As mentioned previously, I gave a presentation on IT Risk at the 2017 Security BSides Orlando Conference. The title was "Risk: It's more then just a game from Parker Brothers". Was trying to be a little cute and have a catchy title.
The talk was about IT Risk, and I was aiming it at infosec professionals. My idea is that risk is important to understand, as we do security to reduce risk to the organizations we work for. But I think too many infosec folks just don't have a good understanding of this.
Now, the talk was posted. Not sure how well it comes out. I'll update with a link.
But what I wanted to give here was information on the sources and materials I used for the talk.
Showing posts with label training. Show all posts
Showing posts with label training. Show all posts
Tuesday, April 11, 2017
Friday, November 25, 2016
SANS Miami 2016
A couple of weeks ago I attended the SANS Miami 2016 conference. While I have taken a few SANS courses, this was actually the largest SANS event I've been able to attend. The previous events I was at were SANS Community events, one with only one course over several weeks, another was a week-long event with just 2 courses. The rest I did on-line.
For the last few years SANS had been doing small events in our area, first in Ft Lauderdale before moving to Miami. These events had about 5 courses. The first few ones were mainly focused on forensics courses, which were not of interest to me. This one had a more devise set of courses, and took one of their security management courses: MGT514: IT Security Strategic Planning, Policy and Leadership.
Overall I thought this course was good. For me, it was a mix of stuff I knew, stuff I had heard of but didn't know much about, and new stuff. A lot of what I've learned has been learned on the job vs in a course, so I often have gaps in my knowledge, or I might not know the "proper" way of things. So this kind of course helps me fill those gaps.
SANS already has SANS Miami 2017 on their calendar for next year, but haven't yet announced the 5 classes they will be offering. Will see if I'm able to attend.
For the last few years SANS had been doing small events in our area, first in Ft Lauderdale before moving to Miami. These events had about 5 courses. The first few ones were mainly focused on forensics courses, which were not of interest to me. This one had a more devise set of courses, and took one of their security management courses: MGT514: IT Security Strategic Planning, Policy and Leadership.
Overall I thought this course was good. For me, it was a mix of stuff I knew, stuff I had heard of but didn't know much about, and new stuff. A lot of what I've learned has been learned on the job vs in a course, so I often have gaps in my knowledge, or I might not know the "proper" way of things. So this kind of course helps me fill those gaps.
SANS already has SANS Miami 2017 on their calendar for next year, but haven't yet announced the 5 classes they will be offering. Will see if I'm able to attend.
Sunday, March 13, 2016
Resources for workshop on security standards/frameworks/regulations for information security professionals
At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals. While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
- CIS CSC
- NIST CSF (plus FFIEC CAT)
- ISO/IEC 27001
- FISMA
- HIPAA
- GLBA
- SOX (plus COSO)
- PCI-DSS
- COBIT 5
- ITIL
Labels:
certification,
Cobit,
COSO,
Critical Security Controls,
CSC,
FFIEC,
FFIEC CAT,
FISMA,
frameworks,
GLBA,
HIPAA,
ITIL,
NIST,
NIST CSF,
PCI-DSS,
regulations,
SANS Top 20,
SoX,
training
Wednesday, June 26, 2013
SL Powers IT Security Lunch & Learn event
Tying in with my recent posting on getting involved with local security events, today I attending a "lunch and learn" event organized by one of our local IT services companies, SL Powers. They apparently do these events in our local area about once a month, in different locations. This one had two presentations, both were pretty good.
First up, we had Silka Gonzalez, President & CEO of Enterprise Risk Management, a local company focused on helping their clients with risk management and assessments. She gave a good overview of some of the various regulatory compliance standards out there that many of us have to deal with: GLBA, FACTA, SoX, HIPAA/HITECH, FERPA, FISMA, and PCI-DSS. What I particularly liked was how she pointed out the similarities among many of these, and what are the basic underlining concepts that are common in all of them.
The second talk was by Tom Leffingwell of Juniper Networks. Now, I have known Juniper as a competitor to Cisco in terms of networking equipment. What I wasn't aware of was their work in the area of network security. So it was good to learn more about what they do in this area. As with these kinds of presentations, you run the risk of being more a sales pitch then a technical overview, and I think he did a good job of staying more technical then sales.
I will keep my eye out for further sessions like these. SL Powers also has a series of sessions called "Tech on Tap", which also sounds interesting.
