Showing posts with label learning. Show all posts
Showing posts with label learning. Show all posts

Tuesday, April 3, 2018

Keeping Up with the Podcasts!

   I listen to a lot of podcasts.  Probably way to many.

   But podcasts are just such a great way to keep up with timely information in security, technology, news, finance, sports and other topics.  So I listen... a lot!

   I did a post on this topic nearly 6 years ago!  In that post I provided a list of podcasts.  It's way short compared to the list I'll be sharing here.  I also wrote about using podcasts as a learning resource here and here.

   Before I provide the actual list, here are few important notes:

  • I’ve tried to put these into categories
  • Within each category, the order is not how much I like the podcast but just the order they are in my podcatcher (and that order has little rhyme or reason)
  • Yes, I am crazy
  • Yes, I do constantly have earbuds in my ears
  • I do use a podcatcher that has variable speed and I typically listen at 2.2x! (I still use DoggCatcher)  Yes, we’ve already established that I’m crazy.  And, I have a lot of casts to get through.
  • Some of these podcasts may no longer exist.  Since my list is so long, if some drop out of existence I really don’t notice unless they are one of my few top favs.
  • I actually left some off – I have an casual interest in real estate investing and subscribe to 6-8 casts on that subject
   With that... let's get to the list!

Tuesday, December 6, 2016

Information Security Learning Resources part 2

   Today we have part 2 of a 2-part guest post by security analyst Chris Goff.  Chris has collected a set
of info, links and lists that definitely qualify as extremely cool resources!  You can check out Chris' website at http://chris-goff.com/ or follow him at https://www.linkedin.com/in/goffchris

   There's a lot of info packed in here, and it's pretty technical. But you don't have to memorize it all now and there won't be a test!  Just skim it, enjoy it and bookmark it!

Security Concepts
There are three key concepts of information security which you may or may not be familiar with:
    -      Confidentiality
o   Confidentiality is the characteristic of information whereby only those with sufficient privileges and a demonstrated need may access certain information. When unauthorized individuals or systems can view information, confidentiality is breached.
    -      Integrity
o   Integrity is the quality or state of being whole, complete, and uncorrupted. The integrity of information is threatened when it is exposed to corruption, damaged, destruction, or other disruption of its authentic state. Corruption can occur while information is being entered, stored, or transmitted.
    -      Availability
o   Availability is the characteristic of information that enables user access to information in a usable format without interference or obstruction. A user in this definition may be either a person or another computer system. Availability does not imply that the information is accessible to any user; rather, it means availability to authorized users.

This is known as the “security triad”. It can be further expanded upon:
    -      Privacy
o   Information that is collected, used, and stored by an organization is intended only for the purposes stated by the data owner at the time it was collected. Privacy as a characteristic of information does not signify freedom from observation (the meaning usually associated with the word), but in this context, privacy means that information will be used only in ways known to the person providing it. Many organizations collect, swap, and sell personal information as a commodity. It is now possible to collect and combine information on individuals from separate sources, which has yielded detailed databases whose data might be used in ways not agreed to, or even communicated to, the original data owner. Many people have become aware of these practices and are looking to the government for protection of the privacy of their data.
    -      Identification
o   An information system possesses the characteristic of identification when it is able to recognize individual users. Identification is the first step in gaining access to secured material, and it services as the foundation for subsequent authentication and authorization. Identification and authentication are essential to establishing the level of access or authorization that an individual is granted. Identification is typically performed by means of a user name or other ID.
    -      Authentication
o   An information system possesses the identity that he or she claims. Examples include the use of cryptographic certificates to establish Secure Sockets Layer (SSL) connections or the use of cryptographic hardware devices--for example, hardware tokens provided by companies such as RSA's SecurID--to confirm a user's identity.
    -      Authorization
o   After the identity of a user is authenticated, a process called authorization assures that the user (whether a person or a computer) has been specifically and explicitly authorized by the proper authority to access, update, or delete the contents of an information asset. An example of authorization is the activation and use of access control lists and authorization groups in a networking environment. Another example is a database authorization scheme to verify that the user of an application is authorized for specific functions such as reading, writing, creating, and deleting.
    -      Accountability
o   Accountability of information exists when a control provides assurance that every activity undertaken can be attributed to a named person or automated process. For example, audit logs that track user activity on an information system provide accountability. (Management of Information Security by Michael E. Whitman and Herbert J. Mattord)

Tuesday, November 22, 2016

Information Security Learning Resources part 1

   Today we have a guest post by security analyst Chris Goff.  Chris has collected a set of info, links and lists that definitely qualify as extremely cool resources!  You can check out Chris' website
at http://chris-goff.com/ or follow him at https://www.linkedin.com/in/goffchris

   There's a lot of info packed in here, and it's pretty technical. But you don't have to memorize it all now and there won't be a test!  Just skim it, enjoy it and bookmark it!



