<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>International Society of Cyber Security Professionals</title>
	<atom:link href="http://iscsp.org/feed" rel="self" type="application/rss+xml" />
	<link>http://iscsp.org</link>
	<description>Just another WordPress site</description>
	<lastBuildDate>Sun, 20 Nov 2011 19:45:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Cyber Security Defense Failures Due To A Lack Of Project Management Skills</title>
		<link>http://iscsp.org/archives/91</link>
		<comments>http://iscsp.org/archives/91#comments</comments>
		<pubDate>Wed, 24 Aug 2011 23:10:39 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CISM]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Project]]></category>
		<category><![CDATA[Joey Hernandez]]></category>
		<category><![CDATA[Project Management]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=91</guid>
		<description><![CDATA[Having performed assessments on organizations with multi-million dollar budgets and managing projects to the same, I have been able to see a trend. In the beginning I wasn’t quite sure what “it” was and I always focused on believing it &#8230; <a href="http://iscsp.org/archives/91">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Having performed assessments on organizations with multi-million dollar budgets and managing projects to the same, I have been able to see a trend. In the beginning I wasn’t quite sure what “it” was and I always focused on believing it was a lack of Policy understanding by Technical people and the lack of technical objectives from Policy writers. I realized stepping back that the problem existed outside the understanding. There continues to be failures in this area and it is no longer a finger pointing game.  For those in the industry long enough you know Cyber Security people for the most  part – are biased. They believe that anything that appears before them having a familiar stench – can be cleaned up “the same way they handled it last time!” This is a falsity, as there is never an exact duplication in dealing with Cyber Security activities.</p>
<p>So what is the fix action – Not Re-creating The Wheel:</p>
<p>Project Management has been around for a while and although Security is a process, you will achieve more success handling it in a projected manner.  There is success in structure, Fluidity is not the same as Flexibility, it is a sign of a lack of professional experience.<br />
I have seen too often smart infrastructure and system administrator types move forward on installation, upgrades, and initiatives with no direction. They don’t know there customer, they don’t know the operational impact, and they don’t have an idea where the requirement began and where it will end.</p>
<p>The reason, they have never formalized the processes. Understanding the risk, will ensure you researched all of the previous. The “Who” in who is going to perform the work is based on who knows the most about something similar – failure.  Funny thing, is the argument is always that the input required for project planning takes too long. Incorrect, recovering from an outage, handling customer complaints, saving face to external agencies &amp; reputation recovery take much more time and are overall more detrimental than stratifying efforts.</p>
<p>Handling incidents is the same. According to ENISA Incident Handling, has been refocused to Incident Management. The organization produced the latest guidance in 2011. In it, the document references frameworks, workflow, and lifecycle – interestingly enough these are commonalities in Project Management Bodies Of Knowledge.  A Security Operations Center assessed in the past would take in tickets from customers and “that ticket” became case law. By this I mean any ticket that came in with a similar feel went straight to the conclusion/recovery stage. Relating it to Project there was no real initiation, planning, execution and the only control came through a ticket management system.  The team also relied heavily on creating metric by review rather than utilizing the systems established metric capabilities.</p>
<p>Turning Cyber Security  Processes into projects will be a difficult sell to many members of a security team, but I believe the long term benefit will better help organizations in SOP creation and moving forward.</p>
<p>I would like to know of incidents where you saw success or failures using this approach.</p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/91/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security+ &amp; Certified Information Systems Security Professional CISSP Instructors needed</title>
		<link>http://iscsp.org/archives/85</link>
		<comments>http://iscsp.org/archives/85#comments</comments>
		<pubDate>Sat, 22 Jan 2011 16:20:32 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=85</guid>
