Mile2® Certification Updates
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Our friends at Splunk are pleased to announce that Registration is Now Open for SplunkLive! Washington, D.C. on July 19.
Date: July 19, 2018
Time: 8:00 am – 4:00 pm
Location: Walter E Washington Convention Center
801 Mount Vernon Place NW
Washington, DC 20001
Registration page: http://live.splunk.com/splunkliveDC-07192018
Keynote Speaker:
Declan Morris, Splunk CIO
Public Sector Luncheon:
Special luncheon, including a panel discussion exclusively for Public Sector (government, Aerospace & Defense, Higher Education) participants
Breakout Sessions & SE Presenters:
The final agenda including the breakout sessions is listed below.
Agenda:
| Time | Description | |||
| 8:00am | Breakfast and Registration | |||
| 9:00am | Turn Data into Answers with Splunk Declan Morris, CIO, Splunk |
|||
| Overview Track | IT Ops Track | Security Track | Industry Track | |
| 10:45am | Improve Your Velocity With Splunk Cloud | Gain Real Time Insights from Your Data Using Splunk and AWS Cloud | Solve Your Security Challenges with Splunk | Leveraging Continuous Monitoring with Splunk to Support Compliance Requirements |
| 11:45am | Lunch | |||
| 12:45pm | Get More from Your Machine Data with Splunk AI | Analytics Through DevOps Lifecycle | Intro to Security Analytics Methods | Enabling Efficient Government with Splunk |
| 2:00pm | Getting Data In | Predictive, Proactive and Collaborative ML with Splunk ITSI | Accelerate Incident Response Using Automation and Orchestration | Keeping Agency Operations Humming with Event Analytics |
| 3:00pm | Reception — PartnerZone | |||
A new version of the popular CompTIA Security+ certification is out, and the content it covers has expanded significantly over the past three years. The six domains the exam covers remain the same, but four new sections were added to deal with cloud computing, incident response, mobile devices and network-enabled devices that could accidentally become part of your network. Two more new sections increase coverage of physical security and application of the “CIA triad” (confidentiality, integrity and availability).
In addition to these six new sections, dozens of other changes were made to existing sections to cover evolving malware, business continuity, big data, secure file transfer and other issues. The new SY0-401 “Certification Exam Objectives” document (which replaces 2010’s SY0-301 of the same name) also adds dozens of terms to its glossary and adds new but incomplete advice on suggested classroom equipment.
New Section: Implications of Integrating with Third Parties
A brand new section in SY0-401’s compliance and operational security domain was added to deal with business use of cloud services. The new section is entitled “summarize the security implications of integrating systems and data with third parties” (2.2) and contains ten topics.
Three new technical topics in this section are onboarding and offboarding business partners, social media networks and applications and data backups. Five new policy and risk topics are privacy considerations, risk awareness, unauthorized data sharing, data ownership and security policy and procedures.
Finally, there are two topics devoted to legal agreements and contracts. One, entitled “interoperability agreements,” covers service level agreements (SLA), blanket purchase agreements (BPA), memorandum of understanding (MOU) and Interoperability Solutions for (European Public) Administration (ISA). The second topic is entitled “review agreement requirements to verify compliance and performance standards” and contains no subtopics.
New Section: Incident Response
SY0-301’s one line entry about “Incident response” has been replaced with a whole new section (2.5) with eleven topics in SY0-401’s compliance and operational security domain. The new section begins with preparation, followed by first responder, incident identification and incident isolation (including quarantine and device removal). Next comes escalation and notification, mitigation steps, damage and loss control and data breach. Finally, lessons learned, reporting, recovery and reconstitution procedures are covered.
New Section: Physical Security
Limited coverage of physical security in SY0-301 has been replaced with an new “physical security and environmental controls section” (2.7) in SY0-401’s compliance and operational security domain. All of the existing environmental controls, including HVAC and EMU shielding are the same as the previous version. All of the of the old physical security controls, such a hardware locks and mantraps, were also carried forward.
The new content creates two new top-level topics physical security and control types. New physical security controls include proper lighting, signs, guards, barricades, biometrics, protected distribution (e.g., cabling), alarms and motion detection. Control types cover theoretical security design and are listed as deterrent, preventative, detective, compensating, technical and administrative. (CISSP and other security students may find this section strange because they are used to using these control types to design security for any system, not just physical systems.)
New Section: Confidentiality, Integrity, Availability and Safety Controls
SY0-401’s fleshes out brief mention of the “CIA triad” (confidentiality, integrity and available) from previous versions in a new section (2.9) in the compliance and operational security domain.
