Tuesday, November 29, 2016

ITPalooza 2016

If you're in the South Florida area, the 4th annual ITPalooza is coming up next week on Dec 8th, 2016.

This event, now sponsored by the South Florida Technology Alliance, is planned to be bigger then even and has moved to the Signature Grand.  Now an all day event of speakers and activities, there will be booth from vendors and user/professional groups and a job fair with a variety of recruiters and companies in attendance.

Full info is available at their website.  Tickets can be obtained there.  As always, you can get a free ticket if you bring 2 new unwrapped toys.


Friday, November 25, 2016

SANS Miami 2016

A couple of weeks ago I attended the SANS Miami 2016 conference.  While I have taken a few SANS courses, this was actually the largest SANS event I've been able to attend.  The previous events I was at were SANS Community events, one with only one course over several weeks, another was a week-long event with just 2 courses.  The rest I did on-line.

For the last few years SANS had been doing small events in our area, first in Ft Lauderdale before moving to Miami.  These events had about 5 courses.  The first few ones were mainly focused on forensics courses, which were not of interest to me.  This one had a more devise set of courses, and took one of their security management courses:  MGT514: IT Security Strategic Planning, Policy and Leadership.

Overall I thought this course was good.  For me, it was a mix of stuff I knew, stuff I had heard of but didn't know much about, and new stuff.  A lot of what I've learned has been learned on the job vs in a course, so I often have gaps in my knowledge, or I might not know the "proper" way of things.  So this kind of course helps me fill those gaps.

SANS already has SANS Miami 2017 on their calendar for next year, but haven't yet announced the 5 classes they will be offering.  Will see if I'm able to attend.

Wednesday, November 23, 2016

2016 ISSA International Conference

Well, a bit behind in this posting.

November 2-3, 2016, the Information System Security Association (ISSA) had their International Conference in Dallas, TX.  I was part of the Steering Committee and also attended the ISSA Chapter Leaders Summit held the day before.

Overall this was a great conference.  I had been to the previous 2 conferences (Chicago and Orlando), and this was an improvement over those.  We had more attendees and more sponsors then before.  We had a lot of great speakers and some great additions to the conference.

We had a "party in the skill" in the Reunion Tower connected to the Hyatt Regency where the conference was held at.  During the party, we had a Capture the Flag game going on.  They had a job fair (first time), with several recruiting companies.   There were 2 books given to participants and the authors were there to sign them: Becoming the Customer by Peter McLaughlin  and Managing Risk and Information Security 2nd ed by Malcolm Harkins (I have the 1st edition, so this was a welcome update).  And there was a special deal for training and testing for the CEH and C|CISO cert from EC-Council.

On a personal note, I was honored at the awards luncheon with ISSA Fellow status.

The next conference will be October 10-11, 2017 in San Diego.  I plan on being on the Steering Committee again, as I want to see certain things continued and other things improved.  Will see if I'm able to attend it.

Monday, September 26, 2016

FFIEC updates (finally) their Information Security IT Examination Handbook

Well, after ten years, the FFIEC has finally updated their Information Security IT Examination Handbook.

So probably some are wondering what this is and why should they care.  If you don't work in the financial industry, you may not be aware of all of this.

The FFIEC is the Federal Financial Institutions Examination Council, which is a government interagency body that sets down uniform principles, standards, and report forms regarding the examination of financial instituions.  The Council is make up of Federal Reserve System (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), the Consumer Financial Protection Bureau (CFPB), and the State Liaison Committee (SLC), which itself includes representatives from the Conference of State Bank Supervisors (CSBS), the American Council of State Savings Supervisors (ACSSS), and the National Association of State Credit Union Supervisors (NASCUS).

So basically if you work for banks or credit unions, you have dealt with this.  If you do IT Security consulting in this realm, you have come across them.


Monday, September 19, 2016

Updates to the CIS Critical Security Controls

Hopefully most people are aware of the Critical Security Controls, which are too often called the "SANS Top 20" or the like, even tho SANS no longer manages them.  (they do offer a course and cert on them.)

SANS actually turned them over to a group called the Council on CyberSecurity in 2013, and put out at least version 5.0 of the controls.  The Council merged with the Center for Internet Security in 2015, who released version 6.0.  Properly they are the CIS Critical Security Controls, or CIS CSC.

With v6.0, they did some revamping and re-ordering the controls.

And CIS has continued to support the CSC.  They have released some new items!

Wednesday, August 31, 2016

I recently attending the 2016 GRC Conference.  This conference was a joint event of IIA & ISACA, and was held in my area in Ft. Lauderdale.  It was a two day conference with speakers in several tracks, along with an exhibitor area.  There were some special sessions before and after the main conference.  This is the sixth time they have done this conference.  Next year's event will be in Texas.

For me, I attended because they had several sessions on cybersecurity.  I was able to attend for free because I volunteered at the conference as a member of ISACA.

Monday, August 29, 2016

SFISSA's 2016 Hack the Flag/Chili Cookoff FINAL UPDATE

The South Florida ISSA Chapter is again holding our annual Hack the Flag/Chili Cookoff in 2016.  This is looking to be our biggest ever.

New location.

New stuff,

Want to be a part of it???  Register TODAY!!!  Go HERE to register.  Want to be a sponsor?? Let us know!!  Only a few slots are available.