Security's Everyman

Security's Everyman
Showing posts with label SCC. Show all posts
Showing posts with label SCC. Show all posts

Wednesday, February 06, 2008

Security Catalysts Community Roundup

When I started following blogs a couple of years ago I discovered several blogger's who impressed me with their knowledge of various aspects of security. I thought I had hit a gold mine in finding their blogs. Now I had places to go and get information on various topics. I could even ask them questions and usually get a reply from them. Towards the end of 2006 a few of them started talking about a new community that was starting up. It offered a place to post your thoughts, questions, comments, ideas, etc and interact with other security professionals. So I decided to check it out and saw a few things that I liked.

  1. The boards weren't stuffed to the gills with questions so it made it easy to find what you were looking for.
  2. The boards are kept organized. There aren't hundreds of user created main topic areas that clutter the boards.
  3. When you posted a question or idea others chimed in with comments that were meaningful. There is no name calling or belittling others. If someone does do that their comment is removed and they may soon follow.
  4. You actually saw who you were interacting with and not some cryptic screen name. This allowed me to have a sense or whether or not I could trust them. All members are required to register with and use their real names. (OK, so we don't do ID checks on everyone but you get the picture)

These are just a few of the things  that I really liked. I then hooked up via email with Michael Santarcangello who could be called the "Father of the Security Catalyst Community". I had listened to his podcast and read his blog and liked what he had to say and the way that he thinks. He, like many in the SCC, doesn't think along the same old "best practices" lines that seem to infect many in IT and Security. He thought outside the box and tried to get others to do the same.

That was Jan. 2006 and since joining the SCC I have benefited tremendously. It has provided me a place to get answers, feedback, support and development friendships and networking with other Security Professionals. Lots of people have joined the community and many of them participate regularly in what is going on. I'd like to invite you to stop by and check out what is going on. I'm going to highlight a few of the conversations that have gone on in the recent past and a few of the people who have their own blogs. My goal in this is to give you a little more insight into what the community is all about and entice you to come join us and add your voice to what will become a major voice in security in the future.

Recent SCC Posts of note:

  • Rootkits and MBRs - As soon as news of the new (ok, not new but new in the news) MBR Rootkits hit the gang at the SCC jumped on this one. Read what the community has to say about this topic. I personally think that the first response post is packed with wisdom and insight. :)
  • ICMP Tunneling - I went back a while on this one because it has some useful information on a topic that we don't hear much about and many people haven't really considered as a threat to our data.
  •  Value of asp.net web.config file encryption - Here is another topic that isn't very sexy and doesn't get a lot of attention in the media and blogs but that doesn't stop us from discussing it. We all know the importance of web app security but we can't forget the server itself.
  • Project Management Training - We all like to stay on top of our game and training and opportunities to learn and improve ourselves is a major focus of the community. Here we discuss how to prepare yourself to be successful in Project Management.

We have lots of blogger's and others who have their own web sites. You can find a complete list of them by clicking on the "members" link from any page in the community and then click on the website column. Many of the names you will recognize right away because they are the "big names" in information security blogging (and usually in their field of specialty also) and some you may not be familiar with but they have great things to say. I wanted to bring a couple of them to your attention.

  • Michael Dickey (aka - LonerVamp) blogs at terminal23. Michael caught my attention early on because he has lots of good things to say. He's a Linux guru who understands security and has a great grasp on using linux both to help secure your environment and as your everyday OS. He can get pretty technical so beware. Sometimes he makes my head hurt.
  • Adam Dodge has a website called Educational Security Incidents (ESI) where he maintains a ongoing list and discussion of breaches in the .edu space. Those of you who work in the .edu space need to know Adam and his site. Colleges and Universities have their own unique challenges when it comes to information security that most of us don't face. They have to find the balance between the "free flow of data" nature in a university environment and protecting the PII, research and other important data. There are lots of other .edu security gurus in the community that will benefit you greatly if you are in that field.
  • Alex Hutton is another blogger that is worth your read. His focus is on Risk Management and he blogs at and maintains a site called Riskanalys.is (yes the .is is correct). Alex usually doesn't talk too technical but don't let that fool you. He knows his stuff from everyday security to the implications of not being compliant to how risk can make or break your company.

Well, that's it. A quick recap of what's going on in the Security Catalysts Community and why you should be involved.

Sunday, September 16, 2007

Travel, training and technology

Over the last couple of weeks I've been to two different "free" one day classes. The first one was put on by TechTarget's Searchsecurity.com and focused on Data Protection and Storage. It consisted of 3 or 4 sessions talking about various aspects of security data and a couple of round table discussions. This is the second free TechTarget seminar I've been to and I have to say that both of them were pretty good. Especially for the price. :) They both have been informative and I've either learned something new or they spurred some thoughts and ideas that have proven to be helpful to me.

The second class was done by Foundstone. It was a one day mini class of their Hacking Essentials class. The presenter was Carric Dooley and he spent the day covering basic hacking essentials. He discussed some of the threats, attack methods and ways we can protect against them. It was a good day but I don't think that I really learned anything new. Again, it did spur some thoughts and I met some good people that I look forward to getting to know better over the next few weeks. I must say I'm glad that Carric is on the good guys side. He is a smart guy that I wouldn't want trying to break into my network.

Hopefully I'm going to be in Cincinnati for a couple of days the week of the 24th. I'm planning on taking some Cisco training up there. If anyone is in the area let me know and maybe we can meet up. Then in October I'm going to Orlando for a day or two to meet with the other members of the Symantec Advisory Council and some of Symantecs team, including John Thompson. That will be a whirlwind trip, but hopefully it will be beneficial. The Symantec Council has been pretty much inactive since the beginning but they now seem to be on the road to getting it going. I know that Santa members who are also members of the will be there and I'm hoping that a couple of my buddies from the SCC will also be there. Michael Farnum, Alan Shimel, and Kurt Wismer are all SCC members who are also on the Symantec Council. I'm not sure if they will be there or not but I hope that they are so we can meet face to face. I've enjoyed the interaction I've had with them in the SCC and via email and our various blogs.

Lots of exciting things going on in the next few weeks. I hope that I have time to update you on what's going on and adding insight as I can.

Sunday, September 09, 2007

Security Catalyst Community

I know that many of you that read my blog also read Michael Santarcangello's blog and are members of the SCC. For those who didn't get the word and for those who forgot :) I wanted to remind you that the SCC web address has changed. Now to get the the SCC you need to go to:

www.securitycatalyst.org

The look has changed somewhat but the functionality and content are still the same. I encourage all of you to check it out and give serious consideration to joining. Those who participate quickly learn that this isn't just another forum. It's truly a community where people are excited about changing the way we do information security and how we protect data. I don't think you will be disappointed.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.