Sponsors

Friday, July 24, 2009

Top 20 List of Most Critical Cyber Security Controls


The twenty controls were agreed upon by by cyber security experts from various Federal Government agencies.



Note: The list of controls includes fifteen that are able to be validated in an automated manner and five that must be validated manually.

Consensus Audit Guideline Controls



Critical Controls Subject to Automated Measurement and Validation:

1: Inventory of Authorized and Unauthorized Hardware.

2: Inventory of Authorized and Unauthorized Software.

3: Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers.

4: Secure Configurations of Network Devices Such as Firewalls and Routers.

5: Boundary Defense 5

6: Maintenance and Analysis of Complete Security Audit Logs

7: Application Software Security

8: Controlled Use of Administrative Privileges

9: Controlled Access Based On Need to Know

10: Continuous Vulnerability Testing and Remediation

11: Dormant Account Monitoring and Control

12: Anti‐Malware Defenses

13: Limitation and Control of Ports, Protocols and Services

14: Wireless Device Control

15: Data Leakage Protection

Additional Critical Controls (not directly supported by automated measurement and validation):

16. Secure Network Engineering

17. Red Team Exercises

18. Incident Response Capability

19. Data Recovery Capability

20. Security Skills Assessment and Training to Fill Gaps



The controls above were agreed upon by knowledgeable individuals from the Federal Government entities listed below.



Contributing Federal Groups:



  • Red team members in NSA tasked with finding ways of circumventing military cyber defenses
  • Blue team members at NSA who are often called in when military commanders find their systems have been compromised
  • US‐CERT and other non‐military incident response employees and consultants who are called upon by civilian agencies and companies to identify the most likely method by which the penetrations were accomplished
  • Military investigators who fight cyber crime
  • Cybersecurity experts at US Department of Energy laboratories and Federally Funded Research and Development Centers (FFRDCs).
  • DoD and private forensics experts who analyze computers that have been infected
  • Civilian penetration testers who test civilian government and commercial systems to find how they can be penetrated
  • Federal CIOs and CISOs who have intimate knowledge of cyber attacks
  • The Government Accountability Office (GAO)


Reference:

http://csis.org/files/media/csis/pubs/090223_cag_1_0_draft4.1.pdf

Monday, July 20, 2009

Share Files Effortlessly over the Internet with RapidShare



You ever want to share a file with friends or collaborators effortlessly without having to the person to logon or share login information?

RapidShare.com allows you to upload files then share the link with others so they can download the file to their computer.

RapidShare is a free service, but based on the file size, users of the free service must wait 30- 140 seconds before the download starts. Customers who pay for instant access to uploaded files can download immediately.

According to WikiPedia, RapidShare.com is a German owned company with its servers hosted in Switzerland. RapidShare has grown to be one of the largest File hosting service sites and the 17th most visited site on the internet.

Enjoy!

Julius





Wednesday, July 15, 2009

Merchants and Wireless Security


Merchants Have New Guidelines to protect Cardholder Data from the risks of Using Wireless Technology.

The PCI Counsel issued new PCI Wireless Guidelines This week. Some of the new changes are as follows:

1. Perform a security risk assessment of merchant's environment prior to implementation and using findings to design controls to mitigate discovered risks.

2. Mount Wireless Devices on ceiling if possible to reduce the risk of unauthorized access to the device physically disable console interface and use a tamper proof chassis.

3. The Wireless device must sit on the outer edge of the merchant's network, meaning that all wireless traffic must flow through a firewall before entering network with Card Holder Data flowing or is stored.

4. Only non-sensitive information should be allowed to go through the wireless device.

5. AES encryption is the recommended encryption method. WEP encryption makes the Vendor non-compliant to PCI Standards.

6. Businesses must conduct a wireless assessment to detect active rouge wireless devices quarterly and implement security measures to reduce risks from them. Large organizations must set up automatic scanning and have an updated incident response plan to handle rouge wireless devices when detected.

