This past Friday, the South Florida ISSA Chapter held its 2017 Security Conference. The chapter holds these every 2 years, and this year's event was our more successful one to date.
We had 4 tracks of talks, include a track of workshops (twice the length of a regular presentation), a breakfast and lunch keynote, and a CISO Panel of 4 local CISOs.
Wednesday, March 15, 2017
Wednesday, March 8, 2017
News on NIST's update to Cybersecurity Framework
As I have previously posted, and hopefully most are aware, NIST (National Institute of Standards and Technology) has released a draft for an update of the Cybersecurity Framework (CSF), to be v1.1.
Recently NIST held 2 webinars on the CSF, each an hour long. One was an overview, and the other on the proposed updates. The webinars had a limited number that could watch them live, but they have now put up the videos on their website. Both are good to watch.
Recently NIST held 2 webinars on the CSF, each an hour long. One was an overview, and the other on the proposed updates. The webinars had a limited number that could watch them live, but they have now put up the videos on their website. Both are good to watch.
Wednesday, February 22, 2017
Memorial Healthcare pays $5.5 million HIPAA settlement
Well, at this point hopefully those in the infosec field, especially in the healthcare arena, are aware of the recent settlement by Memorial Healthcare (Hollywood, Florida) for $5.5 million. This was for violations of HIPAA that resulted in the protected health information (PHI) of over 100,000 individuals being potentially exposed. While not the highest penalty, certainly up there.
You can read the whole press release HERE. As well as the settlement agreement HERE which includes the corrective measures they must take.
For me, this is notable as Memorial Healthcare is one of the local hospital groups in my area. Now, I have no connection with Memorial, I do NOT have any inside information on them. All I know is what I have read in the above articles.
You can read the whole press release HERE. As well as the settlement agreement HERE which includes the corrective measures they must take.
For me, this is notable as Memorial Healthcare is one of the local hospital groups in my area. Now, I have no connection with Memorial, I do NOT have any inside information on them. All I know is what I have read in the above articles.
Friday, February 17, 2017
BSides Tampa 2017 report
This past weekend, February 11th, I was in Tampa for the 4th BSides Tampa Conference. This is my second time attending, and second time presenting.
Overall it was a good conference. There were some differences from last year, most positive. They clearly need to move to a larger venue. This year and last was at the Stetson Law Center in Tampa. This location has a nice facility, but is limited in parking, and there is no place to get lunch. Last year they brought in KFC for everyone, this year was food trucks. But there was only 2 and I didn't have the time to get lunch before I had to do my session.
Overall it was a good conference. There were some differences from last year, most positive. They clearly need to move to a larger venue. This year and last was at the Stetson Law Center in Tampa. This location has a nice facility, but is limited in parking, and there is no place to get lunch. Last year they brought in KFC for everyone, this year was food trucks. But there was only 2 and I didn't have the time to get lunch before I had to do my session.
Thursday, February 16, 2017
ISACA's State of Cyber Security 2017 Report
Recently ISACA released the result of a survey as their State of Cyber Security Report 2017, part 1. You can download it at their website HERE.
Part 1 focuses on topics like "workforce challenges" and "persistent skills gap". Like many other groups, ISACA continues to push the narrative of a skills gap, and of course their solution is to train more folks in cybersecurity, ideally with their new set of CSX training and certifications.
Part 1 focuses on topics like "workforce challenges" and "persistent skills gap". Like many other groups, ISACA continues to push the narrative of a skills gap, and of course their solution is to train more folks in cybersecurity, ideally with their new set of CSX training and certifications.
Thursday, February 9, 2017
Commentary on Cyber Resilience
At the upcoming HackMiami5 conference I will be speaking on "Cyber Resilience". I have been looking at this term over the last several months. As an infosec/cybersecurity professional, I wanted to better understand what this "cyber resilience" is and how it fits in.
Now, at my talk at HM2017 I will be going into several "models" for cyber resilience and other resources, and I will NOT be posting that information here on my blog until sometime later. So this posting, which maybe part of a series, is more my thoughts on what cyber resilience is.
Now, the more or less standard definition I hear for cyber resilience is "the ability to recover from attacks quicker and keep losses to a minimum."
Now, at my talk at HM2017 I will be going into several "models" for cyber resilience and other resources, and I will NOT be posting that information here on my blog until sometime later. So this posting, which maybe part of a series, is more my thoughts on what cyber resilience is.
Now, the more or less standard definition I hear for cyber resilience is "the ability to recover from attacks quicker and keep losses to a minimum."
Friday, January 13, 2017
Upcoming Conferences in South Florida 2017
There are several conferences in the South Florida (and general area) that I plan to be at in the coming months, and some I hope to speak at.
The South Florida ISACA Chapter will be having their 10th WOW event on Friday,February 24th. [UPDATE: Friday, April 21st] This will be an all day event at the FIU Biscayne Campus as usual. Registration is already open and the focus is on "Emerging Threats in Cybersecurity".
The South Florida ISSA Chapter will be having their biannual security conference on Friday, March 10th. This will be an all day event at the Signature Grand. Registration is open, sponsors are being lined up and a call for presenters is open.
BSides Orlando will be April 8th, again at University of Central Florida. Unlike past years, this will be a one day event, but will again be right before SANS Orlando.
HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.
So some great events and I look forward to them.
The South Florida ISACA Chapter will be having their 10th WOW event on Friday,
The South Florida ISSA Chapter will be having their biannual security conference on Friday, March 10th. This will be an all day event at the Signature Grand. Registration is open, sponsors are being lined up and a call for presenters is open.
BSides Orlando will be April 8th, again at University of Central Florida. Unlike past years, this will be a one day event, but will again be right before SANS Orlando.
HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach.
So some great events and I look forward to them.
Subscribe to:
Posts (Atom)
