Showing posts with label Training. Show all posts
Showing posts with label Training. Show all posts

Friday, September 13, 2013

How To Develop Security Awareness?

Six Steps To Successful Security Awareness Training

If you would schedule an event to teach people about Internet Security, and make it optional to attend, only about 5% of your entire office population will show up. And guess what, those 5% are probably the people that need it least.

Here are the six elements of a successful Internet Security Awareness Training Program

  • Formulate, and make easily available a written Security Policy.
  • Each employee needs to read the document and sign it as an acknowledgment they understand the policy and will apply it.
  • Give all employees a mandatory (online) Security Awareness Course, with a clearly stated deadline. It is highly recommended to explain to them in some detail why this is necessary.
  • Make this Security Awareness Course part of the onboarding process of each new employee.
  • Keep all employees on their toes with security top of mind, by continued testing. Sending a simulated phishing attack once a week is extremely effective to keep them alert.
  • Never publicly identify an employee that fails a simulated attack, let their supervisor or HR take this up privately. Give a quarterly prize for the three employees with the lowest ‘fail-rate’.
  • If you use posters, stickers and or screensavers, change the pictures or messages monthly. After a few weeks people simple don’t ‘see’ them anymore. It’s more effective to send them regular ‘Security Hints & Tips’ via email.

Tuesday, May 15, 2012

Top 15 Paying IT Certifications According to Global Knowledge Training

Certifications are good for marketing and a necessary evil, but certainly not the be all/end all!


Global Knowledge Training LLC published a white paper outlining the top 15 paying IT certifications for 2012 based upon a survey they conduct annually. In the white paper, they don’t specify how they selected their sample for the survey; however they do maintain that the certifications and associated salaries were included only if there were at least 200 responses for that particular certification in the survey.


As such (and as the author points out), some certifications that do not have a large population in the work force (or that are more exclusive) may be inadvertently – and obviously – missing from this list (e.g., CCIE, VCDX, or OCSP).


Here are the results from the survey:


PMP - Project Management Professional $111,209
CISSP – Certified Information System Security Professional $110,342
CCDA – Cisco Certified Design Associate $101,915
ITIL v3 Foundation $97,691
MCSE – Microsoft Certified Systems Engineer $91,650
VCP – Vmware Certified Professional $91,648
CCNP – Cisco Certified Network Professional $90,457
CompTIA Server+ $84,997
MCITP – Microsoft Certified IT Professional $84,330
CCNA – Cisco Certified Network Associate $82,923
MCSA – Microsoft Certified Systems Administrator $82,923
CompTIA Security+ $80,066
MCP – Microsoft Certified Professional $79,363
CCENT – Cisco Certified Entry Network Technician $74,764
CompTIA Network+ $71,207


These results are based on US job market but you can use these figures as a benchmark or if you already have above certification, you can campre your salary with the US market.


MyCPEs.com is a free online tool built to help certified professionals manage and track their continuing education. Sign up for a free account now.

Monday, February 20, 2012

Learn the process of documentation writing to implement ISO 27001

ISO 27001 Video Tutorials

One of the biggest obstacles for companies starting to implement ISO 27001 is writing various documents required by this information security standard.

Information Security & Business Continuity Academy has launched ISO 27001 Video Tutorials, a new product that facilitates the process of documentation writing.

According to ISO Survey of Certifications published by the International Organization for Standardization (ISO), ISO 27001 is within the 5 most popular management standards, and is also one of the standards with the highest growth in the number of certified companies – about 20% annually.

However, the fact that a large percentage of companies that have started to implement this standard never finish the job is less known. The reason for failure is very often insufficient time or lack of knowledge for writing the documentation – ISO 27001 has very specific requirements about how the documentation should look like.

At the moment 13 video tutorials are available, and each month 2 new tutorials will be published. A total of 50 video tutorials are planned, which will cover all the steps in ISO 27001 implementation – from setting up the project all through successful certification.

Dejan Kosutic, the author of the video tutorials said:
"I've worked with quite many companies as a consultant, and most of those companies struggle with the same thing – how to fill in the documentation. I believe these video tutorials will increase the success rate of ISO 27001 projects by at least 25%, and increase the speed of implementation by 50%".

Thursday, January 5, 2012

How Developers Can Secure their Code?

5 Application Security Tips

Over the last 30 years, many organizations have done an amazing job of automating their business, resulting in productivity gains, efficiencies and innovations.