7. Change the default settings like: Administrative passwords, encryption settings, reset function, disable SNMP access if possible. Do not advertise or organization names in the SSID transmission.

8. A Wireless usage policy should be established for "explicit management approval to used wireless networks on the same network where cardholder data flows or is stored.

These guidelines will help merchants better protect cardholder data while allowing them to benefit from wireless technology.



PCI Standards Guideline can be found at:

https://www.pcisecuritystandards.org/security_standards/download.html?id=pci_dss_v1-1.pdf

Network World Article:

http://www.networkworld.com/news/2009/071509-pci-wireless-guidelines.html?page=2

Friday, June 19, 2009

Microsoft Windows Malicious Software Removal Tool


The Microsoft Windows Malicious Software Removal Tool checks computers running:

  • Windows Vista;
  • Windows XP;
  • Windows 2000;
  • Windows Server 2003;

for infections by specific, prevalent malicious software—including Blaster, Sasser, and Mydoom—and helps remove any infection found. When the detection and removal process is complete, the tool displays a report describing the outcome, including which, if any, malicious software was detected and removed.

Having an anti-virus program installed and by running this tool occasionally, will help you achieve some effective results on some prominent malicious software that attacks your computer.

This software tool deals with malware differently than anti-virus software, because it removes the most prominent malicious software from a PC that is infected and actively running on a PC. Anti-Virus software is good at the quarantine of a malicious program, but sometimes cannot remove it completely form an infected computer.


Microsoft releases an updated version of this tool on the second Tuesday of each month, and as needed to respond to security incidents. The tool is available from Microsoft Update, Windows Update and the Microsoft Download Center.

Because computers can appear to function normally when infected, Microsoft advises you to run this tool even if your computer seems to be fine. You should also use up-to-date antivirus

Download the Tool Free!

http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

Enjoy,

Julius

Friday, June 12, 2009

2008 African American Information Technology Experience

2008 African American Information Technology Experience

by: Julius Clark


This is a re-post originally featured by the BDPA Education Foundation.


I pulled these statistics from different sources to make a compelling point regarding the state of the African American Information Technology Professional in 2008. Barack Obama used the Internet to help him win the presidency like no other and has re-written the book on political campaigning.

In the U.S., 20% of all undergraduate degrees received by African Americans are Business Degrees. But in the age of information, only 3% of undergraduate degrees awarded to African Americans are in Computer Science; when technology professionals are in such a desperate demand in this country; despite the color of an individual, and despite the slowing economy.

We have a lot of work to do in influencing our children to pursue careers in technology. It can be difficult when on one end of the spectrum, Science and Technology competes with little punch against the images of athletics and entertainment, which are so dominant in the African American culture for just a small few of individuals to successfully get into.


    1. Community - African American children have made strives and the digital divide is narrowing in our community, but we need to stop boring our brightest children to death with continued basic computer literacy. They need to be taught how to solve problems with computers and the Internet.


    2. Academia/ College
      • African Americans represent 13-14% of the American Population, but only represent 3% of BS degrees awarded in Computer Science. This could change if we emphasize early to kids to use computers to solve problems.


      • Only 1% of PhD degrees are earned by African Americans this year and each year in the near future. People with the PhDs get money to research problems. The problem here is that our community has lots of problems, yet only 1% of African Americans with PhDs are qualified as researchers at universities to seek the funding to research solutions for our communities problems. This is not an efficient problem solving method.


    3. IT Professional
      • Only 3% of Information Technology jobs are held by African Americans. Hmmm... this number is the same as BS degrees awarded to African Americans.


      • African American IT professionals are making 85.9 cents to every dollar of our white computer Professionals. Last year we made 86.4 percent; we lost some ground.


      • One identified gap for the salary lag: "intangibles" -- subjective factors that determine where in the compensation range an individual falls. The building of trusted relationships that enables people to reach the higher end of the subjective range apparently hasn't strengthened in the past year and is disappointing.


