StoreSecurity SalonInto The BreachContact

Archive for May, 2006

Security Round Table - Episode 1 - Email Security

SRTListen in as Martin McKeay (Network Security), Dan Kuykendal (Mighty Seek), Larry Pesce (Pauldotcom Security) and Michael Santarcangelo (The Security Catalyst) discuss email security during the first Security Round Table. We recorded the podcast from a conference bridge, so the quality is about what you would expect from the broadcast radio.

This is our first effort - and I learned some ideas that I wrote down, and hope you do, too! Please send us feedback and let us know what other topics you would like for us to cover.

Check out more at the Security Round Table.

Please send me feedback and suggestions to securitycatalyst@gmail.com

Discuss this episode with others here in The Security Catalyst Forums

 
icon for podpress  SRT 1 [50:24m]: Play Now | Play in Popup | Download

Posted in Information Protection | Print this post Print this post | | Comments

Security Round Table Launched **AND FEATURED** in the Apple iTunes Store

I am pleased to announce the launch of the Security Round Table - and effort to bring the top security podcasts together on a regular basis to discuss top security issues. We recorded our first effort last weekend and will be releasing it shortly.

The founding podcasts include: The Security Catalyst, Network Security, Mighty Seek, and Pauldotcom Security

You can find our artist group in the iTMS by clicking here (you will need to have iTunes loaded)
And our logo is:

Thanks for your continued support of the Security Catalyst; I hope you enjoy our efforts on the Security Round Table!

Posted in Information Protection | Print this post Print this post | | Comments

Added a new infosec blog aggregator to Catalyst today

I’ve decided to give a try (after receiving an invitation) to an infosec blog aggregator that’s just started up: http://www.viralinks.com/computersecurity/

I checked to make sure no “hacker” sites. It seems fairly promising and provides yet another reason to stop by and check out www.securitycatalyst.com.

Might be something to consider for your blog/website. As always, feedback appreciated!

Posted in Information Protection | Print this post Print this post | | Comments

Security Catalyst 29 (Insider Interviews) - Botnets with Jim Lippard, Part I

We’ve all heard the term “botnet — and have even seen the recent arrests,successful trials and sentencing of botnet “herders.” So what exactly are botnets, how do they affect us and why should we care?

Jim Lippard joins us to share his insights on how botnets work, and helps us understand why they are continuing to grow at an alarming rate. Listen to this first of two interviews with Jim to understand the basics of botnets and get ready to learn how we can combat them on the next episode.

Please take 5 minutes to complete the Security Catalyst Listener Survey and help improve the program.

Discuss Security Catalyst 29 and Botnets here.

Ideas and suggestions about Trusted Catalysts Here.

 
icon for podpress  SC 29 [28:07m]: Play Now | Play in Popup | Download

Posted in Information Protection | Print this post Print this post | | Comments

Security Catalyst Research - Call for Financial Industry Participation

The Security Catalyst is conducting a study of the Financial Industry perspectives regarding the FFIEC mandate for stronger authentication (http://www.ffiec.gov/pdf/authentication_guidance.pdf). Given it’s been six months since the guidance was issued we expect most organizations to have assessed what the guidance means for them and initial conversations indicate the impact has been significant.

We are looking at various approaches within the industry to risk assessment, interpretations of the guidance, integration issues, and lessons learned. If you’re working for a financial institution and interested in participating, it takes 5-10mins and discussions are confidential, please contact the security catalyst at securitycatalyst@gmail.com.

We will provide participants with the results of the study over the next few weeks. We will present the results at an upcoming industry meeting in June

Posted in Information Protection | Print this post Print this post | | Comments

Connecting Security Job Seekers with Security Jobs - Part II

Based on some requests, feedback and conversations, I posted a forum topic about expanding the Catalyst community to include finding a way to help qualified security professionals find good jobs. We got some good initial comments and feedback, and I got a few solid emails, too.
Based on those discussions and my own “lessons learned” in hiring people,I have worked out a few ideas on paper — and they all come down to validating the people applying for the position and working with the hiring managers to make sure they know what they need, and ask for what they need.As I have been working on this, I came across an interesting study in the April 2006 Harvard Business Review where the researchers studied the top 6 skills and traits of sales people - by asking the companies what they thought were important, then asking the customers and lastly measuring what the companies actually hired for.
Results? You guessed it — the companies had a different set of expectations from their clients (and disconnect is bad); more over, the companies were not hiring for the same skills that they said they valued (and didn’t manage to hire based on what the clients found important). April 2006 Harvard Business Review Reprint: F0604G
Bottom line: we are in a quickly maturing industry — and we’re finding that people claim security when they shouldn’t, and hire for security when they shouldn’t.
Here’s the rub: the validation on both sides that this requires takes time. Since it will cost time, I don’t foresee this being a volunteer effort. The reality of it is, in my opinion, that job boards don’t work. And the hiring process for a lot of positions is flawed. If we can circumvent that and validate people and positions — we solve a problem.

