Recently ISACA released the result of a survey as their State of Cyber Security Report 2017, part 1. You can download it at their website HERE.
Part 1 focuses on topics like "workforce challenges" and "persistent skills gap". Like many other groups, ISACA continues to push the narrative of a skills gap, and of course their solution is to train more folks in cybersecurity, ideally with their new set of CSX training and certifications.
Thursday, February 16, 2017
Thursday, February 9, 2017
Commentary on Cyber Resilience
At the upcoming HackMiami5 conference I will be speaking on "Cyber Resilience". I have been looking at this term over the last several months. As an infosec/cybersecurity professional, I wanted to better understand what this "cyber resilience" is and how it fits in.
Now, at my talk at HM2017 I will be going into several "models" for cyber resilience and other resources, and I will NOT be posting that information here on my blog until sometime later. So this posting, which maybe part of a series, is more my thoughts on what cyber resilience is.
Now, the more or less standard definition I hear for cyber resilience is "the ability to recover from attacks quicker and keep losses to a minimum."
Now, at my talk at HM2017 I will be going into several "models" for cyber resilience and other resources, and I will NOT be posting that information here on my blog until sometime later. So this posting, which maybe part of a series, is more my thoughts on what cyber resilience is.
Now, the more or less standard definition I hear for cyber resilience is "the ability to recover from attacks quicker and keep losses to a minimum."
Friday, January 13, 2017
Upcoming Conferences in South Florida 2017
There are several conferences in the South Florida (and general area) that I plan to be at in the coming months, and some I hope to speak at.
The South Florida ISACA Chapter will be having their 10th WOW event on Friday,February 24th. [UPDATE: Friday, April 21st] This will be an all day event at the FIU Biscayne Campus as usual. Registration is already open and the focus is on "Emerging Threats in Cybersecurity".
The South Florida ISSA Chapter will be having their biannual security conference on Friday, March 10th. This will be an all day event at the Signature Grand. Registration is open, sponsors are being lined up and a call for presenters is open.
BSides Orlando will be April 8th, again at University of Central Florida. Unlike past years, this will be a one day event, but will again be right before SANS Orlando.
HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.
So some great events and I look forward to them.
The South Florida ISACA Chapter will be having their 10th WOW event on Friday,
The South Florida ISSA Chapter will be having their biannual security conference on Friday, March 10th. This will be an all day event at the Signature Grand. Registration is open, sponsors are being lined up and a call for presenters is open.
BSides Orlando will be April 8th, again at University of Central Florida. Unlike past years, this will be a one day event, but will again be right before SANS Orlando.
HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.
So some great events and I look forward to them.
NIST Cybersecurity Framework v1.1 is coming!!!
Well, NIST (National Institute of Standards and Technology) has announced an update for the Cybersecurity Framework (CSF). The new version will be v1.1, an incremental update which was expected.
They have released a draft of this update for comments.
You may read about it HERE. There is also THIS page that explain the update AND gives info on feedback, which has a deadline of APRIL 10, 2017 and were to send comments.
At that page you can read the draft in a couple of different versions.
What has been added/updated?
They added more stuff regarding supply chain. They did a few tweaks on the Core. I had hoped they would have gotten rid of the Implementation Tiers, but instead of dumping it or major work they did some tweaks to it. And there is a new section on metrics and measurement.
I was disappointed they didn't update the Critical Security Controls references. They are still listing v5, which is no longer valid and the group that managed it is no more. However, they note they are still updating all the Information References, so hopefully that is just something that is in progress and will appeared in the released version.
I had hoped that the HIPAA crosswalk that was done would be incorporated into the document, at least as an appendix. And I think the should add a PCI DSS crosswalk. Am told it exists, and think it would be good to include it. Again, maybe this will be including in the final version.
Am debating if I should put together a talk on this proposed draft for upcoming conferences.
They have released a draft of this update for comments.
You may read about it HERE. There is also THIS page that explain the update AND gives info on feedback, which has a deadline of APRIL 10, 2017 and were to send comments.
At that page you can read the draft in a couple of different versions.
What has been added/updated?
They added more stuff regarding supply chain. They did a few tweaks on the Core. I had hoped they would have gotten rid of the Implementation Tiers, but instead of dumping it or major work they did some tweaks to it. And there is a new section on metrics and measurement.
I was disappointed they didn't update the Critical Security Controls references. They are still listing v5, which is no longer valid and the group that managed it is no more. However, they note they are still updating all the Information References, so hopefully that is just something that is in progress and will appeared in the released version.