There are four major topics in this section (confidentiality, integrity, availability and safety) but most of the subtopics in this section are covered in more depth elsewhere. For example, confidentiality topics include encryption, access controls and stenography, two of which are covered elsewhere.
The full list of integrity topics found here includes hashing, digital signatures, certificates and non-repudiation. Availability topics include redundancy, fault tolerance and patching. Finally, safety topics cover fencing, lighting, locks, CCTV, escape plans, drills, escape routes and testing controls.
New Section: Mobile Security
A new mobile security section (4.2) is a welcome addition to the application, data and host security domain. A handful of topics such as device encryption and GPS were covered in SYO-301, but SY0-401 adds dozens more and organizes the content into device security, application security and BYOD concerns.
The new device security category includes information about full device encryption (“full” is new), remote wiping, lockout, screen-locks, GPS, application control, storage segmentation, asset tracking, inventory control, mobile device management, device access control, removable storage and disabling unused features.
The new application security category includes information about key management, credential management, authentication, geo-tagging, encryption, application whitelisting and transitive trust and authentication.
Finally, the new BYOD concerns category includes information about data ownership, support ownership, patch management, antivirus management, forensics, privacy, on-boarding and off-boarding, adherence to corporate policies, user acceptance, architecture and infrastructure considerations, legal concerns, acceptable use policy and on-board camera and video.
New Section: “Static Environment” Risk Mitigation
The new “static environment” section (4.5) in the application, data and host security domain requires some explanation. The term tries to encompass all the legacy devices, “smart” hardware, handheld game units, stationary bicycles, icemakers, car-borne computers and other network-enabled technology that may be entering or interacting with your business network. Since you generally have little or no control over the technology itself, CompTIA refers to the technologies as participating in a “static environment.”
Environment topics specifically called out in this section include SCADA (“supervisory control and data acquisition”; common in industrial automation), embedded (including printers, smart TVs and HVAC controls). Android, iOS, mainframe, game consoles and in-vehicle computing systems.
Read the rest at the InfoSec Institute
*** Receive a $200 discount for any (4-6) day SANS course with code: SANS_SecOrb200 ***
For a complete list of courses and complete descriptions, please see:
http://www.sans.org/u/oj
SANS will be back in Orlando at Disney for SANS 2015 with more than 35 courses, evening talks and activities, and vendor events. Please plan to attend on April 11-18 at the Walt Disney World Swan Resort for a full SANS Live Training Event experience. This is where you can get the skills you need and learn tips and tricks from the experts so that you can win the battle against the wide range of cyber adversaries that want to harm your environment. SANS 2015 is one of SANS’ largest events with something for everyone.
A look at our Event Webpage will show that our courses are being taught by SANS top Instructors who will ensure that you not only learn the material, but that you can also apply it immediately when you return to the office.
Note our list of new courses and our list of 5- and 6-day courses (arranged by discipline for your convenience) that will raise your level of security preparedness:
================================
New Cutting-Edge Courses
================================
– New! SEC511: Continuous Monitoring and Security Operations (Simulcast) taught by Eric Conrad
– New! SEC760: Advanced Exploit Development for Penetration Testers taught by Stephen Sims
================================
Security and Pen Testing Courses
================================
– SEC301: Intro to Information (GIAC-GISF, Simulcast) taught by Keith Palmgren
– * SEC401: Security Essentials Bootcamp Style (GIAC-GSEC, Simulcast) taught by Dr. Eric Cole
– * SEC501: Advanced Security Essentials – Enterprise Defender (GIAC-GCED,
Simulcast) taught by Paul A. Henry
– * SEC503: Intrusion Detection In-Depth (GIAC-GCIA, Simulcast) taught by Mike Poor
– * SEC504: Hacker Tools, Techniques, Exploits and Incident Handling
(GIAC-GCIH) taught by John Strand
– SEC505: Securing Windows with the Critical Security Controls
(GIAC-GCWN) taught by Jason Fossen
– SEC542: Web App Penetration Testing and Ethical Hacking (GIAC-GWAPT) taught by Seth Misenar
– SEC560: Network Penetration Testing and Ethical Hacking (GIAC-GPEN) taught by Ed Skoudis
– SEC561: Intense Hands-on Pen Testing Skill Development (with SANS
NetWars) taught by Tim Medin
– SEC566: Implementing and Auditing the Critical Security Controls – In-Depth (GIAC-GCCC) taught by James Tarala
– SEC573: Python for Penetration Testers taught by Mark Baggett
– SEC575: Mobile Device Security and Ethical Hacking (GIAC-GMOB) taught by Joshua Wright
– SEC579: Virtualization and Private Cloud Security taught by Dave Shackleford
– SEC617: Wireless Ethical Hacking, Penetration Testing, and Defenses
(GIAC-GAWN) taught by Larry Pesce
– SEC642: Advanced Web App Penetration Testing and Ethical Hacking taught by Justin Searle
– SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking (GIAC-GXPN) taught by James Lyne
================================
Application Developer Courses
================================
– DEV522: Defending Web Applications Security Essentials (GIAC-GWEB) taught by Johannes Ullrich, Ph.D.
