Sponsors

Sunday, March 29, 2009

Risky Flash Drives Could Mean Your Lost Data





Risky Flash Drives Could Mean Your Lost Data

Flash Drives, Memory Sticks, Jump Drives…etc, are not all made equally. I myself have had quite a few flash drives go bad on me; especially those given out for free at IT conferences.

Julius will tell you the real deal around flash drives!

Not all flash drives have the same quality and reliability. Some are made cheaply for mass distribution and given out as freebies, while some are made with top of the line manufacturing processes to insure that the data you save or backup to the flash device is ready for use when you need it.

Generally, Flash drives are divided up along four quality grades:

Grade A: Tier 1, a manufactures own brand made with their brand of premium chips with a lifetime warranty. Ex. Samsung & Hynix.

Grade B: Tier 1, OEM type chips sold to other companies to place their name on, these are made by legitimate chip manufacturers but are without the manufacturer's name imprinted on them. These chips are reliable but are not of the same standards that the manufacturer would consider putting their name on it.

Grade C: Now you are putting your information at great risk! These flash drives are the least expensive and have failure rates around 30% - 40%. The chips used to manufacture these are made from RECYCLED or RECLAIMED chips. The original manufacture did not use them in their flash devices, because they are viewed as GARBAGE chips! Manufactures make money on this waste by selling off their junk by the truck load to other companies.

Grade D: Bootleg chips with other manufactures names on them, but they are still of the GARBAGE breed. Just like bootleg hand bags and watches; they come from the same notorious country infamous for this.

Note that all electronic devices will eventually fail, but if you pay a little more for quality you should be able to get many uses from a flash drive when you need it. Hope this helped you understand the differences between flash drives. Pay more attention to who made the flash drive than to the low price and nice plastic cover.

Julius Clark, CISSP, CISA


Reference:

Flash Drive Direct: http://www.flashdrivedirect.com/FlasDriveRipOffs.htm

Thursday, February 5, 2009

Was Harriet Tubman a CISSP?


Black History Month Celebration



Was Harriet Tubman a CISSP?
This is my way to celebrate and honor the woman Harriet Tubman was. She is the African American woman I most admire for her courage and dedication to secure freedom for her people, despite the high risk of losing her life. The following Chart maps each Certified Information Systems Security Professional (CISSP) security domain with Harriet Tubman's life work of ensuring freedom for runaway slaves.

Mapping of Harriet Tubman Abolitionist Activities to the 10 CISSP Security Domain Principles
***Note***

If you are having problems viewing text in the table do the following from your browser:

  1. From your browser Pull Down menu, choose View
  2. Then Text > Smallest or Zoom In/Out, and adjust text size accordingly.



The 10 CISSP Security Domains
CISSP Security Usage
Harriet Tubman's Usage
Security management practices
The security management practices domain sets the foundation for security professionals by identifying key concepts, controls:

  • Confidentiality,
  • Integrity
  • Availability


(CIA) triad provides the three tenets for which security practices are measured.
Confidentiality – She never disclosed any on the methods or structure of the Underground Railroad until the Civil War was over.



Integrity – Use of Secret codes, Songs with hidden meaning to communicate with other slaves.



Accessibility – Tubman used her extensive network of people from different backgrounds who were dedicated to the cause of freeing slaves. Keeping this system available for slaves fleeing slavery was vital and was accessible for over 40 years
Access control systems and methodology
The key to access controls is declaring who you are when before entering a system and having the system verify that you are allowed access. This is known as identification and authentication. There are three way to authenticate users:

  1. Something you know (PIN, password, phrase, pass code)
  2. Something you have (smart card, ATM card, token)
  3. Something you are (retina scan, fingerprint, voice scan)
As and abolitionist in the Underground railroad, spy for the Union Army and having knowledge of the many safe houses and points along the Underground Rail Road, Tubman would be a master of this CISSP domain as it relates to her time and activities. Tools: extensive network of secrecy, hidden songs with codes, and disguises.

