Wednesday, March 16, 2016

Security BSides Orlando 2016 Report

The weekend of March 12-13, the 2016 Security BSides Orlando Conference was held.  As last year, this was done just before SANS Orlando, which moved from April (its long time traditional time) to March.  And like last time, it was held at the University of Central Florida, but in a new building.



This was my third year attending and my second year speaking.  I gave a 2 hour workshop on various security standards, frameworks, and regulations such as NIST CSF, ISO/IEC 27001, HIPAA, PCI-DSS and more.  Sadly, it seem a lot of people didn't understand it was a 2 hour workshop and left halfway thru it.  I recently posted the various resources for the workshop (references, training, certifications) here on the blog.

Attendance was over 400, and I understand they got a lot of students, who got to come for free.  There were 2 tracks of talks, along with some workshops which run longer, tho I think it turned out mine was the only workshop.  In addition, they had a Capture the Flag game going on, a Lockpick Village, and several vendors and orgs in attendance.  So a great event overall.

This year's badges were different, being different colored cassette tapes depending on if you were an attendee, speaker, sponsor, staff, silver or gold.


There was a conference t-shirt and stickers.  Speakers got some extra nice things.  I'll have to take some pics of those and upload them.

Check out their Facebook group for pics.  Not sure when videos of the talks will go live on their YouTube channel, but think very soon.  Sadly, my workshop was not taped.

I look forward to next year's event.  I have some ideas for next time.  I think my topic this year was too broad, so am looking at some more focused ones.  I really hope SANS 2017 will be in April for a couple of reasons.


Sunday, March 13, 2016

Resources for workshop on security standards/frameworks/regulations for information security professionals

At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals.  While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.

Not covered were enterprise architecture models like Zachman or TOGAF.  Left out are other security frameworks like SABSA or things like RESILIAFedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.

Covered were:
  • CIS CSC
  • NIST CSF (plus FFIEC CAT)
  • ISO/IEC 27001
  • FISMA
  • HIPAA
  • GLBA 
  • SOX (plus COSO)
  • PCI-DSS
  • COBIT 5
  • ITIL

Wednesday, March 9, 2016

HackMiami 2016 Conference

The 2016 HackMiami Conference will be coming up in a few months on May 13-15.  This will be the fourth time for this annual conference.  Been to every one and plan on attending again as I will be speaking (for the second time).

A change for this year is they have a new venue:  Miami Beach Deauville Beach Resort.  I think they had some problems with the prior location.  Hopefully things will be better with this one.

They have announced their keynote speakers, and John McAfee is returning as an announced speaker.  (last year he was a surprise keynote speaker).  This year's general theme is a return to the start of the hacker/cracker culture.  They are still taking proposals, so don't yet know what will be the speakers and tracks.  There will again be the lockpick village and "capture the flag" event as before, and training on the first day.

If you are in Florida, check out this conference.  It's a lot of fun.



Monday, March 7, 2016

Security BSides Orlando & Tampa 2016

Well, here we are in 2016.

This year I am working on speaking at several upcoming conferences.  Two are coming up this month and next:  BSides Orlando and BSides Tampa.


Security BSides Orlando 2016 will be held the weekend of March 12-13, just before SANS Orlando.  This is the 4th year of the conference, and the conference again returns to the University of Central Florida, but in a different building from last year.

I will be giving a 2 hour workshop on various security standards, frameworks, and regulations such as NIST CSF, ISO/IEC 27001, HIPAA, PCI-DSS and more.  I will be posting here a list of the recommended sources of info, training, etc for this presentation.



Security BSides Tampa 2016 will be held on Saturday, April 16 at Stetson College of Law – Tampa Campus.  This is the third year of the conference and my first time attending.  I will be giving a presentation on the NIST Cybersecurity Framework on its second year of existence.  I have something special in regards to this presentation which I will review later.

I took forward to both conference.  If you have never been to a BSides Conference, check to see if there is one coming up in your general area.  Just in Florida we have 3, tho I'd love to see one start here in South Florida.

As I learn about the other conferences I have submitted proposals to, I'll post them here.


Sunday, October 18, 2015

2015 ISSA International Conference

This past week I attended the 2015 Information System Security Association (ISSA) International Conference.  It was held in Chicago on October 12-13.  Before that the CISO Forum was held, and afterwards, they held the one-day Chapter Leaders Summit.  The CISO Forum was only open to members of ISSA's CISO Forum, and the Chapter Leader Summit brought together chapter officers for workshops and sessions to help them improve their chapters.

This is the second ISSA Conference I've attended.  I thought this was was pretty good.  We had a couple of good keynote sessions (Vinton Cerf and Dan Geer).  There were several sessions organized into different tracks, and all were tied to the ISSA's Cybersecurity Career Lifecycle model.  There were a few other special events, such as CISO Forum luncheon and the awards luncheon where several were recognized with ISSA Awards.  There was also a reception at 360 Chicago at the John Hancock Center.

This year they had a conference app, which I've seen such used at other events I attend.  This one also had people scan QR codes on name badges, at the vendor tables, and at events and sessions.  Those who got the most would get prizes.  So, obviously, at an infosec conference, some hacked the app.

They had a good number of vendors this year, tho many I had never heard of.  Disappointed that some of the major security vendors weren't there.

As a chapter officer, I also attended the Chapter Leaders Summit.  A good event.  I almost wish it was longer.

Next year's conference will be in Dallas around the same time.  Hopefully I can attend.


Saturday, May 16, 2015

Resources for the Internet of Things Security

At the HackMiami Conference  on May 16, 2015, I did a presentation on an Introduction to Internet of Things Security.  The presentation is now up on YouTube.  I have the link below.

As a tie-in to the presentation, I am providing here links to the various resources that I covered in the presentation, along with others I didn't have the time to.  If you come across other items of interest, please add them to the comments.

Friday, April 24, 2015

"The Frugal CISO" by Kerry Anderson

Currently I am reading thru Kerry Ann Anderson's The Frugal CISO (CRC Press, 2014).

I am always on the lookout for good infosec books, and one area that I think is under served are those that are aimed at the top-level security professional on how to implement a good information security program.

This one I had discovered thanks to a related article the author had in a recent issue of the ISACA Journal on information security maturity models ("From Here to Maturity—Managing the
Information Security Life Cycle" v6, 2014). She makes use of the Nolan Model, which I wasn't familiar with (being more familiar with the CMM/CMMI based models).  The article was interesting, and I wanted to know more on the idea and she spends a chapter on this concept, which is good.  I think this would be a better maturity model for infosec groups to use then a CMM-based one.

I am currently reading thru the book, basically jumping around based on my interests.  What I see is pretty good.  She has stuff on hiring and building an infosec team, policies, controls, and more.  Her main theme overall is being frugal, being smart with you are spending money on, an important concept in today's cost-cutting attitude.

This is not a full review of the book.  I will probably post something like that later on.