<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; risk</title>
	<atom:link href="http://www.novainfosecportal.com/tag/risk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:30:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Job: Chief Security Officer in Rockville, MD</title>
		<link>http://www.novainfosecportal.com/2011/12/06/job-chief-security-officer-in-rockville-md/</link>
		<comments>http://www.novainfosecportal.com/2011/12/06/job-chief-security-officer-in-rockville-md/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 22:27:01 +0000</pubDate>
		<dc:creator>judykavuo</dc:creator>
				<category><![CDATA[Job Board]]></category>
		<category><![CDATA[cso]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7188</guid>
		<description><![CDATA[Wanna be responsible for IT security for an entire organization? Well here&#8217;s your chance! It looks like a great opportunity for a very experienced infosec professional interested in a managerial or business leadership position. The opportunity requires 15-20 years of experience in a security role and someone who knows network security architecture and infrastructure. And don&#8217;t forget &#8230; if your organization is interested in posting their career opportunities here, head on over to our Job Board page for all the details. Well anyway &#8230; on to the job post. Overview A client of CSO Security Risk is seeking a Chief Security Officer (CSO) who will be responsible for directing activities of the corporate security function and operational risk management to enhance the value of the company and brand. The successful candidate will work closely with the VP of Infrastructure and Operations to manage security functions related to corporate information systems and data centers. The CSO will oversee a network of employees and vendors who safeguard the company&#8217;s assets, intellectual property and computer systems. Physical protection responsibilities will include physical safety of employees and visitors, asset protection, workplace violence prevention, access control systems, video surveillance, and more. Information protection responsibilities will [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Job%3A+Chief+Security+Officer+in+Rockville%2C+MD+http%3A%2F%2Fj.mp%2FupD5OP" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/12/06/job-chief-security-officer-in-rockville-md/&amp;t=Job%3A+Chief+Security+Officer+in+Rockville%2C+MD" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7193" src="http://www.novainfosecportal.com/wp-content/uploads/2011/12/cso-logo-300x152.jpg" alt="The Letters C, S, and O" width="300" height="152" />Wanna be responsible for IT security for an entire organization? Well here&#8217;s your chance! It looks like a great opportunity for a very experienced infosec professional interested in a managerial or business leadership position. The opportunity requires 15-20 years of experience in a security role and someone who knows network security architecture and infrastructure.</p>
<p>And don&#8217;t forget &#8230; if your organization is interested in posting their career opportunities here, head on over to our <a href="/general/job-board/">Job Board</a> page for all the details. Well anyway &#8230; on to the job post.</p>
<p><strong>Overview</strong></p>
<p>A client of CSO Security Risk is seeking a Chief Security Officer (CSO) who will be responsible for directing activities of the corporate security function and operational risk management to enhance the value of the company and brand. The successful candidate will work closely with the VP of Infrastructure and Operations to manage security functions related to corporate information systems and data centers.</p>
<p>The CSO will oversee a network of employees and vendors who safeguard the company&#8217;s assets, intellectual property and computer systems. Physical protection responsibilities will include physical safety of employees and visitors, asset protection, workplace violence prevention, access control systems, video surveillance, and more. Information protection responsibilities will include firewalls, network security architecture and infrastructure, network access and monitoring policies, employee education and awareness, and more. This person must be able to develop and implement flexible security solutions, dictated by the needs of a hybrid and rapidly evolving decentralized business environment.</p>
<p><strong>Roles &amp; Functions</strong></p>
<ul>
<li>Work closely with corporate executives, business managers, audit and legal counsel to understand corporate requirements related to security and regulatory compliance, and to map those requirements to current security projects</li>
<li>Manage the development and implementation of global policies, processes, and guidelines related to corporate security strategy and associated architecture and engineering standards to ensure ongoing maintenance of security</li>
<li>Oversee the continuous monitoring and protection of facilities, personnel and information systems. Evaluate suspected security breaches and recommend corrective actions (including incidents involving outside vendors)</li>
<li>Define and implement an ongoing Risk Assessment program, which will define, identify, and classify critical assets, assess threats and vulnerabilities regarding those assets, and implement safeguard recommendations</li>