– DEV544: Secure Coding in .NET: Developing Defensible Applications
(GIAC-GSSP-.NET) taught by Eric Johnson
================================
Computer Forensics Courses
================================
– FOR408: Windows Forensic Analysis (GIAC-GCFE, Simulcast) taught by Rob Lee
– * FOR508: Advanced Digital Forensics and Incident Response (GIAC-GCFA) taught by Chad Tilbury
– FOR572: Advanced Network Forensics and Analysis (GIAC-GNFA) taught by Philip Hagen
– FOR585: Advanced Smartphone Forensics taught by Cindy Murphy
– FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques (GIAC-GREM) taught by Lenny Zeltser
================================
Security Management Courses
================================
– * MGT414: SANS(R) +S(TM) Training Program for the CISSP(R) Certification Exam (GIAC-GISP) taught by Jonathan Ham
– * MGT512: SANS Security Leadership Essentials For Managers with Knowledge Compression(TM) (GIAC-GSLC) taught by David Hoelzer
– MGT514: IT Security Strategic Planning, Policy and Leadership taught by G. Mark Hardy
– MGT525: IT Project Management, Effective Communication, and PMP(R) Exam Prep (GIAC-GCPM) taught by Jeff Frisk
================================
Security Audit Courses
================================
– * AUD507: Auditing & Monitoring Networks, Perimeters & Systems
(GIAC-GSNA) taught by Tanya Baccam
================================
Legal Course
================================
– LEG523: Law of Data Security and Investigations (GIAC-GLEG) taught by Benjamin Wright
================================
NetWars
================================
– NetWars – Tournament
– DFIR NetWars Tournament
* Courses with Certifications that align with DOD Directive 8570
For a complete list of courses and complete descriptions, please see:
http://www.sans.org/u/oj
*** Receive a $200 discount for any (4-6) day SANS course with code: SANS_SecOrb200 ***
Metasploit has become the defacto standard for pentesting today. Most security professionals have some familiarity with it, but few can REALLY get in and drive it like a pro.
Take your Metasploit skills to the next level in this new live online course that is designed to take a user from little to no experience with Metasploit to using all of the most advanced features of the tool has to offer.
The course cost is $500, but the first 25 signups will get the course at $350 so signup now!
Syllabus
Day 1: Metasploit Fundamentals and Scanning
Day 2: Exploitation
Day 3: Bypassing defensive mechanisms
Day 4: Writing your own modules
Day 5: Writing exploits
Schedule
This class will be held live online from 16 – 20 February from 10am EST to 4pm EST each day.
Videos
Each class will be recorded and made available to the students via email. So you can keep up with the class even if you have to miss time, or even a whole day.
Price
The class cost is $500USD.
The first 25 signups will get the course at $350 so signup now!
SANS Cyber Defense Initiative (CDI) 2014 will once again bring together the nation’s cyber defense community on December 10-19 at the Grand Hyatt Washington in DC.
CDI 2014 is not only a leading cyber defense training event, it is also powered by SANS’ NetWars! Learn more about the Core NetWars, DFIR NetWars, and the 3rd Annual NetWars Tournament of Champions taking place at CDI 2014 at the event page below, as well as the more than 25 courses available in IT security, pen testing, security management, IT audit, and digital forensics. Short courses can also be taken with a long course to enhance your training.
New courses include the debut of SEC562: CyberCity Hands-on Kinetic Cyber Range Exercise at CDI 2014. Competing in simulated attacks, participants will learn how to devise strategies and employ tactics to thwart computer attacks that would cause significant real-world damage. The battles ensue inside CyberCity, a miniature physical city featuring real-world Industrial Control Systems and a power grid. CyberCity’s in-depth and ambitious challenges include maintaining control of vital city infrastructure including water, power, transportation, hospitals, banks, retail, and residential.
On the final day of the SEC562 course participants compete in a free-for-all battle for turf in CyberCity. Teams are tasked with taking over turf from other teams while simultaneously protecting their own turf in a red-team/blue-team faceoff.
