Thursday, October 2, 2014

Week 5 Blog - CYBR650
Well, I have continued to struggle this week with my new laptop.  Needed Visio for a class assignment, of course, could not get it to load to save my soul.  Wasted two days on trying to get it on before finally giving up and searching for an alternate freeware program to use in the meantime.  Finally got my network diagram done and turned in, but later than expected.  Hoping the Professor understands.

This week I caught an article "Breach Prevntion:  The Missing Link" that looked interesting.  This piece addresses gaps in mobile policies and how those gaps threaten corporate data protection.  I found this interesting because I know BYOD is becoming more and more popular.  They had just started allowing it at TD Ameritrade while I was interning.  I know I bring my own iPad to my current job to work with, not anything to do with my job, but I do access the network with my own device.

This piece opens up stating that one of the huge issues, and what managers find most often, is that a large portion of their workforce are using mobile devices, applications and cloud services that are outside of an organization's sanctioned and approved services, and out of the organization's control.

This leaves organizations struggling to determine what "shadow IT" services are being utilized by their workforce, as well as what type of security and privacy aspects are being exercised by the providers, if any.

Apparently many IT departments are playing catch up with this issue, as well as the organizations themselves.  This increased personal device usage many times find Company policy and standards and procedures lagging behind and containing gabs and other inconsistencies on their use and their security.

The piece did suggest that in order to increase breach prevention in these circumstances, they need to account for mobile pieces and incorporate the following:

Recognize the advanced sophistication of malware attacks on mobile applications and work to mitigate those risks;

Go beyond implementing a mobile device management system to address application and network layer security;

Encrypt mobile devices, including laptops, in order for them to safely and securely store sensitive company information; and

Consider establishing a mobile center of excellence to educate employees on safe mobile device use.



Roman, J. (2014, September 30). Breach Prevention: The Missing Link. Retrieved from databreachtoday.com: http://www.databreachtoday.com/breach-prevention-missing-link-a-7369
 



Wednesday, September 24, 2014

Well, what to write about.  Besides my week from hell, hum.  I'll start with that.  My luck was shining through, starting last Friday.  Got off work a couple hours early and thought I was going to have a nice long relaxing weekend.  Huh.  The car overheated and broke down, luckily it was just a hose, then my laptop decided it didn't like me and died as I was finishing up my homework and getting ready to submit it.  Found out it is just dead.  Waiting to get my files off of it, if I can.  I did manage to get a new one, but gosh, what a decision to make.  There are so many systems out there anymore to choose from.  Try reading reviews and researching and it's not any less confusing.  My daughter tried to take me to the dark side and tried to convince me to by a MAC, but I was able to resist...this time.  Bahahaaha.  Ended up getting an HP Envy, which I'm a little concerned because it reported that I already a ton of things that needed to be cleaned off when I installed the virus protection, which was a whole other decision.
I have some type of protection offered through my local cable company, but you know the salesman, it's on sale, here, you gotta get it.  Last time I bought virus protection for my computer I bought Kaspersky and loved it.  This time they talked me into trying Webroot.  We'll see how I like that one, I guess.
The other big thing this week is all the hacking being done and all the celebrity photos being leaked that are stored on the cloud.  I find this interesting because I wondered how long it would take for someone to hack into a cloud provider.  The cloud was being presented as being more secure and reliable and it hasn't taken hackers long at all to figure out how to get in.  So, do the pics belong to the celebrities who are in the pics or into the cloud service and who is going to attempt to pursue these hackers?  I guess first of all, you should really think about what you store in the cloud until it is proven to be a little more secure, and second, you would think they would have learned by now, there is no way in this day and age that you can say or do anything or take a pic that you don't want released for public consumption.  It is just far too easy for people to get their hands on things whether you think they are secure or not.

Sunday, September 14, 2014

September 14, 2014


Gosh, what to address this week.  It's kind of been a busy week, so not much time to do any extra reading besides what has been required for class.  Our reading and assignments had to do with Threat Modeling and tools that can be used to perform threat modeling.  It was very interesting to read about the different tools available.  It seems like they all have some step that incorporate STRIDE.  To me, that shows how beneficial STRIDE is to the security community.

This week I did hear that the Home Depot breach may be even bigger than the Target breach last winter.  I have not had time to dig into this incident very much, but found it entertaining when I heard on my local news the other night that Home Depot will not force it's customers to pay for any unauthorized charges to their account.  I found that laughable as I thought that was the standard with credit cards.  Plus, when the organization itself is the one that has the breech, that seems like a no-brainer.

Sunday, September 7, 2014

Credible Sources

This week we are told that one of the first steps in our threat modeling process should be to identify credible sources of information for threats, vulnerabilities, updates, and security news in general. In our blog post this week, we are told to include a list of sources we consider to be credible and why we consider them to be credible.

1.  One of my favorite sites, and one I subscribe to and get regular updates from, is techtarget.com, also has SearchSecurity.  I have utilized techtarget.com over and over for various information.  They also have SearchSecurity which contains information on a multitude of topics regarding IT security, Access Management, Governance and more.  I have always found techtarget and SearchSecurity to be reliable and current on all their information and consider them a very credible source.

2.  Another newsletter that I get that I consider a credible source is IT News Daily.  They discuss everything; issues with Android, MAC; they also discuss patches and other news in the IT world.  I have found them to be up to date and credible.  They are a good source of both news of what is going on in the IT world as well as information on current issues out there.

3.  I also find CNet a reliable source.  They are another source that is a wealth of information, including information security issues.  They have always proved to be dependable and timely.