<li>Assist internal audits in the development of appropriate criteria needed to assess the level of new/existing applications and/or technology infrastructure elements for compliance with enterprise security standards</li>
<li>Establish and monitor formal certification programs regarding enterprise security standards relating to the planned acquisition and/or procurement of new applications or technologies</li>
<li>Assist in the review of applications and/or technology environments during the development or acquisitions process to (a) assure compliance with corporate security policies and directions and (b) assist in the overall integration process regarding the company&#8217;s own technology environment</li>
<li>Oversee the development of, and be the enterprise champion of, a corporate security awareness and training program</li>
<li>&#8230;</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>At least 15-20 years of experience in a security role, with proven leadership experience in enterprise security</li>
<li>Must have experience in a managed healthcare/HIPAA compliant company</li>
<li>Must be an intelligent, articulate and persuasive leader who can serve as an effective member of the senior management team</li>
<li>Able to communicate security-related concepts to a broad range of technical and non-technical staff</li>
<li>Should have experience with business continuity planning, auditing, and risk management, as well as contract and vendor negotiation</li>
<li>Must have strong working knowledge of pertinent law and the law enforcement community</li>
<li>Must have a solid understanding of information technology and information security</li>
<li>Must be an excellent public speaker who can interface effectively with external customers</li>
<li>Must be a results-oriented person who can achieve tangible improvements in the corporate security arena</li>
<li>Excellent technical and communications skills are a must+</li>
</ul>
<p>For additional details and contact information on how to apply for this position, please head over to the <a href="http://www.csoonline.com/security/jobs/detail/1882">posting on CSO Online</a>.</p>
<p align="center">#####</p>
<p style="text-align: center"><em>You can find more career opportunities over on our <a href="/general/job-board/">Job Board</a>. Head on over there for all the details. Today&#8217;s post image is from <a href="http://honeywellnow.files.wordpress.com/2009/05/cso-logo.jpg">HoneyWellNow.files</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Job%3A+Chief+Security+Officer+in+Rockville%2C+MD+http%3A%2F%2Fj.mp%2FupD5OP" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/12/06/job-chief-security-officer-in-rockville-md/&amp;t=Job%3A+Chief+Security+Officer+in+Rockville%2C+MD" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2011/12/06/job-chief-security-officer-in-rockville-md/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype and the Enterprise</title>
		<link>http://www.novainfosecportal.com/2011/11/28/skype-and-the-enterprise/</link>
		<comments>http://www.novainfosecportal.com/2011/11/28/skype-and-the-enterprise/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 01:43:18 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[skype]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7085</guid>
		<description><![CDATA[I read an interesting article this morning over on InfosecIsland.com that discussed the security of using Skype in the enterprise. As expected it didn&#8217;t give us the magic &#8220;yes&#8221; or &#8220;no&#8221; but instead the typical &#8220;it depends.&#8221; Overall, I thought the author made a very good point in that we trust a lot of our data to third parties, as I&#8217;ve mentioned in my teleconference security post, and Skype is just another third-party. The decision to use Skype should just follow the same considerations you&#8217;d normally take when acquiring any new third-party service. But I know &#8230; you want the magic &#8220;yes&#8221; or &#8220;no&#8221;&#8230; The article described the initial premise of &#8220;within a business environment for very specific cases.&#8221; And let&#8217;s assume that those &#8220;specific cases&#8221; don&#8217;t include discussing your top-secret plans to take over the world. I&#8217;d say go for it! Furthermore, I&#8217;d say probably 95% of the content in our daily conversations is already publicly known (shoulders, giants, dwarfs and all), mindless dribble, gossip or basically stuff that just isn&#8217;t sensitive at all and as such it&#8217;s fine to use Skype practically all the time. No sense throwing the baby out with the bathwater&#8230; via InfosecIsland.com SecureState was [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Skype+and+the+Enterprise+http%3A%2F%2Fj.mp%2FuEOebr" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/11/28/skype-and-the-enterprise/&amp;t=Skype+and+the+Enterprise" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7087" title="Throwing the Baby Out with the Bathwater" src="http://www.novainfosecportal.com/wp-content/uploads/2011/11/baby-bathwater-300x200.jpg" alt="Confused Baby in Bathtub" width="210" height="140" />I read an interesting article this morning over on InfosecIsland.com that discussed the security of using Skype in the enterprise. As expected it didn&#8217;t give us the magic &#8220;yes&#8221; or &#8220;no&#8221; but instead the typical &#8220;it depends.&#8221; Overall, I thought the author made a very good point in that we trust a lot of our data to third parties, as I&#8217;ve mentioned in my <a title="The Vulnerability We All Love to Ignore" href="/2011/10/13/the-vulnerability-we-all-love-to-ignore/">teleconference security post</a>, and Skype is just another third-party. The decision to use Skype should just follow the same considerations you&#8217;d normally take when acquiring any new third-party service.</p>