      • Whites saw a 3.4% compensation increase from last year, compared with 2.7% for African Americans, the lowest increase for any ethnicity


    4. 2008 Computerworld Salary Survey - Click here to the survey


    5. Heartening Discoveries -
      • African American children are addicted to computers and the Internet and want to be challenged more. Let's not bore or ignore them.


      • When asked how satisfied they were with their decision to pursue an IT career, 89.3% of African Americans said they were satisfied or very satisfied. That's the highest percentage of support for the career path voiced by any ethnicity, including whites, at 84.5%. Hey, we love what we do!!


    6. eCommerce - In 2008 African Americans made up 11.8% of all Internet purchases. Very high numbers here and they are rising. We need to get more African American students interested in Computer Science and get some of this eCommerce money.
    7. My Final Thoughts - An Information Technology career is the best return on investment for your money and time. The satisfaction rate of African Americans in IT demonstrate our perseverance as a people in the wake of continuing disparities. I welcome the future with hopeful feelings. Let's keep it with the "Change We Need" and "From the Classroom to the Boardroom" mantras. Go BDPA Information Technology Thought Leaders!!!

      Championing the cause,
      Julius Clark, President-Elect
      BDPA Charlotte Chapter

Friday, May 29, 2009

President Obama Prioritizes Computer Security for America

How cool it is to have a President who understands technology and the risks associated with it, and what needs to be done to protect it. This is a very powerful stance and message coming from the White House, which will bring more awareness and provide better protection of our nations cyber Infrastructure.

A great day for the Information Security field!

President Obama Declares Americas' computing infrastructure "A Strategic National Asset"



FULL VIDEO (17 minutes)



Julius

Thursday, May 28, 2009

How To Pass The CISSP Exam




How To Prepare For and Pass The Certified Information Systems Security Professional (CISSP) Exam


The CISSP security certification for an IT Security Professional is a must have and it is becoming increasingly difficult to gain employment as an Information Security Professional without it. PayScale.com reports that the average salary for a person with a CISSP certification, with 1-4 years experience is $71,000.

The main focus and purpose of Information Security is to provide (CIA):
  • Confidentiality
  • Integrity
  • Accessibility 
This is known as the Security Triad.

The Security Triad (CIA) protects:
  • People
  • Processes
  • Technology


Julius Clark's Recommendation to Successfully Pass the CISSP examination

  • First, give yourself 3-6 months to prepare before you schedule to sit for the exam.
  • Read the CISSP for Dummies or the Mike Myers CISSP Certification Passport ; both of these condensed books are great and are perfect to get you started at the 50,000 ft level first!.


  • These publications are small enough to get your mind focused on the main aspects of the Common Body of Knowledge (CBK); The 10 Domains of Information Security as taken from the British Security Standard BS7799, (a.k.a, ISO/IEC 17799 and ISO/IEC 27001:2005); you can easily read through these condensed CISSP study guides within one to two weeks. Don't dive straight into the larger CISSP study books just yet!

  • Now on to some FREE CISSP instructor lead training! Go to CCCUR.org and register for a FREE account. This course is very similar to the official week long (ISC)2 training course costing over $2,500, but again this is FREE. Once registered go to: Tutorials > CISSP Tutorial > Veridon and start viewing the training videos in the following order:

    • Information Security and Risk Management;
    • Access Control;
    • Security Architecture and Design;
    • Application Security ;
    • Cryptography;
    • Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP);
    • Telecommunications and Network Security;
    • Legal, Regulations, Compliance and Ethics;
    • Operations Security;
    • Physical Security.

  • After you read through one of the books mention above and watched all of the FREE training videos on CCCUR.org, you are now ready to read through a bigger CISSP study guide, such as the Shon Harris All-in-One Study Guide;


  • Purchase the most recent version. Reading a larger CISSP study guide should be slow. Take your time and learn the security principles and theories of Information Security, because you are greatly needed by society to help protect computing systems from harm; man-made or natural.


