Showing posts with label ISACA. Show all posts
Showing posts with label ISACA. Show all posts

Monday, January 18, 2021

Forward into 2021

 Well, here we are in 2021.  A lot has happened to all of us this past year.  I think all the security conferences I usually attend this past year from March on were either cancelled or went virtual.  And it looks like the same will occur thru some of this year.

I've also been behind in trying to post regularly on this blog and hope to address this and aim to post at least twice a month.  I am planning on tackling some additional certifications in the cloud and privacy areas, and will be posting on this, as well as areas I have an interest in.  Futher, I plan on presenting at upcoming conferences and events, so will be posting on that.

Here in Florida, I know that BSides Tampa will be virtual in 2021, and I have proposed a few ideas.  Not sure about BSides Orlando.  South Florida ISSA does plan on doing their Hack the Flag, hopefully live.  Both SFISSA and HackMiami will be having regular meetings on-line, as well as South Florida ISACA.

If anyone has any ideas or suggests, please post them.


Monday, February 17, 2020

Upcoming Security Events in Florida

There are several upcoming information security events in Florida that some may not be aware of.

First up is the South Florida ISACA Chapter's annual WOW event.  This year its the thirteenth year of the event.  It will be held on Friday February 21st, 2020, again at FIU's Koven Center at their Biscayne Bay campus.  This is a single-track conference, with various speakers and a panel discussion.  Its usually a good event, and plan on being there.

Next up is Security BSides Tampa.  The seventh year for this event, it will be held Saturday, February 29th, 2020 at the Embassy Suites on the USF Campus in Tampa.  There will be training sessions on Friday.  This event is a multi-track conference, with tracks including CISO, Cloud, and job fair.  They also have other activities like a CTF, Lockpicking, and more.  This is a pretty good event.  Sadly, I don't plan on attending this year.

Then there is Security BSides Orlando.  This will be Saturday, April 11, 2020 at Full Sail University's Live Venue.  I believe they are planning on doing training sessions on Friday.  The schedule hasn't yet been announced.  They also have other activities like CTF, Lockpicking, and more.  This is also a pretty good event and it seems BSides Tampa and Orlando have some of the largest BSides outside of Vegas.  I'm not sure at this point if I'll be going.

Finally, there is HackMiamiCon.  This time it will be Saturday, May 30th, 2020 at Broward Library.  There will be training events on Friday.  This is a change of venue from hotels on Miami Beach, so will remain to be seen how this works out.  They should have other activities like a CTF.  This is also a good event.  Due to a conflict with another event, I may not attend this year.

These are all great events and I encourage folks to check them out and attend.


Thursday, February 22, 2018

Report on ISACA South Florida's WOW Event

The South Florida Chapter of ISACA has been holding an annual one-day conference each year in February known as the WOW! Event.  In 2018, they held their 11th conference on Friday, February 16th at FIU's Koven Conference Center at their Biscayne Bay campus.

This year's theme was "The InfoSec of Things: Emerging issues in Privacy and Security".  There were about 250 people in attendance for the day, with several speakers and a panel discussion with several local CISOs.

Speakers included:

Friday, February 2, 2018

Upcoming Conferences in early 2018

There are several local security conferences coming up in my general area, some of which I'll be speaking at.

Here are the ones over the next few months:

* SecureMiami 2018, co-located with BrewMiami.  Organized by DigitalEra, this is the second time for this half day event at the main campus of Florida International University.  Held on Saturday, February 10th.  Registration is open NOW and I encourage people to attend.

* ISACA South Florida Chapter's 11th WOW Event is coming up on Friday, February 16th at FIU's Biscayne Bay campus.  The theme: The InfoSec of Things: Emerging issues in Privacy and Security, and have great lineup of speakers.  So register NOW.

* BSides Tampa 2018 is coming up Saturday, February 17th again at Stetson Law in Tampa.  I will be speaking here on the topic of "SOC for Cybersecurity".  I think they are sold out, but check anyway.

* BSides Orlando 2018 is coming up on Saturday, April 7th.  Location this year will be Full Sail Live Venue in Winter Park.  CFP is open, and I've submitted some proposals, and registration is open NOW.

* HackMiamiCon6 is coming up May 18-20.  This year they will be at Sea Coast Suites in Miami Beach.  I will be speaking there on protecting your organization with resilience and disaster recovery.  Registration is open NOW.

So, there are more coming down the road.  Stuff in the summer and stuff coming up in the Fall, especially in October do to Cybersecurity Awareness Month.

Check back for more.  I will be doing postings reporting on these events after they are done.



Monday, September 18, 2017

"Hacker Summer Camp" 2017

This past July I went out to Las Vegas for the first to attend some of the events referred to as "hacker summer camp": Black Hat, BSides, and Defcon.

Now, I did not attend Black Hat as the event was pretty expensive.  I did want to drop by the exhibit hall, but couldn't get in.  I did attend the ISSA and ISC(2) receptions tied to the event.  I was a little disappointed that ISACA made a big deal about being at Black Hat but didn't do a reception of some kind.

I mainly came to attend BSides and Defcon and stayed at the Tuscany Suites where BSides was being held, which I recommend.  This guaranteed you a ticket for BSides.  I also got the meal ticket deal (breakfast & lunch) at BSides, which made me a sponsor and got me earlier checking at the sponsor table.  I also pre-ordered a t-shirt (recommended).

There were a lot of interesting sessions I attended.  I'll need to do another posting on some of the sessions I went thru and give more info on them.

Once BSides was over I attended Defcon.  This event was a bit overwhelming.  There was a big line for the trading post (cash only!), and I mainly wanted to get a t-shirt.  I was a little disappointed that the badge this year was a rubber badge, not an electronic one.  But many others had their own badge and I got a few.

Defcon is almost a collection of conferences.  There are main Defcon sessions, which are in HUGE rooms, four at a time.  Then there are a half dozen or so "villages" which have activities and their own sessions.  Skytalks was a good one, but there are villages for privacy & crypto, car hacking, IoT, and many others.  There was also a vendor area (but not open the first day).  There were many interesting vendors.  One I had met at BSides is HackerBoxes. 

As I noted, a lot of groups, including some of the villages, had their own electronic badges.  I really wanted a few, but they were cash only.  I didn't consider that and didn't bring a lot of cash with me.  And using ATMs was expensive.  So next time I will bring a lot more cash. 

I did some fun things, like solider a small badge at the Hardware Hacking Village (wasn't their big electronic badge they had, missed out on that).  Had some interesting conversations with several people. Met a few interesting people and groups.

Not sure if I'll go back next year or when I'll go back.  I would probably want to submit some talk proposals to BSides (I had thought of doing some this year, but wasn't certain if any I do would get accepted, but after seeing the sessions I should have submitted some).  I would again get a room at the Tuscany and had debated getting one just in case I decided to go.  Just don't know at this point.

I'll post some pics soon.

Wednesday, April 5, 2017

Upcoming Security Conferences for 2017

There are several conferences in the South Florida (and other areas) that I plan to be at in the coming months, and am speaking or hope to be.

BSides Orlando will be April 8th, but now moved to Valencia College-West Campus.  Also different this year is this will be a one day event, but will again be right before SANS Orlando.  I will be there speaking on the topic of Risk.  This talk is aimed at the entry level security professional to help them gain a better understanding of the importance of IT Risk in what we do in security.


The South Florida ISACA Chapter will be having their 10th WOW event on Friday, April 21st.  This will be an all day event at the FIU Biscayne Campus as usual.  Registration is already open and the focus is on "Emerging Threats in Cybersecurity".  Will be there.  Had hoped to speak, but didn't happen.

HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.  I will be speaking there on the topic of Cyber Resilience.


Further out, there is of course Black Hat, DefCon, BSides out in Las Vegas from July 22-30th.  I have never been out there, and plan to go out for BSides and DefCon.  Barring any financial issues.  I am also planning to submit for BSides.  Probably submit a few of my talks and see if any get picked.  Not sure if what I speak on would be accepted at DefCon.

Interestingly, ISC(2) has moved their Security Congress event out of being co-located with ASIS's conference.  This one will be September 25-27 in Austin, TX.  To be honest, I have no plans to attend this.  I felt their event was a bit pricey.

Now, ASIS, which is more for security folks who deal with physical security then information security, will have their conference September 25-28 in Dallas, TX.  ISSA is working with them to have infosec speakers at this event.  Kind of filling the void that ISC2 left.  And again, Infragard is co-hosting their annual conference there as well.  Sounds interesting, but again, probably will not be at this event.  Just can't afford it.

ISSA will be having their 2017 International Conference in San Diego from October 9-11.  I am on the conference committee for this one again, and again submitted some talk proposals.  Unless one of my talks gets picked I'm not certain I'll go this year. [UPDATE: my talk on Cyber Resilience was picked]. I do want to go next year when it'll be in Atlanta.

Now, the only other conferences this year I look forward to is a possible Security BSides happening in Southwest Florida, where I am from.  Heard about this at BSides Tampa and the group hopes to have this in Ft Myers.  I hope to hear more about it as I'd love to be involved.  Tentative time they are aiming for is June.

Another one I should mention is BSides Jacksonville.  This is usually held in October.  I've never been to one.

If any will be at the above ones I'll be at, stop by and say hi!

Thursday, February 16, 2017

ISACA's State of Cyber Security 2017 Report

Recently ISACA released the result of a survey as their State of Cyber Security Report 2017, part 1.  You can download it at their website HERE.

Part 1 focuses on topics like "workforce challenges" and "persistent skills gap".  Like many other groups, ISACA continues to push the narrative of a skills gap, and of course their solution is to train more folks in cybersecurity, ideally with their new set of CSX training and certifications.

