A couple of weeks ago I attended the SANS Miami 2016 conference. While I have taken a few SANS courses, this was actually the largest SANS event I've been able to attend. The previous events I was at were SANS Community events, one with only one course over several weeks, another was a week-long event with just 2 courses. The rest I did on-line.
For the last few years SANS had been doing small events in our area, first in Ft Lauderdale before moving to Miami. These events had about 5 courses. The first few ones were mainly focused on forensics courses, which were not of interest to me. This one had a more devise set of courses, and took one of their security management courses: MGT514: IT Security Strategic Planning, Policy and Leadership.
Overall I thought this course was good. For me, it was a mix of stuff I knew, stuff I had heard of but didn't know much about, and new stuff. A lot of what I've learned has been learned on the job vs in a course, so I often have gaps in my knowledge, or I might not know the "proper" way of things. So this kind of course helps me fill those gaps.
SANS already has SANS Miami 2017 on their calendar for next year, but haven't yet announced the 5 classes they will be offering. Will see if I'm able to attend.
Showing posts with label SANS Institute. Show all posts
Showing posts with label SANS Institute. Show all posts
Friday, November 25, 2016
Monday, September 19, 2016
Updates to the CIS Critical Security Controls
Hopefully most people are aware of the Critical Security Controls, which are too often called the "SANS Top 20" or the like, even tho SANS no longer manages them. (they do offer a course and cert on them.)
SANS actually turned them over to a group called the Council on CyberSecurity in 2013, and put out at least version 5.0 of the controls. The Council merged with the Center for Internet Security in 2015, who released version 6.0. Properly they are the CIS Critical Security Controls, or CIS CSC.
With v6.0, they did some revamping and re-ordering the controls.
And CIS has continued to support the CSC. They have released some new items!
SANS actually turned them over to a group called the Council on CyberSecurity in 2013, and put out at least version 5.0 of the controls. The Council merged with the Center for Internet Security in 2015, who released version 6.0. Properly they are the CIS Critical Security Controls, or CIS CSC.
With v6.0, they did some revamping and re-ordering the controls.
And CIS has continued to support the CSC. They have released some new items!
Thursday, October 9, 2014
ISACA's new Cybersecurity Nexus
ISACA, the professional association for those involved in IT Audit and Controls, has decided to move into the realm of "cybersecurity" with their Cybersecurity Nexus (CSX).
I've been a member off and on for several years, but for me the group was about IT audits and IT control, such as COBIT. I joined other organizations for cybersecurity, such as ISSA, and SANS. I don't know why ISACA feels they need to move into that area, it's not like there is a need for yet another group involved here.
Further, as part of this, they've created a new entry level certificate, Cybersecurity Fundamentals. This is meant for those just getting into cybersecurity. It has no experience requirements, nor does it expire. For me, certificates that don't require experience or don't expire are not as valuable as those which do. And unlike ISACA's other certifications, this one is taken on-line on-demand.
I'm one of those people who doesn't see the value in duplicating effort. I feel they are duplicating effort that is already being done by other organizations (ISSA, ISC(2), SANS, etc). I'd rather see them partner with an existing group then move beyond their "core purpose".
Any other thoughts?
I've been a member off and on for several years, but for me the group was about IT audits and IT control, such as COBIT. I joined other organizations for cybersecurity, such as ISSA, and SANS. I don't know why ISACA feels they need to move into that area, it's not like there is a need for yet another group involved here.
Further, as part of this, they've created a new entry level certificate, Cybersecurity Fundamentals. This is meant for those just getting into cybersecurity. It has no experience requirements, nor does it expire. For me, certificates that don't require experience or don't expire are not as valuable as those which do. And unlike ISACA's other certifications, this one is taken on-line on-demand.
I'm one of those people who doesn't see the value in duplicating effort. I feel they are duplicating effort that is already being done by other organizations (ISSA, ISC(2), SANS, etc). I'd rather see them partner with an existing group then move beyond their "core purpose".
Any other thoughts?
Wednesday, May 29, 2013
SANS' Securing the "Internet of Things" Summit
I recently learned that the SANS Institute, a leading IT Security training and certification organization, has a Call for Papers (CFP) for an upcoming one day workshop on securing the "Internet of Things".
The event is the Securing the Internet of Things Summit, being held on October 21st in San Fransisco.
The page has full info on the event, including the CFP.
The event sounds pretty good. I'd love to be there, but most likely won't be able to. I do hope that the papers presented will be available to others. (say a conference report or the like).
The event is the Securing the Internet of Things Summit, being held on October 21st in San Fransisco.
The page has full info on the event, including the CFP.
The event sounds pretty good. I'd love to be there, but most likely won't be able to. I do hope that the papers presented will be available to others. (say a conference report or the like).
Subscribe to:
Posts (Atom)