Amazon

6.4.10

Cyber Security Warfare



Over the years I have had the opportunity to see many different cyber security or information security programs. It would seem that most folks in the field are now used to preparing for the type of information warfare that is either underway against their enterprise or they are preparing for what they see happening to others. As infosec programs adapt, evolve and expand I see a greater emphasis on good layered, or defense in depth, security. It's great to see programs that "get it" and their desire to move towards a proactive approach rather than the traditional "whack-a-mole". Special thanks to one of the dudes who interviewed me for the whack a mole phrase.

As an infosec professional, it's very refreshing to see this shift in thought. Many times in the past I have seen or heard the many excuses that plague this field. So often budgets are not allocated for security or the wrong personnel are placed in the wrong position to affect needed change. As information warfare continues to escalate it's been comforting to see so many organizations that truly desire excellence in their programs from philosophy to implementation. I have also talked with several government entities or government contractors that are definitely ready to win the war against those people, groups, or nations that would want to use our data for harm against this great country. Better Internet neighborhoods are something I always wanted to see in the past but that I felt couldn't happen based on some of the issues I had run into over the past 7 years. I have hope now as I see these teams pushing towards their common goal.

5.3.10

Job Search



My job hunt has been going quite well with five opportunities being actively researched right now. the current titles I am researching/interviewing for are researcher, assessor, project consultant, Information Security Architect, and cyber security analyst. God is really taking care of us right now and I am very grateful for that. The project consultant position would be 3-6 months and may actually let me get my own business up and running. We are praying about this daily and just want to see where the Lord leads us during this search.

The potential for the consultant position also has me wanting to get a website up and running if anyone can assist with that. If your organization is in need of information security analysis, testing, architecture, and remediation please get in touch with me.

15.2.10

Information Security today



While I am job hunting, I thought I would jump on and see if any of my readers are in need of an information security/assurance professional. Sadly it appears most organizations are well behind the curve when it comes to protecting their data. I wonder how many CEO and CFO guys are wondering if their company's data is secure or just wondering what all of us geeks are telling them every day. In these days of risk and compliance initiatives, several industries need to hire someone full time just to manage their information security program. If you are an organization, or individual, that needs someone to scope your program and make sure all of your bases are covered just let me know. I would be happy to come in and see whether or not I can offer anything for you or your organization.

19.8.09

"C-Level " Professionals Jumping Ship



Well, I wouldn't say they're actually jumping ship but people are leaving at quite a frenetic pace right now. This is what happens when you hire people that are passionate about what they do for a living yet do not have the authority needed to get the job done. Sadly, this is all too common in information technology as a whole and especially within information security. Too often I think you get unqualified people who mismanage money because they lack the subject matter expertise to properly spend it. It is a given at the executive level that your technical skill sis probably not on par with those who work for you so listening and discerning becomes the critical skill when seeking funding. Being able to justify the funding requests is also a massive hurdle and this is often when we find out that an accountant is actually in charge of everyone.

This post from Richard Bejtlich's blog does a good job of explaining both the need for money and what you can do with it once you have it. So, what's the point here? The point is that you must find talented people to run your program and empower them, fund that program, and have a vision of what that program should look like. There must be a reasonable balance between security and convenience and you must always "sharpen the saw." Trying to have an infosec program without all of those elements is like trying to have fire without heat, fuel and oxygen.