Unfortunately, the threat landscape has changed dramatically during this time. A lot of that application code, written without security in mind decades ago, is still the heart-and-soul of many enterprises. That code was designed for a world where computers could not be accessed remotely.

Since then, it has been wrapped, integrated, connected, ported, and most importantly, exposed. That application code is not strong enough to withstand today's threat.

OWASP has a number of free and open-source resources that developers can use right now to help secure their code.

5 Tips for Developers

Start with the OWASP Top Ten
- This awareness document will help you understand, identify, and fix the most critical application security risks quickly.

Get hands-on with WebGoat - WebGoat is a deliberately flawed application that is riddled with holes to give people the opportunity for hands-on learning. It is open-sourced to help developers and security testers get experience with real vulnerabilities.

Leverage the OWASP Cheat Sheets - This is a fantastic series from leading experts globally. Let me know what you think of the Cross-Site Scripting Prevention Cheat Sheet, one of OWASP's most popular pages.

Verify Your Applications - There is no substitute for getting real facts about the security of your application portfolio. OWASP Application Security Verification Standard helps developers get started scanning, testing and code reviewing with tools like OWASP Zap and CSRFTester.

Get Training - Perhaps the hardest thing about application security is that there are so many different ways that software can fail, particularly when it's targeted by a motivated attacker. The key is training to get started with securing applications quickly.

If instructor-led training isn't possible, eLearning solutions are available to allow developers to learn on-demand and get hands-on, practical experience with vulnerabilities, security controls and real code. Training is a remarkably effective way to reduce vulnerabilities.

Before you trust your business to application software, make certain that the people who are writing your code know how to defend your business and its assets. It's time to learn.

Tuesday, December 27, 2011

DDoS Testing Methodology

A methodology to measure the resiliency of network infrastructure against DDoS and botnet attacks

Distributed denial of service (DDoS) attacks are rampant, successfully targeting Fortune 100 businesses, not to mention government, news media, communication and financial networks throughout the world. It has become more important to assess network equipment and application servers using these same attacks. Only through realistic attack simulation can organizations visualize their own weaknesses and vulnerabilities within the IT infrastructure and how resilient these elements are when under attack.

DDoS Testing Methodology

BreakingPoint has created a definitive DDoS testing methodology that creates a variety of attacks to help users find their network weaknesses before others do. Such attacks include the following:
  • DDoS designed to consume all available bandwidth, all disk space or all available CPU cycles

  • DDoS designed to disrupt important information flow such as routing tables by injecting false routes, thus causing packets to be misrouted

  • DDoS designed to break the physical layer of the network and obstruct the communication between the end-point and the user

  • Botnets designed to send large quantities of unsolicited e-mail to trigger Delivery Server Notifications to spoofed originating email addresses
To download the methodology please refer here (registration may be required)

Thursday, December 22, 2011

SC Webcast: Top cyber threat predictions for 2012

Learn about the top (internal and external) security predictions of 2012

With the tremendous growth of workforce mobility, telecommuting, and enterprise social networking, 2012 is again likely to pose some complex cyber security challenges for businesses worldwide.

As such I thought you might be interested in SC’s upcoming webcast which will get to grips with what the experts predict to be the top cyber threats in the year ahead.

You can secure your complimentary place here - http://www.scwebcasts.tv/?btcommid=40027

LIVE WEBCAST: CYBER SECURITY IN 2012 – TOP 5 THREAT PREDICTIONS
Streamed live to your desk: 26th January 2012, 3pm GMT
http://www.scwebcasts.tv/?btcommid=40027

This webcast will enable you to:
  • Learn about the top (internal and external) security predictions of 2012 (from mobile threats to spear phishing)
  • Understand the impact of social networking's impact on enterprise security in 2012 to help you prioritise your response
  • Develop ideas for a 360 degree cyber security strategy that keeps up with the sophistication of attacks in the year ahead
Speakers:

Aaron Sheridan, Senior Security Engineer, FireEye
Clive Longbottom, Founder and Industry Analyst, QuoCirca
View more information at http://www.scwebcasts.tv/?btcommid=40027

Monday, December 12, 2011

The top 5 information security certifications

Recent Security Incidents Push Demand for Information Security Professionals

The top 5 information security certifications include the CISSP, CISM, GIAC, CEH and vendor credentials offered by companies such as Cisco and Microsoft. These certifications are in demand not only for their demonstration of IT security proficiency, but also because certified candidates go through training that reflects a higher standard of ethical conduct - a topic that has renewed focus by hiring managers.