I found out about this event via Eventbrite. If you aren't familiar with this site, check it out. Great way to find out about events in your area, both free and fee. As IT people, we need to keep up our skills, so attending these events have multiple benefits.
First up, we had Silka Gonzalez, President & CEO of Enterprise Risk Management, a local company focused on helping their clients with risk management and assessments. She gave a good overview of some of the various regulatory compliance standards out there that many of us have to deal with: GLBA, FACTA, SoX, HIPAA/HITECH, FERPA, FISMA, and PCI-DSS. What I particularly liked was how she pointed out the similarities among many of these, and what are the basic underlining concepts that are common in all of them.
The second talk was by Tom Leffingwell of Juniper Networks. Now, I have known Juniper as a competitor to Cisco in terms of networking equipment. What I wasn't aware of was their work in the area of network security. So it was good to learn more about what they do in this area. As with these kinds of presentations, you run the risk of being more a sales pitch then a technical overview, and I think he did a good job of staying more technical then sales.
I will keep my eye out for further sessions like these. SL Powers also has a series of sessions called "Tech on Tap", which also sounds interesting.
I found out about this event via Eventbrite. If you aren't familiar with this site, check it out. Great way to find out about events in your area, both free and fee. As IT people, we need to keep up our skills, so attending these events have multiple benefits.
Monday, June 24, 2013
Getting involved locally- joining, learning, networking
So its been too long since I've posted. Something in the back of my mind is my observations of my collegues in the IT and IT Security realm. What has long disappointed me was how many never bothered to keep learning and being involved in the larger "community". Other then taking some training courses, many didn't bother to keep up with what is going on in the industry- didn't read journals (either print or on-line), didn't get engaged with local groups or events or the like.
For me, I joined USENIX and SAGE when I got involved as an IT admin. When I got involved in IT Security, I joined ISSA and got involved in the South Florida ISSA chapter. I was briefly involved with ISACA (and thought about getting back involved). I know about other groups (we have a chapter of ISC(2) getting formed) and have looked at others to see if they were worth joining.
I tried to get involved with local events tied with those groups (my chapter runs a security conference every 2 years, and has an annual "hack the flag" event), as well as others. Last year in December we had the ITPalooza event, which will happen again this year.
So my advise to you is if you want to succeed in your IT career: GET INVOLVED. Depending on what your interest or focus is, see if there are groups that are appropriate for that, and join them. Especially get involved with local chapters of these groups. Maybe think about becoming an officer. If you are the type, consider making a presentation, even its at a local event.
So, if you've had experience getting involved, comment about what you've done and what you've gotten out of it.
For me, I joined USENIX and SAGE when I got involved as an IT admin. When I got involved in IT Security, I joined ISSA and got involved in the South Florida ISSA chapter. I was briefly involved with ISACA (and thought about getting back involved). I know about other groups (we have a chapter of ISC(2) getting formed) and have looked at others to see if they were worth joining.
I tried to get involved with local events tied with those groups (my chapter runs a security conference every 2 years, and has an annual "hack the flag" event), as well as others. Last year in December we had the ITPalooza event, which will happen again this year.
So my advise to you is if you want to succeed in your IT career: GET INVOLVED. Depending on what your interest or focus is, see if there are groups that are appropriate for that, and join them. Especially get involved with local chapters of these groups. Maybe think about becoming an officer. If you are the type, consider making a presentation, even its at a local event.
So, if you've had experience getting involved, comment about what you've done and what you've gotten out of it.
Wednesday, June 12, 2013
"A Great Course" on Cybersecurity
Not sure if others are aware of the company The Great Courses, which sells college-level courses on CD & DVD. I've gotten a few and enjoyed them.
In their most catalog, I saw a new course that would be interested to this audience.
"Thinking about Cybersecurity", a 18 lecture course by Professor of Law Paul Rosenzweig. (Course #9523)
The lecture listing has a lot of topics regarding with cybersecurity. Not sure the level of technical information, or if its more on the policy side.
Has anyone gotten this yet and can comment?
In their most catalog, I saw a new course that would be interested to this audience.
"Thinking about Cybersecurity", a 18 lecture course by Professor of Law Paul Rosenzweig. (Course #9523)
The lecture listing has a lot of topics regarding with cybersecurity. Not sure the level of technical information, or if its more on the policy side.
Has anyone gotten this yet and can comment?
Subscribe to:
Posts (Atom)