<p>But I know &#8230; you want the magic &#8220;yes&#8221; or &#8220;no&#8221;&#8230; The article described the initial premise of <em>&#8220;within a business environment for very specific cases.&#8221;</em> And let&#8217;s assume that those <em>&#8220;specific cases&#8221;</em> don&#8217;t include discussing your top-secret plans to take over the world. I&#8217;d say go for it!</p>
<p>Furthermore, I&#8217;d say probably 95% of the content in our daily conversations is already publicly known (shoulders, giants, dwarfs and all), mindless dribble, gossip or basically stuff that just isn&#8217;t sensitive at all and as such it&#8217;s fine to use Skype practically all the time. No sense throwing the baby out with the bathwater&#8230;</p>
<p>via InfosecIsland.com</p>
<blockquote><p>SecureState was recently asked if using Skype within a business environment for very specific cases was a good idea.</p>
<p>The company asking the question was unsure of the security implications and what risk would be introduced by implementing the Skype application.</p>
<p>Concerns over security and privacy have existed ever since Skype was launched over eight years ago. What is the consensus now regarding data protection when using Skype in the enterprise?</p></blockquote>
<p>Continued <a href="https://www.infosecisland.com/blogview/18371-Skype-in-the-Enterprise-Is-Your-Security-Program-Ready-to-Chat.html">here</a>.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>What do you think? Is Skype secure enough? Trusted enough? This article&#8217;s post image was found over at <a href="http://www.parkerliveonline.com/2011/07/26/off-the-wall-6/">ParkerLiveOnline.com</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Skype+and+the+Enterprise+http%3A%2F%2Fj.mp%2FuEOebr" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/11/28/skype-and-the-enterprise/&amp;t=Skype+and+the+Enterprise" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2011/11/28/skype-and-the-enterprise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Job: Security Engineer II in Fairfax, VA</title>
		<link>http://www.novainfosecportal.com/2011/11/25/job-security-engineer-ii-in-fairfax-va/</link>
		<comments>http://www.novainfosecportal.com/2011/11/25/job-security-engineer-ii-in-fairfax-va/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 18:43:48 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Job Board]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[engineer]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[icf]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7025</guid>
		<description><![CDATA[Looks like a great job opportunity has turned up over at the NoVA Hackers Association&#8217;s  facility host. I know several of the folks that work in their security department over there and it seems like a challenging and rewarding place to work. The Company ICF International (NASDAQ:ICFI) partners with government and commercial clients to deliver professional services and technology solutions in the energy and climate change; environment and infrastructure; health, human services, and social programs; and homeland security and defense markets. The firm combines passion for its work with industry expertise and innovative analytics to produce compelling results throughout the entire program life cycle, from research and analysis through implementation and improvement. Since 1969, ICF has been serving government at all levels, major corporations, and multilateral institutions. More than 3,500 employees serve these clients worldwide. ICF&#8217;s Web site is www.icfi.com. Job Description ICF International is currently looking for a Security Engineer II with enterprise security architecture and engineering experience. This position will report directly to the Information Security Officer in the Corporate Information Technology group. The Security Engineer II will implement, utilize and maintain security solutions related to host and network based intrusion detection and prevention, access control, system hardening, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Job%3A+Security+Engineer+II+in+Fairfax%2C+VA+http%3A%2F%2Fj.mp%2FuMcXef" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/11/25/job-security-engineer-ii-in-fairfax-va/&amp;t=Job%3A+Security+Engineer+II+in+Fairfax%2C+VA" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7027" title="ICF International" src="http://www.novainfosecportal.com/wp-content/uploads/2011/11/icflogo-300x149.jpg" alt="ICF Logo" width="240" height="119" />Looks like a great job opportunity has turned up over at the NoVA Hackers Association&#8217;s  facility host. I know several of the folks that work in their security department over there and it seems like a challenging and rewarding place to work.</p>
<p><strong>The Company</strong></p>
