Category: Cybersecurity

Systems Thinking: Part 1
Common sense tells us different problems need different solutions, having a “systematic” way of evaluating new problems can help us avoid relying too fully on our assumptions and default response. Use this introduction to systems thinking to evaluate where your problems generally land on the Cynefin Model.
Systems Thinking Part One – YouTube
ISSA hosted talk: Using the NIST Cybersecurity Framework to Align your Organization’s Risk Management Practices
Last month ISSA hosted Patrick von Schlag for a talk on Organizational Risk Management. There were difficulties with the sound and Patrick recorded this version for those who were unable to follow the original talk.
You are invited to listen to the recorded session on ISSA’s website Using the NIST Cybersecurity Framework to Align your Organization’s Risk Management Practices.
If you would like to discuss any of ideas presented in the seminar further, please bring up questions in the NCSP Mentoring Community Patrick runs on LinkedIn:
Related posts: NIST and the Art of Security Maintenance
NIST Cybersecurity Framework free webinar
ISSA and Patrick von Schlag from Deep Creek Center have teamed up to provide a free webinar on implementing NIST aimed particularly at small and medium sized businesses. Please read Patrick’s note below:
Hey all; I’m doing a free webinar with ISSA on how to effectively use the NIST Cybersecurity Framework to identify and prioritize security gaps in your organization. The links are below…hope to see you there!
FREE WEBINAR!
Join the Information Systems Security Association (ISSA) and Patrick von Schlag for this free webinar on how to use the NIST Cybersecurity Framework as a vehicle to identify, prioritize, and execute your cybersecurity risk management program, and as a roadmap to help you plan your assessments and actions.
Whether you are a small- or medium-sized business or a global enterprise, this approach can help better align cybersecurity into your overall organizational risk management program and provide a vehicle to help you build the adaptive culture you’ll need to sustain success.
December 15 @ 1:00 pm – 2:00 pm EST
Register today!
Using the NIST Cybersecurity Framework to Align your Organization’s Risk Management Practices
#cybersecurity_professionals #nistcybersecurityframework #nistcsf #nistcybersecurityawareness
Making IT Work episode 10: The Agile Mindset
If 2020 has taught us anything it is that We don’t know what we don’t know.
Welcome to the world of Agile. This year has offered the world the opportunity to learn the most important mindset lessons from Agile: listening, collaboration, progress toward solutions not fixed results.
The Agile Mindset is not limited to programming but should inform the culture of the entire business as Patrick von Schlag makes clear in this episode of Making IT Work: The Agile Mindset.
For another look at Agile please see The Great Convergence
NIST and the Art of Security Maintenance
Making IT Work: episode 9
I’ve been spending a lot of time this year working with clients beginning the long process of implementing security controls in support of the NIST Cybersecurity Framework. I’ve been feeling the need to share a few lessons learned from these early stage activities, and some implications for organizations as they progress.
- Adoption starts at the top! Organizations having the best success with the framework begin by gaining buy-in and commitment from the highest levels of the organizations; Boards of Directors and senior C-level management. Fundamentally, the value proposition of using a framework like this is in facilitating business-centered conversations, about risk, risk optimization, and investment prioritization.
Computer Security Signpost Showin - Business-side stakeholders need enough awareness of the Framework to collaborate. Ultimately the purpose of a Cyber Security Company is to enable and protect business workflows, business processes, and business information. All of these are owned by business side stakeholders; process managers, line of business managers, and customer relationship managers. These key stakeholders need to have a clear voice alongside risk and audit on how to best optimize the cost/risk/value balance and enable the organization to successfully deliver value to stakeholders. Extensive conversations between business leadership and security practitioners is absolutely essential…and these conversations must take place in business language and reflect business priorities. The NIST Framework provides the necessary language and structure to enable these conversations without devolving into technical jargon.
- An adaptive, Agile approach is necessary. Information security is necessarily always responding to new vulnerabilities, threats, risks, and issues. Security professionals benefit from adopting certain core Agile principles and practices in order to remain flexible and adaptive as the threat landscape evolves.
- The NIST Framework -really- is useful to any size organization, and adapts readily to the realities of small/medium sized businesses. Many of my customers are not huge enterprises and don’t have dozens or hundreds of personnel focused on the implementation of security practices. Many more of them, with tens or hundreds of employees, are more likely to “have a guy” who is tasked with “doing security.” Eventually one of the main benefits to using a framework like the NIST Cybersecurity Framework is to provide any-size organization with an approach to help organizations recognize that security is an organization-wide problem, that real-world constraints can and do exist, and that the most effective approach is to assess current capabilities and prioritize needs, with the goal to be establishing a functional beachhead that enables the organization to do with the most critical issues, then work using a process of continuous improvement to start iteratively chipping away at other capabilities.