In 2012, the rise in security incidents and mobile devices creates hot demand for certifications such as the GIAC, which are technically focused in specific areas of forensics, incident response and application security.

Top 5 Certifications

Based on a review of job boards and various research conducted by IT security recruiters and employers, here is the list of the top five security certifications:

CISSP

The Certified Information Systems Security Professional continues to be the gold standard in certifications.

The CISSP, which is known for its high-level overview on the profession, has recently opened the certification for further specialization in areas such as architecture and management.

The push for this credential is also coming from the U.S. Department of Defense 8570.1 Directive, which requires all government and contract employees working on DoD IT projects to carry an approved certification for their particular job classification.

CISSP certification is usually for mid and senior management IT security positions. This certification is offered through (ISC)2, the not-for-profit consortium that offers IT security certifications and training.

The CISSP examination is based on what (ISC)2 terms the Common Body of Knowledge (or CBK). Candidates interested in taking the exam must possess a minimum of five years of direct full-time security work experience in two or more of the 10 (ISC)2 information security domains (CBK), and agree to abide by their codes-of-ethics and policy for continuous education.

In addition, they need to pass the exam with a scaled score of 700 points or greater out of 1000 possible points. The exam is multiple-choice, consisting of 250 questions with four options each, to be answered over a period of six hours.

For further information please refer here.

CISM

Certified Information Security Manager is in demand, as organizations increasingly need executives to focus on governance, accountability and the business aspects of security.

As with the CISSP, the 8570 Directive requires CISM certification for senior managers that particularly focus on governance, compliance and risk management issues.

CISM is ideal for IT security professionals looking to grow their career into mid-level and senior management positions. CISM is offered by ISACA, an international professional association that deals with IT Governance.

The CISM designation is awarded to individuals with an interest in security management who meet the following requirements: They need to successfully pass the CISM exam; adhere to ISACA's code of professional ethics; agree to comply with the continuing education policy.

They also must submit verified evidence of a minimum of five years of IT security work experience, including a minimum of three years of management work experience; and submit an application for CISM certification.

For further information please refer here.

GIAC

Global Information Assurance Certification is rising in demand specifically in areas of incident handling, forensics, intrusion detection and reverse malware engineering.

Many organizations are seeking such experts for their IT security teams because of the growing threat landscape and rise in security incidents. Usually, professionals turn to GIAC certifications to get further expertise in a particular discipline.

The GIAC is essentially geared toward mid-level security professionals who are looking to carve out a niche career path for themselves. The certification is offered by Sans Institute, a cooperative research and education organization.

There are no official prerequisites to take the GIAC certifications. Any candidate who feels that he or she has the knowledge may take the exam. Candidates can pursue GIAC exams with or without purchasing SANS training.

The exam fees usually include two practice exams and one proctored exam. Each exam has an expiration date of 120 days accessible from their SANS Portal Account. Exams are taken online, however SANS now requires that a proctor be present when candidates take their test.

For further information please refer here.

CEH

Certified Ethical Hacker is gaining popularity as companies seek experts to perform web application and penetration testing to ensure their infrastructure is secure.

A blooming field is security testing, and certifications like CEH are challenging technically and very valuable. This certification is useful for entry-to-mid-level practitioners that are looking to conduct vulnerability assessments.

CEH is offered by the International Council of Electronic Commerce Consultants(EC-Council), a professional certification body. EC-Council's goal is to certify security practitioners in the methodology of ethical hacking. It largely demonstrates an understanding of the tools used for penetration testing.

To obtain the CEH, candidates can choose a path of self-study or complete a training course offered by EC-Council. Candidates must have at least two years of security experience and must sign an agreement to not misuse the knowledge acquired.

For further information please refer here.

Vendor Certifications

Securing an organization's infrastructure and keeping up-to-date with emerging technologies are critical. Vendor certifications, including Cisco's Certified Network Associate Certification (CCNA) and Microsoft's Certified Systems Engineer (MCSE), with focus on security and Check Point's Certified Security Expert (CCSE), are particularly in demand.