Friday, January 13, 2017

Upcoming Conferences in South Florida 2017

There are several conferences in the South Florida (and general area) that I plan to be at in the coming months, and some I hope to speak at.

The South Florida ISACA Chapter will be having their 10th WOW event on Friday, February 24th. [UPDATE: Friday, April 21st] This will be an all day event at the FIU Biscayne Campus as usual.  Registration is already open and the focus is on "Emerging Threats in Cybersecurity".



The South Florida ISSA Chapter will be having their biannual security conference on Friday, March 10th.  This will be an all day event at the Signature Grand.  Registration is open, sponsors are being lined up and a call for presenters is open.



BSides Orlando will be April 8th, again at University of Central Florida.  Unlike past years, this will be a one day event, but will again be right before SANS Orlando.



HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.



So some great events and I look forward to them.


Wednesday, August 31, 2016

I recently attending the 2016 GRC Conference.  This conference was a joint event of IIA & ISACA, and was held in my area in Ft. Lauderdale.  It was a two day conference with speakers in several tracks, along with an exhibitor area.  There were some special sessions before and after the main conference.  This is the sixth time they have done this conference.  Next year's event will be in Texas.

For me, I attended because they had several sessions on cybersecurity.  I was able to attend for free because I volunteered at the conference as a member of ISACA.

Friday, July 1, 2016

Upcoming Security Events (I plan to be at) in 2016

Well, there are several upcoming events I hope to be involved within the coming months.  Several of these I hope to have further postings to promote them, but here is a quick run down.

Wednesday, November 12, 2014

ISACA's 2014 IT Risk/Reward Barometer

Recently, ISACA released their IT Risk/Reward Barometer, based on a survey they conducted.

They have a page at their site with the survey results and other information, along with several infographics.  I thought they were pretty interesting.


Tuesday, November 4, 2014

Is there an IT Security Skill Set Gap??

Over the last year or so, I have heard from several sources that we have a "cybersecurity skills gap".  That we have more IT security positions then we have skilled people to fill them.

Here is one example of such claims:



Now, as an experienced cybersecurity professional who has been on the job market for some time without too much success, I have a hard time accepting this.  Why do I say this?

Thursday, October 9, 2014

ISACA's new Cybersecurity Nexus

ISACA, the professional association for those involved in IT Audit and Controls, has decided to move into the realm of "cybersecurity" with their Cybersecurity Nexus (CSX).

I've been a member off and on for several years, but for me the group was about IT audits and IT control, such as COBIT.  I joined other organizations for cybersecurity, such as ISSA, and SANS.  I don't know why ISACA feels they need to move into that area, it's not like there is a need for yet another group involved here.

Further, as part of this, they've created a new entry level certificate, Cybersecurity Fundamentals.  This is meant for those just getting into cybersecurity.  It has no experience requirements, nor does it expire.  For me, certificates that don't require experience or don't expire are not as valuable as those which do.  And unlike ISACA's other certifications, this one is taken on-line on-demand.

I'm one of those people who doesn't see the value in duplicating effort.  I feel they are duplicating effort that is already being done by other organizations (ISSA, ISC(2), SANS, etc).  I'd rather see them partner with an existing group then move beyond their "core purpose".

Any other thoughts?


Monday, June 24, 2013

Getting involved locally- joining, learning, networking

So its been too long since I've posted.  Something in the back of my mind is my observations of my collegues in the IT and IT Security realm.  What has long disappointed me was how many never bothered to keep learning and being involved in the larger "community".  Other then taking some training courses, many didn't bother to keep up with what is going on in the industry- didn't read journals (either print or on-line), didn't get engaged with local groups or events or the like.

For me, I joined USENIX and SAGE when I got involved as an IT admin.  When I got involved in IT Security, I joined ISSA and got involved in the South Florida ISSA chapter.  I was briefly involved with ISACA (and thought about getting back involved).  I know about other groups (we have a chapter of ISC(2) getting formed) and have looked at others to see if they were worth joining.

I tried to get involved with local events tied with those groups (my chapter runs a security conference every 2 years, and has an annual "hack the flag" event), as well as others.  Last year in December we had the ITPalooza event, which will happen again this year.

So my advise to you is if you want to succeed in your IT career: GET INVOLVED.  Depending on what your interest or focus is, see if there are groups that are appropriate for that, and join them.  Especially get involved with local chapters of these groups.  Maybe think about becoming an officer.  If you are the type, consider making a presentation, even its at a local event.

So, if you've had experience getting involved, comment about what you've done and what you've gotten out of it.

Friday, June 14, 2013

Upcoming South Florida Security Event: State Sponsored Hacking

For those IT Security professionals in the South Florida area, there is an upcoming security event they should know about.

Hosted at Nova Southeastern University on July 23rd, its on State Sponsored Hacking.  Its organized by SherlockTech Staffing.

Full info and free registration at Eventbrite:  http://nsu-securityevent-es2.eventbrite.com

Signup today!!!