<p>ICF International (NASDAQ:ICFI) partners with government and commercial clients to deliver professional services and technology solutions in the energy and climate change; environment and infrastructure; health, human services, and social programs; and homeland security and defense markets. The firm combines passion for its work with industry expertise and innovative analytics to produce compelling results throughout the entire program life cycle, from research and analysis through implementation and improvement. Since 1969, ICF has been serving government at all levels, major corporations, and multilateral institutions. More than 3,500 employees serve these clients worldwide. ICF&#8217;s Web site is www.icfi.com.</p>
<p><strong>Job Description</strong></p>
<p>ICF International is currently looking for a Security Engineer II with enterprise security architecture and engineering experience. This position will report directly to the Information Security Officer in the Corporate Information Technology group.</p>
<p>The Security Engineer II will implement, utilize and maintain security solutions related to host and network based intrusion detection and prevention, access control, system hardening, firewalls, encryption, PKI, and configuration/incident/vulnerability management. The Security Engineer II will interface with internal and external users and ICF business clients to identify, mitigate, and provide timely resolution of information security issues and events.</p>
<p><strong>Qualifications</strong></p>
<p><strong><em>Key Responsibilities:</em></strong></p>
<ul>
<li>Serve as an internal information security consultant to the organization</li>
<li>Enforce compliance with information security policies and procedures</li>
<li>Initiate, facilitate, and promote information security awareness</li>
<li>Perform risk assessments and serve as an internal auditor for security issues</li>
<li>Perform security assessments, penetration tests, and code reviews</li>
<li>Conduct incident response and system triage</li>
<li>Conduct forensic investigations of systems and network communications</li>
</ul>
<p><em><strong>Basic Qualifications:</strong></em></p>
<ul>
<li>Bachelor&#8217;s degree</li>
<li>At least 3 years of experience working in an environment performing information security related tasks as defined responsibilities or comparable experience conducting documented information security research is required.</li>
<li>At least 1 year of experience scripting and/or programming experience (Python, Ruby,C, Java)</li>
<li>Experience identifying and resolving security issues on computer systems</li>
<li>Experience with log monitoring, analysis, and correlation</li>
<li>Experience performing enterprise incident monitoring, response, and analysis</li>
<li>Experience using commercial and open source security software such as Nmap, Nessus, Wireshark, Rapid7, WebInspect, Metaspl0it Framework, Ettercap, Burp Suite, etc</li>
</ul>
<p><strong><em>Special Job Conditions:</em></strong></p>
<ul>
<li>Must be bondable</li>
<li>Must be able to live 25lbs</li>
<li>Must pass background check and drug screen</li>
<li>Must be available for on-call incident response</li>
<li>Must be available to work scheduled hours for position</li>
<li>Must be available to work overtime if necessary to meet deadlines</li>
</ul>
<p><strong><em>Preferred Skills/Experience:</em></strong></p>
<ul>
<li>Bachelor&#8217;s degree in Computer Science, Information Systems Engineering, Computer Forensics or Computer/IT related degree</li>
<li>Systems Engineering, Computer Forensics, or an equivalent amount of IT industry training and/or work experience</li>
<li>Web application testing and/or development experience</li>
<li>Experience conducting forensic analysis and investigations</li>
<li>Experience working with databases and implementing database security controls</li>
<li>Experience managing Arcsight Logger and/or Arcsight ESM</li>
<li>Malware analysis and reverse engineering experience</li>
<li>Familiarity and understanding of Microsoft, Apple, and UNIX/Linux operating systems</li>
<li>Knowledge of current NIST and Executive security policies, standards, and regulations</li>
<li>Strong knowledge of TCP/IP communication, routing protocols, and client server communication technology</li>
<li>Ability to apply for and be granted a Top Secret security clearance</li>
<li>Any of the following certifications:</li>
<ul>
<li>Microsoft: MCITP, MCTS, MCPD</li>
<li>Cisco: CCNA, CCNA-Security, CCNP, CCSP</li>
<li>IT Governance: CISA, CISM, GSNA</li>
<li>General: CISSP, SSCP, GSEC, GISP</li>
<li>Linux: RHCE, LPI</li>
<li>Offensive: OSCP, OSCE, OSWP, GPEN</li>
<li>Forensics: EnCE, GCFE, GCFA, GREM</li>
<li>ArcSight: ACSA, ACIA, ACASA, ACAIA</li>
<li>Applications: GWAPT</li>
<li>Incidents: GCIA, GCIH</li>
</ul>
</ul>
<p><strong><em>Professional Skills:</em></strong></p>
<ul>
<li>Able to present a professional appearance and demeanor at all times</li>
<li>Strong oral and written communication and organization skills</li>
</ul>
<p>ICF offers an excellent benefits package, an award winning talent development program, and fosters a highly skilled, energized and empowered workforce.</p>
<p>ICF International is an Equal Opportunity and Affirmative Action Employer &#8211; M/F/D/V</p>