		<description><![CDATA[The iSCSP is seeking Certified Professionals to instruct the curriculum and Bodies of Knowledge for both the CISSP and Security+ Certifications. iSCSP will provide the course materials to the instructors and assist in support. Instructors must have experience in and &#8230; <a href="http://iscsp.org/archives/85">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The iSCSP is seeking Certified Professionals to instruct the curriculum and Bodies of Knowledge for both the CISSP and Security+ Certifications. iSCSP will provide the course materials to the instructors and assist in support. Instructors must have experience in and must be able to convey knowledge in the following focus areas:</p>
<p>Access Control<br />
Application Development Security<br />
Assessments &amp; Audits<br />
Business Continuity and Disaster Recovery Planning<br />
Cryptography<br />
Information Security Governance and Risk Management<br />
Legal, Regulations, Investigations and Compliance<br />
Network Infrastructure<br />
Operations Security<br />
Organizational Security<br />
Physical (Environmental) Security<br />
Security Architecture and Design<br />
Systems Security<br />
Telecommunications and Network Security</p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/85/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>First Annual Cyber Warfare Summit Philippines</title>
		<link>http://iscsp.org/archives/80</link>
		<comments>http://iscsp.org/archives/80#comments</comments>
		<pubDate>Thu, 21 Oct 2010 03:48:29 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Outreach]]></category>
		<category><![CDATA[Cyber Warfare]]></category>
		<category><![CDATA[Global Knowledge PH]]></category>
		<category><![CDATA[Philippines]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=80</guid>
		<description><![CDATA[iSCSP is a proud contributor and co-sponsor of the 1st Annual Cyber Warfare Summit,  Mandaluyong City, Philippines, December 10, 2010. The increased threat to the Cyber Commons demands cyber security professionals elevate the thought process and actions taken to mitigate &#8230; <a href="http://iscsp.org/archives/80">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>iSCSP is a proud contributor and co-sponsor of the 1<sup>st</sup> Annual Cyber Warfare Summit,  Mandaluyong City, Philippines, December 10, 2010. The increased threat to the Cyber Commons demands cyber security professionals elevate the thought process and actions taken to mitigate attacks against the enterprise. The summit will provide industry professionals the tools and knowledge required to understand these threats. A few topics covered will include:</p>
<ul>
<li>Cyber Intelligence</li>
<li>Forensics Investigation Supporting Cyber Warfare Program</li>
<li>Cyber Warfare Capacity of the Philippines</li>
<li>Defensive Cyber Warfare Capability and Strategy</li>
</ul>
<p>More information and registration available @ <a href="http://www.cyberwarfaresummitph.com/">http://www.cyberwarfaresummitph.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/80/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cyber Security Training &amp; Professional Development Work Group</title>
		<link>http://iscsp.org/archives/75</link>
		<comments>http://iscsp.org/archives/75#comments</comments>
		<pubDate>Sat, 16 Oct 2010 20:28:02 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Training & Education]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=75</guid>
		<description><![CDATA[Over the past few weeks Ron Mehring an iSCSP member has been working to create the direction for the CSTPD working group.  This WG will contribute on a quarterly basis or as needed articles, commentary and guidance to the business &#8230; <a href="http://iscsp.org/archives/75">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Over the past few weeks <a href="http://www.linkedin.com/pub/ronald-mehring/2/b85/621" target="_blank">Ron Mehring</a> an iSCSP member has been working to create the direction for the CSTPD working group.  This WG will contribute on a quarterly basis or as needed articles, commentary and guidance to the business community, community leadership and other organizations requiring or requesting assistance in these particular areas. The emphasis of the working group would be discuss, develop and harmonize cyber security training practices across international boundaries. This working group will focus on the entire training and development continuum, from the beginner to the seasoned professional. Progression in this WG may generate new direction for the Cyber Security Training &amp; Professional Development Work Group.</p>
<p>We look forward to your participation and any comments regarding this effort.</p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/75/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Patriot: National High School Cyber Defense Competition</title>
		<link>http://iscsp.org/archives/35</link>
		<comments>http://iscsp.org/archives/35#comments</comments>
		<pubDate>Tue, 24 Aug 2010 00:45:27 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Outreach]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=35</guid>
		<description><![CDATA[Multiple leaders from the Cyber Security arena in the United States will be reaching out this year to support local Cyber Patriot teams/participants. &#8220;CyberPatriot is the National High School Cyber Defense Competition created by the Air Force Association (AFA) to &#8230; <a href="http://iscsp.org/archives/35">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Multiple leaders from the Cyber Security arena in the United States will be reaching out this year to support local <a href="http://www.uscyberpatriot.org/" target="_blank">Cyber Patriot</a> teams/participants.</p>
