Been awhile since I've done any book reviews or the like on this blog. Am a little behind on my series looking at the "20 Books".
I'd thought I should bring to peoples attention a pair of books that came out a few years ago. No so much technical security works as more philosophical: Beautiful Security and The Myths of Security. Both are from O'Reilly and came out in 2009. And both share an author (kind of).
Wednesday, April 27, 2016
Friday, April 22, 2016
New in the Internet of Things
While I await my CHIP to arrive, I thought I'd note some of the other new items that have popped up in the last few months in terms of new boards for IoT. I think most should be aware of these, but some may not be aware of all of these.
Wednesday, April 20, 2016
Security BSides Tampa Report
On Saturday, April 16th, the third Security BSides Tampa was held. This year it was hosted at Stetson College of Law- Tampa Campus. This was the third year of this event, but my first time attending. I also gave a talk. They had 3 keynotes, about 15 speakers broken up over 3-4 tracks, and in addition had a Maker/Hacker Space, capture the flag event, lockpick village, and vendor space.
Monday, April 18, 2016
One of my slides from my NIST CSF presentation
When I did my recent presentation on the NIST CSF at BSides Tampa, I had some ask about the source of one of the pictures in my presentation.
All the pictures I got off Google Images, btw.
Here is the picture in question:
The source is this article on the ISACA website, in the section on "Information Security Management at HDFC Bank"
Hope this is of use to others.
All the pictures I got off Google Images, btw.
Here is the picture in question:
The source is this article on the ISACA website, in the section on "Information Security Management at HDFC Bank"
Hope this is of use to others.
Wednesday, April 13, 2016
NIST hosts a Cybersecurity Framework Workshop for 2016
For two days, April 6 and 7 2016, NIST (National Institute for Standards and Technology) hosted a workshop for the Cybersecurity Framework (CSF). This is the 7th they have held.
In developing the CSF, NIST held a series of 5 such workshops to gather feedback which was used in developing the Framework. A 6th workshop was held shortly after the Frameworks release. As part of the process in further developing and supporting the Framework, NIST put our a Call for Information (CFI) on the Frameworks use as well as solicite comments on possible improvements or revisions (say a 1.x update or a 2.0 update). This CFI ran from December to February of 2016. This workshop was held to review the outcomes of that CFI, as well as to gather further feedback.
For more info on these past workshops, go HERE. At present, their report on this workshop won't be available until mid May, however, the webcast recordings should now be available.
In developing the CSF, NIST held a series of 5 such workshops to gather feedback which was used in developing the Framework. A 6th workshop was held shortly after the Frameworks release. As part of the process in further developing and supporting the Framework, NIST put our a Call for Information (CFI) on the Frameworks use as well as solicite comments on possible improvements or revisions (say a 1.x update or a 2.0 update). This CFI ran from December to February of 2016. This workshop was held to review the outcomes of that CFI, as well as to gather further feedback.
For more info on these past workshops, go HERE. At present, their report on this workshop won't be available until mid May, however, the webcast recordings should now be available.
Wednesday, March 16, 2016
Security BSides Orlando 2016 Report
The weekend of March 12-13, the 2016 Security BSides Orlando Conference was held. As last year, this was done just before SANS Orlando, which moved from April (its long time traditional time) to March. And like last time, it was held at the University of Central Florida, but in a new building.
This was my third year attending and my second year speaking. I gave a 2 hour workshop on various security standards, frameworks, and regulations such as NIST CSF, ISO/IEC 27001, HIPAA, PCI-DSS and more. Sadly, it seem a lot of people didn't understand it was a 2 hour workshop and left halfway thru it. I recently posted the various resources for the workshop (references, training, certifications) here on the blog.
Attendance was over 400, and I understand they got a lot of students, who got to come for free. There were 2 tracks of talks, along with some workshops which run longer, tho I think it turned out mine was the only workshop. In addition, they had a Capture the Flag game going on, a Lockpick Village, and several vendors and orgs in attendance. So a great event overall.
This year's badges were different, being different colored cassette tapes depending on if you were an attendee, speaker, sponsor, staff, silver or gold.
There was a conference t-shirt and stickers. Speakers got some extra nice things. I'll have to take some pics of those and upload them.
Check out their Facebook group for pics. Not sure when videos of the talks will go live on their YouTube channel, but think very soon. Sadly, my workshop was not taped.
I look forward to next year's event. I have some ideas for next time. I think my topic this year was too broad, so am looking at some more focused ones. I really hope SANS 2017 will be in April for a couple of reasons.
This was my third year attending and my second year speaking. I gave a 2 hour workshop on various security standards, frameworks, and regulations such as NIST CSF, ISO/IEC 27001, HIPAA, PCI-DSS and more. Sadly, it seem a lot of people didn't understand it was a 2 hour workshop and left halfway thru it. I recently posted the various resources for the workshop (references, training, certifications) here on the blog.
Attendance was over 400, and I understand they got a lot of students, who got to come for free. There were 2 tracks of talks, along with some workshops which run longer, tho I think it turned out mine was the only workshop. In addition, they had a Capture the Flag game going on, a Lockpick Village, and several vendors and orgs in attendance. So a great event overall.
This year's badges were different, being different colored cassette tapes depending on if you were an attendee, speaker, sponsor, staff, silver or gold.
There was a conference t-shirt and stickers. Speakers got some extra nice things. I'll have to take some pics of those and upload them.
Check out their Facebook group for pics. Not sure when videos of the talks will go live on their YouTube channel, but think very soon. Sadly, my workshop was not taped.
I look forward to next year's event. I have some ideas for next time. I think my topic this year was too broad, so am looking at some more focused ones. I really hope SANS 2017 will be in April for a couple of reasons.
Sunday, March 13, 2016
Resources for workshop on security standards/frameworks/regulations for information security professionals
At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals. While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
- CIS CSC
- NIST CSF (plus FFIEC CAT)
- ISO/IEC 27001
- FISMA
- HIPAA
- GLBA
- SOX (plus COSO)
- PCI-DSS
- COBIT 5
- ITIL
Labels:
certification,
Cobit,
COSO,
Critical Security Controls,
CSC,
FFIEC,
FFIEC CAT,
FISMA,
frameworks,
GLBA,
HIPAA,
ITIL,
NIST,
NIST CSF,
PCI-DSS,
regulations,
SANS Top 20,
SoX,
training
Subscribe to:
Posts (Atom)