<p>To apply for this position please visit<a href="http://www.icfi.com/careers/"> ICF&#8217;s Career Center</a> and search for job number 1100002525.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Today&#8217;s post image is from <a href="http://nationaldefensemegadirectory.com/company.php?id=407329&amp;company=ICF+International">NationalDefenseMegaDirectory.com</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Job%3A+Security+Engineer+II+in+Fairfax%2C+VA+http%3A%2F%2Fj.mp%2FuMcXef" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/11/25/job-security-engineer-ii-in-fairfax-va/&amp;t=Job%3A+Security+Engineer+II+in+Fairfax%2C+VA" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2011/11/25/job-security-engineer-ii-in-fairfax-va/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIST Wants You &#8230; Again &#8230; this Time for Risk Assessment</title>
		<link>http://www.novainfosecportal.com/2011/09/26/nist-wants-you-again-this-time-for-risk-assessment/</link>
		<comments>http://www.novainfosecportal.com/2011/09/26/nist-wants-you-again-this-time-for-risk-assessment/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 21:20:48 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[800-30]]></category>
		<category><![CDATA[feedback]]></category>
		<category><![CDATA[govinfosecurity]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=6426</guid>
		<description><![CDATA[Last week I noticed NIST put out another draft infosec document that they need comments on. This time the publication that needs updated is SP 800-30, Guide for Conducting Risk Assessment, Revision 1. And updated it is in need of&#8230; NIST released the original version almost 10 years ago. Then it was known as the &#8220;Risk Management Guide for Information Technology Systems.&#8221; This revision narrows the focus of the document to just risk assessment rather than the entire risk management process. As you may know SP 800-39, Managing Information Security Risk, has taken over those duties. Over the years we&#8217;ve had several posts discussing this key document. @rybolov talked about it way back in 2008 where he discussed how NIST should not change it. SP 800-30 also made several appearances at many of the local meetups, including this ISSA DC meeting two years ago. A few months later @rybolov hit on it again in an overview post about NIST&#8217;s core publications. NIST puts these recommendations out and many of us working around DC have to deal with them due to customer requirements. And we spend a lot of time complaining about what they should and shouldn&#8217;t be. Instead of complaining, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=NIST+Wants+You+%E2%80%A6+Again+%E2%80%A6+this+Time+for+Risk+Assessment+http%3A%2F%2Fj.mp%2Fq4cs4b" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/09/26/nist-wants-you-again-this-time-for-risk-assessment/&amp;t=NIST+Wants+You+%E2%80%A6+Again+%E2%80%A6+this+Time+for+Risk+Assessment" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-full wp-image-6434" title="Risk Assessment" src="http://www.novainfosecportal.com/wp-content/uploads/2011/09/risk-assessment.jpg" alt="Puzzle Piece with Risk Assessment On It" width="168" height="168" />Last week I noticed NIST put out another draft infosec document that they need comments on. This time the publication that needs updated is SP 800-30, Guide for Conducting Risk Assessment, Revision 1. And updated it is in need of&#8230; NIST released the original version almost 10 years ago. Then it was known as the &#8220;Risk Management Guide for Information Technology Systems.&#8221; This revision narrows the focus of the document to just risk assessment rather than the entire risk management process. As you may know SP 800-39, Managing Information Security Risk, has taken over those duties.</p>
<p>Over the years we&#8217;ve had several posts discussing this key document. @<a href="http://twitter.com/rybolov">rybolov</a> talked about it way back in 2008 where he discussed how NIST should <a href="/2008/06/16/the-way-not-to-change-nist-sp-800-30/">not change it</a>. SP 800-30 also made several appearances at many of the local meetups, including <a href="/2009/06/10/issa-dc-chapter-infosec-meetup-event-tuesday-07-16-changes-in-nist-800-53/">this ISSA DC meeting</a> two years ago. A few months later @<a href="http://twitter.com/rybolov">rybolov</a> <a href="/2009/12/14/old-saint-nist-ho-ho-hold-on-what%E2%80%99s-this/">hit on it again </a>in an overview post about NIST&#8217;s core publications.</p>
<p>NIST puts these recommendations out and many of us working around DC have to deal with them due to customer requirements. And we spend a lot of time complaining about what they should and shouldn&#8217;t be. Instead of complaining, this is our chance &#8230; again &#8230; to give some feedback.</p>
<p>You can grab a copy of the draft <a href="http://csrc.nist.gov/publications/drafts/800-30-rev1/SP800-30-Rev1-ipd.pdf">here</a> [PDF]. Comments should be emailed to <a href="mailto:sec-cert@nist.gov">sec-cert@nist.gov</a> by November 11th.</p>
<p>via GovInfoSecurity.com</p>
<blockquote><p>The National Institute of Standards and Technology unveiled Monday its initial draft of an update to its Guide for Conducting Risk Assessment, Special Publication 800-30, Revision 1.</p>
<p>The update&#8217;s focus on risk assessment, one of the four steps in the risk management process, expands from the earlier version of SP 800-30 to include more in-depth information on a variety of factors essential to determining information security risk, such as threat sources and events, vulnerabilities and impact and likelihood of threat occurrence. The draft guidance describes a three-step process that includes key activities to prepare for risk assessments, activities to successfully conduct risk assessments and approaches to maintain the currency of assessment results.</p></blockquote>
