<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Andy ITGuy</title><link>http://www.andyitguy.com/blog</link><description>The voice of reason in a world of FUD</description><language>en</language><lastBuildDate>Fri, 06 Nov 2009 13:31:30 PST</lastBuildDate><generator>http://wordpress.org/?v=2.8.5</generator><sy:updatePeriod xmlns:sy="http://purl.org/rss/1.0/modules/syndication/">hourly</sy:updatePeriod><sy:updateFrequency xmlns:sy="http://purl.org/rss/1.0/modules/syndication/">1</sy:updateFrequency><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/AndyItguy" type="application/rss+xml" /><feedburner:emailServiceId>AndyItguy</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Atlanta NAISG November Meeting</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/b_gkc47f04M/</link><category>NAISG</category><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Fri, 06 Nov 2009 13:31:30 PST</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=820</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p class="MsoPlainText"><strong>This month marks the one year anniversary of the Atlanta Chapter of the National Information Security Group. Come and join us as we continue to move forward and meet the needs of those seeking to secure their home and work systems. We’re a small group of passionate and committed security professionals who have a desire to share with and learn from others in the Atlanta market. Please make plans to join us!</strong></p>
<p class="MsoPlainText"><strong>When:</strong></p>
<p class="MsoPlainText">Wednesday, November 11, 2009</p>
<p class="MsoPlainText">7pm – Networking</p>
<p class="MsoPlainText">730pm – ATL NAISG Business</p>
<p class="MsoPlainText">740pm – Keynote Presentation</p>
<p class="MsoPlainText">830pm – End </p>
<p class="MsoPlainText"><strong>Where:</strong></p>
<p class="MsoPlainText">Taco Mac – Lindbergh City Center</p>
<p class="MsoPlainText">573 Main Street   <br />Atlanta, Georgia 30324</p>
<p class="MsoPlainText"><strong>What:</strong></p>
<p class="MsoPlainText">Taking Incident Response to the Next Level</p>
<p class="MsoPlainText">This exciting and interactive presentation will discuss taking security incident response, not matter where you are, to the next level. We&#8217;ll specifically use the case study of a Fortune 100 company moving from a disjointed and undocumented response plan to the establishment of a Computer Security Incident Response Team. Topics will include realistic self-assessment, developing the business case, addressing small yet vital issues, and continual improvement. </p>
<p class="MsoPlainText"><strong>Who:</strong></p>
<p class="MsoPlainText">Martin Fisher</p>
<p class="MsoPlainText">Manager-Computer Security Incident Response Team</p>
<p class="MsoPlainText">Delta Air Lines</p>
<p class="MsoPlainText">Martin Fisher currently is leading the Computer Security Incident Response Team at Delta Air Lines. His 20-year IT career includes a broad set of experiences, including working the last five years at Delta to develop enhanced security incident response. A leader focused on developing teams, Martin currently is working to create a consolidated CSIRT for the largest airline in the world.</p>
<p class="MsoPlainText"><strong>Why:</strong></p>
<p class="MsoPlainText">Atlanta has lots of User groups and technology related organizations that meet every month. So why should you attend NAISG? </p>
<ol>
<li>
<div class="MsoPlainText">Great opportunity to interact with some of Atlanta’s top security talent.</div>
</li>
<li>
<div class="MsoPlainText">Good food, conversation and networking.</div>
</li>
<li>
<div class="MsoPlainText">A focus on you and helping you in your day to day security endeavors.</div>
</li>
<li>
<div class="MsoPlainText">Relevant topics that are interesting, entertaining, informative and most of all not a vendor sales pitch.</div>
</li>
<li>
<div class="MsoPlainText">Focus on the needs of those in both operations and management.</div>
</li>
<li>
<div class="MsoPlainText">No membership fees, sales pitches, or pressure to do anything but show up and learn (having a good time is encouraged though)</div>
</li>
</ol>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=b_gkc47f04M:E4-DpWWnbs4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=b_gkc47f04M:E4-DpWWnbs4:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=b_gkc47f04M:E4-DpWWnbs4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=b_gkc47f04M:E4-DpWWnbs4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=b_gkc47f04M:E4-DpWWnbs4:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/b_gkc47f04M" height="1" width="1"/>]]></content:encoded><description>This month marks the one year anniversary of the Atlanta Chapter of the National Information Security Group. Come and join us as we continue to move forward and meet the needs of those seeking to secure their home and work systems. We’re a small group of passionate and committed security professionals who have a desire [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=820</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=820</feedburner:origLink></item><item><title>The Tale of an Unsatisfied Security Professional</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/0Ffnb2WHN4o/</link><category>dissatisfaction</category><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Thu, 05 Nov 2009 07:38:39 PST</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=819</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Note: I originally wrote this back in July of 2009 but was holding off on posting it until I landed a new position. I’ve decided to go ahead an post it, partly in response to <a href="http://preachsecurity.blogspot.com/2009/10/csi-annual-2009.html">the post Rafal Los</a> on the CSI 2009 conference this year. </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>I usually don’t blog about stories that everyone else has blogged about. I know that I really get fed up when I go through my RSS feeds and see post after post after post about some story. Take the SSN numbers being predictable story. I know I saw at least 50 different write ups on it. I guarantee you that everyone of you who read my blog saw that same story at least 10 times so why in the world would you want to see me write about it? But this time I’m going to break my own rule and write a little about a story that has made the rounds. I’m <a href="http://www.infosecleaders.com/2009/07/job-satisfaction-in-security/">talking about the survey that Mike and Lee did regarding job satisfaction.</a> Why? Because I <em><strong>was</strong></em> (note the emphasis) one of those “unsatisfied” individuals. </p>
