I am interested in IT security, but I am a programmer by profession. I develop web application using Java. Besides programming, I knew nothing about network/system.

Please advise how can I move on to IT security?