<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Sword &amp; Shield Enterprise Security, Inc.</title>
	
	<link>http://www.swordshield.com</link>
	<description>Your Partner for a Secure Future</description>
	<lastBuildDate>Thu, 09 Feb 2012 15:51:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SwordShieldEnterpriseSecurityInc" /><feedburner:info uri="swordshieldenterprisesecurityinc" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>PCI Compliance Expert to Address Petroleum Retail Industry</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/j5keQFqsgRc/</link>
		<comments>http://www.swordshield.com/2012/01/20/pci-compliance-expert-to-address-petroleum-retail-industry/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 15:09:30 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=4064</guid>
		<description><![CDATA[Sword &#38; Shield Principal Risk &#38; Compliance Consultant Penny Walton will be a keynote luncheon speaker at the Petroleum Convenience Alliance for Technology Standards (PCATS) annual conference Jan. 23-26 in Tucson, AZ. Walton will address the issues surrounding PCI compliance in the convenience store and petroleum retail industries at Monday&#8217;s session. PCATS is  a non-profit organization devoted to [...]]]></description>
			<content:encoded><![CDATA[<p>Sword &amp; Shield Principal Risk &amp; Compliance Consultant Penny Walton will be a keynote luncheon speaker at the <a href="http://www.pcats.org">Petroleum Convenience Alliance for Technology Standards</a> (PCATS) annual conference Jan. 23-26 in Tucson, AZ.<img class="alignright" title="PCATS" src="http://www.pcats.org/sites/all/themes/theme165/logo.png" alt="" width="94" height="96" /></p>
<p>Walton will address the issues surrounding PCI compliance in the convenience store and petroleum retail industries at Monday&#8217;s session.</p>
<p>PCATS is  a non-profit organization devoted to the development, maintenance and implementation of standards, education and best practices for the convenience store and petroleum retail segments.</p>
<p>Walton has more than 25 years experience in the technical field in roles such as software engineering, database design &amp; administration, network engineering, enterprise information security management, risk management and compliance oversight.   Additionally, she has extensive business experience in utilizing technology to increase the bottom line and reduce risks while controlling cost.   She possesses many technical certifications including the CRISC (Certified in Risk &amp; Information System Controls), CISM (Certified Information System Manager), CISSP (Certified Information Systems Security Professional), CEH (Certified Ethical Hacker), CIW (Certified Internet Web Master), PCI – QSA (Payment Card Industry Qualified Security Assessor) and HiTrust Security Assessor (Health Information Trust Alliance).</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=j5keQFqsgRc:PTs4BF_Mjik:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=j5keQFqsgRc:PTs4BF_Mjik:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=j5keQFqsgRc:PTs4BF_Mjik:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=j5keQFqsgRc:PTs4BF_Mjik:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=j5keQFqsgRc:PTs4BF_Mjik:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=j5keQFqsgRc:PTs4BF_Mjik:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=j5keQFqsgRc:PTs4BF_Mjik:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=j5keQFqsgRc:PTs4BF_Mjik:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=j5keQFqsgRc:PTs4BF_Mjik:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=j5keQFqsgRc:PTs4BF_Mjik:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/j5keQFqsgRc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2012/01/20/pci-compliance-expert-to-address-petroleum-retail-industry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2012/01/20/pci-compliance-expert-to-address-petroleum-retail-industry/</feedburner:origLink></item>
		<item>
		<title>Protecting Your Online Accounts in the Wake of a Hack</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/cR6kUl6lTHc/</link>
		<comments>http://www.swordshield.com/2012/01/17/protecting-your-online-accounts-in-the-wake-of-a-hack/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 15:17:44 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Videos]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=4055</guid>
		<description><![CDATA[You&#8217;re a Zappos customer and you&#8217;ve just learned your personal information might have been stolen. What do you do? Sword &#38; Shield Director of Computer Forensics and Security Assessments Bill Dean says to change your password&#8230; NOW! Dean gave this advice and more in his conversation with WVLT on Monday:  ]]></description>
			<content:encoded><![CDATA[<p>You&#8217;re a Zappos customer and you&#8217;ve just learned your personal information might have been stolen.</p>
<p>What do you do?</p>
<p>Sword &amp; Shield Director of Computer Forensics and Security Assessments Bill Dean says to change your password&#8230; NOW!</p>
<p>Dean gave this advice and more in his conversation with <a href="http://www.volunteertv.com/home/headlines/How_to_protect_yourself_from_online_hackers_137458313.html">WVLT</a> on Monday:</p>
<p> <br />
<script type="text/javascript" src="http://ww2.volunteertv.com/global/video/videoplayer.js?rnd=168955;hostDomain=ww2.volunteertv.com;playerWidth=300;playerHeight=257;isShowIcon=true;clipId=6645065;flvUri=;partnerclipid=;adTag=News;advertisingZone=;enableAds=true;landingPage=;islandingPageoverride=false;playerType=MINI_EMBEDDEDscript;controlsType=overlay"></script></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=cR6kUl6lTHc:igE4hNHLPmM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=cR6kUl6lTHc:igE4hNHLPmM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=cR6kUl6lTHc:igE4hNHLPmM:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=cR6kUl6lTHc:igE4hNHLPmM:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=cR6kUl6lTHc:igE4hNHLPmM:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=cR6kUl6lTHc:igE4hNHLPmM:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=cR6kUl6lTHc:igE4hNHLPmM:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=cR6kUl6lTHc:igE4hNHLPmM:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=cR6kUl6lTHc:igE4hNHLPmM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=cR6kUl6lTHc:igE4hNHLPmM:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/cR6kUl6lTHc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2012/01/17/protecting-your-online-accounts-in-the-wake-of-a-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2012/01/17/protecting-your-online-accounts-in-the-wake-of-a-hack/</feedburner:origLink></item>
		<item>
		<title>Attorneys: Be Aware When Reviewing Emails in Outlook</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/y9PJI8gD32Y/</link>