<p>My story started a little over 2 years ago. I had just started a new job as the Senior Security Engineer for a company. I started on Monday and Tuesday I got the news that they also wanted me to be the Security Officer for the company. They needed a good deal of work in shoring up the security architecture and program. That meant that I would do less hands-on technical work than planned and spend the majority of my time trying to get the security house in order. I was elated. I had done similar work as part of my duties at my previous 3 employers and was excited at the opportunity to really build a program from the ground up. </p>
<p>One of the early concerns that I had was when the news was given to me about the change I was told that I’d have a dual reporting structure. My day to day reporting would be to the Manager of the Infrastructure group and I’d have a “dotted line” report to the CIO. That sounded reasonable especially early on as things were getting started. Then they told me that the CIO did not want me to go to him directly for anything that when he wanted me he would call me. That sounded odd at first but I figured that since he is the CIO and busy that made a little sense. I assumed that he would schedule a meeting with me in the next couple of weeks to talk about the program and hammer out some of the things that he wanted to see. A couple of weeks went by and still no meeting request. I went to my direct report manager and tried to talk with him about some of the things that needed to be talked about and got what I soon learned was his standard answer “What are the industry standards and best practices?”</p>
<p>One of the first things that I started looking at were policies and procedures. I needed to get a feel for what they said so I could better understand the overall company perspective on things. That didn’t get me too far because they were so old and outdated that they didn’t reflect much that was currently going on in practice nor did they reflect the current company and IT goals. So I set out on updating them as best I could. Since I was still new I spent a good deal of time talking with everyone I could to get a feel for how they needed to look. I still wasn’t getting anything from Management so I put them together and submitted them for review. Most of them sat for quiet some time without ever being looked at (over a year in most cases). Now I knew that I was really facing an up hill battle.</p>
<p>Things such as this continued for much of the time that I was there. I continued to do the things that I felt were necessary to build the house but with out any real help from management it was difficult to know what they really wanted and expected. I tackled PCI, internal audit findings, current practices within the various technology groups, new projects, existing projects. All of this with the goal of building cohesiveness within the security program. Things like ensuring that the server team, network team and application team were communicating regularly to ensure that the security tasks one team was doing was not being undone by another. Making sure that security got visibility into every program and that security has a voice in what was happening from an enterprise level. </p>
<p>Things were going on fairly well but I was quickly becoming unsatisfied. I felt that even though I was making progress and things were really shaping up that management really didn’t care about the program and that as long as we were keeping the auditors happy then everything was OK. When I tried to move the program “beyond the check box” I got push back. When I tried to get clarification on the direction I was taking the program I got blank stares. It was becoming evident that the only reason that they even had me there was because the auditors told them that they needed someone to shore up their program. It wasn’t a enterprise mandate (which unfortunately security rarely is). It wasn’t a Technology mandate or even a technology priority. It was an audit mandate and the technology department was audit driven. Audit reports went to the Board of Directors and therefore whatever audit wanted audit got.</p>
<p>By now I was seriously on my way to unsatisfied. When you are passionate about something and when you truly desire to do your best and you know that it’s not really making a difference because of corporate culture or management push back it’s hard to stay satisfied. It affected me beyond work. Fortunately not to the degree where it affected my family life but it did affect my blogging. You may have noticed that in the last several months my blogging has not been nearly as frequent as it had been. I was just so mentally wore out by the end of the day that I didn’t want to write about security because I was unhappy at work. </p>
<p>I thought about looking for other positions but didn’t want to give up. I still held onto a glimmer of hope that I could enable change. So I stuck with it. I was able to get a few things changed within the program that I felt would really make a difference. One of the “problems” that I saw was that I reported under the Infrastructure group. That meant that even though I had responsibilities for security in other groups they often pulled the “you don’t work in this department, you work in infrastructure” card. Then there was the resistance I got from Infrastructure at times. The “you work for me and will do things as I want” card was used often. I knew that in order to truly be effective I had to have a reporting structure outside the other departments. I needed to either report directly to the CIO or to the Director of the team that was responsible for the ancillary functions of IT. This group contained Change Management, QA and Compliance. I felt that if I could get the security program moved under that group that I would have more authority when needed. Since that group was independent of the other IT groups and due to the way it was structured it had that authority. I was able to convince the CIO to approve the move and that made a difference. </p>