Every course, evening talk, and special event offered at SANS CDI 2014 is designed to keep cyber defenders on the cutting-edge and to ensure that they have the knowledge and skills required to fight against the actions of today’s cyber criminals. Many courses at CDI 2014 can also be used to prepare for GIAC certification.
For a complete list of courses and to register for the training event, please visit:
http://www.sans.org/info/169082
*** Save $150 on your CDI 2014 course with discount code: SANS_SecOrb150 ***
SANSFIRE 2014 is coming up soon at the Hilton Baltimore located in downtown Baltimore’s Inner Harbor district, June 21-30. SANSFIRE 2014 is SANS’ unique annual “ISC Powered” event. This is the event where the Internet Storm Center Incident Handlers present unique talks about the cyber hazards they deal with daily.
For more than 10 years, the Internet Storm Center has been providing free analysis and warning to our community. Some of this year’s highlights include a talk by ISC handler Rob VandenBrink about using virtualization in a consulting practice, Adrien de Beaupre will describe the why and how of attacking your own web-based applications with ZAP, and Richard Porter will use current literature and research as a foundation to discuss the current insider threat and risks. Also, don’t miss the State of the Internet Panel Discussion with Dr. Johannes Ullrich, ISC Director and Marcus Sachs, ISC Director Emeritus.
SANSFIRE 2014 hosts world-class instructors teaching top-quality SANS courses covering penetration testing and hacker exploits, IT security, security management, computer forensics, secure coding, and much more.
Most of courses at SANSFIRE 2014 are associated with GIAC Certifications, and once again, our NetWars – Tournament and the DFIR NetWars Tournament will both be features as part of this event on the evenings of June 26 and 27.
New courses include:
FOR572: Advanced Network Forensics and Analysis taught by Philip Hagen
FOR585: Advanced Smartphone Forensics taught by Heather Mahalik
ICS410: ICS/SCADA Security Essentials (GIAC-GICSP) taught by Paul A. Henry
For complete details regarding SANSFIRE 2014 and to register, please visit:
http://www.sans.org/info/157550
***Save 5% on your SANSFIRE 2014 course registration with code: SecOrb5_SANS ***
It’s that time of year again, the 2nd annual HackMiami Conference is approaching, taking place May 9 – 11, 2014 at the Holiday Inn Oceanfront Hotel on Miami Beach, FL. Last year landed in Rolling Stone, who the hell knows what’s gonna happen this year.
Buy your tickets not before we fill up – https://www.hackmiami.com/buy/
SPEAKERS
Just for starters:
Presentations will be hosted by Dave Marcus, the head of threat intelligence at Intel Security, who will examine the latest trends in bulk malware campaigns, such as infection vectors, methods, and tools. Christopher Elisan, lead malware scientist at EMC RSA Threat Labs will also showcase the latest MacOS trojan infection samples as they relate to ransomware campaigns.
A special presentation by Dave Monnier, the Director of Threat Intelligence and Outreach at Team Cymru will examine the case of hundreds of thousands of compromised routers being used for botnet style DDoS attacks. These particular attacks may have had a potential connection to organized crime groups, and the evidence will be examined and analyzed.
TRAINING
We also got training courses from some of the top people in the industry:
Training courses take place on Friday, May 9, 2014 at the Holiday Inn Oceanfront Hotel in Miami Beach, FL.
Enterprise Penetration Testing Methods with Rod Soto – Friday – May 9, 2014 – This comprehensive course will go over the tools and methodologies that are used during penetration tests in enterprise network environments. The course will utilize a lab environment for hands on instruction of manual penetration testing methods, as well as training on the use of exploitation frameworks, such as Metasploit.
This course will focus on methodology, processes, tools, and techniques. By the end of the course, the student will have an understanding of the underlying workings of network exploitation, and will have experience in the successful execution of attacks.
The course is perfect for those seeking to enter the information security career field, as well as those seeking to develop the skills and experience needed to succeed as a penetration tester.
The course is taught by Rod Soto, co-founder of HackMiami and creator of the Kommand and Kontroll (K&&K) CTF Hacking Tournament.
https://hackmiami.com/training/enterprise-penetration-testing-methods/
Secure Coding Bootcamp wth Jim Manico – Friday – May 9, 2014 – This course will provide an highly intensive and interactive 1-day course provides essential application security training for web application, webservice and mobile software developers and architects.
The class is a combination of lecture, security testing demonstration and code review. Students will learn the most common threats against applications. More importantly, students will learn how to code secure web solutions via defense-based code samples.