<p>Continued <a href="http://www.govinfosecurity.com/articles.php?art_id=4078">here</a>.</p>
<p>InfosecIsland.com also had a <a href="https://www.infosecisland.com/blogview/16668-Risk-Assessment-Guide-for-Federal-Information-Systems.html">recent article on SP 800-30</a> that you may want to check out if you&#8217;re looking for a different perspective.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Today&#8217;s post image is from <a href="http://www.networkarmor.com/Solutions/RiskAssessment/tabid/77/Default.aspx">NetworkArmor.com</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=NIST+Wants+You+%E2%80%A6+Again+%E2%80%A6+this+Time+for+Risk+Assessment+http%3A%2F%2Fj.mp%2Fq4cs4b" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/09/26/nist-wants-you-again-this-time-for-risk-assessment/&amp;t=NIST+Wants+You+%E2%80%A6+Again+%E2%80%A6+this+Time+for+Risk+Assessment" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2011/09/26/nist-wants-you-again-this-time-for-risk-assessment/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Follow-Up: OWASP &#8211; DC/MD Local Chapter Infosec Meetup Event &#8211; Wednesday, 08-20</title>
		<link>http://www.novainfosecportal.com/2008/08/28/follow-up-owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20/</link>
		<comments>http://www.novainfosecportal.com/2008/08/28/follow-up-owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 06:22:31 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[booth]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[fisher]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[meetup]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp-dc/md]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=273</guid>
		<description><![CDATA[The OWASP &#8211; DC/MD Local Chapter infosec meetup event last week featured Rex Booth giving an introduction to OWASP, Matt Fisher looking at web risks and assessments, and a general discussion of BlackHat and DefCon. I wasn&#8217;t able to go but Rex has recently posted his notes from this session to the OWASP &#8211; DC/MD email list for those interested. See our original post for more information.]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Follow-Up%3A+OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20+http%3A%2F%2Fj.mp%2FqqAOT9" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/08/28/follow-up-owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20/&amp;t=Follow-Up%3A+OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>The <a href="http://www.novainfosecportal.com/events/nova-meetups/#owasp-dc">OWASP &#8211; DC/MD Local Chapter</a> infosec meetup event last week featured Rex Booth giving an introduction to OWASP, Matt Fisher looking at web risks and assessments, and a general discussion of BlackHat and DefCon. I wasn&#8217;t able to go but Rex has recently posted his <a href="http://www.mail-archive.com/owasp-washington@lists.owasp.org/msg00000.html">notes from this session</a> to the OWASP &#8211; DC/MD email list for those interested. See our <a href="http://www.novainfosecportal.com/2008/08/20/owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20-owasp-web-assessments-and-con-reviews/">original post</a> for more information.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Follow-Up%3A+OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20+http%3A%2F%2Fj.mp%2FqqAOT9" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/08/28/follow-up-owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20/&amp;t=Follow-Up%3A+OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2008/08/28/follow-up-owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OWASP &#8211; DC/MD Local Chapter Infosec Meetup Event &#8211; Wednesday, 08-20: OWASP, Web Assessments, and Con Reviews</title>
		<link>http://www.novainfosecportal.com/2008/08/20/owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20-owasp-web-assessments-and-con-reviews/</link>
		<comments>http://www.novainfosecportal.com/2008/08/20/owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20-owasp-web-assessments-and-con-reviews/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 05:21:51 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[booth]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[fisher]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[meetup]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp-dc/md]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=244</guid>