<p>Unfortunately it did little to make a difference in the audit driven mentality of the whole IT program. So my dissatisfaction&#160; continued. By this time I knew it was time to move on. Unfortunately before I could start a serious job hunt the economy bit me. Things were pretty well shored up in the house and now they could tell audit that we have things in order and money is tight so we had to make some changes. But that would be OK because they had the framework in place and they would continue to work under it as they had been for the last year or so. They now knew what to do to keep audit happy from a security perspective and since I didn’t do the hands-on day to day tasks needed to run the network I was the logical one to go.</p>
<p>So now I’m no longer a unsatisfied security pro. I’m currently an unemployed one, but I’m thoroughly enjoying getting back into the swing of reading and writing about security. I’m enjoying a renewed passion for security that had been worn down somewhat. It’s refreshing and encouraging. That’s my tale. It actually has a happy ending even though the ending hasn’t been fully written yet. I’m currently riding off into the sunset and waiting to see where the sunset leads.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>To the point that Raf made in saying that the participants in the conference were “lack-luster” and lacked passion I say “I completely understand”. I think that a big portion of Information Security Professionals are just flat wore out. They are having to do more with less and getting little support from management. That really can drain the energy from you and affect how you not only do your job but also your general attitude.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=0Ffnb2WHN4o:LJC52jTKIzQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=0Ffnb2WHN4o:LJC52jTKIzQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=0Ffnb2WHN4o:LJC52jTKIzQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=0Ffnb2WHN4o:LJC52jTKIzQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=0Ffnb2WHN4o:LJC52jTKIzQ:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/0Ffnb2WHN4o" height="1" width="1"/>]]></content:encoded><description>Note: I originally wrote this back in July of 2009 but was holding off on posting it until I landed a new position. I’ve decided to go ahead an post it, partly in response to the post Rafal Los on the CSI 2009 conference this year. 
&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;-
I usually don’t blog about stories that everyone else [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=819</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">2</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=819</feedburner:origLink></item><item><title>How to deal with bug reports and vulnerability disclosures</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/NjPBjlXnm6o/</link><category>error messages</category><category>information security</category><category>vulnerabilities</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Thu, 22 Oct 2009 17:46:00 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=818</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>A few weeks ago I was looking into some online services and was checking out various offerings to see if they would meet my requirements. Of course each of these services requires you to create an account to be able to test them. Although I’m not crazy about this it’s a reality of doing things on the internet. If it’s something that I’m really not comfortable with then I will either pass on the service or use a throw away email account to do my testing with. </p>
<p>Before I go any further let me say that I am not a pen tester, vulnerability researcher or uber hacker by any means. I can and do some of the above when needed but for the most part I’m just a guy who believes strongly in doing my part to keep my little piece of the world secure. Unfortunately, the more places I go on the internet the bigger my piece of the world gets. If I’m going to use a internet based service, no matter what it is, then I expect it to meet a minimum level of various requirements and security is a big one. I also expect reasonable tech support services and a user interface that understandable and usable. </p>
<p>To vary slightly off path I want to say that I believe strongly that every insecure system, application and user out there hurts us all. It’s not just a “it’s my system and I can do what I want with it” world. When you disconnect from the internet and NEVER reconnect again then you can live your computing life that way. Until then you have a responsibility to keep your systems and applications secure and to practice “reasonable and secure” computing. If you don’t it affects way more than just you.</p>
<p>Back to my topic. So as I’m testing services I run across on that has an unusual “feature”. There are 2 “Continue” buttons at the bottom of the first page of the registration process. I’ve never seen this before and obviously am curios as to why. If you push one of the nothing happens (yes, I tested this in a secure environment) and if you press the other one you get different responses depending on whether or not you pushed the other one first.&#160; So as I’m looking into what is going on I check the page source code to see what is going on and it appears that the “second” button is supposed to be hidden and is used for debugging. Someone just forgot to “hide” it after testing.</p>
<p>After I have completed my testing and have a pretty good understanding of exactly what happens under different circumstances I compose an email and send it to 2 different contacts that I was able to find for the site. Thus the reason for this post.</p>
<p>I sent 2 emails with the relevant information. I sent them copies of the error that was displayed, how to recreate the error and information as to why having an error of this type displayed is a hackers dream. To date I have not heard back from them and the site has not changed. It still has 2 “Continue” buttons. It still displays the error when you click the buttons in the right order. So since it’s been a while and nothing has happened I decided to write about it here. Not from the perspective of disclosing the site and hoping to “force their hand” but to talk about how to deal with such issues.</p>