		<comments>http://www.swordshield.com/2012/01/10/reviewing-emails-outlook/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 15:03:27 +0000</pubDate>
		<dc:creator>Bill Dean</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=4023</guid>
		<description><![CDATA[I am well aware that the use of Microsoft Outlook to review email is a perceivably convenient and low cost method to review small volumes of email. However, this method is laced with potential issues that just aren&#8217;t worth the risks &#8211; and there are risks. This article will address some of these risks to [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_3948" class="wp-caption alignright" style="width: 168px"><a href="http://www.swordshield.com/images/DSC24431-cropped-websize.jpg"><img class=" wp-image-3948  " title="Bill Dean" src="http://www.swordshield.com/images/DSC24431-cropped-websize.jpg" alt="Bill Dean" width="158" height="143" /></a><p class="wp-caption-text">Bill Dean, Director of Computer Forensics</p></div>
<p>I am well aware that the use of Microsoft Outlook to review email is a perceivably convenient and low cost method to review small volumes of email. However, this method is laced with potential issues that just aren&#8217;t worth the risks &#8211; and there are risks. This article will address some of these risks to hopefully encourage the use of better technology to review email, or at least educate you enough to understand the risks.</p>
<p>So your client produced his or her email for you to review in a PST format (Microsoft Outlook Email Database). You are already proficient in the use of Microsoft Outlook as it likely already dictates much of your day. Either you already know how to attach this file to Outlook or your &#8220;friendly&#8221; IT staff will do it for you. You have the email loaded and you are ready to begin, but before you start, let&#8217;s talk about keyword searching.</p>
<p>Google has been a great asset to our culture in many ways. For the litigation field, it has inadvertently educated you how to perform<a href="http://www.internettutorials.net/boolean.asp"> Boolean</a> searches. When you search Google for &#8220;Trade secret theft&#8221; and &#8220;Case Law&#8221; in the same query, you have performed a powerful Boolean search. However, Boolean search features such as this are not as intuitive in Microsoft Outlook and require extensive effort to execute. Difficulty performing Boolean searches is the good news. The bad news is that Microsoft Outlook, by default, will not search the contents of attachments for the keywords. Your searches will only address the email fields and the contents of an email message, which could potentially omit responsive information. We will visit the danger of attachments later in this article.</p>
<p>The read receipt option on sent emails presents another concern. If an unread email you are reviewing has the read receipt option set, your review of that email could inadvertently send a message to the sender that the email has been read. Consider the implications for that for a moment. There is one instance in which the custodian was deceased and his widow received a read receipt &#8220;from beyond the grave&#8221;.</p>
<p><span id="more-4023"></span>There are some instances in which the metadata aspects of an email are important. These details could include whether the email had been read or the Outlook folder structure in which the email existed. Examples that we have encountered amplify the significance of whether or not a critical email had been read and the archive location of where an email existed. Reviewing and modifying the metadata of these emails could alter critically important information.</p>
<p> If you are working from the PST provided by your client and simply &#8220;deleting&#8221; the emails that are not responsive, they are not gone. If that PST is provided to opposing counsel, it may still contain those emails unintended for production. Email databases such as PSTs work the same way that computer hard drives work in that the deletion of the email does not mean the email is gone. This even applies to the infamous &#8220;double-delete&#8221;. Leveraging computer forensics methods, these deleted emails are potentially recoverable unless extra efforts are taken to ensure their destruction.</p>
<p>Las<a href="http://www.swordshield.com/images/Forensic-Discoveries.jpg"><img class="alignleft  wp-image-1849" title="Forensic Discoveries" src="http://www.swordshield.com/images/Forensic-Discoveries-350x106.jpg" alt="" width="224" height="68" /></a>tly, I want to cover the risk to your computer and the computer network of your law firm. I serve in various roles as an &#8220;expert&#8221;. These roles include eDiscovery expert, computer forensics expert and incident response expert. I know what you are thinking, &#8220;spread a little thing aren&#8217;t ya?&#8221; Not really, each of these disciplines is based on the same objective, handling large volumes of information to determine what is important to the objective at hand. A large majority of today&#8217;s threats to computers and computer networks are introduced via hyperlinks and attachments that are sent via email. The computer security term for this type of attack is &#8220;<a href="http://en.wikipedia.org/wiki/Phishing" shape="rect" target="_blank">phishing</a>&#8220;, and it is very effective. These malicious hyperlinks and attachments are designed to infect computers and networks with malware that both disrupt computer networks and permit unauthorized remote access to the attackers.</p>
<p>Please understand that on average, your anti-virus software will be successful in stopping a whopping 20 percent of these attacks. When reviewing email with Outlook, you will be susceptible to these attacks that were sent to your client via email. To make matters worse, you don&#8217;t even have to follow the link or open the attachment in some situations. Depending on system configuration and patch level, the email simply being rendered in the auto-preview pane can download malicious software to your computer.</p>
<p>The solution to these issues is simple; use technology designed for the review of electronic information. If it isn&#8217;t clear by now, Microsoft Outlook was not designed to for legal review of email. For small amounts of email that are being reviewed by a single attorney and features such as bates numbering and redacting are not required, I recommend <a href="http://www.avantstar.com/metro/visit" shape="rect" target="_blank">Avantstar&#8217;s Quickview Plus</a>. This software is not exactly stellar for search functionality, but handles the review of hundreds of filetypes and will not alter any metadata (read only). They offer a 30-day free trial and the software price is only $49.99. Please understand that this software is adequate for review only, producing the information can be challenging if large volumes of information are involved. For email review that provides more advanced functionality such as multiple reviewers, advanced searching, data analytics, on the fly redaction and embedded production capabilities, choose a more advanced review platform. For assistance in determining the technology that is best suited for your situation, please <a href="http://www.swordshield.com/contact/" target="_blank">contact us</a>. Given adequate advice, the <a href="http://www.swordshield.com/2010/09/01/ediscovery-someone-has-to-say-it/" shape="rect" target="_blank">costs</a> will be lower than you anticipate.</p>