		<description><![CDATA[Here is some information regarding this week&#8217;s Wednesday OWASP &#8211; DC/MD Local Chapter infosec meetup event. Upon arriving please go to the 9th floor and sign in. Someone will escort you to the meeting location (room 8S026). If you are late and can not get in, please call (202) 270-8715. Who: Rex Booth, Grant Thornton LLP &#38; Matt Fisher What: Booth &#8211; Introduction to OWASP Fisher &#8211; The Big Picture: Web Risks and Assessments Beyond Scanning: This talk will focus on the need to run risk and threat model software and pick appropriate people, tools, and testing techniques to test against the threat model. In today&#8217;s resource-constrained market many organizations are simply turning to automation to test their software security without truly understanding the limitations. This talk will discuss some of the broader threat cases, testing techniques for them, and whether current state of the industry technology is effective against them. Group Discussion &#8211; Security Conference Review: BlackHat &#38; DefCon When: 8/20, 6:30 PM EDT Where: Deloitte &#38; Touche (1001 G Street NW; Washington, DC 20001) For more information on the OWASP &#8211; DC/MD Local Chapter, see its description in our NoVA Meetups section. See our Calendar for a complete [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20%3A+OWASP%2C+Web+Assessments%2C+and+Con+Reviews+http%3A%2F%2Fj.mp%2Fq8AcRk" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/08/20/owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20-owasp-web-assessments-and-con-reviews/&amp;t=OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20%3A+OWASP%2C+Web+Assessments%2C+and+Con+Reviews" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>Here is some information regarding this week&#8217;s Wednesday <a href="http://www.novainfosecportal.com/events/nova-meetups/#owasp-dc">OWASP &#8211; DC/MD Local Chapter</a> infosec meetup event. Upon arriving please go to the 9th floor and sign in. Someone will escort you to the meeting location (room 8S026). If you are late and can not get in, please call (202) 270-8715.</p>
<p><span id="more-244"></span></p>
<ul>
<li><strong>Who:</strong> Rex Booth, Grant Thornton LLP &amp; Matt Fisher</li>
<li><strong>What:</strong>
<ul>
<li>Booth &#8211; Introduction to OWASP</li>
<li>Fisher &#8211; The Big Picture: Web Risks and Assessments Beyond Scanning: This talk will focus on the need to run risk and threat model software and pick appropriate people, tools, and testing techniques to test against the threat model. In today&#8217;s resource-constrained market many organizations are simply turning to automation to test their software security without truly understanding the limitations. This talk will discuss some of the broader threat cases, testing techniques for them, and whether current state of the industry technology is effective against them.</li>
<li>Group Discussion &#8211; Security Conference Review: BlackHat &amp; DefCon</li>
</ul>
</li>
<li><strong>When:</strong> 8/20, 6:30 PM EDT</li>
<li><strong>Where:</strong> <a href="http://www.deloitte.com/">Deloitte &amp; Touche</a> (<a href="http://maps.google.com/maps?f=q&amp;hl=en&amp;geocode=&amp;q=1001+G+Street+NW+Washington+DC+20001&amp;sll=37.0625,-95.677068&amp;sspn=48.106236,72.949219&amp;ie=UTF8&amp;z=16&amp;iwloc=addr">1001 G Street NW; Washington, DC 20001</a>)</li>
</ul>
<p>For more information on the OWASP &#8211; DC/MD Local Chapter, see its <a href="http://www.novainfosecportal.com/events/nova-meetups/#owasp-dc">description</a> in our <a href="http://www.novainfosecportal.com/events/nova-meetups/">NoVA Meetups</a> section. See our <a href="http://www.novainfosecportal.com/events/full-calendar/">Calendar</a> for a complete list of infosec events in and around the NoVA area. Here is a link to the <a href="http://www.owasp.org/index.php/Washington_DC">page with information on this meetup</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20%3A+OWASP%2C+Web+Assessments%2C+and+Con+Reviews+http%3A%2F%2Fj.mp%2Fq8AcRk" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/08/20/owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20-owasp-web-assessments-and-con-reviews/&amp;t=OWASP+%E2%80%93+DC%2FMD+Local+Chapter+Infosec+Meetup+Event+%E2%80%93+Wednesday%2C+08-20%3A+OWASP%2C+Web+Assessments%2C+and+Con+Reviews" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2008/08/20/owasp-dcmd-local-chapter-infosec-meetup-event-wednesday-08-20-owasp-web-assessments-and-con-reviews/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Way Not to Change NIST SP 800-30</title>
		<link>http://www.novainfosecportal.com/2008/06/16/the-way-not-to-change-nist-sp-800-30/</link>
		<comments>http://www.novainfosecportal.com/2008/06/16/the-way-not-to-change-nist-sp-800-30/#comments</comments>
		<pubDate>Mon, 16 Jun 2008 14:26:49 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[800-30]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[rybolov]]></category>
		<category><![CDATA[the guerilla ciso]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/2008/06/16/the-way-not-to-change-nist-sp-800-30/</guid>
		<description><![CDATA[Rybolov from The Guerilla CISO, a local infosec NoVA-based blog, has put together a great blog post about NIST&#8217;s latest effort to modernize SP 800-30: Risk Management Guide for Information Systems. In his post he stresses how NIST should not change this document into a &#8220;catalog of controls gap analysis&#8221; process to favor compliance management over risk management. Overall, Rybolov is right on point! We really need to stop stressing being compliant and start focusing on risk management. Compliance should be a by-product of risk management, not the other way around.]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=The+Way+Not+to+Change+NIST+SP+800-30+http%3A%2F%2Fj.mp%2FnqBDfj" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/06/16/the-way-not-to-change-nist-sp-800-30/&amp;t=The+Way+Not+to+Change+NIST+SP+800-30" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>Rybolov from <a href="http://www.novainfosecportal.com/category/resources/infosec-blogs-podcasts/#guerilla">The Guerilla CISO</a>, a local infosec NoVA-based blog, has put together a great blog post about NIST&#8217;s latest effort to <a href="http://www.guerilla-ciso.com/archives/406">modernize SP 800-30: Risk Management Guide for Information Systems</a>. In his post he stresses how NIST should not change this document into a &#8220;catalog of controls gap analysis&#8221; process to favor compliance management over risk management.</p>