<p>So how should you as a company deal with something such as this? At my last job shortly after I started we got an email from a “white hat” who said he had discovered a SQLi on our site. I did a little investigating myself and confirmed that we really did have a SQLi and so I got with my apps guys and got it fixed in a matter of minutes. I wanted to reach out to the guy who reported it and tell him thanks for the heads up and let him know that we appreciate him handling it this way and not a) exploiting it b) announcing it to the world. Since I was new in the position I decided to run it by my supervisor and he would not allow me to do so. He told me to ignore the guy and hope he left us alone. I wasn’t too keen on this but followed his directive and did not contact the guy. Was this the best course of action? I’m not 100% sure but I know that I didn’t like just leaving him hanging. What if it irritated him&#160; and he came after us in other ways? What if he found other issues later and decided not to report them to us first since we ignored him? What were the implications of this? There are no hard and fast rules on something such as this. If someone says that they are a white hat and they are reporting a vulnerability or bug then chances are that they don’t care to be responded to but if they are a grey hat then this could be just the excuse they are looking for to justify their next step that is in the black hat realm. </p>
<p>Now, I’m not going to turn black hat on them and I really don’t care that they have not contacted me, but I do care that they have not fixed the problem. Because when others, who may be less amiable than me, find this they may have the skills and motivation to use this as an entry point into their network (yes they do have a “for pay” service that you pay for with your credit card) or to use it as a malware distribution point. Neither of which will benefit the company and both of which can hurt you and me. </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=NjPBjlXnm6o:kLUtS6Dt0c4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=NjPBjlXnm6o:kLUtS6Dt0c4:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=NjPBjlXnm6o:kLUtS6Dt0c4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=NjPBjlXnm6o:kLUtS6Dt0c4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=NjPBjlXnm6o:kLUtS6Dt0c4:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/NjPBjlXnm6o" height="1" width="1"/>]]></content:encoded><description>A few weeks ago I was looking into some online services and was checking out various offerings to see if they would meet my requirements. Of course each of these services requires you to create an account to be able to test them. Although I’m not crazy about this it’s a reality of doing things [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=818</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=818</feedburner:origLink></item><item><title>October Atlanta NAISG Meeting</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/veP6rO1oq1Y/</link><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Mon, 05 Oct 2009 13:03:17 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=815</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Here Ye! Hear Ye! Mark your calendars, make your plans and&#160; let nothing interfere. It’s once again time for the monthly meeting of the Atlanta chapter of the National Information Security Group. We’re back in full swing after taking a short summer break. We started things up with a bang in September with Mike Rothman presenting totally new material and now we are following it up with </p>
<p>&#160;</p>
<p align="center"><strong><font size="5" face="Kristen ITC">THE GIRLS OF ERRATA!!</font></strong></p>
<p align="center"><strong><font size="5" face="Kristen ITC"></font></strong></p>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; font-size: 10pt"><strong>Wednesday, October 14th              <br />Taco Mac Lindbergh              <br /></strong></span></p>
<p class="MsoNormal"><span style="font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; font-size: 10pt">7pm &#8211; Food, Drinks, Networking           <br />730pm &#8211; NAISG Chapter Business            <br />740pm &#8211; Keynote Presentation            <br />830pm &#8211; End            </p>
<p><strong>Case Study Analysis: /Social Networking ID Theft &#8211; Who You Gonna             <br />Call?</strong>            </p>
<p><strong>Elizabeth Wharton</strong>, VP Legal Affairs &amp; Business Development, Errata&#160; <br /> Security            </p>
<p><strong>Marisa Fagan</strong>, Security Project Manager, Errata Security            </p>
<p>More and more news stories tell of the vulnerability of sites like&#160; <br /> Facebook, Twitter and Gmail accounts to ID theft and crime. You&#8217;re not&#160; <br /> safe just because you&#8217;re cautious and follow security recommendations&#160; <br /> &#8211; what about your friends, coworkers and colleagues? Are you&#160; <br /> responsible for damages when someone hijacks your Twitter account? Is&#160; <br /> your company liable for disclosures of confidential information thanks&#160; <br /> to an employee&#8217;s unsafe e-mail practices from home? Marisa Fagan and&#160; <br /> Elizabeth Wharton will analyze and discuss recent vulnerability and&#160; <br /> breach case studies related to Facebook, Twitter, Gmail and LinkedIn -&#160; <br /> looking at what happened, prevention methods, and legal implications&#160; <br /> of the examples.            </p>
<p><strong>About our speakers:</strong>            </p>
<p>Elizabeth Wharton is an experienced transactional attorney currently&#160; <br /> serving as Vice President of Legal Affairs and Business Development&#160; <br /> for Errata Security. Ms. Wharton focuses on advising emerging&#160; <br /> companies with their business development and growth related matters.&#160; <br /> Prior to her legal career, Ms. Wharton worked in Washington, D.C. as a&#160; <br /> congressional legislative aide specializing in technology, science,&#160; <br /> education and workplace issues.            </p>
<p>Marisa Fagan currently serves as Security Project Manager for Errata&#160; <br /> Security.During her tenure with Errata Security, Ms. Fagan has&#160; <br /> successfully managed projects for a variety of large and&#160; <br /> small-to-midsized companies. She specializes in rapid development of&#160; <br /> network security tools and is recognized for her research in threat&#160; <br /> modeling and identity theft. Ms Fagan holds a BBA degree from Georgia&#160; <br />State University focused on IT Project Management and Information&#160; <br />Security.            </p>
<p><strong>SAVE THE DATE:</strong>            </p>
<p>*November NAISG-ATL Meeting &#8211; 7pm, Wednesday, November 11^th *            </p>
<p>*Keynote Speaker: *Martin Fisher, Manager, Computer Security Incident&#160; <br /> Response Team (CSIRT), Delta Air lines            </p>