  1. Something he knew – Songs with hidden codes for runaway slaves. Location of safe houses for food and shelter.
  2. Something you have (smart card, ATM card, token)
  3. Something you are – As a spy she would of have
Telecommunications and networking security
The telecommunication and network security domain is one of the most technical, as it addresses the various structures for a network, methods of communication, formats for transporting data, and measures taken to secure the network and transmission.
Her use of the extensive network known as the Underground Railroad that transported and protected runaway slaves as they traveled to the North for freedom.
Cryptography
The cryptography domain addresses the security measures used to ensure that information transmitted is only read and understood by the appropriate individual. In layman's terms, this is commonly referred to as encryption. Encryption is the transformation of plaintext into an unreadable cipher text and is the basic technology used to protect the confidentiality and integrity of data
Her usage of slave songs with encrypted messages: wade in the water: Instructing slaves headed to the North to follow the water to freedom and wade in the water at night to prevent capture. Follow the drinking gourd: Song instructing slaves to follow the Big Dipper (star) that guided travelers north to freedom. Usage of quilts with made with patterns that had hidden meanings which instructed slaves on escaping from the South to freedom in the North.
Security architecture and models
Security professionals must be aware of the software development cycle to ensure that concerns are addressed throughout the process. Information security components should be addressed concurrently in the development cycle (conception, development, implementation, testing, and maintenance).
She also provided specific instructions for about fifty to sixty other fugitives who escaped to the north. Her dangerous work required tremendous ingenuity; she usually worked during winter months, to minimize the likelihood that the group would be seen. One admirer of Tubman said: "She always came in the winter, when the nights are long and dark, and people who have homes stay in them." Once she had made contact with escaping slaves, they left town on Saturday evenings, since newspapers would not print runaway notices until Monday morning. She used spirituals as coded messages, warning fellow travelers of danger or to signal a clear path.
Operations security
The operations security domain is concerned with implementing appropriate controls and protections on hardware, software, and resources; maintaining appropriate auditing and monitoring; and evaluating system threats and vulnerabilities.
The operations of the Underground
"I was conductor of the Underground Railroad for eight years, and I can say what most conductors can't say – I never ran my train off the track and I never lost a passenger." Harriet Tubman
Application and systems development security
System feasibility: Identify the security requirements, policies, standards, etc., that will be needed. Software plans and requirements: Identify the vulnerabilities, threats, and risks. Plan the appropriate level of protection. Complete a cost-benefit analysis. Product design: Plan for the security specifications in product design (access controls, encryption, etc.). Detailed design: Design the security controls in relationship to the business needs and legal liabilities. Coding: Develop the security-related software code and documentation. Integration product: Test security measures incorporated into software and make refinements. Implementation: Implement security measures and software and test before "going live." Operations and maintenance: Monitor security software for changes, test against threats, and implement appropriate changes when necessary.

Feasibility & Purpose
The escape network was solely "underground" in the sense of being an underground resistance. Tubman used security standards of her time and like a well thought out application

Separations of Duties as a Security control
The Underground Railroad consisted of meeting points, secret routes, transportation, and safe houses, and Individuals were often organized in small, independent groups, which helped to maintain secrecy since some knew of connecting "stations" along the route but few details of their immediate area.



Implementation & Production
Escaped slaves would move along the route from one way station to the next, steadily making their way north. "Conductors" on the railroad came from various backgrounds and included free-born blacks, white abolitionists, former slaves (either escaped or manumitted), and Native Americans.



Security Operations & Maintenance
the underground railroad wad designed with security controls, which could adapt to threats and make appropriate changes to keep from being caught by bounty hunters others whose job was to catch runaway slaves.

Physical security
The physical security domain addresses the environment surrounding the information system and components. The key to this domain is identifying the threats and vulnerabilities and applying appropriate countermeasures to physically protect the system.
The systems she was involved in protecting was the Underground Railroad and helping the Union Army during the Civil war.

Use of safe houses that provided security of slaves traveling the Underground Railroad. She even packed a gun and was not afraid to use it.

For the Union Army she was a nurse, scout and spy.

Tubman became the first woman to lead an armed assault during the Civil War
Business continuity and disaster recovery planning
Plans must also be in place to preserve business in the wake of a disaster or disruption of service. This domain addresses two types of planning: business continuity planning (BCP) and disaster recovery planning (DRP)
Harriet Tubman was one of many individuals involved to help slaves flee to the North for freedom, with multiple routes, numerous safe houses and changing plans on the fly to avoid capture.
Laws, investigation, ethics and compliance.
Certified security professionals are morally and legally held to a higher standard of ethical conduct.8 (ISC)2 establishes a code of ethics for credentialed security professionals which includes four main canons:

  1. Protect society, the commonwealth, and the infrastructure
  2. Act honorably, honestly, justly, responsibly, and legally
  3. Provide diligent and competent service to principals
  4. Advance and protect the profession
The ISC code of conduct also gives CISSPs instruction on how to solve conflicts of interest with information security matters. They instruct us to you the code of conflict in order to resolve the conflict. Harriet Tubman Has conflict with cannon #2, because freeing slaves was illegal, but cannon #1 takes precedent over #2 for her heralding efforts to protect society. Later the Emancipation Proclamation was signed into law by President Lincoln freeing slaves, which fueled her passion more than ever in her efforts to lead slaves to their waiting freedom. Additionally, she served the Union Army during the Civil War and the Underground Railroad worked in reverse to bring slaves back to the south to fight for their freedom.