I have the process designed. The bigger question is whether or not people are willing to pay for it. I honestly don’t know what the costs of this approach will be. I have a few “must” follow steps, and a few optional steps that will provide added value, but aren’t needed.

I envision growing our Catalyst efforts into a constructive community that fosters the advancement of security. I see being able to connect qualified job seekers with the right jobs as an important function….

Eventually, I’ll get around to doing a survey. Until then, I’d be curious to hear from both job seekers and current hiring managers:

- what is your biggest challenge in finding a job?
- what is your biggest challenge in finding a talented candidate?
- how much money have you spent searching for a job?
- how much money have you spent searching for a candidate?
- what is the perceived/actual value to you of a service that pre-qualifies people and helps you make a connecction, based on the experience of dedicated and proven professionals?

Let me know - and I’ll work to build it.

Share your ideas, comments, gripes and offers to help, fund or otherwise support it here: FORUM DISCUSSION (Free registration required I am always available to you via email: securitycatalyst*NOSPAM*@gmail.com

Posted in Information Protection | Print this post Print this post | | Comments (1)

Security Catalyst 28 - The Practice of Information Security | Influence the Future of the Catalyst

After a brief and unintended break, I’m back. Actually the beginning of this episode is a bit of an explanation of what the last few weeks were like (basically, life, business and travel all collided). So we’re back - and starting around the 7 minute mark, I explain some insights I have gained on information security and what we need to do to shift the culture of security.

In this episode, I also ask for your comments and insights on how to better focus and improve the security catalyst. If you could take a few minutes to respond to this survey (PLEASE TAKE A MINUTE FOR TO COMPLETE THE SURVEY) or share some ideas with me at securitycatalyst@gmail.com, I’d appreciate learning how I can better serve you.

Look for links and episode information in the forums here: Discuss Security Catalyst 28

Learn about the Security Roundtable here: The Security Roundtable

 
icon for podpress  Security Catalyst 28 [23:18m]: Play Now | Play in Popup | Download

Posted in Uncategorized | Print this post Print this post | | Comments

Security Catalyst Listener/Reader Survey

Just when you thought I was gone, I have surprised you again. Actually, the last two weeks has been an unusual combination of family, travel, business and life happening at an accelerated pace. I’ll have a podcast about it and explaining the exciting programming we have coming up out shortly.

Until then, I have designed a brief survey to get some feedback on what you like and what you would like me to improve on the Security Catalyst.

It’s 5 questions and should take you about 3 minutes. I appreciate the time and feedback — helps me continue this labor of love and change the way people think about security.

Click here to take survey

Posted in Information Protection | Print this post Print this post | | Comments

Podcast(s) and Articles Coming

Sorry for the delay - it’s been a hectic 10 days. I am back from my “West” coast trip, and will be getting back to finishing up some posts and the next few podcasts. I have some new interviews lined up, and the Security Makeover is getting started.

Actually, I’m quite excited about the security makeover, since we’ll be focusing on “Compliance through Security” and leveraging the experience of our organization to highlight effective approaches to compliance. If you’re dealing with compliance issues, this will be an important 10 week series for you. We expect to start those podcasts in about 2 weeks.

Thanks!!

Posted in Information Protection | Print this post Print this post | | Comments

Cinco de Mayo in Phoenix

I’m preparing right now to board a plane tomorrow morning bound for Phoenix, AZ. I’ll be there for a weekend coaching lab, hosted by the National Speaker’s Association. I expect this will provide me a foundation and insight to expand my coaching practice over the next few months.

However, it also means I’ll be in the Phoenix area. I may gather with some friends on Saturday night and catch up over some cocktails. If you’re in Phoenix and want to meet up, drop me a note to securitycatalyst@gmail.com.

Have a great weekend!

Posted in Information Protection | Print this post Print this post | | Comments

« Previous entries