<p><strong>*Follow us on Twitter:*</strong>            <br /><a href="mailto:*@**NAISG_atl">*@**NAISG_atl</a> &lt;<a href="http://twitter.com/NAISG_atl" rel="nofollow" target="_blank"><u><font color="#0066cc">http://twitter.com/NAISG_atl</font></u></a>&gt;***            <br /></span></p>
</p></div>
</p></div>
</p></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=veP6rO1oq1Y:Piuxkq228jg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=veP6rO1oq1Y:Piuxkq228jg:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=veP6rO1oq1Y:Piuxkq228jg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=veP6rO1oq1Y:Piuxkq228jg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=veP6rO1oq1Y:Piuxkq228jg:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/veP6rO1oq1Y" height="1" width="1"/>]]></content:encoded><description>Here Ye! Hear Ye! Mark your calendars, make your plans and&amp;#160; let nothing interfere. It’s once again time for the monthly meeting of the Atlanta chapter of the National Information Security Group. We’re back in full swing after taking a short summer break. We started things up with a bang in September with Mike Rothman [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=815</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=815</feedburner:origLink></item><item><title>A little about ME :)</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/yvWgddn4D8c/</link><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Thu, 17 Sep 2009 12:31:55 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=813</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>OK, so I’m a little late on posting this but I’ve been busy. A few weeks ago the guys at Anue Systems contacted me about doing a short interview and it was posted a couple of weeks ago. You can read it on <a href="http://www.anuesystems.com/blog/2009/09/09/security-pros-on-twitter-spot-andy-willingham/">their blog here</a>. Just a couple of corrections (I haven’t even told them yet b/c I’ve been too busy and it’s not a big deal) I do not live in Canada I live in Atlanta and I don’t work for a Financial Services firm any more. </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=yvWgddn4D8c:lLUxyWM6hJw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=yvWgddn4D8c:lLUxyWM6hJw:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=yvWgddn4D8c:lLUxyWM6hJw:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=yvWgddn4D8c:lLUxyWM6hJw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=yvWgddn4D8c:lLUxyWM6hJw:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/yvWgddn4D8c" height="1" width="1"/>]]></content:encoded><description>OK, so I’m a little late on posting this but I’ve been busy. A few weeks ago the guys at Anue Systems contacted me about doing a short interview and it was posted a couple of weeks ago. You can read it on their blog here. Just a couple of corrections (I haven’t even told [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=813</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=813</feedburner:origLink></item><item><title>Good things to read (if you haven’t already)</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/GuFgJgLoPzc/</link><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Tue, 01 Sep 2009 08:48:48 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=811</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Some of the blogs, articles and such that I’ve saved over the last few weeks have now been read and I wanted to share some of them with you. </p>
<p>First, over at the Security Catalyst Community there are a couple of conversations going on that I think are quiet interesting (of course I started them so I’m biased). <img src='http://www.andyitguy.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  The first one has to do with the doom and gloom mindset that is going around in some corners of InfoSec. <a href="http://www.securitycatalyst.org/forums/index.php?topic=1193.0">You can check it out and add your thoughts here</a> (registration required)</p>
<p><a href="http://www.securitycatalyst.org/forums/index.php?topic=1196.0">Next there is a conversation</a> about some simple things that we can do to simplify our lives and make our environments more secure.</p>
<p>Lori Macvittie has a good write up on Cloud Security considerations at the <a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/09/01/securing-the-other-side-of-the-cloud.aspx">F5 blog</a>. </p>
<p>Now, I haven’t read this yet but I can’t help but think that it’s good and well worth the time to go throught it. <a href="http://csrc.nist.gov/publications/drafts/ir-7621/draft-nistir-7621.pdf">NIST – Small Business Security</a></p>
<p>On a non-security note my favorite Leadership Guru, John Maxwell, has posted the first chapter to a new book online. <a href="http://johnmaxwellonleadership.com/2009/08/31/connecting-increases-your-influence-in-every-situation/">You can read it here</a>.</p>
<p>Another one that I haven’t read yet but looks promising is the new issue of <a href="http://www.mcafee.com/us/research/mcafee_security_journal/summer_2009.html">McAfee Security Journal</a>.</p>
<p>PCI Guru Michael Dahn has a good article of the usefulness of a <a href="http://itknowledgeexchange.techtarget.com/it-compliance/capability-and-maturity-model-creation-in-information-security/">Capability and Maturity Model in a security program</a>. </p>
<p>My good friend Martin Fisher has some great advice for us regarding IR and the leadership needed to have a successful program in your company. He has written 2 articles for the Security Catalyst Blog on this <a href="http://www.securitycatalyst.com/incident-response-leadership-basic-truths/">here</a> and <a href="http://www.securitycatalyst.com/succeeding-by-planning-to-fail/">here</a>.</p>
<p>I’ve got lots more reading to do so I’ll post more later. This should keep you busy for a while anyway. <img src='http://www.andyitguy.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=GuFgJgLoPzc:_hf5Ks_Xiek:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=GuFgJgLoPzc:_hf5Ks_Xiek:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=GuFgJgLoPzc:_hf5Ks_Xiek:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=GuFgJgLoPzc:_hf5Ks_Xiek:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=GuFgJgLoPzc:_hf5Ks_Xiek:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/GuFgJgLoPzc" height="1" width="1"/>]]></content:encoded><description>Some of the blogs, articles and such that I’ve saved over the last few weeks have now been read and I wanted to share some of them with you. 