The top information security certifications Dice has tracked for 2011 include Cisco CCNP Security and Check Point Certified Expert. These certifications are also on the rise because of their in-depth technical focus.

They help in understanding the technical skills associated with what professionals are trying to defend, and the inherent security capabilities of the infrastructure.

For most entry-level positions requiring one-to-two years of experience, employers seek vendor certifications, Security+ and the CEH credential. Mid-to-senior positions demand more mature training in CISSP, CISM and GIAC.

Other certifications in demand include Security+, Offensive Security Certified Professional, Cloud Security Alliance's new Certificate of Cloud Security Knowledge, Systems Security Certified Practitioner and Certified in Risk and Information Systems Control.

Certifications cannot be a substitute for on-the-job experience, but they are turning out to be a good measure for both proficiency and character.

Wednesday, November 2, 2011

WebCast: Hacking Web Servers and Countermeasures

Learn how to secure webserver!

In this on-demand IT security webcast, EC-Council Master Certified Instructor Eric Reed will address the subject of Hacking Webservers. The webcast will cover topics such as webserver architecture, webserver attack methodologies, footprinting tools, and many more critical concepts. The webcast also includes demonstrations on performing a directory traversal attack, fingerprinting a webserver with HTTPRecon, and web-based password cracking with Brutus.

This webcast is available on-demand at http://www.careeracademy.com/ceh-m12-infosec.aspx

Please feel free to forward to others in your organization who may be interested this type of training.

Details:

This free module is a part of CareerAcademy.com’s EC-Council Endorsed CEH Certification course, which gives each student in-depth knowledge and practical experience with current essential security systems.

When a student completes the course they will have hands on understanding and experience in Ethical Hacking and be fully prepared to pass EC-Council Certified Ethical Hacker Exam 312-50.

You can attend this complimentary webcast right now at:

http://www.careeracademy.com/ceh-m12-infosec.aspx

Friday, October 14, 2011

No Charge: Two Live Online CISSP Exam Prep Clinics

Earn Your CISSP in 2011

At no charge, you can attend TWO live online CISSP Exam Prep Clinics taught by a leading (ISC)2® instructor!

Register at: http://www.ufairfax.net/cissp-2011-hlist/
  • CISSP Clinic I: Domains 1 – 4
  • CISSP Clinic II: Domains 5 – 10
Both clinics are available live online and on demand following the webinar*.

If you’ve been studying for the CISSP exam, you’ll want to attend these TWO live online CISSP Exam Prep Clinics sponsored by University of Fairfax, Information Security Community, 1105 Media-- FOSE & GovSec-- and Tenacity.

You’ll discover strategies to increase your chances of success! You’ll learn techniques to help you quickly assess which questions to address first, which to delay answering and how to eliminate the less likely answers. The Clinics include tips for all 10 domains covered in the exam.

Register today so you pass the CISSP Exam in 2011!
http://www.ufairfax.net/cissp-2011-hlist/

When:

Thursday, October 20, 2011, 2 – 3 PM ET

Both clinics are also available on demand following each webinar*. There is No Charge for you to attend! Register now to prepare for your CISSP Exam.

Register Now: http://www.ufairfax.net/cissp-2011-hlist

Monday, October 3, 2011

Free CISSP On-Demand WebCast by Shon Harris

WebCast on Information Security and Risk Management

CareerAcademy.com has offered a free On-Demand CISSP WebCast with Shon Harris to try out their training delivery platform.

The course offered is on CISSP Domain 1: Information Security and Risk Management, and is intended for IT professionals. The course description is below, along with a link to try it out.

Please feel free to forward to others in your organization who may be interested in this type of training.

Sign up for the free training course:
http://www.careeracademy.com/download/freeinfoseccissp.html

Course Description:

This free course module of Domain 1 of our CISSP Certification Training will give the student in-depth knowledge on such topics as: security definitions, vulnerabilities, regulations, risk management, data collection, security enforcement issues, and many more critical concepts. Test drive Career Academy's CISSP training today.

Whether you are a security professional, a seasoned engineer, or are looking for a career change, the Shon Harris CISSP Series brings together all the materials, tools, and study aids you need to take your career to the next level. Our superior technology based course curriculum, strictly adheres to all of (ISC)2 exam objectives. We have invited the foremost CISSP trainer and author, Shon Harris, to help us develop the ultimate training and certification program which includes everything you will need to fully prepare for the CISSP certification exams.