<p>On the surface, Microsoft Outlook appears to be a low cost solution to review email in various matters. However, you should be well aware of the issues that accompany this decision: inadequate searching capabilities, the altering of metadata, read receipts, the potential recovery of deleted emails from productions and the inherent computer compromise issues. When considering the facts, it is strongly suggested that you choose a review platform that is designed for your needs.</p>
<p><em>Bill Dean is the Director of <a href="http://www.swordshield.com/services/forensics-ediscovery/" target="_blank">Computer Forensics</a> for Sword &amp; Shield Enterprise Security. Dean has more than 15 years of experience in the technical field in roles such as programmer, systems support, enterprise systems design and engineering, virtualization, digital forensics, and information security. Dean is a frequent speaker and published author on the topics of computer security, digital forensics and electronic discovery for numerous legal and technical associations. Follow him on <a href="https://twitter.com/#!/BillDeanCCE" target="_blank">Twitter</a>.</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=y9PJI8gD32Y:dmlmapfn6I8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=y9PJI8gD32Y:dmlmapfn6I8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=y9PJI8gD32Y:dmlmapfn6I8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=y9PJI8gD32Y:dmlmapfn6I8:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=y9PJI8gD32Y:dmlmapfn6I8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=y9PJI8gD32Y:dmlmapfn6I8:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=y9PJI8gD32Y:dmlmapfn6I8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=y9PJI8gD32Y:dmlmapfn6I8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=y9PJI8gD32Y:dmlmapfn6I8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=y9PJI8gD32Y:dmlmapfn6I8:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/y9PJI8gD32Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2012/01/10/reviewing-emails-outlook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2012/01/10/reviewing-emails-outlook/</feedburner:origLink></item>
		<item>
		<title>Information Security: There’s Not an App for That</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/IOnsMxXfqfM/</link>
		<comments>http://www.swordshield.com/2012/01/04/information-security-theres-not-an-app-for-that/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 15:38:14 +0000</pubDate>
		<dc:creator>Stephen Haywood</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[app for that]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[vulnerability scanners]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3989</guid>
		<description><![CDATA[Vulnerability assessments and exploitation, like so many other areas of technology, have progressed from being understood by a few elite practitioners to being automated for the masses. Each day information security professionals are releasing new software or improving on existing software to make identifying and exploiting network vulnerabilities easier. Unfortunately, these automated tools have produced a [...]]]></description>
			<content:encoded><![CDATA[<p>Vulnerability assessments and exploitation, like so many other areas of technology, have progressed from being understood by a few elite practitioners to being automated for the masses.</p>
<p>Each day information security professionals are releasing new software or improving on existing software to make identifying and exploiting network vulnerabilities easier. Unfortunately, these automated tools have produced a &#8220;there&#8217;s an app for that&#8221; attitude toward information security. Many business owners and managers believe that an automated tool can determine if  their network is secure, which is ridiculous. Information security encompasses not only vulnerability scanning and exploitation but risk management, user management, and other business processes. No automated tool can identify vulnerabilities in business processes &#8211; only a qualified information security professional can do that.</p>
<p>Vulnerability scanners are designed to identify specific issues in network services, operating systems, web applications and software but cannot identify vulnerabilities in the underlying vulnerability management and configuration management processes. Exploitation frameworks, like Metasploit and Core Impact, can exploit a machine but have no ability to determine the value of the data on the compromised machine or the affect the loss of that data would have on the business. In other words when it comes to information security there is not an app for that.</p>
<h3><span id="more-3989"></span>What Should an Information Security Assessment Look Like?</h3>
<p>Many IT service companies use automated tools to identify and exploit network vulnerabilities, and then provide a report that is nothing more than a rewording of the output from the tools. In contrast, a thorough information security assessment will include automated vulnerability scanning but will go further and identify the root causes of the vulnerabilities, which typically include:  ineffective access controls, ineffective security update management, and poor configuration management. A thorough assessment will also include exploitation but will again go further and identify the types and value of the data accessible on exploited machines. In other words, a proper information security assessment identifies vulnerabilities in and recommends changes to business processes. It attempts to identify the sickness and not only the symptoms.  </p>
<h3>Who Should Perform an Information Security Assessment?</h3>
<p>Information security assessments should only be performed by qualified information security professionals. Unfortunately, the &#8220;there&#8217;s an app for that&#8221; attitude, the constant push by certification bodies to certify more people, and the prevalence of automated tools make it easy for anyone to hold themselves out as an information security professional. A true professional is identified not only by his or her certifications, but by his or her body of work as well: what contributions has she made to the information security community or at what conferences has he spoken? These tell the true story of an information security professional&#8217;s abilities.</p>