Long before there were the CISSP 10 pillars of Information Security, Harriet Tubman embodied the essence of their principles to secure freedom for her people with 100% success per attempt. In her own words:
"I was conductor of the Underground Railroad for eight years, and I can say what most conductors can't say – I never ran my train off the track and I never lost a passenger."

Harriet Tubman, CISSP

A security professional abolitionist, & humanitarian

By

Julius Clark, MBA, CISSP, CISA

BDPA CIO , National BDPA

In addition, if you are new to the IT Security field, or have no experience and want to change your career consult with me at:


References:

The 10 Security Domains (AHIMA Practice Brief) - American Health Information Management Association

Wikipeida.com

Tuesday, February 3, 2009

ChaCha The Human Assisted Mobile Phone Search Engine



ChaCha the Human Guided Search Engine

  • Have you ever wondered how many vehicles are in the US?
  • Want to get stats of your favorite football player?
  • Have you ever been in a heated debate over Michael Jordan Statistics on the basketball court?
  • Ever need the recipe to make toll house cookies?
  • Have you ever had a need to get answers to any thought, but all you have available is your cell phone?

Then Meet ChaCha! ChaCha has taken the search engine to the next level by using a human search engine to do the searching for you and spit you back your answer (or as close to your answer as possible). Brought to you by Scott A. Jones, digital voice-mail inventor and holder of numerous voice-mail storage patents.

Registration Required

Go to www.chacha.com and register your mobile phone number online.

Limitations

  • The ChaCha service does not work from a land line phone only a mobile phone.
  • You can only have 4 guided questions within 72 hours.
  • The service makes a best effort to answer your message you texted in.
  • Answers are not instantaneous can take up to 10 minutes.
  • Service is free to use, but subject to the terms and conditions of your cell phone messaging plan.


My Test of ChaCha

Text from my cell to 242242:

What is the BDPA?

Reply text to my cell:

BDPA stands for Black Data Processing Associates. They help spur professional growth & technical development in the IT industry.

Not bad!

Enjoy ,

Julius



Monday, January 19, 2009

Divine Driven Leadership: The Great Power Within



The Bondage Breaker

I was inspired by my inner compass to write "The Great Power Within" three years ago and I feel that the vision depicted in my writing is for all to realize ones own inner power, which is installed by our creator. To me this is so relevant as the first African American is sworn in as President of the United States of America today. He was not to be denied.

The Great Power Within

A man from generational bloodlines of conquerors and kings is not always guaranteed victory, even though one from such a lineage is often powerful, feared and rarely challenged. A man whose only material belonging is the air his lungs acquire to sustain his life, and who has the ability to hone into his inner strength and harnesses the spirit of all beautiful things around him, gains a strength far superior to any conqueror or king. If this man is raised by wise handlers, a pure heart will be harvested that can attain a power never imagined by limited minds or hearts. This man will develop a desire to challenge himself by competing with the best around him. He lives for the thrill of contest and unknowingly is being prepared to protect himself and the universe from any threat. Fueled by his sense of righteousness, bestowed upon him by his creator, he will prevail in any situation despite the hopeless odds placed against him and when all is said and done, he will not lie down to die until he has fought and won a perceivably un-winnable fight.

Author, Julius Clark Sr.

Obama’s Infrastructure Stimulus Hopes to Increase IT Jobs







The Business Software Alliance reports that President Elect Obama's economic stimulus agenda will include a "Pro-Tech" emphasis; a sweet sound to an IT professionals ears!





Information Technology Job Creation Breakdown:

Obama's' Stimulus Impact Estimate

  • 10 percent increase in IT Jobs: 300,000 new IT jobs.
Skills Needed In

  • Construction & Engineering Firms
  • Alternate Energy Systems
  • Health Care Process Modernization
  • Bioinformatics
Hottest IT Areas

  • Business analysis
  • Financial and human resources applications
  • Program management
  • Application development
  • And last but not least. Information Security
To Sum it Up

Information Technology will continue to a Rosetta stone for interpreting and translating historic complex problems to formulas that we can solve in this economic crisis.

