means complete, comprehensive or unbiased.

If I would have to summarise the book in only one sentence, I would say ALBR. The acronym of Act, Learn, Build and Repeat. This is what authors recommend to put in practice your own ideas. Note that they start with the word Action. The beauty of this book comes now: You select the scope and the context in which you will apply your own ideas: in your startup, with your current employer, at home, during your leisure time... actually these learning points can be applied everywhere and anytime.

I also like a lot the fact that this book, published in 2014 also proposes something that I was already suggesting in my first Information Security book: IT Securiteers - Information Security Management: Take baby steps, small steps so that you can always be in control and, if needed, revert back. Baby steps are an important risk-management measure.

The book is full of US-based examples. At the end of every chapter you have a nice little box with the key learning points (just as the IT Securiteers book, where you can also find a summary of the applicable MBA models at the end of every chapter).

The first section of the book describes how our professional world has changed compared to the one previous generations had and how this fact requires new skills (and new approaches) in all of us. Worth highlighting regarding risk management, the book confirms how the best entrepreneurs are quite risk averse.

The second section actually proposes the Act/Learn/Build/Repeat process to manage risk when starting off a new endevour. This process, plus the use of small baby steps, make you ready to fail safe, since there will never be something really major, or not manageable, at stake.

The third section is very realistic. It first confirms that not all our likes and passions will be payed by the market i.e. we can only follow our passion if we can (economically and realistically) afford it. Let's remember we need to live in this world. This is a convenient time to mention the model I wrote about in the IT Securiteers book on the intersection of your skills, your passions and the market to make a living.

The fourth section provides an interesting spin to starting something new: They propose to do it outside your everyday job. Certainly the possibility to start something new within your current job, providing even more value to your employers, should not be discarded. Actually, for those ranking high in risk-aversion, it is even recommendable. 

This section continues with the small steps approach and how your long term goals can only be achieved focusing on small deltas every day. This also applies to Information Security programmes and projects.

I like this sentence from the book: "Remember, your next job is probably not your last one".

Lastly, the authors remind you that you are the ultimate control point of both your job (and eventually, your life).


Happy future reading!

 

Away from monotony!



Process explorer vs process hacker

I have been playing with process explorer and with process hacker. I initially wanted to select the best of the two but I will finally keep and use both to identify running processes (and compromised workstations). Why?

- Both tools are useful pilot light-alike tools for your e.g. MS Windows XP or 7 computers. They provide useful information on which processes are running real time on the machine.

- Both tools help identifying what a specific process does in the machine. They complement each other.




In process hacker:

- You can inject your own dlls on a running process.
- The network and the services tabs, in the main panel, help overseeing all existing network connections and services.
- You hace access to all tokens related to a process and to all registry keys in use (also in process explorer through the lower pane).
- There is even more process related information than in process explorer.
- You can create your own service and look for hidden processes.
- You don't need to install .net in your machine (since version 2).
- There is a portable app version.

But...
- You need(ed) to install .net in your machine. [Well, not anymore - thanks to Mantas for the comment]

In process explorer:

- In the process properties option, you can perform a strings command on the process (which is useful to identify specific pieces of code). You can also do this in process hacker but it is a little more hidden in the memory tab - search string.
- The "find process" functionality is really handy. Just place the moving target on the window you wonder which process it is and it identifies the process.
- There is also a portable app version.
- Less functionality sometimes means more clarity.


But...
- You have access to network information per process, but not in the main panel.

All in all, I am happy to rectify but I would say that process hacker provides everything that process explorer brings plus an additional set of goodies.

Happy March!

ps By the way, little note for the readers of this blog. If you are a passionate IT security professional, able to work in English and willing to relocate in Central Europe for some months while adding undoubtful technical Infosec value to your CV, please contact me (an email address always appears in this blog's main page).