As we continue to work to help organizations adopt and adapt this framework, I expect I’ll have a lot more to share. Remember, be willing to “win a little,” consolidate your gains, and do it again!
One of the resources we provide is free access to our online LinkedIn Mentoring Community, where interested professionals can ask questions, share links and information, and support one another in adoption and adaptation of the NIST CSF and various Informative References.
To gain access to the community, follow the link https://www.linkedin.com/groups/12376016/
Related posts: Agile as a Business Transformation Practice
Security+
[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]
Course Description
You will implement and monitor security on networks, applications, and operating systems, and respond to security breaches.
Course Objectives
Upon successful completion of this course, students will be able to:
- Identify the fundamental concepts of computer security.
- Identify security threats and vulnerabilities.
- Examine network security.
- Manage application, data, and host security.
- Identify access control and account management security measures.
- Manage certificates.
- Identify compliance and operational security measures.
- Manage risk.
- Manage security incidents.
- Develop a BCP and DRP.
Who Should Attend?
This course is targeted toward the information technology (IT) professional who has networking and administrative skills in Windows®-based Transmission Control Protocol/Internet Protocol (TCP/IP) networks and familiarity with other operating systems, such as Mac OS® X, Unix, or Linux, and who wants to further a career in IT by acquiring a foundational knowledge of security topics; prepare for the CompTIA Security+ Certification examination; or use Security+ as the foundation for advanced security certifications or career roles.
Course Length
5 days
Course Outline
Security Fundamentals
- The Information Security Cycle
- Information Security Controls
- Authentication Methods
- Cryptography Fundamentals
- Security Policy Fundamentals
Security Threats and Vulnerabilities
- Social Engineering
- Physical Threats and Vulnerabilities
- Network-Based Threats
- Wireless Threats and Vulnerabilities
- Software-Based Threats
Network Security
- Network Devices and Technologies
- Network Design Elements and Components
- Implement Networking Protocols
- Apply Network Security Administration Principles
- Secure Wireless Traffic
Managing Application, Data, and Host Security
- Establish Device/Host Security
- Application Security
- Data Security
- Mobile Security
Access Control, Authentication, and Account Management
- Access Control and Authentication Services
- Implement Account Management Security Controls
Managing Certificates
- Install a CA Hierarchy
- Enroll Certificates
- Secure Network Traffic by Using Certificates
- Renew Certificates
- Revoke Certificates
- Back Up and Restore Certificates and Private Keys
Compliance and Operational Security
- Physical Security
- Legal Compliance
- Security Awareness and Training
Risk Management
- Risk Analysis
- Implement Vulnerability Assessment Tools and Techniques
- Scan for Vulnerabilities
- Mitigation and Deterrent Techniques
Managing Security Incidents
- Respond to Security Incidents
- Recover from a Security Incident
Business Continuity and Disaster Recovery Planning
- Business Continuity
- Plan for Disaster Recovery
- Execute DRPs and Procedures
Mapping Course Content to the CompTIA® Security+® (Exam SY0-301) Objectives
Prerequisites
Basic Windows skills and a fundamental understanding of computer and networking concepts are required. Students can obtain this level of skill and knowledge by taking the following Element K courses: Introduction to Networks and the Internet and any one or more of the following:
- Introduction to Personal Computers: Using Windows 7
- Microsoft® Windows® 7: Level 1
CompTIA A+ and Network+ certifications, or equivalent knowledge, and six to nine months experience in networking, including experience configuring and managing TCP/IP, are strongly recommended. Students can obtain this level of skill and knowledge by taking any of the following courses:
- CompTIA® A+® Certification: A Comprehensive Approach for all 2009 Exam Objectives (Windows® 7)
- CompTIA® Network+® Certification (2009 Objectives)
Additional introductory courses or work experience in application development and programming or in network and operating system administration for any software platform or system are helpful but not required.
Exam
Students who wish to take the Security+ Certification exam must schedule and pay for the exam on their own through Pearson Vue (a Comptia testing partner).
Course Director
Patrick von Schlag
Mr. von Schlag has more than 25 years of real-world experience managing IT and business organizations. He has served as a consultant, facilitator, and instructor in support of more than 200 ITSM program deployments, with a focus on practical benefits. He holds all 11 ITIL 2011 certifications and runs an accredited learning consultancy focused on Making ITIL Work ™ in real organizations. His customer list includes The Walt Disney Company, Microsoft, Nike, Sears, US Marine Corps, US Army, US Air Force, 2nd and 5th Fleet US Navy, DISA, IRS, Federal Reserve, The Hartford, Citigroup, Amgen, Los Angeles County, Port of Long Beach, GDIT, Accenture, Serco, Deloitte, and hundreds of other market-leading companies.
[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]