Thursday, January 15, 2009

Wednesday, January 14, 2009

To the Office of the President-Elect: Kids, Technology & Problem Solving





I received and email from President Elect Obama's Change.Gov. Open government was a campaign promise that Obama consistently made, and he is delivering on his promise. Change.gov is set up to take ideas from Americans that can be used to fix our nation's problems. I could not resist the opportunity to offer my two cents to the Office of the President-Elect.

My Comments:

Teach Kids How to Use Computer Technology to Solve Problems

To the Office of the President-Elect,

I volunteer in a professional organization (BDPA) that teaches children (8th-12th grade) in underserved communities, 3 tier web design (HTML, .NET & MySQL) to solve problems. We accept students from all walks of life, with little to no programming experience. Along with programming, students across the country in this volunteer initiative, learn project management, career skills and team building. We are proving that kids in underserved communities can learn and apply college level education, while in still in grade school to solve complex problems, when they are mentored and handled by wise hands. Some of those students go on to compete against other students across the country in a High School Computer Competition (HSCC) for bragging rights, but most importantly college scholarships. They have created Information Technology Systems in these competitions such as:

  • Global Troop Deployment Systems
  • Charity Donation Sites
  • Online PC Ordering Sites
  • Terrorist Tracking Databases

Children are naturally interested in computer technology, so let's develop a national directive that takes their passion with the internet, gaming and teach them to solve problems, which in return will create a workforce of very talented future leaders, who will keep America competitive and creative, while solving a world of problems. If the volunteers of the BDPA can turn out hundreds of students each year on Saturdays to and influence them to pursue Computer Science careers, imagine the impact to our economy, business innovation and Homeland Security if our nation can reproduce our results.

Julius



Thursday, January 8, 2009

SharePoint Team Sites: Rich Information Collaboration & Document Management Solution



SharePoint Solving Problems

In 2008 I proposed to the Charlotte chapter of the Black Data Processing Associates (BDPA) to use Microsoft SharePoint Team sites to manage our chapter and possibly become our main website. I presented to BDPA Charlotte the powerful and rich document management and calendar features that we as Information Technology professionals were so accustomed to using in corporate America. Prior to this we solely used Yahoo Groups for document management and calendar usage, but most of us work for corporations that block or restrict Yahoo Groups for us to effectively use it to collaborate, manage, and share information while on the job. Not to mention that you don't need a web designer to maintain it.

SharePoint Collaboration Features

http://www.microsoft.com/sharepoint/capabilities/collaboration/features.mspx


Cost Effective Solution

For $29.00 per month an organization, club or small business can obtain SharePoint services from an Internet Service Provider (ISP). To support SharePoint In house it could cost over $3,000 to purchase the product, hardware to run it, with software licenses and thousands more in support and maintenance costs.

SharePoint Website as Internet Presence

Many organizations, businesses, the federal government and colleges are using SharePoint to efficiently manage their Internet website allowing department to quickly update information on their own with no lag time due to a web designer finding time to update the website. View the following links for SharePoint examples and case studies.

SharePoint ISPs

We selected sharepointhosting.com to suite our needs, but there are many more ISPs that offer the service. Many will allow you to use the service free for 30 days before being billed.


The Future

I feel that the future of website management will be done with products like SharePoint that will allow organizations without skilled programmers or web developers to manage their documents and work collaborately.

Wednesday, January 7, 2009

Rid Yourself of Information Security Bad Habits




Improving on Your Information Security Bad Habits

First, I welcome 2009 amidst a multitude of perplexing world challenges. Second Technology is going to be more important than ever as more things are done with less people and with people trying to find more opportunities with limited time. Start the year off with better Information Security habits that will protect your physical wellbeing and database wellbeing. Adhere to the following suggestions and make measurable efforts to rid yourself of these Information Security bad habits:

Things to improve on

  • Not respecting and adhering to your employer's computer security policies.
  • Not changing your passwords with some frequency. If you have had your password for a while or if others know it, Change it!
  • Sharing your login account name and passwords with others.
  • Start using strong passwords comprising of numbers, upper & lower case letters and special keyboard characters.
  • Stop using the same password for all of your online login activities.
  • Not using or renewing the anti-virus product you use to keep receiving critical security updates to help protect your online computer activities and identity.
  • Not inspecting the content of your Childs social networking profiles. Your children can fall prey to others if they reveal information that others can use to steal from them, find them or hijack their identities.
  • Stop signing up for everything online that you receive via email. The less information you give out about yourself the less you have to worry about protecting.
  • Not backing up your data routinely. Once it is lost is gone!
  • Not respecting an entities copy write rights.