<h3>Final Thoughts</h3>
<p>Whether a business chooses to keep its information security program completely in house or outsource portions of the program, it must recognize that information security is a complex problem and can only be solved by competent security professionals providing thorough information security assessments. When it comes to information security there is not an app for that.</p>
<p><em>Stephen B. Haywood is a principal security analyst for Sword &amp; Shield Enterprise Security where he is active in professional and technical security services for government and commercial clientele. He is skilled at security design and programming secure applications and is experienced in working all aspects of the system security life cycle from planning and design to implementation and testing.  His blog is <a href="http://averagesecurityguy.info/">http://averagesecurityguy.info/</a>. Follow him on Twitter <a href="http://twitter.com/#!/averagesecguy">@averagesecguy</a>.</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=IOnsMxXfqfM:5VA9wQWsmjo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=IOnsMxXfqfM:5VA9wQWsmjo:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=IOnsMxXfqfM:5VA9wQWsmjo:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=IOnsMxXfqfM:5VA9wQWsmjo:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=IOnsMxXfqfM:5VA9wQWsmjo:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=IOnsMxXfqfM:5VA9wQWsmjo:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=IOnsMxXfqfM:5VA9wQWsmjo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=IOnsMxXfqfM:5VA9wQWsmjo:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=IOnsMxXfqfM:5VA9wQWsmjo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=IOnsMxXfqfM:5VA9wQWsmjo:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/IOnsMxXfqfM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2012/01/04/information-security-theres-not-an-app-for-that/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2012/01/04/information-security-theres-not-an-app-for-that/</feedburner:origLink></item>
		<item>
		<title>Join Us For a Webinar with our New Partner: Prism Microsystems</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/U5AQuo2gUis/</link>
		<comments>http://www.swordshield.com/2011/12/14/join-us-for-a-webinar-with-our-new-partner-prism-microsystems/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 16:10:34 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3972</guid>
		<description><![CDATA[Sword &#38; Shield will host a webinar Thursday, Dec. 15 at 2 p.m. EST with its new partner, Prism Microsystems, to feature EventTracker, a comprehensive security information and event management (SIEM). EventTracker combines log consolidation and log management, real-time threat monitoring and behavioral correlation, incident management with forensic analysis, regulatory compliance and reporting, monitoring of [...]]]></description>
			<content:encoded><![CDATA[<p>Sword &amp; Shield will host a <a href="https://www2.gotomeeting.com/register/334465178">webinar</a> Thursday, Dec. 15 at 2 p.m. EST with its new partner, Prism Microsystems, to featu<a href="http://www.eventtracker.com/"><img class="alignright" title="EventTracker" src="http://www.eventtracker.com/wp-content/header-images/ET-Logo.jpg" alt="EventTracker" width="212" height="49" /></a>re <a href="http://www.eventtracker.com/">EventTracker</a>, a comprehensive security information and event management (SIEM).</p>
<p>EventTracker combines log consolidation and log management, real-time threat monitoring and behavioral correlation, incident management with forensic analysis, regulatory compliance and reporting, monitoring of file integrity and USB devices and performs system change audits and management with automatic remediation.</p>
<p><a href="https://www2.gotomeeting.com/register/334465178">Attend</a> the webinar and see EventTracker in action. Participants are also registered to win a Kindle Fire.</p>
<p>Prism CEO A.N. Ananth will host the event and will demonstrate EventTracker&#8217;s real-time log analysis and automated response to:</p>
<ul>
<li>Network Attacks</li>
<li>Insider Threats</li>
<li>Security Policy Violations</li>
<li>Unauthorized Application Useage</li>
<li>Managing USB Storate Devices</li>
</ul>
<p>If you&#8217;re an IT professional, financial executive or business manager with responsibility for regulatory compliance, risk management or technology investments, please click <a href="https://www2.gotomeeting.com/register/334465178">here</a> to register.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=U5AQuo2gUis:L6CYU4MpiSI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=U5AQuo2gUis:L6CYU4MpiSI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=U5AQuo2gUis:L6CYU4MpiSI:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=U5AQuo2gUis:L6CYU4MpiSI:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=U5AQuo2gUis:L6CYU4MpiSI:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=U5AQuo2gUis:L6CYU4MpiSI:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=U5AQuo2gUis:L6CYU4MpiSI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=U5AQuo2gUis:L6CYU4MpiSI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=U5AQuo2gUis:L6CYU4MpiSI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=U5AQuo2gUis:L6CYU4MpiSI:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/U5AQuo2gUis" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2011/12/14/join-us-for-a-webinar-with-our-new-partner-prism-microsystems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2011/12/14/join-us-for-a-webinar-with-our-new-partner-prism-microsystems/</feedburner:origLink></item>
		<item>
		<title>Join Sword &amp; Shield and Barracuda for Lunch</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/xXMylCdtw3o/</link>
		<comments>http://www.swordshield.com/2011/11/04/join-sword-shield-and-barracuda-for-lunch/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 14:32:01 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3930</guid>
		<description><![CDATA[Sword &#38; Shield and our vendor partner, Barracuda Networks will host a Lunch N&#8217; Learn Thursday, Nov. 10 at Ruth&#8217;s Chris Steak House in downtown Knoxville to address the latest trends in content security, data discovery and protection and application delivery solutions to improve your company’s productivity. Bill Dean, Sword &#38; Shield&#8217;s director of computer forensics, will speak about the importance [...]]]></description>