Use the link above to sign up, and or more information, visit http://www.careeracademy.com

Tuesday, September 20, 2011

Two Live Online CISSP Exam Prep Clinics

Free Online Course Sponsored by University of Fairfax

At no charge, you can attend TWO live online CISSP Exam Prep Clinics taught by a leading (ISC)2 instructor!

Register at: http://www.ufairfax.net/cissp-2011-hlist/
  • CISSP Clinic I: Domains 1 – 4
  • CISSP Clinic II: Domains 5 – 10
Both clinics are available live online and on-demand following the webinar*.

If you’ve been studying for the CISSP exam, you’ll want to attend these TWO live online CISSP Exam Prep Clinics. You’ll discover strategies to increase your chances of success! You’ll learn techniques to help you quickly assess which questions to address first, which to delay answering and how to eliminate the less likely answers.

The Clinics include tips for all 10 domains covered in the exam.

Register today so you pass the CISSP Exam in 2011!
http://www.ufairfax.net/cissp-2011-hlist/

When:
  • Thursday, October 13, 2011, 2 – 3 PM ET
  • Thursday, October 20, 2011, 2 – 3 PM ET
Both clinics are also available on demand following each webinar*. There is No Charge for you to attend! Register now to prepare for your CISSP Exam.

--> http://www.ufairfax.net/cissp-2011-hlist/

Wednesday, September 7, 2011

Social Media: Training Is Key

How we can manage risks of Social Media through Policies?

Frequent face-to-face training on social media policies is a vital component of any risk management effort.
Once an organization develops social media policies designed, in part, to prevent privacy violations, in-person training sessions offer the best way to make certain that policies are followed.

Training sessions should provide real-world examples of inappropriate uses of social media to reinforce the risks involved. In spelling out proper uses of social media for communication, an organization must ensure that employees "understand that posting on Facebook is really no different than talking at the water cooler or sending an e-mail.

Because organisations can use social media for many purposes, It is highly recommended to create a multi-disciplinary team to develop policies. The team should include representatives of the human resources, legal, information technology, marketing, risk management, public relations and compliance departments.

The other key recommendations are:
  • Document current and intended social media use. For example, if a human resources department intends to use social media for recruiting and hiring purposes, that will require the creation of policies about allowable uses of information gathered.
  • Perform a risk assessment. A key component of this effort, is to conduct a workshop with upper management and key stakeholders to discuss all risks identified so they can be mitigated.
  • Expand current policies to include social media and implement safeguards. For example, organizations may want to expand their information security policy to explain the potential for downloading malware by clicking on a malicious Facebook page. In addition to adding new details to existing policies, organizations may also want to create a freestanding social media policy to highlight key issues.
  • Provide social media training. It's important to provide frequent updates with reminders about security incidents in the news.
  • Monitor social media channels. By tracking mentions of their organization on social media, executives can use the information to adjust their marketing message, offer personalized replies to negative comments and capitalize on positive comments.

Wednesday, August 24, 2011

Test Drive Career Academy CISA Training Video Free

Free Certified Information Security Auditor training

CareerAcademy.com is offering a free CISA training video course to try out their training delivery platform.

The course offered is on Certified Information Systems Auditor (CISA): The Importance of Information Security, and is intended for IT security professionals. The course outline is below, along with a link to try it out.

Please feel free to forward to others in your organization or your friends who may be interested in this type of training.

Link to sign up for the free training course:
http://www.careeracademy.com/download/freeinfoseccisa.html

Course Description:

CISA Certification Training will give the student in-depth knowledge on such topics as: Key Elements of Information Security Management, Mandatory and Discretionary Access Controls, Identification of Risks Related to External Parties, Security Incident Handling and Response, and many more critical concepts. We have invited the best security trainers in the industry to help us develop the ultimate training and certification program which includes everything you will need to fully prepare for the CISA certification exam.

Sign up for the free training course:
http://www.careeracademy.com/download/freeinfoseccisa.html

Sunday, July 31, 2011

Security Training Video: Investigating DoS Attacks

Introduction to DoS Attacks and techniques

CareerAcademy.com is offering a free EC-Council training video to try out their training delivery platform.

The course offered is on Computer Hacking Forensics Investigator (CHFI): Investigating DoS Attacks, and is intended for IT security professionals. The course outline is below, along with a link to try it out.