First, over at the Security Catalyst Community there are a couple of conversations going on that I think are quiet interesting (of course I started them [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=811</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=811</feedburner:origLink></item><item><title>From “We’re screwed” to a little rational thinking</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/QXwyNc4kt64/</link><category>FUD</category><category>GRIRST</category><category>Rational Thinking</category><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Fri, 28 Aug 2009 11:53:01 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=810</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>My friend Martin Fisher labels it the <span style="widows: 2; text-transform: none; text-indent: 0px; border-collapse: separate; font: 16px &#39;Times New Roman&#39;; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span"><span style="line-height: 16px; font-family: verdana; font-size: 13px" class="Apple-style-span">&quot;Post Blackhat/DefCon Stress Disorder&quot;. That time of the year when it seems that everyone is bemoaning the bad shape of things in information security. Doom and gloom prevail at talks and conferences. No one has anything good to say about the state of security. I guess it’s a natural progression when we hear all of the cool, new and scary stuff that is going on. </span></span></p>
<p><span style="widows: 2; text-transform: none; text-indent: 0px; border-collapse: separate; font: 16px &#39;Times New Roman&#39;; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span"><span style="line-height: 16px; font-family: verdana; font-size: 13px" class="Apple-style-span">Not that there isn’t plenty for us to be worried about, but we have to keep our rational minds about us. We can’t just talk about what’s wrong we have to focus on what’s right and what we can do to make things better. One of the things that I noticed at the GFIRST conference this week in Atlanta is that there was plenty of “woe is me” and very little of “here’s what we can do”. Even those that did have an idea as to what we need to do didn’t have much “real meat” to give us. If you don’t have good ideas or solutions and you are just sharing info then please make sure that you have run it through the tempering process. Are things really as bad as you think or is it just because you have seen a good deal of bad stuff lately? Are we beyond repair or is your perception currently clouded? Is it “game over” or are we just at half time and we’re needing to regroup?</span></span></p>
<p><span style="widows: 2; text-transform: none; text-indent: 0px; border-collapse: separate; font: 16px &#39;Times New Roman&#39;; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span"><span style="line-height: 16px; font-family: verdana; font-size: 13px" class="Apple-style-span">These are the things that we need to think about before we get up and share information with others. Unless our goal is to engage them in the solution process then we need to really temper our thoughts. And I would venture to say that a conference is not the place to share info with the goal of engaging others in the solution. </span></span></p>
<p><span style="widows: 2; text-transform: none; text-indent: 0px; border-collapse: separate; font: 16px &#39;Times New Roman&#39;; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span"><span style="line-height: 16px; font-family: verdana; font-size: 13px" class="Apple-style-span">FUD is rampant right now and we have to slow it’s progress. We have to look at who is saying it, where they got their data, what their motive is or may be, and what are their ideas on a solution. If we can’t get decent answers to these questions then I’d think twice about putting much stock into what they are saying. Let me give you a good example. Dave DeWalt, CEO of McAfee, said that there are 20+ countries armed and ready for cyber warfare. I tweeted that and shortly after that I got a request from Brian Honan for a link or some solid data to back that up. I didn’t have anything other than Mr. DeWalts word. Brian wanted facts to back up the quote because he was thinking rationally and not buying the FUD (or possible FUD).</span></span></p>
<p><span style="widows: 2; text-transform: none; text-indent: 0px; border-collapse: separate; font: 16px &#39;Times New Roman&#39;; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span"><span style="line-height: 16px; font-family: verdana; font-size: 13px" class="Apple-style-span">I like to think that I’m a fairly rational thinker and that I don’t spread FUD and that I even put a stop to some of it. Hopefully I do. What I want to challenge you to do is also think rationally. Don’t react but plan ahead and think about what you hear and see. If there seems to be validity to it then think about possible solutions and engage others in the process. This is the kind of stuff that will gain us great strides in securing our systems and changing the way things are done. </span></span></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=QXwyNc4kt64:uaDdtD7v4zQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=QXwyNc4kt64:uaDdtD7v4zQ:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=QXwyNc4kt64:uaDdtD7v4zQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=QXwyNc4kt64:uaDdtD7v4zQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=QXwyNc4kt64:uaDdtD7v4zQ:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/QXwyNc4kt64" height="1" width="1"/>]]></content:encoded><description>My friend Martin Fisher labels it the &amp;#34;Post Blackhat/DefCon Stress Disorder&amp;#34;. That time of the year when it seems that everyone is bemoaning the bad shape of things in information security. Doom and gloom prevail at talks and conferences. No one has anything good to say about the state of security. I guess it’s a [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=810</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=810</feedburner:origLink></item><item><title>September NAISG in the ATL</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/B2-fb-tqle0/</link><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Thu, 27 Aug 2009 13:18:07 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=809</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>We’re less than two weeks away from the fall kick-off of the Atlanta NAISG speaker series. We have lots of good things in store for the rest of the year. We took the summer off to sit back and relax with less formal meetings and now we are ready to kick it into high gear. </p>
<p>We’re starting off with a bang! Atlanta’s own (he’s been here long enough to say that) Mike “Security Incite” Rothman will be presnting all NEW material. That means he’s not recycling old (yet very inciteful) material. I’ve talked with him about the presentation and I think that it’s something that we all need to hear. </p>
<p>PLEASE, PLEASE, PLEASE make plans to attend. Tell your friends! Tell your Twitter Tweeple and FaceBook friends. Announce it at work and anywhere else that there are people who want to hear more about security. They don’t have to work in security or even technology. The more non-techies we can get means that more people are learning how to do things securely and that means that Aunt Martha won’t be calling you for tech support as much.</p>
<p>Now that I’m through rambling here are the details!</p>
<p> <span style="widows: 2; text-transform: none; text-indent: 0px; border-collapse: separate; font: 16px &#39;Times New Roman&#39;; white-space: normal; orphans: 2; letter-spacing: normal; color: rgb(0,0,0); word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span"><span style="font-family: &#39;times new roman&#39;" class="Apple-style-span">
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt"><b><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">September 9, 2009 &#8212; Atlanta NAISG Meeting</span></b></p>
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt"><b><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">Taco Mac – Lindbergh (private room upstairs)</span></b></p>
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt"><b><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">7pm – Networking</span></b></p>
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt"><b><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">730pm – Presentation</span></b></p>
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt"><b><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">Keynote:</span></b><span style="font-family: &#39;Arial Narrow&#39;, sans-serif"><span class="Apple-converted-space">&#160;</span>Mike Rothman, SVP Strategy &amp; Chief Marketing Officer for eiQNetworks, Chief Blogger at Security Incite and author of the Pragmatic CSO</span></p>
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt">&#160;<b><i><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">The Pursuit of Security Happyness</span></i></b></p>
<p style="margin: 0px; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt"><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">For the most part, security professionals are a pretty grumpy lot. A good day for us is when nothing happens and we are always worrying about how we are going to die tomorrow. And it&#8217;s not getting any easier. Between bot outbreaks, audit findings, new mandates, budget cuts, and stupid users &#8211; it&#8217;s enough to put a security pro into a rubber room for a long period of time. Mike will provide a candid assessment of our self-inflicted angst and preview content from an upcoming manifesto that provides a number of techniques to do your job, without making yourself crazy.</span></p>
<p style="margin: 0in 0in 0pt; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt" class="MsoNormal"><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">Please RSVP to<span class="Apple-converted-space">&#160;</span><a style="color: blue; text-decoration: underline" href="mailto:Meetings-Atlanta@naisg.org" rel="nofollow" target="_blank" ymailto="mailto:Meetings-Atlanta@naisg.org">Meetings-Atlanta@naisg.org</a>. </span></p>
<p style="margin: 0in 0in 0pt; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt" class="MsoNormal"><span style="font-family: &#39;Arial Narrow&#39;, sans-serif"></span></p>
<p style="margin: 0in 0in 0pt; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt" class="MsoNormal"><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">Our Sponsor this month will be eIQNetworks. They will be providing appetizers and and the first round of drinks. </span></p>
<p style="margin: 0in 0in 0pt; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt" class="MsoNormal"><span style="font-family: &#39;Arial Narrow&#39;, sans-serif"></span></p>
<p style="margin: 0in 0in 0pt; font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt" class="MsoNormal"><span style="font-family: &#39;Arial Narrow&#39;, sans-serif">Hope to see many of you there!</span></p>
<p>   </span></span></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=B2-fb-tqle0:ab1ykj0oXBY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=B2-fb-tqle0:ab1ykj0oXBY:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=B2-fb-tqle0:ab1ykj0oXBY:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=B2-fb-tqle0:ab1ykj0oXBY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=B2-fb-tqle0:ab1ykj0oXBY:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/B2-fb-tqle0" height="1" width="1"/>]]></content:encoded><description>We’re less than two weeks away from the fall kick-off of the Atlanta NAISG speaker series. We have lots of good things in store for the rest of the year. We took the summer off to sit back and relax with less formal meetings and now we are ready to kick it into high gear. [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=809</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=809</feedburner:origLink></item><item><title>GFIRST Conference Summary</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/YitCwPgQeaA/</link><category>GFIRST</category><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Wed, 26 Aug 2009 21:52:28 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=808</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>OK, first let me say that the GFIRST conference was a lot of fun. I’m not 100% sure why because if you followed my <a href="http://www.twitter.com/andywillingham">Twitter</a> comments about some of the talks I wasn’t overly impressed. Yet, in spite of that I still really enjoyed myself. Here is a short summary of my 2 days there.</p>
<p>Day One   <br />The Keynote by Dave DeWalt, President and CEO of McAfee, was entertaining if nothing else. He does give a good talk, but it leaves you wondering. He had lots of great figures and talking points but nothing to back it up. What I mean was no references just “McAfee Research”. Not that I doubt what he said so much as it would be nice to see some of the data that was used to get to these numbers. </p>