			<content:encoded><![CDATA[<p>Sword &amp; Shield and our vendor partner, <a href="https://www.barracudanetworks.com/ns/news_and_events/Seminar/Knoxville1110/index.html">Barracuda Networks</a> will host a Lunch N&#8217; Learn Thursday, Nov. 10 at <a href="http://www.ruthschris.com/">Ruth&#8217;s Chris Steak House</a> in downtown Knoxville to address the latest <a rel="attachment wp-att-2144" href="http://www.swordshield.com/2010/03/17/join-sword-shield-and-barracuda-for-lunch-in-kingsport/barracuda_logo/"><img class="alignright size-full wp-image-2144" title="barracuda_logo" src="http://www.swordshield.com/images/barracuda_logo.png" alt="" width="234" height="67" /></a>trends in content security, data discovery and protection and application delivery solutions to improve your company’s productivity.</p>
<p>Bill Dean, Sword &amp; Shield&#8217;s director of computer forensics, will speak about the importance of eDiscovery.  Participants will also learn how to streamline backup strategies by eliminating removable media and how to achieve massive storage reductions by using data deduplication technology.  Whether it’s recovering from a single or lost file, or a hurricane-damaged building,  backups can be simplified and provide quick data recovery.</p>
<p>A Barracuda representative will discuss the Baracuda product line and how it can benefit your company by archiving emails for compliance readiness and how the operational efficiency of your email server can be improved by offloading email messages.  Learn how users can archive calendar items, contacts and tasks from Microsoft Exchange and other email servers, and how to eliminate the need for PST file storage.</p>
<p><strong><a href="https://www.barracudanetworks.com/ns/news_and_events/Seminar/Knoxville1110/index.html">Click Here to For More Details and to Register</a></strong></p>
<p><span id="more-3930"></span>Dean has more than 14 years of experience in the technical field in roles such as programmer, systems support, enterprise systems design and engineering, virtualization, digital forensics, and information security.  In 2005, he was recognized as the primary architect for an Intel virtualization/server consolidation project and was awarded <em>Network World’s</em> “Enterprise All Star” and <em>InfoWorld’s</em>&#8220;Top 100 Projects”. Since that time, Dean has focused his career on the specialties of systems security, electronic discovery, digital forensics, and incident response. He served as the technical expert and provided federal court testimony in the 7th largest eDiscovery case in 2007.  He is a Certified Penetration Testing Specialist, Certified Computer Examiner, GIAC Certified Incident Handler (GCIH), a GIAC Certified Forensic Analyst (GCFA), AccessData Certified Examiner, and an active member of the International Society for Forensic Computer Examiners.</p>
<p><a href="http://www.swordshield.com/services/forensics-ediscovery/">Sword &amp; Shield’s forensics/eDiscovery</a>consulting practice is a full service, one-stop litigation support technology provider, offering a full spectrum of electronic discovery and forensic services.  They understand and respect the chain of custody rules, the rules of evidence and proper and well-accepted forensic techniques that produce findings that are admissible in court.  Sword &amp; Shield partners with law firms, corporate legal department and small- to medium-sized businesses to offer technology solutions at each stage of the eDiscovery or forensics investigation process: electronic data collection, restoration, profiling, culling, reviewing and reporting.<strong> </strong></p>
<p><strong></strong></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=xXMylCdtw3o:Xc_0g8Mvlks:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=xXMylCdtw3o:Xc_0g8Mvlks:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=xXMylCdtw3o:Xc_0g8Mvlks:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=xXMylCdtw3o:Xc_0g8Mvlks:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=xXMylCdtw3o:Xc_0g8Mvlks:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=xXMylCdtw3o:Xc_0g8Mvlks:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=xXMylCdtw3o:Xc_0g8Mvlks:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=xXMylCdtw3o:Xc_0g8Mvlks:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=xXMylCdtw3o:Xc_0g8Mvlks:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=xXMylCdtw3o:Xc_0g8Mvlks:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/xXMylCdtw3o" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2011/11/04/join-sword-shield-and-barracuda-for-lunch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2011/11/04/join-sword-shield-and-barracuda-for-lunch/</feedburner:origLink></item>
		<item>
		<title>Job Posting: Senior Consultant, PCI Risk &amp; Compliance</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/mImN902n4c0/</link>
		<comments>http://www.swordshield.com/2011/10/27/job-posting-senior-consultant-pci-risk-compliance-2/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 14:08:33 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Hiring Notices]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3927</guid>
		<description><![CDATA[Join Sword &#38; Shield, one of the most trusted and fastest-growing security consulting firms in the United States! Position Title: Senior Consultant, PCI Risk &#38; Compliance Skills: PCI Risk Assessments/Gap Analysis/Remediation Plans Tax Term: Full Time Pay Range: $80-$110k commensurate with experience Length: Indefinite Travel Required: &#60; 50% Telecommute: Negotiable POSITION DESCRIPTION The Senior PCI [...]]]></description>
			<content:encoded><![CDATA[<p>Join Sword &amp; Shield, one of the most trusted and fastest-growing security consulting firms in the United States!<img class="alignright" title="Send Resumes as a Word or PDF Attachment" src="http://www.swordshield.com/images/Jobs-flattened.gif" alt="Send Resumes as a Word or PDF   Attachment" width="134" height="128" /></p>
<p><strong>Position Title:</strong> Senior Consultant, PCI Risk &amp; Compliance</p>
<p><strong>Skills: </strong>PCI Risk Assessments/Gap Analysis/Remediation Plans</p>
<p><strong>Tax Term:</strong> Full Time</p>
<p><strong>Pay Range:</strong> $80-$110k commensurate with experience</p>
<p><strong>Length</strong>: Indefinite</p>
<p><strong>Travel Required</strong>: &lt; 50%</p>
<p><strong>Telecommute: </strong>Negotiable</p>
<p><strong>POSITION DESCRIPTION</strong></p>
<p><span id="more-3927"></span></p>
<p><img title="More..." src="http://www.swordshield.com/wordpress/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" />The Senior PCI Risk &amp; Compliance Consultant will work with Sword &amp; Shield customers to conduct procedural and operational assessments of information security processes and system controls – <strong>with a focus on PCI DSS compliance</strong> Senior consultants will leverage analytical skills and security and compliance knowledge to review organizations’ current security policies, processes, and controls to provide in-depth gap analyses and guidance on best practices in Governance, Risk, and Compliance (GRC) as it relates to the PCI DSS standards.</p>
