Showing posts with label certification. Show all posts
Showing posts with label certification. Show all posts

Monday, February 10, 2020

2020 Update

Here we are in 2020, and there are many updates to go over.  I plan on further postings on several of these items, and need to get back into blogging here with more regularity.

Here are some of the new things that are out.

CCPA.  Privacy as an issue just seems to get bigger and bigger.  Even as a security professional I find myself being pulled into it.  I wonder if I need to join IAPP, maybe even study and get one of their certs.  We had the GDPR that came out last year.  I really though more companies would address it, but just didn't see that.  Now California came out with their CCPA law.  CCPA is not quite "California's GDPR".  Its not a broad privacy law, but aimed at consumer data.  I've seen some companies be concerned about it, but not as many as I thought.  But am sure I'll be getting more into it.

NIST Privacy Framework- NIST has been working on this for the last year and released v1 recently.  I have a copy and am reading over it.  I plan on giving a talk at an upcoming local meeting, and may do a conference talk about this as well.  Am hoping I'll be able to attend NIST's upcoming cybersecurity conference, as I'm sure it will be a topic of discussion.  We'll have to see how well this works in helping companies prepare for privacy regulations.

FISMA Updates- NIST is still working on the updates for the documents used for FISMA.  The next one they are working on is SP 800-53 Release 5.  We don't have a release date, but hope it will be soon as they've been working on it for so long.  Once its out, we should see other documents that are relying on it, such as 53A and 53B, an new version of 800-171 and others.  All we have so far on this is THIS page.

DoD CMMC- The DoD released this month the first version of their Cybersecurity Maturity Model Certification (CMMC).  This is an interesting items, its a certification for vendors of the DoD.  From a quick read, it combines the CMM/CMMI 5-level maturity model with the categories of the NIST SP 800-171, which is about protecting controlled unclassified data (CUI).  SP800-171 based on the control set of SP 800-53.  I plan on posting on this and may do a presentation as well.

PCI-DSS v4- yes, there is a new update of PCI-DSS.  I first heard about this a couple of years ago.  This should be a revamp of PCI-DSS.  I just have no idea how it will look like until its released.  Which I expect sometime this year.  I don't have an inside track, I just know from reading here and there that its getting closer to release.  Yes, I hope to posting on this as well.

There are several events coming up in my general area and will be posting in these soon.

Tuesday, September 19, 2017

My first SANS/GIAC certification

I have several infosec certifications, but most are from ISC(2) and ISACA.

This past week I learned that I passed the test I took for a new GIAC certification: the GSTRT, which is for the GIAC Strategic Planning, Policy, and Leadership.  Its tied to SANS's new MGT514: IT Security Strategic Planning, Policy, and Leadership, which I took last year.  At the time there was no cert, so I got to beta test the new exam.

Not having done any of the GIAC certs, this was a new experience for me.  GIAC allows you to bring your books with you, so I knew it was vital to prep for the cert.  I read and re-read my books and also created my own index of the books.  This was vital because one volume was devoted to leadership concepts, and it had a lot, many I wasn't familiar with when I took the course.  In many cases, they almost introduced a new concept every 2-3 pages!

I don't know my score yet, but am curious to learn how well I did.


Tuesday, April 11, 2017

Resources for presentation on IT Risk

As mentioned previously, I gave a presentation on IT Risk at the 2017 Security BSides Orlando Conference.  The title was "Risk: It's more then just a game from Parker Brothers".  Was trying to be a little cute and have a catchy title.

The talk was about IT Risk, and I was aiming it at infosec professionals.  My idea is that risk is important to understand, as we do security to reduce risk to the organizations we work for.  But I think too many infosec folks just don't have a good understanding of this.

Now, the talk was posted.  Not sure how well it comes out.  I'll update with a link.

But what I wanted to give here was information on the sources and materials I used for the talk.

Thursday, February 16, 2017

ISACA's State of Cyber Security 2017 Report

Recently ISACA released the result of a survey as their State of Cyber Security Report 2017, part 1.  You can download it at their website HERE.

Part 1 focuses on topics like "workforce challenges" and "persistent skills gap".  Like many other groups, ISACA continues to push the narrative of a skills gap, and of course their solution is to train more folks in cybersecurity, ideally with their new set of CSX training and certifications.

Wednesday, May 18, 2016

HackMiami 2016 Conference Report

This past weekend, May 13-15, the 2016 HackMiami Conference was held.  This was the fourth time for this annual conference.  Been to every one and this was my second time speaking.

A change for this year is they have a new venue:  Miami Beach Deauville Beach Resort.  They had some problems with the past location, so hopefully there were no issues this year and they will be back there next year.

Sunday, March 13, 2016

Resources for workshop on security standards/frameworks/regulations for information security professionals

At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals.  While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.

Not covered were enterprise architecture models like Zachman or TOGAF.  Left out are other security frameworks like SABSA or things like RESILIAFedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.

Covered were:
  • CIS CSC
  • NIST CSF (plus FFIEC CAT)
  • ISO/IEC 27001
  • FISMA
  • HIPAA
  • GLBA 
  • SOX (plus COSO)
  • PCI-DSS
  • COBIT 5
  • ITIL

Friday, January 30, 2015

So you want to hire an InfoSecurity professional? [Part 1]

The following posting is an opinion piece.  It's based on personal experiences and anecdotal information.  deal with it.

So your organization is looking to hire one or more Information Security Professionals.  Maybe you are growing your InfoSec organization, adding to your IT organization, or realizing that, yes, you need to create an InfoSec group.  (all those big breaches in the news have you running scared)

Do you have a good idea of what you need in terms of skills, knowledge, and experience?  Do you have a good idea what kind of role you are trying to fill?  Do you have an idea of salary candidates with the skills you need are expecting?  You best figure this out soon. (hopefully you've consulted with professionals to help you out, and I don't mean recruiters.)  Here are some things to consider.



Now, a word of warning.  It may seem that I am stating the obvious at several points, and in a condescending manner.  But the sad thing is that in speaking with recruiters and HR people is that they don't seem to understand these points.  As an infosec professional, this p*sses me off, and so I feel I need to state the obvious for those who don't get it.