Please feel free to forward to others in your organization who may be interested this type of training.

Link to sign up for the free training course:
http://www.careeracademy.com/download/freeCHFIm31.html

Course Description:

This free introductory online training course (Value at $195) will immerse the student in an interactive environment where they will be shown how to investigate DoS attacks. Students will be introduced to the types of DoS attacks, buffer overflow, DoS attack techniques, intrusion detection systems, live demonstrations of SYN Flooding, Smart Sniff, 3D Trace Routes, and many more critical concepts.

Use the link above to sign up, and or more information, visit www.careeracademy.com or contact CareerAcademy.com at 1-800-807-8839 x201 (US), 1-781-453-3900 x201 (International), email: info@careeracademy.com

This course is Module 31 of a 51 module EC-Council Computer Hacking Forensic Investigator CHFI Training CBT Boot Camp.

Wednesday, July 6, 2011

Webcast: Cloud Security and Smart Security

Security in the cloud – where are we now?

Cloud security is now a very different proposition compared to a year ago with expanding access points, more personal devices, and increasingly sophisticated threats.

In light of this, I thought you might be interested in SC’s upcoming webcast which will give you a valuable, real-world update on where we are today.

The full session and sign up can be found at http://www.scwebcasts.tv.

I have pasted a few more details below though for your reference.

SECURING THE CLOUD - LOCKING DOWN 2011’s MULTIPLE ACCESS POINTS

Going live on 14th July 10:00 am ET / New York, 3pm / London @ http://www.scwebcasts.tv

The webcast will give you tools to:
  • Facilitate strong end user and multifactor authentication in public and private clouds to secure identity and protect your business
  • Keep up to date with current cloud technology and gain architectural perspectives to manage user activity and log ins
  • Gain visibility across the multiple layers of cloud security and assure data protection and ownership in storage and encryption
  • Integrate outsourced IT services with in-house programmes to maximize staff productivity and reduce costs
You may also be interested in another 2 of SC’s recent projects which have proved very popular with group members:
  1. SC WEBCAST: Smart Security for SMEs: Key Cyber-Threats And How To Tackle Them – Going live on July 12 at 10:00 am ET / New York, 3pm / London at http://www.scwebcasts.tv.
  2. SC STUDIO SHOW: The Risks and Rewards of Archiving – hard-hitting video available now at http://www.scstudio.tv.
If you can’t make the live date of the webcasts, you can of course watch them on-demand in the archive at your leisure at http://www.scwebcasts.tv .

As always, feel free to get in touch with any questions.

Saturday, June 25, 2011

Logical Security offering 10 Free On-Line Videos

Discussing Security Topics Now Available!

Logical Security is providing free videos that discuss various security topics. Some of these topics are: Block Ciphers, Digital Certificates, ITIL Problem Management, and Wireless Security.

The videos can be found at http://www.logicalsecurity.com/resources/resources_videos.html

Tuesday, June 21, 2011

Webinar: Effective Information Security Risk Assessments

Align Practices with Business Strategy

From payment card fraud to skimming attacks and corporate account takeover, we've seen a wide variety of threats to banking institutions and their customers.
And with the advent of the ID Theft Red Flags Rule, and in the aftermath of the economic upheaval, we know banking regulators are paying closer attention to institutions' information security practices.

So, in light of increased threats and greater regulatory scrutiny, how should a banking institution approach one of its most critical undertakings - the information security risk assessment?

Learn how in this exclusive new webinar on 30th June 2011 and 18th July 2011. Guided by an experienced banking/security leader, you will receive timely, hands-on advice and new risk assessment tools regarding:
  • How to build process and strategies to identify and manage risks;
  • Risk assessment techniques that work - and those that don't;
  • How to satisfy your regulators' and customers' security and privacy needs and requirements.
Refer here for further details and to register for the event.

Wednesday, May 11, 2011

Application Security Intelligence

Free Online Event

Forward-thinking organizations have begun to adopt a holistic approach to securing applications rather than investing in perimeter defenses like firewalls and intrusion prevention systems.

Join on May 19th for a full day of interactive webcasts to hear leading IT security experts discuss the role of application security intelligence in enabling software security assurance programs to proactively reduce business risk across the enterprise.