<p>This position requires an extensive knowledge of security concepts and architecture, technical auditing techniques and standards, as well as a strong background in and knowledge PCI DSS compliance mandates. This function also requires excellent communication skills over phone and email and particularly the ability to correctly convey solutions to more or less knowledgeable customer contacts.</p>
<p>You can enjoy a casual work environment while working with a close, family-oriented peer group of security professionals. Sword &amp; Shield is a small privately-owned company with large government contracts and Fortune 1000 commercial accounts. If you enjoy hands-on interactive network security work&#8230;this is the place for you. Our work environment allows our security consultants the opportunity to showcase their skills and abilities and receive the credit they deserve as individuals.</p>
<p><strong>REQUIRED</strong></p>
<div>
<ul>
<li>United States Citizenship: <strong>an absolute must have.</strong></li>
<li>Specific experience with, and in-depth knowledge of, PCI DSS compliance regulations and performing audits and assessments on these mandates: <strong>an absolute must have.</strong></li>
<li>Strong understanding of risk management and information security management.</li>
<li>BS degree (or higher) in a technical discipline.</li>
<li>Strong IT experience including at least five (5) years of IT securityAt least five (5) years of performing PCI DSS audit/risk assessments, preferably as a consultant and a QSA.</li>
<li>Technical operational knowledge of firewalls, routers and switches, intrusion detection systems, event log management, anti-malware, encryption, and additional information security areas</li>
<li>Strong understanding of Unix and Windows platforms, as well as TCP/IP protocols; expertise in using MS Excel, MS Word</li>
</ul>
<p><strong>DESIRED (But Not Required):</strong></p>
<ul>
<li>Active or past Qualified Security Assessor (QSA) certification for performing PCI audits.</li>
<li>Experience with commercial and freeware governance, risk, and compliance tools such as Modulo Risk Manager, RSAM, or TruArx.</li>
<li>Experience with other compliance areas such as: FISMA/NIST, FFIEC, GLBA, and HIPAA</li>
<li>CISSP, CISM or CISA certifications</li>
</ul>
<p><strong>IDEAL PERSONAL CHARACTERISTICS:</strong></p>
<ul>
<li>Proven ability to interact with company and business leaders at the &#8220;C&#8221; level (e.g. CIO, CFO, CSO)</li>
<li>Strong, creative problem solving and analytical thinking</li>
<li>Willing to accept new challenges and learn in new areas; strong communication skills</li>
<li>Flexibility and responsive to changing situations; adaptable</li>
</ul>
<p>In addition to a career in the challenging world of computer and network security, Sword &amp; Shield Enterprise Security, Inc. offers competitive salaries, full benefits, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.</p>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=mImN902n4c0:ARV-SLqaGEE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=mImN902n4c0:ARV-SLqaGEE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=mImN902n4c0:ARV-SLqaGEE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=mImN902n4c0:ARV-SLqaGEE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=mImN902n4c0:ARV-SLqaGEE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=mImN902n4c0:ARV-SLqaGEE:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=mImN902n4c0:ARV-SLqaGEE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=mImN902n4c0:ARV-SLqaGEE:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=mImN902n4c0:ARV-SLqaGEE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=mImN902n4c0:ARV-SLqaGEE:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/mImN902n4c0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2011/10/27/job-posting-senior-consultant-pci-risk-compliance-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2011/10/27/job-posting-senior-consultant-pci-risk-compliance-2/</feedburner:origLink></item>
		<item>
		<title>Job Posting: Senior Consultant, HIPAA Risk &amp; Compliance</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/RlVdo1eTVBA/</link>
		<comments>http://www.swordshield.com/2011/10/20/job-posting-senior-consultant-hipaa-risk-compliance-2/#comments</comments>
		<pubDate>Thu, 20 Oct 2011 14:05:07 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Hiring Notices]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[HIPAA consultant]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3912</guid>
		<description><![CDATA[Join Sword &#38; Shield, one of the most trusted and fastest-growing security consulting firms in the United States! Position Title: Senior Consultant, HIPAA Risk &#38; Compliance Skills: HIPAA Risk Assessments/Gap Analysis/Remediation Plans Location: Negotiable Tax Term: Full Time Pay Range: $80-$110k commensurate with experience Length: Indefinite Travel Required: &#60; 50% Telecommute: Negotiable POSITION DESCRIPTION The [...]]]></description>
			<content:encoded><![CDATA[<p>Join Sword &amp; Shield, one of the most trusted and fastest-growing security consulting firms in the United States!<img class="alignright" title="Send Resumes as a Word or PDF Attachment" src="http://www.swordshield.com/images/Jobs-flattened.gif" alt="Send Resumes as a Word or PDF   Attachment" width="134" height="128" /></p>
<p><strong>Position Title:</strong> Senior Consultant, HIPAA Risk &amp; Compliance</p>
<p><strong>Skills: </strong>HIPAA Risk Assessments/Gap Analysis/Remediation Plans</p>
<p><strong>Location: </strong>Negotiable</p>
<p><strong>Tax Term:</strong> Full Time</p>
<p><strong>Pay Range:</strong> $80-$110k commensurate with experience</p>
<p><strong>Length</strong>: Indefinite</p>
<p><strong>Travel Required</strong>: &lt; 50%</p>
<p><strong>Telecommute: </strong>Negotiable</p>
<p><strong>POSITION DESCRIPTION<img title="More..." src="http://www.swordshield.com/wordpress/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" /></strong></p>
<p><span id="more-3912"></span></p>
<p><img title="More..." src="http://www.swordshield.com/wordpress/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" />The Senior HIPAA Risk &amp; Compliance Consultant will work with Sword &amp; Shield customers to conduct procedural and operational assessments of information security processes and system controls – <strong>with a focus on HIPAA compliance.</strong> Senior consultants will leverage analytical skills and security and compliance knowledge to review organizations’ current security policies, processes, and controls to provide in-depth gap analyses and guidance on best practices in Governance, Risk, and Compliance (GRC) as it relates to HIPAA security and privacy standards.</p>
<p>This position requires an extensive knowledge of security concepts and architecture, technical auditing techniques and standards, as well as a strong background in and knowledge of HIPAA security and privacy rules. This function also requires excellent communication skills over phone and email and particularly the ability to correctly convey solutions to more or less knowledgeable customer contacts.</p>