Information Security Learning Resources
or information security for the self-learner
by Chris Goff

This is the result of many years of notes. This is by no means an exhaustive list, nor the definitive path to information security.

If you come across a dead link, use the Internet Way Back Machine (https://www.archive.org).

Bookmark these Google Search cheat sheets, they will come in handy:

Official Google Cheat Sheet - http://www.google.com/help/cheatsheet.html

Google Advanced Operators Cheat Sheet - http://www.googleguide.com/print/adv_op_ref.pdf

Learning How To Learn - http://l.goodbits.io/l/407nqn1n

Core competencies

Here are three core competencies within information technology that will provide a solid foundation on which to start a security career:
  • Systems Administration
  • Network Administration
  • Programming
It is also critical that you learn to deal with people and business. Take some public speaking classes (Toastmasters: https://www.toastmasters.org/), volunteer for presentations at local groups, and volunteer to deliver training for folks at your workplace. One of the greatest methods of learning is to teach.

The core competencies are not a requirement, however be aware that InfoSec is expected to be a Subject Matter Expert (SME) on most topics. If you wish to be successful diversity of knowledge is key.
“There is no security without understanding.” – Michael Lucas, author Absolute OpenBSD

Tuesday, July 30, 2013

The Need To Read

   I recently read a great article on summer brain drain on ParentsChoice.org's Read More. Play More. Learn More. blog.

   The article is mostly directed to parents, making the point that kids forget school topics over the summer and often need time to get back up to speed.  This can be remedied with fun, stimulating activities, like brain games.  The article links to some brain games from the Museum of Science and Industry in Chicago.

   And, as the post points out, adults can also suffer from the same brain drain due to the inevitable schedule variations of the summer.

   But the specific article aside... what a great name and concept.  We could all read more, play more and learn more.

   We all need to exercise our brains.  Many people read articles and other material as part of their job.  But regardless of how in-depth, creative or technical that job may be, I think it's important to read and learn about other topics.

   So read.  Read blogs, and books of all kinds: non-fiction, historical fiction, mysteries, sci-fi... whatever you enjoy.  Read things in your field, but be sure to also read other info and read for enjoyment.  And, if you don't have time to sit down with a book, try audiobooks and podcasts.

   What are some of your favorite reading, educational or brain activity resources?

Tuesday, June 25, 2013

Countdown - the end of a (Google) reader

   The clock is ticking.  On July 1, Google will remove support for the RSS aggregator tool, Google Reader.

   In the past I've talked about how I keep up with the vast amount of information and changes in the security and IT fields.  That article focused on podcasts.  Another key tool I use is an RSS aggregator.

   An RSS aggregator is a program used to collect information from online sources.  You "subscribe" to a site (such as this blog), and then notices of new articles are automatically brought into the aggregator.  The power of the tool is that you can organize your subscriptions by categories you choose.  You can then quickly browse new articles by category.

Tuesday, May 14, 2013

One Size Does Not Fit All

   The annual Secure360 conference kicked off yesterday in St. Paul with pre-conference sessions. 
Secure360 is the major upper Midwest security conference and has become a US national event, now in its 11th year (I think!).

   I'll be pretty busy at this year's conference.  I've actually spoken at every Secure360, but this year I did a half-day seminar yesterday on BYOD, and tomorrow I've got back-to-back talks - one on the Insider Threat I call "The Accidental Insider" (blog post), and one on authentication "3 Factors of Fail" (blog series starts here).  Slides for all are on my slideshare site.

   I've got a wide variety of topics to cover!

   And that's what is so cool, and critical, about conferences.

Monday, December 10, 2012

We're All In This Together

   You are not alone. I've written on topics relevant to parents, families, digital citizens, computer users, security professionals, IT professionals, leaders. No matter what your questions or concerns, whether you are a parent trying to decide if your child is old enough for a smart phone or a Facebook account, or a security professional trying to move your program forward, you're in good company.

   Last week I was at the NG Security Summit in Austin Texas. One of the great things about a security leadership conference like this is that we get to talk with, and hear from, people from many organizations and situations who have security responsibility. In particular, regardless of industry segment, size of organization, locality or product, we all have similar challenges.  The topics and challenges resonate. Common themes emerge.

Tuesday, December 4, 2012

Keeping Up and Podcasts

   Recently I was talking with a colleague about keeping up with information. We actually were comparing smartphones. During the conversation we talked about podcasts and podcatching software. I'll talk about what I use below.
   We are talking about what podcasts we listen to.  One thing that was surprised me was that he mentioned that many technical people he interacts with don't listen to podcasts! I found that surprising. I figured most technical and security people know all about podcasts. Podcasts are hardly new.
   There are podcasts for all kinds of subjects. I listen to podcasts about security, technology, sports, news, science, leadership, getting things done/productivity and other subjects.
   I think that listening to podcasts is one of the best ways to both learn and keep up.