About the event:

"Traditionally, organizations have responded to security threats by investing in perimeter defenses like firewalls and intrusion prevention systems. While effective in the short-term, this approach is simply a bandage that offers reactive protection only, falling short of proactively and programmatically securing the applications and assets that are the lifeblood of any modern business. Recently, some organizations have begun to adopt a holistic and strategic approach to securing their applications. Join us to hear leading software security experts discuss the role of application security intelligence in enabling software security assurance programs to proactively reduce the business risk of insecure software across the enterprise."

Presentations include:

"Application Security Intelligence: Managing Application Risk"
Roger Thornton, CTO & Founder, Fortify Software, an HP company

"Optimizing Security in Software Development: Secure at the Source"
Derek Brink, VP & Research Fellow, Aberdeen Group

"Application Security Strategy in a Mobile World"
John South, CISO, Heartland Payment Systems

"Cloud Security and Its Impact on Application Security"
Dennis Hurst, Founding Member, Cloud Security Alliance

"Addressing the Top 5 Web Application Security Threats"
Dave Wichers, OWASP Board Member & COO, Aspect Security


Sign up to attend any or all of the May 19 webcasts at: http://bit.ly/mPYS1V

Saturday, May 7, 2011

Free On-Line CEH Course

Logical Security is providing 25 hours of free CEH on-line training

The video modules are outlined below and can be found here.

Hope you find them useful!

1. Ethical Hacking and Penetration Testing
2. Footprinting and Reconnaissance
3. TCP/IP Basics and Scanning
4. Enumeration and Verification
5. Hacking and Defending Wireless/Modems
6. Hacking and Defending Web Servers
7. Hacking and Defending Web Applications
8. Sniffers and Session Hijacking
9. Hacking and Defending Windows Systems
10. Hacking and Defending Unix Systems
11. Rootkits, Backdoors, Trojans and Tunnels
12. Denial of Service and Botnets
13. Automated Penetration Testing Tools
14. Intrusion Detection Systems
15. Firewalls
16. Honeypots and Honeynets
17. Ethics and Legal Issues

All videos can be viewed at
www.logicalsecurity.com/resources/resources_videos.html

Thursday, March 3, 2011

SC Magazine - Upcoming Webcasts

Cyber crime costs over $1 trillion; join our webcast debates

As you may have read recently, Cybercrime is now costing the UK $43.5 billion and around $1 trillion globally. Given the release of these statistics, I thought you might be interested in 3 of SC magazine’s upcoming webcasts (http://www.scwebcasts.tv/) which will offer valuable insights into the shape of these threats today and what can be done to avoid them.

I have pasted in details of the 3 webcasts below, SC have some great speakers lined up from companies including Capita and Vodafone so it may well be worth a listen:

1. BENCHMARKING YOUR SECURITY: HOW DO YOU MEASURE UP?
3pm, 29th March – view more info at http://www.scwebcasts.tv/
> As the cyber threat mounts and with mobile platforms changing the face of security, this webcast will give you some surprising statistics from real companies on how secure you really are next to your peers….

Speakers: Marco Ermini, Network Security Manager at Vodafone Group and Jim Acquaviva, VP of Product Strategy, nCircle
Register Now: http://www.scwebcasts.tv/

2. ONLINE VULNERABILITY MANAGEMENT: A 360º PERSPECTIVE
3pm, 6th April - view more info at http://www.scwebcasts.tv/
> With so many disparate online systems, this webcast will offer you a 360º insight into where companies are most commonly attacked and the PCI and other policy considerations you need to know about to stay safe online.

Speakers: Dave Whitelegg, Head of IT Security for Capita and Daan Dia, Director of Strategic Business Development for Outpost24
Register Now: http://www.scwebcasts.tv/

3. CYBERTHREATS: PUBLIC VS. PRIVATE SECTOR
3pm, 7th April - view more info at http://www.scwebcasts.tv/
> An interesting point to emerge from SC’s recent research with global IT Directors was the fact that online threats do differ from Private to Public sector. In this webcast you will hear more on the specific online security priorities of your particular sector to give you food-for-thought that will help streamline your efforts.

Speakers: Mark Jackson, security architect in Cisco's UK Public Sector operation & private sector focused colleague
Register Now: http://www.scwebcasts.tv/

Many of you have attended an SC webcast at some time or another but they involve a very easy one-off sign up process. They are also live to give you the ability to interact via questions and votes. If you can’t attend the live date by securing your free place to each webcast you will be able to access the archive.