  • As you finish each chapter read more information regarding the particular domain. You would want to download NIST (National Institute of Standards and Technology) documents that your good old tax dollars pay for. These guides contain lots of information, but they are easy to read. They will help you make sense of the material you are reading from the Shon Harris study guide and help you in your career as an Information Security professional. Most corporations use the NIST security publications as a main guide and blueprint to design their corporations IT security architecture. 






      • SP 800-12 An Introduction to Computer Security
      • SP 800-14 Generally Accepted Principles and Practices for Securing Information Technology Systems
      • SP 800-30 Risk Management
      • SP 800-34 Contingency Planning Guide for Information Technology Systems
      • SP 800-86 Guide to Integrating Forensic Techniques into Incident Response
      • SP 800-100 Information Security Handbook: A Guide for Managers
      • SP 800-115 Information Security Testing and Assessment


  • Take the tests at the end of each chapter in the book.
  • Take the Quizzes on the CCCUR.org website. This site is the BEST on the internet for FREE CISSP study and the test engine is very customizable to help you with your study and testing.

  • Study the (ISC)2 Code of Ethics. This is one of the easiest ways to get points on the CISSP exam, because you are guaranteed to be tested on them.

In addition, if you are new to the IT Security field, or have no experience and want to change your career consult with me at:


This is what I used to study for and pass the exam so study well, good luck and I will see you after you pass the exam and join the prestigious club of Certified Information Systems Security Professionals!

Enjoy!

Sincerely,

Julius Clark, CISSP





Friday, May 22, 2009

First Black Woman CEO for a Fortune 500 company



First Black Woman Named as CEO for a Fortune 500 company

I personally want to congratulate Ms. Ursula Burns for earning the Chief Executive Officer (CEO) position at Xerox, the pioneer and giant in the photo copier industry. This for me is on the same level as having elected the first Black U.S. President. Black women are too often seen as supporters of leaders in corporate America. Through hard work, Ms. Burns has shattered the glass ceiling that keeps other Black women from acquiring a corporation's top job.

Retiring CEO, Anne Mulcahy had the following praise for Ms. Burns:

"For the better part of the past decade, she has been at my side helping to turn Xerox around," Burns will join the ranks of four other Black CEOs, as well as 15 other women who sit in the CEO chair at Fortune 500 Companies.

I would like for my 12 year old daughter to learn more about women like Ursula Burns, regardless of race, because of the significance it has in building a girls' self-esteem. Additionally, it is always exciting when there is something different and there is a new hero for millions of individuals to look up to and emulate.

Ursula Burns epitomizes the BDPA creed "From the Classroom to the Boardroom".

It is also noteworthy that she did this sporting a natural African American hairstyle!

The global corporate culture can't help but keep changing and I am so glad to witness progress for women CEOs in my lifetime.

Hot Innovating Xerox Product

Xerox Corporation this year launched the world's first high-speed solid ink multifunction printer, which cuts the cost of color pages by up to 62 percent compared to traditional color lasers - without compromising print quality. Utilizing Hybrid Color Plans, customers pay only for the amount of color they use on a given page. For example, an office document with a logo and small graphic will cost the same as if it were printed in black: one penny!


Career Highlights

Company: Xerox

  • Company Assets: $18 Billion

Positions Held

  • Started as an summer Mechanical Engineering Intern in 1980.
  • Named company president in 2007

Education:

  • BS in from F Univ
  • Master's Degree in Mechanical Engineering, Columbia.

Personal:

  • Wife
  • Mother of two
  • Avid Biker




Reference:

http://www.cnbc.com/id/30884640




Thursday, May 21, 2009

LooksTooGoodToBeTrue.com


While the Internet can be a safe and convenient place to do business, scammers are out there in "cyber world" targeting unsuspecting consumers.


The Looks Too Good To Be True.com website was built to educate you, the consumer, and help prevent you from becoming a victim of an Internet fraud scheme.

Get Expert Advice!