I had hoped that the HIPAA crosswalk that was done would be incorporated into the document, at least as an appendix. And I think the should add a PCI DSS crosswalk. Am told it exists, and think it would be good to include it. Again, maybe this will be including in the final version.
Am debating if I should put together a talk on this proposed draft for upcoming conferences.
BSides Tampa 2017
I will be speaking at BSides Tampa 2017 this February.
The topic will be on "HIPAA for Security Professionals". My aim is to introduce to security professionals what HIPAA is and what they need to know about it. With the increased pressure on healthcare organizations and their third party vendors for information security, this is important. Especially with HHS doing random audits going forward.
Hope to see many of you there.
The topic will be on "HIPAA for Security Professionals". My aim is to introduce to security professionals what HIPAA is and what they need to know about it. With the increased pressure on healthcare organizations and their third party vendors for information security, this is important. Especially with HHS doing random audits going forward.
Hope to see many of you there.
Tuesday, December 13, 2016
Recent events: ITPalooza and SecureMiami
This past week I attended a couple of events here in South Florida.
First up was the 5th ITPalooza. A bigger event then last year, the South Florida Technology Alliance organized the event and moved it to Signature Grand, a large banquet/conference center here in the area. The event took over the whole place, which I've never seen. Usually I'll be there and there will be 3 or 5 other events going on.
They had a large exhibit hall with various vendors, organizations, schools, and recruiters. Unlike past years, they didn't have the recruiters relegated to another room. I was there helping man the South Florida ISSA booth, promoting our org. Had several people drop by, so hope we will get more members. We also talked with some vendors and local universities.
In addition, there where several tracks of speakers. The CIO track was exclusive to the iCoast CIO Council, others were open to all. Here good things about those, but missed out.
For a first time event with new people in charge, I saw good and bad. There is always room for improvement. They have already set the date for next year's event as December 7th, 2017. Look forward to it.
A new event held this year was SecureMiami. This was held in conjunction with the existing BrewMiami event at FIU. SecureMiami was organized mainly by DigitalEra and was located at the Graham Center from 2-5pm. There was a keynote speaker, Jack Daniels, with speakers from 3 other vendors followed by a panel discussion with several VP Infosec/CISOs. All the speakers were good. It seemed the bad weather in the area discouraged some from coming, but they missed out.
Afterwards most went over the BrewMiami, where we had a VIP section just for the SecureMiami folks. Here one could sample various beers and food from local brewers and vendors.
Not sure if they will do this event again, but if so, they will have a lot of work to top this one.
First up was the 5th ITPalooza. A bigger event then last year, the South Florida Technology Alliance organized the event and moved it to Signature Grand, a large banquet/conference center here in the area. The event took over the whole place, which I've never seen. Usually I'll be there and there will be 3 or 5 other events going on.
They had a large exhibit hall with various vendors, organizations, schools, and recruiters. Unlike past years, they didn't have the recruiters relegated to another room. I was there helping man the South Florida ISSA booth, promoting our org. Had several people drop by, so hope we will get more members. We also talked with some vendors and local universities.
In addition, there where several tracks of speakers. The CIO track was exclusive to the iCoast CIO Council, others were open to all. Here good things about those, but missed out.
For a first time event with new people in charge, I saw good and bad. There is always room for improvement. They have already set the date for next year's event as December 7th, 2017. Look forward to it.
A new event held this year was SecureMiami. This was held in conjunction with the existing BrewMiami event at FIU. SecureMiami was organized mainly by DigitalEra and was located at the Graham Center from 2-5pm. There was a keynote speaker, Jack Daniels, with speakers from 3 other vendors followed by a panel discussion with several VP Infosec/CISOs. All the speakers were good. It seemed the bad weather in the area discouraged some from coming, but they missed out.
Afterwards most went over the BrewMiami, where we had a VIP section just for the SecureMiami folks. Here one could sample various beers and food from local brewers and vendors.
Not sure if they will do this event again, but if so, they will have a lot of work to top this one.
Monday, December 12, 2016
South Florida ISSA Security Conference 2017
Well the South Florida ISSA Chapter has announced our 2017 Security Conference.
Our conference website is setup HERE with full info, including call for sponsors and call for presenters. Registration is already open.
Check it out. We have some new ideas for this next conference.
Our conference website is setup HERE with full info, including call for sponsors and call for presenters. Registration is already open.
Check it out. We have some new ideas for this next conference.
Subscribe to:
Posts (Atom)