Sunday, August 31, 2014

CYBR650 - Current Trends in Cybersecurity - Blog - Week 1

Hey, everyone!  Well, I think we have finally made it through this degree path!  Yay!  If you are like me, you have had days where you thought, "wow, how cool", as well as those days were you thought, "what the heck was I thinking doing this", especially when it is around time for those fund "projects" to be done.  LOL!  I'm excited to be in this class, both for what I can learn and will be taught, and to know that this is my final class and all my hard work is paying off.  I hope to find some interesting things that I will discuss, and I hope you enjoy reading it.  If you have any input, please let me know, I am always interested to receive feedback and get my thought train back on track if we are in process of derailing!

To this class and to having a chance to work with all of you for the last time, thanks, and I look forward to all the interesting conversations we will have in the near future.

Thanks, Angel

Sunday, November 11, 2012

Pros and Cons of Information Security Certifications

This week we discussed, among other things, job descriptions and certifications.  We all had our own views about available certifications.  It is apparent that many times these certifications are not only desired by employers, but many times they are required.  While we were discussing this this week, I ran across the article "Pros and Cons of Information Security Certifications" on the SearchSecurity site. 

In this piece they also state that one of the questions they are most frequently asked, by both prospective and currently enrolled students, ask which security certifications would be best in or to be competitive in the information security field.  The response to this question is far more complex than one would think, and is therefore there is no simple response.  However, the real question students should be asking have more to deal with the value that certificates provide for a security professionals career.  There is no Holy Grail of security certifications.  The most important thing for one to do is to understand what certifications represent and what they do not, as well as understanding that certifications have both pros and cons.

One of the more exciting things about information security is that the knowledge in the discipline is constantly and rapidly changing.  This is both positive and negative for the information security profession.   While one we get to enjoy an ever changing landscape, this is also the cause for the us to have to keep our skills and knowledge updated.  Unlike other sciences where challenges are presented by nature, our challenges lie in people.  People can be our adversaries and highly motivated to cause damage.  These highly motivated people only need find one weakness in order to exploit a system and gain access to any information they desire.  So we need to find those weaknesses and strengthen them.  This is why when security education in practice is considered, security professionals do not have a straight forward, static reply.  The information security professionals career is dynamic.

So one wonders where certificates fit into all this.  According to this author, certificates should be viewed as a measurement of master in ones career in the profession of information security other than as an end.  Security professionals are less dependent on memorization and passing a certification and more dependent on the ability to learn and think independently.  The author feels that professional development in security is much more about continuing one's education and keeping one's skills and knowledge current than about certifications and all the letters they add behind one's name.

This is not to be taken as saying that certifications are not important.  Certifications have a place.  For some, a certification provides motivation to learn something new while the eventual completion of the test is gives them visual verification of what they have learned.  Certifications can also be used for measurements in employment.  In some cases, employees can earn more money by earning certifications.  In some cases, employers require certification as a condition of employment.  Many of these certifications require periodic renewals as well as continuing education in order to maintain them.

The best certification to get is the one that will help one continue to learn and stay current on what is happening in the security realm.  It is best to always keep in mind that a certification is a milestone, not the end of the road.

Reference



Jacobson, D. a. (Unknown). SearchSecurity - Pros and Cons of Information Security Certifications. Retrieved from techtarget.com: http://searchsecurity.techtarget.com/opinion/Pros-and-Cons-of-Information-Security-Certifications
 




Sunday, November 4, 2012

South Carolina's Recent State Tax Return Breach

So, this week's reading discussed Firewalls and encryption.  Very ironic considering the piece seen on the MSN front page on Wednesday afternoon.  "Data Breach Targets 3.6M taxpayers" the headline screamed from the screen.  Naturally, being inquisitive as I am, and considering my current Degree pursuit, I had to click on the headline and get the details.  As I read, I had to shake my head.

Apparently, citizens that have filed a South Carolina tax return anytime since 1998 are at risk of having their identity stolen.  Hackers accessed the state Department of Revenue server in August of this year and accessed 3.6 million Social Security numbers and 387,000 debit and credit cards.  Five thousand of those debit and credit cards were expired, and the Department claims that the rest were expired.

However, the 3.6 million Americans who had their Social Security numbers stolen will have to monitor their credit for many years to come.  These people include children who do not even know what a Social Security number is, yet they may end up learning the hard way because of this breach. 

Apparently hackers like to target state and local governments who are either unwilling or unable to sufficiently secure their information.  From late September through mid-October of this year damaging hacks were reported by the City of Burlington, WA, the Centers for Medicare and Medicaid Services in Baltimore, MD, the town Council of Chapel Hill, NC, the Robeson County Board of elections in Lumberton, NC, the Brightline Interactive, Army chief of Public Affairs office in Alexandria, VA, the City of Tulsa, OK, and the town of Willimantic, CT, and these are just the entities that have willingly disclosed breaches.

Only one in four State Chief Information Security Officers nationwide report that they are confident in the ability of their State to stand against an attack on data from an external cyberattack.

In the South Carolina instance, the State has negotiated a $12 deal with Experian in order to provide the affected people, who sign up, a free year of credit monitoring, a lifetime of fraud resolution with personalized assistance if an account is opened in their name.  This offier also applies to children that have been effected.

Of course, that State has recommended that victims immeddiatly begin to monitor their credit reports, and bank and credit card accounts for any suspicious activities.

I just begin to wonder, with this occurring over and over when will Government entities and businesses realize how at risk their data is.  Information security seems to be the last thought and the last place anyone wants to invest money, giving hackers the opportunity to ruin the everyday man's credit.

References



Datko, K. (2012, October 30). MSN Money. Retrieved from msn.com: http://money.msn.com/saving-money-tips/post.aspx?post=99d34310-0d33-44f2-9981-b2dc18667074