<p>&#8220;<span style="font-family: arial,verdana,helvetica,sans serif; font-size: x-small;"><span style="font-family: arial,verdana,helvetica,sans serif; font-size: x-small;"><span style="font-family: arial,verdana,helvetica,sans serif; font-size: x-small;"><em>CyberPatriot</em> is the National High School Cyber Defense Competition created by the   Air Force Association (AFA) to  							excite, educate, and motivate the  next generation of cyber  defenders and other science, technology,  engineering, and mathematics  (STEM) graduates our nation needs.&#8221; </span></span></span></p>
<p>If your team requires sponsorship or you would like to support a local team on behalf of iSCSP please contact us. For independent support of a local team: call Jessica Archer, Senior Network analyst UTSA CIAS @210-458-2128</p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/35/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>iPhone Application for Cyber Security Professionals</title>
		<link>http://iscsp.org/archives/28</link>
		<comments>http://iscsp.org/archives/28#comments</comments>
		<pubDate>Mon, 23 Aug 2010 00:23:23 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=28</guid>
		<description><![CDATA[Free Click Here The iSCSP application was built to provide you information, in conjunction with http://iscsp.org, from multiple resources covering the latest standards, developments, research, and thought pieces. Documents: In addition the iSCSP application allows you to send the documents &#8230; <a href="http://iscsp.org/archives/28">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://itunes.apple.com/us/app/iscsp/id367564039?mt=8#" target="_blank">Free Click Here</a></p>
<p>The iSCSP application was built to provide you information, in  conjunction with http://iscsp.org, from multiple resources covering the  latest standards, developments, research, and thought pieces.</p>
<p>Documents:<br />
In  addition the iSCSP application allows you to send the documents through  email with a push of a button.  Feedback has shown that Professionals  can have guidance with them at all time to reference or provide proof of  concept. We will work to keep the documents updated based on inputs  from YOU the user community. Currently the application contains  documents from ISO, NIST, DASD, ITU, CERT, ENISA and others.</p>
<p>Feeds:<br />
We  follow the best and the brightest in the industry and will stream to  you their ideas, thoughts and conversations concerning Cyber Security,  Information Security, Risk Management and Incident Management. We will  continue to add to this feed ensuring YOU get the best and most relevant  news related to Cyber Security.</p>
<p>Featured:<br />
The iSCSP  application provides Professionals with the ability to quickly access  additional resources from the areas and topics covered in both the  Documents, and Feeds area. This area provides YOU connectivity to  Professionals, Organizations, Think Tanks, Businesses, Education  Institutes, and other users. We will continue to update this area based  on relevance and user input.</p>
<p>The iSCSP application is your resource for the Bodies of Knowledge required for all Professionals.</p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/28/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A different approach</title>
		<link>http://iscsp.org/archives/16</link>
		<comments>http://iscsp.org/archives/16#comments</comments>
		<pubDate>Sat, 21 Aug 2010 22:24:24 +0000</pubDate>
		<dc:creator>Joey Hernandez</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://iscsp.org/?p=16</guid>
		<description><![CDATA[Most organizations created have agendas around individualistic intent. We do not want to follow that path. In an effort to work together internationally we continue to reach out to members and colleagues from around the globe. Our approach is to &#8230; <a href="http://iscsp.org/archives/16">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Most organizations created have agendas around individualistic intent. We do not want to follow that path. In an effort to work together internationally we continue to reach out to members and colleagues from around the globe. Our approach is to deal with the cyber threat from multiple visible angles. We are first raising awareness through relationship and partnership building with organizations such as the <a href="http://www.impact-alliance.org">International Multilateral Partnership Against Cyber Threat </a>, The <a href="http://www.isgafrica.org/blog/" target="_blank">Information Security Group of Africa</a> and <a href="https://ktn.innovateuk.org/web/cyber-security" target="_blank">The Knowledge Transfer Networks Cyber Security Group</a>. We don&#8217;t want to say we are international we want to BE international.</p>
]]></content:encoded>
			<wfw:commentRss>http://iscsp.org/archives/16/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

