Skip to main content

Home/ NBISE Institute/ Group items tagged NBISE

Rss Feed Group items tagged

dhtobey Tobey

Lockheed Martin hit by cyber attack - Yahoo! Finance - 0 views

  • Lolita C. Baldor, Associated Press, On Sunday May 29, 2011, 4:13 am EDT
  • Hackers launched a "significant and tenacious" cyber attack on Lockheed Martin, a major defense contractor holding highly sensitive information, but its secrets remained safe, the company said Saturday.
  • Lt. Col. April Cunningham, speaking for the Defense Department, said the impact on the Pentagon "is minimal and we don't expect any adverse effect."
  • ...1 more annotation...
  • Chris Ortman, Homeland Security spokesman, said his agency and the Pentagon were working with the company to determine the breadth of the attack and "provide recommendations to mitigate further risk."Lockheed Martin said in a statement that it detected the May 21 attack "almost immediately" and took countermeasures.
  •  
    Attack announcement that should be included in NBISE CoP library.
dhtobey Tobey

Conference IntestCom.org | conference.intestcom.org - 0 views

  •  
    Possible outlet for NBISE competency modeling methodology paper.
dhtobey Tobey

Security Training, CEH, Ethical Hacking, Penetration Testing, Certified Ethical Hacker,... - 0 views

  •  
    Potential partner in developing and distributing assessments targeting the entry level of operational security testing.
dhtobey Tobey

GIAC Security Expert (GSE) - 0 views

  •  
    Potential source of Competency Model Development Panel members.
dhtobey Tobey

Home - Performance Testing Council - 0 views

  • The Performance Testing Council is your gateway to freely exchange experiences, knowledge, and yes, passion with others in the practice of performance testing. Membership will help you refine your evaluation program as you learn from experts, share best practices, help define research, expand your marketplace and help establish common delivery standards.
  •  
    Community of interest group for performance testing
dhtobey Tobey

Outgunned: How Security Tech Is Failing Us -- InformationWeek - 0 views

  • "Years ago when we started writing checks, we might have been tackling five to 10 a day," says Paul Wood, a senior analyst with Symantec Hosted Services. "It's now well over 10,000 a day and growing." According to McAfee's 2010 Q2 Threat Report, the company identified 10 million pieces of malware in the first half of this year and is tracking close to 45 million in its malware database.
  • Vulnerability assessment products are also behind the curve, as Greg Ose and Patrick Toomey, both Neohapsis application security consultants, found when they recently set out to measure the relative effectiveness of various vulnerability scanners. "It's a question frequently raised by our customers," Toomey says. "They know the tools aren't going to catch all of the problems, but can they count on them to catch, say, 80% of the bad ones?" What Ose and Toomey discovered was far worse than even they had anticipated. Out of the 1,404 vulnerabilities accounted for by the Common Vulnerabilities and Exposures project during the sample period, there were only 371 signatures. In the best cases, the tools were in the 20% to 30% effectiveness range.
  • Toomey's observations are in line with those of security researcher Larry Suto, who earlier this year reported that Web application vulnerability scanners missed almost half (49%) of the vulnerabilities present during his tests.
  • ...5 more annotations...
  • But there's also a new twist to consider: With an increased number of attackers targeting and hijacking the credentials of IT personnel, the outsider can become the insider, at least from the perspective of our technology controls. Forward-thinking companies will move now to address this scenario. Think about how you'll detect large, anomalous query spikes against key tables in sensitive databases. Ensure you can spot large-scale document downloads from file shares and internal document management systems. If a hijacked credential is used to log into a large number of machines during a short time frame, you should have the ability to spot that activity.
    • dhtobey Tobey
       
      Investing in workforce development and professionalizatino of the infosec workforce may do more.. combat ingenuity with ingenuity, not automation.
  • investing even a small percentage of your security budget in only a few specialized systems to help here will go further than throwing good money at yesterday's outdated controls.
  • Stop rewarding ineffectiveness and start rewarding innovation. Maybe right now you're struggling with a scary realization: "The millions I'm spending on firewalls and antivirus technology is relatively worthless if my adversary is skilled."
  • Greg Shipley is an InformationWeek contributor and a former CTO
dhtobey Tobey

TheBrain :: TeamBrain - 1 views

  • TeamBrain It's time to collaborate.  Learn how to grow your ideas and streamline projects with your peers.
  •  
    Check out this video tutorial! Should we consider adding The Brain to our NBISE Institute Community Desktop? Steve, I'd like to hear from you how this might be integrated into the tabbed page structure and KE. Mike, what do you think about using Brain for shared mindmapping in lieu of MindManager since our Catalyst license expired and Brain is much more cost effective. We could still attach MindManager files to nodes in The Brain for sharing of more static mindmaps. Just a thought...
dhtobey Tobey

Whatcom Community College's computer program honored for its cyber security - Top Stori... - 0 views

  • BELLINGHAM - Whatcom Community College's computer program is now considered one of the best in the country, especially in the areas of cyber security.The college was recently named as a National Center of Academic Excellence in Information Assurance by the National Security Agency and the Department of Homeland Security.
  • "It is a major threat to our security," said Corrinne Sande, Computer Information Systems program coordinator at WCC,
  • WCC is one of only 13 two-year schools in the country with the designation, which was opened to community and technical colleges last year. The University of Washington is also a Center of Academic Excellence in this area, but for a university instead of a two-year school.
  •  
    Candidate for Northwest ADAPTS program
dhtobey Tobey

Beyond Camping, Canoeing, Boy Scouts Add Robotics : NPR - 0 views

  • The Boy Scouts of America, which offers more than 120 badges ranging from archery to wilderness survival, next week will unveil a robotics merit badge meant to promote science, technology, engineering and math, fields collectively known as STEM. In doing so, the 101-year-old Texas-based organization is trying to remain relevant and better reflect boys' interests, said Matt Myers, who oversees the Boy Scouts' STEM initiative.
  • Developing the robotics badge requirements took 14 months and involved help from more than 150 scouts, their leaders and industry professionals. Ken Berry, who led the effort, said the badge is a bit overdue given that hundreds of thousands of children and teens already are participating in robotics competitions around the country. "We're promoting stretching of the mind like athletics promotes stretching of the body," said Berry, assistant director of the Science and Engineering Education Center at the University of Texas at Dallas.
  • Officials expect at least 10,000 of the nation's 2.7 million Boy Scouts to earn the new badge in the next year, compared with the roughly 500,000 who earn the most popular badge — first aid — each year.
  • ...1 more annotation...
  • "One of the biggest problems we have for high school kids and Boy Scouts included, is that there aren't a lot of opportunities to tinker and experience what it's like to be an engineer, so when they get to the college level, students are often ill prepared to do an engineering degree," he said. NASA, which allowed its Mars rover to be depicted on the badge, also agreed to take 100 patches into space on the Endeavour shuttle mission. Those badges will be distributed through an online contest.
  •  
    Possible avenue to extend NBISE certifications to K-12 groups in collaboration with the US Cyber Challenge?
1 - 9 of 9
Showing 20 items per page