<p>You can enjoy a casual work environment while working with a close, family-oriented peer group of security professionals. Sword &amp; Shield is a small privately-owned company with large government contracts and Fortune 1000 commercial accounts. If you enjoy hands-on interactive network security work&#8230;this is the place for you. Our work environment allows our security consultants the opportunity to showcase their skills and abilities and receive the credit they deserve as individuals.</p>
<p><strong>REQUIRED</strong></p>
<div>
<ul>
<li>United States Citizenship: <strong>an absolute must have.</strong></li>
<li>Specific experience with, and in-depth knowledge of, HIPAA security and privacy rules, including the HITECH Act, as well as performing audits and assessments on these mandates: <strong>an absolute must have.</strong></li>
<li>Strong understanding of risk management and information security management.</li>
<li>BS degree (or higher) in a technical discipline.</li>
<li><strong>Strong IT experience including at least five (5) years of IT security</strong></li>
<li><strong>At least five (5) years of performing HIPAA audits/risk assessments, preferably as a consultant.</strong></li>
<li>Technical operational knowledge of firewalls, routers and switches, intrusion detection systems, event log management, anti-malware, encryption, and additional information security areas</li>
<li>Strong understanding of Unix and Windows platforms, as well as TCP/IP protocols; expertise in using MS Excel, MS Word</li>
</ul>
<p><strong>DESIRED (But Not Required):</strong></p>
<ul>
<li>Active or past HIPAA certification(s) and/or training <strong>strongly preferred</strong></li>
<li>In-depth knowledge or certification in HITRUST methodology <strong>strongly preferred</strong></li>
<li>Experience with commercial and freeware governance, risk and compliance tools such as Modulo Risk Manager, RSAM or TruArx</li>
<li>Experience with other compliance areas such as: FISMA/NIST, FFIEC, GLBA, and HIPAA</li>
<li>CISSP, CISM or CISA certifications</li>
</ul>
<p><strong>IDEAL PERSONAL CHARACTERISTICS:</strong></p>
<ul>
<li>Proven ability to interact with company and business leaders at the &#8220;C&#8221; level (e.g. CIO, CFO, CSO)</li>
<li>Strong, creative problem solving and analytical thinking</li>
<li>Willing to accept new challenges and learn in new areas; strong communication skills</li>
<li>Flexibility and responsive to changing situations; adaptable</li>
</ul>
<p>In addition to a career in the challenging world of computer and network security, Sword &amp; Shield Enterprise Security, Inc. offers competitive salaries, full benefits, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.</p>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=RlVdo1eTVBA:bDZkszH5QN8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=RlVdo1eTVBA:bDZkszH5QN8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=RlVdo1eTVBA:bDZkszH5QN8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=RlVdo1eTVBA:bDZkszH5QN8:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=RlVdo1eTVBA:bDZkszH5QN8:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=RlVdo1eTVBA:bDZkszH5QN8:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=RlVdo1eTVBA:bDZkszH5QN8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=RlVdo1eTVBA:bDZkszH5QN8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=RlVdo1eTVBA:bDZkszH5QN8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=RlVdo1eTVBA:bDZkszH5QN8:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/RlVdo1eTVBA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2011/10/20/job-posting-senior-consultant-hipaa-risk-compliance-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2011/10/20/job-posting-senior-consultant-hipaa-risk-compliance-2/</feedburner:origLink></item>
		<item>
		<title>Lunch at Club LeConte; Learn About Advanced Threats</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/H4Ba8grlNY0/</link>
		<comments>http://www.swordshield.com/2011/10/19/lunch-at-club-leconte-learn-aboubt-advanced-threats/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 15:09:47 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3902</guid>
		<description><![CDATA[Sword &#38; Shield Director of Computer Forensics Bill Dean will discuss how both industry and government can better understand today&#8217;s advanced threats at a Lunch N&#8217; Learn, Friday Nov. 4 from 11:30 a.m. to 1:30 p.m. at Club LeConte. Today’s cyber attacks are more stealthy and malicious than ever before and are programmed to remain [...]]]></description>
			<content:encoded><![CDATA[<p>Sword &amp; Shield Director of Computer Forensics Bill Dean will discuss how both industry and government can better understand today&#8217;s advanc<a rel="attachment wp-att-1851" href="http://www.swordshield.com/about/company-logos/forensic-discoveries-5/"><img class="alignright size-medium wp-image-1851" title="Forensic Discoveries" src="http://www.swordshield.com/images/Forensic-Discoveries-350x106.png" alt="Forensic Discoveries" width="245" height="74" /></a>ed threats at a Lunch N&#8217; Learn, Friday Nov. 4 from 11:30 a.m. to 1:30 p.m. at Club LeConte.</p>
<p>Today’s cyber attacks are more stealthy and malicious than ever before and are programmed to remain unnoticed for as long as possible until an opportune time in the future to inflict damage. In addition, data breaches can mean the loss of reputation and revenue and result in legal expenses.</p>
<p>Sword &amp; Shield analysts have discovered that many computer security breaches occur today because of the time lag between discovery of a vulnerability and installation of security patches. Simply stated: traditional anti-virus vendors continue to lag behind online criminals when it comes to detecting and protecting against new and quickly evolving Internet threats. Add this time lag to the patching schedules of diligent IT administrators, you have approximately a three month vulnerability window through which malware can be injected into the network.</p>
<p>“A network vulnerability assessment/penetration test determines the vulnerabilities that may be exploited in the future, while a <a href="http://www.swordshield.com/services/security-testing/databreachthreat/">Data Breach Threat Analysis</a> works to determine whether or not your systems have already been compromised,&#8221; Dean said.</p>