Happy New Year!

Julius Clark, MBA, CISSP, CISA

Monday, December 8, 2008

10 Essential Information Security Strategies to reduce Technology Risks for Small Business



10 Essential Information Security Strategies to reduce Technology Risks for Small Business

by

Julius Clark


  1. Consider these basic measures to secure your business' desktop/ laptop computers:
    • Install or configure a built-in software firewall product.
    • Install an antivirus program, set it up to update automatically and scan often. Installing a few malware/ spyware programs is a good idea as well.
  2. Keep up with patching for your Operating System and all installed software applications.
  3. Secure your desktop login by using a password that is difficult to be guessed or cracked with a password cracking program and don't ever share it. Changing it often (every 90 days) will offer more protection.
  4. Consider the following basic measures to secure your wireless network to protect the computers behind it lower the risk of being hacked:
    • Change the "Default Settings" on your wireless router.
    • Enable the hardware firewall features on your wireless router. This will reject anonymous requests for information sent from the internet and block unauthorized traffic.
    • Enable built-in encryption (WPA-2 recommended) on your wireless router. Follow the guidance in step 3 to create a strong passphrase that should be kept secret.
    • Disable wireless router from broadcasting its signal. This will prevent your network from showing up as a wireless access point on others computers that are in close proximity.
  5. Securely store your laptop out of site when not in use. If you can't take it with you then lock it up in your car trunk. If your vehicle doesn't have a trunk, don't attempt to cover it up under a seat just take it with you. Additionally, the data contained on your laptop is far more valuable than the hardware.
  6. Consider using encryption technology to protect your confidential data.
    • Use software that encrypts the entire laptop hard drive if you store credit card or social security numbers, health records or any other confidential/ sensitive information. A secret key will be required to decrypt the laptop's hard drive to boot it up, and the contents of the laptop can't be accessed; even the hard drive is taken out and place it into another device, the data will remain protected from unauthorized access. Note, laptop encryption protects the contents of your computer prior to start up. Encryption gets turned off once you login with secret key to decrypt or when your laptop is in sleep or suspended mode. Completely log off and shut down your laptop for encryption to be engaged again.
    • Encrypt your email communications if you transmit confidential information over the internet.
    • Use an encrypted flash drive that you have to authenticate to when accessing the files.
  7. Routinely backup your most critical data on to a flash/ thumb drive and keep it offsite. If managing offsite data regularly is not ideal, consider using an online data backup service. If any of your files are lost due to deletion, hard drive failure or if a laptop is lost/ stolen, the data can be easily restored over the internet and onto another computer once you provide the correct credentials.
  8. Setup a password to login to your mobile phone, just in case your phone is lost or stolen. This could prevent a person from accessing its contents.
  9. GPS or car Navigation units should not be preset with addresses to your business, home or locations where your children and parents are at.
  10. Implement Security Awareness practices for your business:
    • Create an information security policy that employees are expected to follow.
    • Become knowledgeable of Federal, State, Regulations and Laws pertaining to your industry regarding the safeguarding of confidential records.
    • Be on wary of individuals asking suspicious questions over the phone or in person regarding the technology your business uses. The information an attacker gains could be used to figure out a way to compromise your data/network assets.
    • Be conscious of your surroundings at airports, cyber cafes, etc. Individuals can use a social engineering technique called "shoulder surfing" to steal your user IDs and passwords. If possible, have your back facing a wall and give yourself a better view of all in front of you; consider purchasing a laptop privacy filter/ screen.
    • Shred confidential information before throwing it in the trash.
    • If you suspect that an unlawful criminal activity has occurred involving your business computers or internet activity, report it to law enforcement immediately.

Finally, if you are not computer savvy enough to implement these security strategies yourself, contact a qualified Information Security consultant.

"There is a world of difference between a certified computer technician and a certified information security professional."

Julius Clark, MBA, CISSP, CISA

Information Security Professional

Nice & Intelligent Business Solutions

www.niceandintelligent.com

Get Expert Advice!