<p>Overall, Rybolov is right on point! We really need to stop stressing being compliant and start focusing on risk management. Compliance should be a by-product of risk management, not the other way around.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=The+Way+Not+to+Change+NIST+SP+800-30+http%3A%2F%2Fj.mp%2FnqBDfj" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/06/16/the-way-not-to-change-nist-sp-800-30/&amp;t=The+Way+Not+to+Change+NIST+SP+800-30" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2008/06/16/the-way-not-to-change-nist-sp-800-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ISSA &#8211; NoVA Chapter Infosec Meetup Event &#8211; Thursday, 5/15: Managing the Risk Equation &#8211; Cyber Attacks and Data Loss Prevention</title>
		<link>http://www.novainfosecportal.com/2008/05/13/issa-nova-chapter-infosec-meetup-event-thursday-515-managing-the-risk-equation-cyber-attacks-and-data-loss-prevention/</link>
		<comments>http://www.novainfosecportal.com/2008/05/13/issa-nova-chapter-infosec-meetup-event-thursday-515-managing-the-risk-equation-cyber-attacks-and-data-loss-prevention/#comments</comments>
		<pubDate>Wed, 14 May 2008 01:56:17 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[issa-nova]]></category>
		<category><![CDATA[loss]]></category>
		<category><![CDATA[meetup]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/2008/05/13/issa-nova-chapter-infosec-meetup-event-thursday-515-managing-the-risk-equation-cyber-attacks-and-data-loss-prevention/</guid>
		<description><![CDATA[Here is some information regarding this week&#8217;s Thursday ISSA &#8211; NoVA Chapter infosec meetup event. Who: David Graziano What: Managing the Risk Equation: Cyber Attacks and Data Loss Prevention This session will investigate examples of cyber attacks, an examination of technological and psychological methodologies employed by hackers, plus proper defense-in-depth strategies to mitigate these threats. Many of these solutions will provide improved visibility and situational awareness that mitigate cyber threats as automatic enforcement of security policy. When: 5/15, 6:30 PM EST Where: Nortel Government Solutions (12730 Fair Lakes Circle, Fairfax, VA 22033) For more information on ISSA &#8211; NoVA Chapter, see its description in our NoVA Meetups section. Here are links to the post about this meetup.]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ISSA+%E2%80%93+NoVA+Chapter+Infosec+Meetup+Event+%E2%80%93+Thursday%2C+5%2F15%3A+Managing+the+Risk+Equation+%E2%80%93+Cyber+Attacks+and+Data+Loss+Pr...+http%3A%2F%2Fj.mp%2FrhK0V0" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/05/13/issa-nova-chapter-infosec-meetup-event-thursday-515-managing-the-risk-equation-cyber-attacks-and-data-loss-prevention/&amp;t=ISSA+%E2%80%93+NoVA+Chapter+Infosec+Meetup+Event+%E2%80%93+Thursday%2C+5%2F15%3A+Managing+the+Risk+Equation+%E2%80%93+Cyber+Attacks+and+Data+Loss+Prevention" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p>Here is some information regarding this week&#8217;s Thursday <a href="http://www.novainfosecportal.com/category/events/nova-meetups/#issa-nova">ISSA &#8211; NoVA Chapter</a> infosec meetup event.<span id="more-58"></span></p>
<ul>
<li><strong>Who:</strong> David Graziano</li>
<li><strong>What:</strong> Managing the Risk Equation: Cyber Attacks and Data Loss Prevention
<ul>
<li>This session will investigate examples of cyber attacks, an examination of technological and psychological methodologies employed by hackers, plus proper defense-in-depth strategies to mitigate these threats. Many of these solutions will provide improved visibility and situational awareness that mitigate cyber threats as automatic enforcement of security policy.</li>
</ul>
</li>
<li><strong>When:</strong> 5/15, 6:30 PM EST</li>
<li><strong>Where:</strong> Nortel Government Solutions (12730 Fair Lakes Circle, Fairfax, VA 22033)</li>
</ul>
<p>For more information on ISSA &#8211; NoVA Chapter, see its <a href="http://www.novainfosecportal.com/category/events/nova-meetups/#issa-nova">description</a> in our <a href="http://www.novainfosecportal.com/category/events/nova-meetups/">NoVA Meetups</a> section. Here are links to the <a href="http://www.issa-nova.org/">post about this meetup</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ISSA+%E2%80%93+NoVA+Chapter+Infosec+Meetup+Event+%E2%80%93+Thursday%2C+5%2F15%3A+Managing+the+Risk+Equation+%E2%80%93+Cyber+Attacks+and+Data+Loss+Pr...+http%3A%2F%2Fj.mp%2FrhK0V0" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2008/05/13/issa-nova-chapter-infosec-meetup-event-thursday-515-managing-the-risk-equation-cyber-attacks-and-data-loss-prevention/&amp;t=ISSA+%E2%80%93+NoVA+Chapter+Infosec+Meetup+Event+%E2%80%93+Thursday%2C+5%2F15%3A+Managing+the+Risk+Equation+%E2%80%93+Cyber+Attacks+and+Data+Loss+Prevention" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2008/05/13/issa-nova-chapter-infosec-meetup-event-thursday-515-managing-the-risk-equation-cyber-attacks-and-data-loss-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