<p>To reserve your seat for the Lunch N&#8217; Learn, please RSVP by emailing <a href="mailto:forensics@swordshield.com">forensics@swordshield.com</a>. Space is limited and registration must be approved by Tuesday, Nov. 1.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=H4Ba8grlNY0:QDKUoEb0tuU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=H4Ba8grlNY0:QDKUoEb0tuU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=H4Ba8grlNY0:QDKUoEb0tuU:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=H4Ba8grlNY0:QDKUoEb0tuU:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=H4Ba8grlNY0:QDKUoEb0tuU:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=H4Ba8grlNY0:QDKUoEb0tuU:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=H4Ba8grlNY0:QDKUoEb0tuU:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=H4Ba8grlNY0:QDKUoEb0tuU:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=H4Ba8grlNY0:QDKUoEb0tuU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=H4Ba8grlNY0:QDKUoEb0tuU:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/H4Ba8grlNY0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2011/10/19/lunch-at-club-leconte-learn-aboubt-advanced-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2011/10/19/lunch-at-club-leconte-learn-aboubt-advanced-threats/</feedburner:origLink></item>
		<item>
		<title>Sword &amp; Shield to Partner with MAD Security</title>
		<link>http://feedproxy.google.com/~r/SwordShieldEnterpriseSecurityInc/~3/9T2D7S5whCk/</link>
		<comments>http://www.swordshield.com/2011/10/12/sword-shield-to-partner-with-mad-security/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 16:39:01 +0000</pubDate>
		<dc:creator>Lara Bergman</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[MAD Security]]></category>
		<category><![CDATA[NASA SEWP]]></category>

		<guid isPermaLink="false">http://www.swordshield.com/?p=3892</guid>
		<description><![CDATA[MAD Security to Offer Security Solutions for US Government on Sword &#38; Shield’s NASA SEWP IV Contract Henderson, NV &#8211; October 10, 2011 &#8211; MAD Security, an information security firm that provides full-service information security solutions, services and training, announced today that it has partnered with Sword &#38; Shield Enterprise Security to offer and implement [...]]]></description>
			<content:encoded><![CDATA[<h3><em>MAD Security to Offer Security Solutions for US Government on Sword &amp; Shield’s NASA SEWP IV Contract</em></h3>
<p><strong>Henderson, NV &#8211; October 10, 2011</strong> &#8211; MAD Security, an information security firm that provides full-service<a href="http://www.swordshield.com/images/mad_security_logo.png"><img class="alignright size-full wp-image-3893" title="mad_security_logo" src="http://www.swordshield.com/images/mad_security_logo.png" alt="" width="150" height="64" /></a> information security solutions, services and training, announced today that it has partnered with Sword &amp; Shield Enterprise Security to offer and implement security solutions and training for government agencies through Sword &amp; Shield’s <a href="http://www.sewp.nasa.gov/info/geninfo.shtml">NASA SEWP IV</a> contract.</p>
<p>Providing industry-leading customized training offerings &#8211; including <a href="http://www.thehackeracademy.com/">The</a><a href="http://www.thehackeracademy.com/"> </a><a href="http://www.thehackeracademy.com/">Hacker</a><a href="http://www.thehackeracademy.com/"> </a><a href="http://www.thehackeracademy.com/">Academy</a>, a cloud-based training system for information security professionals &#8211; and security awareness programs, in addition to MAD Security’s leading solution implementation and architecture services on SEWP IV allow agencies to learn, practice and stay up to date on the latest in information security.</p>
<p>&#8220;MAD Security’s comprehensive security services and training offerings have been helping government agencies reduce overall security risk and improve technology infrastructure security for years,”, said Mad Security Managing Partner Dean Pace.  “Provisioning MAD Security training and solutions on SEWP will greatly simplify the process for agencies that want to find the right methods to enhance the  protection of their critical business assets&#8221;.</p>
<p>&#8220;While Sword &amp; Shield maintains core competencies in Network Security services and products, we engage in strategic partnerships with industry leading companies. Our new partnership with MAD Security will allow us to provide an even greater depth and breadth of offerings across the Federal IT landscape,” said Sword &amp; Shield President and CEO John McNeely.</p>
<p><strong><span id="more-3892"></span>About MAD Security</strong></p>
<p>MAD Security is a small business and leading provider of information security training, services, and solutions.   With a focus on enterprise cyber-security, MAD Security provides organizations including all branches of government and commercial customers with information security behavioral modification programs, role-based training for security, customized end user awareness training programs and the world renowned Hacker Academy, an on-line training platform (<a href="http://www.thehackeracademy.com/">www</a><a href="http://www.thehackeracademy.com/">.</a><a href="http://www.thehackeracademy.com/">thehackeracademy</a><a href="http://www.thehackeracademy.com/">.</a><a href="http://www.thehackeracademy.com/">com</a>).   In addition to these training programs, MAD provides IT security solutions, design and procurement services, all available through GSA IT Schedule 70 listing, GS-35F-0563X.  For more information visit,<a href="http://www.madsecinc.com/"> </a><a href="http://www.madsecinc.com/">www</a><a href="http://www.madsecinc.com/">.</a><a href="http://www.madsecinc.com/">madsecinc</a><a href="http://www.madsecinc.com/">.</a><a href="http://www.madsecinc.com/">com</a></p>
<p><span style="text-decoration: underline;"> </span></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=9T2D7S5whCk:fBbsWrUtwIE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=9T2D7S5whCk:fBbsWrUtwIE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=9T2D7S5whCk:fBbsWrUtwIE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=9T2D7S5whCk:fBbsWrUtwIE:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=9T2D7S5whCk:fBbsWrUtwIE:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=9T2D7S5whCk:fBbsWrUtwIE:D7DqB2pKExk" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=9T2D7S5whCk:fBbsWrUtwIE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=9T2D7S5whCk:fBbsWrUtwIE:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?a=9T2D7S5whCk:fBbsWrUtwIE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SwordShieldEnterpriseSecurityInc?i=9T2D7S5whCk:fBbsWrUtwIE:V_sGLiPBpWU" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SwordShieldEnterpriseSecurityInc/~4/9T2D7S5whCk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.swordshield.com/2011/10/12/sword-shield-to-partner-with-mad-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.swordshield.com/2011/10/12/sword-shield-to-partner-with-mad-security/</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 1.132 seconds. --><!-- Cached page generated by WP-Super-Cache on 2012-02-09 10:58:28 -->

