Showing posts with label SANS. Show all posts
Showing posts with label SANS. Show all posts

Tuesday, March 20, 2018

Critical Security Controls v7 RELEASED

I have previously posted on the Critical Security Controls, which many still incorrectly called the "SANS Top 20" and the like, tho SANS hasn't been managing them for some time.  The current org that manages them is the Center for Internet Security, which has overseen them since around 2015.  They previously put out v6 and after about a year working on the have released v7.  You can download them from the CIS website, along with other materials.

I haven't had the chance to full look at v7 and take a look at the differences from v6.  There are still 20 "controls", but they've done some rearrangement and have made tweaks to the "subcontrols" by adding, spitting, merging, moving (from one control to another), rewording, or deleting some.

Tuesday, September 19, 2017

My first SANS/GIAC certification

I have several infosec certifications, but most are from ISC(2) and ISACA.

This past week I learned that I passed the test I took for a new GIAC certification: the GSTRT, which is for the GIAC Strategic Planning, Policy, and Leadership.  Its tied to SANS's new MGT514: IT Security Strategic Planning, Policy, and Leadership, which I took last year.  At the time there was no cert, so I got to beta test the new exam.

Not having done any of the GIAC certs, this was a new experience for me.  GIAC allows you to bring your books with you, so I knew it was vital to prep for the cert.  I read and re-read my books and also created my own index of the books.  This was vital because one volume was devoted to leadership concepts, and it had a lot, many I wasn't familiar with when I took the course.  In many cases, they almost introduced a new concept every 2-3 pages!

I don't know my score yet, but am curious to learn how well I did.


Friday, January 13, 2017

Upcoming Conferences in South Florida 2017

There are several conferences in the South Florida (and general area) that I plan to be at in the coming months, and some I hope to speak at.

The South Florida ISACA Chapter will be having their 10th WOW event on Friday, February 24th. [UPDATE: Friday, April 21st] This will be an all day event at the FIU Biscayne Campus as usual.  Registration is already open and the focus is on "Emerging Threats in Cybersecurity".



The South Florida ISSA Chapter will be having their biannual security conference on Friday, March 10th.  This will be an all day event at the Signature Grand.  Registration is open, sponsors are being lined up and a call for presenters is open.



BSides Orlando will be April 8th, again at University of Central Florida.  Unlike past years, this will be a one day event, but will again be right before SANS Orlando.



HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.



So some great events and I look forward to them.


Friday, November 25, 2016

SANS Miami 2016

A couple of weeks ago I attended the SANS Miami 2016 conference.  While I have taken a few SANS courses, this was actually the largest SANS event I've been able to attend.  The previous events I was at were SANS Community events, one with only one course over several weeks, another was a week-long event with just 2 courses.  The rest I did on-line.

For the last few years SANS had been doing small events in our area, first in Ft Lauderdale before moving to Miami.  These events had about 5 courses.  The first few ones were mainly focused on forensics courses, which were not of interest to me.  This one had a more devise set of courses, and took one of their security management courses:  MGT514: IT Security Strategic Planning, Policy and Leadership.

Overall I thought this course was good.  For me, it was a mix of stuff I knew, stuff I had heard of but didn't know much about, and new stuff.  A lot of what I've learned has been learned on the job vs in a course, so I often have gaps in my knowledge, or I might not know the "proper" way of things.  So this kind of course helps me fill those gaps.

SANS already has SANS Miami 2017 on their calendar for next year, but haven't yet announced the 5 classes they will be offering.  Will see if I'm able to attend.

Monday, September 19, 2016

Updates to the CIS Critical Security Controls

Hopefully most people are aware of the Critical Security Controls, which are too often called the "SANS Top 20" or the like, even tho SANS no longer manages them.  (they do offer a course and cert on them.)

SANS actually turned them over to a group called the Council on CyberSecurity in 2013, and put out at least version 5.0 of the controls.  The Council merged with the Center for Internet Security in 2015, who released version 6.0.  Properly they are the CIS Critical Security Controls, or CIS CSC.

With v6.0, they did some revamping and re-ordering the controls.

And CIS has continued to support the CSC.  They have released some new items!

Friday, July 1, 2016

Upcoming Security Events (I plan to be at) in 2016

Well, there are several upcoming events I hope to be involved within the coming months.  Several of these I hope to have further postings to promote them, but here is a quick run down.

Wednesday, May 29, 2013

SANS' Securing the "Internet of Things" Summit

I recently learned that the SANS Institute, a leading IT Security training and certification organization, has a Call for Papers (CFP) for an upcoming one day workshop on securing the "Internet of Things".

The event is the Securing the Internet of Things Summit, being held on October 21st in San Fransisco.



The page has full info on the event, including the CFP.

The event sounds pretty good.  I'd love to be there, but most likely won't be able to.  I do hope that the papers presented will be available to others.  (say a conference report or the like).