The Secure Coding Bootcamp is taught by Jim Manico, world renowned author, Secure-Coding Instructor, and OWASP Global Board Member
https://hackmiami.com/secure-coding-bootcamp/
Web Application Hacking and Server Takeover with Matias Katz – Friday – May 9, 2014- This course will examine methods used to compromise and use web servers making use of different tools and methods. Students will understand how to make use of chained exploitation against multiple vulnerabilities in a realistic lab environment.
The Web Appication and Server Takeover course is taught by Matias Katz, the founder of Andsec and a known speaker who has presented at BlackHat, Ekoparty, H2HC, Campus party, OWASP and many other information security conferences.
https://hackmiami.com/training/web-application-hacking-and-server-takeover/
RFID/NFC workshop for fun (and profit?) – May 9, 2014 Enter the world of the RFID technology (Radio Freq. ID), focusing on highfrequency NFC standard. Also, the low frequency band will be reviewed because of its well-known use in individual physical access to buildings.
From the use of traditional NFC 13.56Mhz readers, their API and proprietary software, to Proxmark3 hardware, open source software (LibNFC), known attacks and other uses and practical ideas.
The course is taught by Nahuel Grisolía, owner of Cinta Infinita. He has delivered trainings in multiple conferences around the world: BugCON (Mexico), H2HC (Brazil), Ekoparty (Argentina), OWASP events (Argentina), TROOPERS (Germany), PHDays (Russia), etc.
https://hackmiami.com/training/rfidnfc-workshop-for-fun-and-profit/
==================
BUY YOUR TICKETS TODAY
Buy your ticket here: https://www.hackmiami.com/buy/
Buy your training here: https://www.hackmiami.com/trainings/
If you are a student, and can prove it, you have a discount code here: https://hackmiami.com/STUDENTSGA75/
Need a place to stay? Check AirBnB before you check any hotel – https://www.airbnb.com/tell-a-friend?airef=7mf7vzf1e23zz5
LIMITED AVAILABILITY – ACT NOW
==================
-Alex Heid-
@alexheid – Twitter
alex@hackmiami.info
www.hackmiami.org
www.hackmiami.com
SANS Security West 2014 is a vital event for information security professionals looking to stay on top of industry trends, to acquire certifications, and to learn and immediately apply new cybersecurity skills. Security West features:
* Panel discussions on emerging trends in cybersecurity
* 25+ hands-on immersion InfoSec courses
* Industry-leading instructors with real-world experience
=========================
Emerging Trends in Cybersecurity
=========================
Security West features emerging trends in cybersecurity and is highlighted by evening talks and star-studded panel discussions from teams who will present the following:
* Keynote: Emerging Security Trends: Crossing the Chasm to Protecting a “Choose Your Own IT” World presented by John Pescatore
* Emerging Trends Panel: DFIR led by Rob Lee
* Emerging Trends Panel: Offense Informs Defense, but How? led by Ed Skoudis
* Emerging Trends Panel: Will The Real Next Generation Security Please Stand Up? led by John Pescatore
=========================
Security Training Courses
=========================
This training event will offer more than 25 outstanding hands-on immersion courses for all security professionals in IT audit, security management, technical security, penetration testing, and computer forensics. At SANS Security West, you have the opportunity to advance your information security skillset, learn to prepare your organization for the future, and enjoy the Pacific Ocean and San Diego!
For a complete list of course descriptions and to register, please visit:
http://www.sans.org/info/154435
( Save 5% on your course with discount code: SecOrb5_SANS )
SANS will be back in Orlando at Disney for SANS 2014 with more than 40 courses, evening talks and activities, and vendor events. Please plan to attend on April 5-14 at the Walt Disney World Dolphin with our top-rated instructors and a full SANS Training Event experience. SANS 2014 is one of our biggest events where you will learn how to protect yourself and your organization; register now!
Register here:
http://www.sans.org/info/148640
(Save 5% on your course with discount code: SecOrb_SANS5 )
================================
New Cutting-Edge Courses
================================
– New! SEC503: Intrusion Detection In-Depth (GIAC-GCIA, Simulcast) taught by Mike Poor
– New! SEC561: Intense Hands-on Pen Testing Skill Development taught by Tim Medin
– New! FOR572: Advanced Network Forensics and Analysis taught by George Bakos and Philip Hagen
– New! MGT415: A Practical Introduction to Risk Assessment taught by James Tarala
For a list of all courses and complete descriptions at SANS 2014, please see:
http://www.sans.org/info/148640