<p>I sat in on 4 sessions other than the keynote and got a 50% passing score. What I mean was that 2 of them were pretty good and the other two…. One was OK except that the information was dated and at least to me a bit elementary. Maybe part of that is because I’m cynical and hang around with too many really smart people who keep me in the loop better than many others. The other talk was just painful. To the point where it was all I could do to not walk out (as I’ve been known to do). I just kept holding out hope that the guy would pull it together and I’d discover that Web 2.0 wasn’t all messed up, but he didn’t. Actually the only thing that the talk had to do with Web 2.0 was the fact that the title contained the word Web 2.0</p>
<p>Day Two   <br />Today was a better day. I was only able to sit in on two sessions and both of them were pretty good. No complaints from either. One was a “Tool Talk” where the presenter basically gave a list of IR tools and talked a little about them and what they were best suited for. The other was a talk on the evolving strategies around cyber security. The presenter was Amit Yoran of NetWitness and he has some interesting takes on the state of the industry and what we need to do to make it better. The one phrase that stuck with me was basically “We’ve already lost and it’s going to get worse before it get’s better”. Not exactly a pep talk, but when you’re getting your butt kicked sometime a reality check is what is needed more than a pep talk.</p>
<p>The folks that put on GFIRST did a first class job in organizing and executing. I wish I could go back for Thursday and Friday but I need to get cracking on my honey do list.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=YitCwPgQeaA:4mUKR3rBuqA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=YitCwPgQeaA:4mUKR3rBuqA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=YitCwPgQeaA:4mUKR3rBuqA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=YitCwPgQeaA:4mUKR3rBuqA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=YitCwPgQeaA:4mUKR3rBuqA:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/YitCwPgQeaA" height="1" width="1"/>]]></content:encoded><description>OK, first let me say that the GFIRST conference was a lot of fun. I’m not 100% sure why because if you followed my Twitter comments about some of the talks I wasn’t overly impressed. Yet, in spite of that I still really enjoyed myself. Here is a short summary of my 2 days there.
Day [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=808</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">0</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=808</feedburner:origLink></item><item><title>HISP Training</title><link>http://feedproxy.google.com/~r/AndyItguy/~3/7UFilFl0nR4/</link><category>information security</category><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andyitguy</dc:creator><pubDate>Wed, 26 Aug 2009 16:24:02 PDT</pubDate><guid isPermaLink="false">http://www.andyitguy.com/blog/?p=807</guid><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>If you are not familiar with <a href="http://www.hispi.org">HISPI</a> (Holistic Information Security Practitioner Institute) you may want to check it out. I just recently learned about them and was very fortunate to be able to attend the training class last week. I first found about about <a href="http://www.efortresses.com">eFortresses</a> when they started following me on Twitter. When I receive notice that I have a new follower I take a look at their profile and see if they are someone that I’d be interested in following also. I noticed that eFortresses was here in Atlanta so I checked out their web site and liked what I saw. Their&#160; philosophy about security is very similar to mine. So I decided to send them an email to try and schedule a meeting over coffee. One thing lead to another and I ended up attending the training last minute.</p>
<p>The week was quiet good. Not only did I get to meet some new friends I also was “fire hosed” with information. Not in a bad way. There is a lot of information to cover in a week but the instructor, Taiye Lambo, did a great job in keeping it relevant and interesting. It was honestly one of the few instructor led classes that i’ve taken where I didn’t have to fight sleep. The HISP is a fairly new cert, I think it started in 2005, and is meant to compliment others such as the CISSP, CISA, CISM. It focuses on using the ISO 27000 series as a basis for your security program. They encourage the implementation of a Information Security Management System and the course is meant to help you attain that goal. </p>
<p>The certification also requires CPE’s yearly so there is a “keeping fresh” component to it as well. It’s not a “pass the test and put initials after your name” program. You have to keep it up with CPE’s to maintain certification. Of course it’s not the letters or the certification that holds the value it’s the incentive to stay current and relevant that gives it value. It’s also the focus on a structured program that will help you implement and maintain a secure environment that will meet the varying and moving requirements of many different regulations and laws.</p>
<p>Check it out and even if the class or cert aren’t for you I’d encourage to dialogue with the guys and eFortresses. They are a great bunch and will add value to your day.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/AndyItguy?a=7UFilFl0nR4:3YTRdKzw60w:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=7UFilFl0nR4:3YTRdKzw60w:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=7UFilFl0nR4:3YTRdKzw60w:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/AndyItguy?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/AndyItguy?a=7UFilFl0nR4:3YTRdKzw60w:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/AndyItguy?i=7UFilFl0nR4:3YTRdKzw60w:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AndyItguy/~4/7UFilFl0nR4" height="1" width="1"/>]]></content:encoded><description>If you are not familiar with HISPI (Holistic Information Security Practitioner Institute) you may want to check it out. I just recently learned about them and was very fortunate to be able to attend the training class last week. I first found about about eFortresses when they started following me on Twitter. When I receive [...]</description><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.andyitguy.com/blog/?feed=rss2&amp;p=807</wfw:commentRss><slash:comments xmlns:slash="http://purl.org/rss/1.0/modules/slash/">1</slash:comments><feedburner:origLink>http://www.andyitguy.com/blog/?p=807</feedburner:origLink></item></channel></rss>
