IT Security Certification (Part 2)

/
According to a survey by InfoSecurity magazine that stated IT professionals' average salaries overall decreased by 5.5%, while those in IT security increased by 3.1% show that experience in security is a valuable skill. Furthermore, The US Department of Defense (DoD) Directive 8570.1-M requires every part-time or full-time military member or defense contractor that has access to a privileged DoD system to be held by trained and CERTIFIED personnel in a commercial certification to enhance Information Assurance (IA) of the US Department of Defense's (DoD) information, information systems, and networks.

The Federal System’s Need for a Security Assessment Process, Part 2: Categories of Security Assessments

/
Security assessments can fall into many categories and an organization’s core competency often dictates which ones management is more interested in conducting. For example, an organization that has an external presence may be very interested in how they appear to the outside world and how well they are protecting their internal resources from external entities trying to harm them. Whereas, another governmental institution maybe more concerned with their internal security posture and controls as compared to how they appear to the outside world. They may have a pressing need to verify internal access control, password compliance and proper network segmentation as opposed to what protocols are accessible from the public network. The actual type of assessment performed usually depends on the organization’s mission as well as their overall security need.

Hackademic

/
Hackademic is a three day security conference that aims to bring together the hacking community and members from the academic community in order to learn from each others successes and failures.

EU-U.S. Joint Statement on Data Protection by European Commission Vice-President Viviane Reding and U.S. Secretary of Commerce John Bryson

/
Today's High Level Conference on Privacy and Protection of Personal Data, held simultaneously in Washington, DC and Brussels with the participation of Vice-President Viviane Reding and Secretary John Bryson, represents an important opportunity to deepen our transatlantic dialogue on commercial data privacy issues. The United States and the European Union clearly share a commitment to promoting the rights of individuals to have their personal data protected and to facilitating interoperability of our commercial data privacy regimes.

Security Bulletin: MS12-020 high-risk vulnerability in the RDP (Remote Desktop)

/
On March 14, 2012, Microsoft released a critical software patch that fixes a very high-risk vulnerability in the RDP (Remote Desktop) service installed on most Windows-based systems. The vulnerability may allow the execution of malicious code by sending a malformed packet to an RDP enabled system. Security Bulletin: MS12-020

SANS Security West 2012 is coming to San Diego, CA

/
SANS is presenting nine days of training that will take place at our Manchester Grand Hyatt campus, May 10-18. With more than 20 courses offered in security management, IT audit, IT security, and computer forensics, register now to take the training you need! Security West 2012 will feature the following special evening event: