Careers, Concepts, Security Education, Security Management

Breaking into Security

One of the common questions I am asked is, “How do I get a job in information security?”  Infosec continues to be a hot career field with many job opportunities.  Therefore, we continue seeing people who are interested, but don’t know the steps it takes to gain employment in information security.  This blog post answers the question, “How do I break into (the) security (career field)?”

A few years ago, I was asked a similar question of how I got started in security.  It all started as a computer science major at Michigan State University. I was also in Air Force ROTC.  This combination allowed me to start developing my security mindset.  As a military intelligence officer, I learned about data classification and safeguarding sensitive information. I left the Air Force for a job as a UNIX systems administrator where I learned how to apply technical controls to protect the systems and its data. As a junior security analyst, I learned the importance of policies and awareness. The combination of technical and managerial experience led me to security management roles. (You can read more about my experiences here: Me and my Job: Ron Woerner, Bellevue University, SC Magazine, April 2011)

To become a security professional, you need a mix of experience, knowledge, and abilities. It’s not generally an entry level career field, because you need time to develop yourself as a security professional who understands the many aspects of cybersecurity. The security community has a vast number of articles on breaking into the security career field.

This reminds me that everything old is new again. Many of the articles I mention above were written a few years ago. Things really haven’t changed over the years.  The career path still requires education, training, experience, and persistence.

As an extra, added bonus, here’s a 3 ½ minute Ted talk from Richard St. John: 8 secrets of success http://www.ted.com/talks/richard_st_john_s_8_secrets_of_success.html (Watch for his explanation of CRAP).  It’s great, general information on how to succeed in any career.

Human Aspects, Online Safety Tips, Security Education, Security Management

Security for the Real World – Password Policies

Passwords suck.  They always have; they always will.  But we’re stuck with them.  They are the cheapest and easiest means of user authentication.

With passwords, come the ubiquitous password policies.  This post addresses two of them seen at most organizations*:
1. Thou shalt not share they password.
2. Thou shalt not write down thy password.

* “Thou shalt” isn’t usually used in policies.  I’m using it for effect.

There are many problems with these rules.  First, they are almost impossible to enforce, unless it’s a really small organization or you have a large police force.  Second, they are often violated by the top echelon in the company.  How many CEO’s share their account with their admin?  Are you going to tell the CEO that he’s violating the company policy?  That’s a CLM (Career Limiting Move) if you ask me.

Rules like the ones above are to protect the organization, not the employee.  They cannot be enforced, except when something bad happens.  Then, the enforcer can point to the policy and report the violation.  I call it a “speed limit” policy, which are good to follow, but aren’t continually nor consistently enforced.

Here’s the key to making those policies work: make the user responsible for his/her account.  The policy statement would then be, “All users are responsible for protecting their login credentials from unauthorized access like they would protect any other corporate asset.”  This puts the onus on the user.  If someone gains unauthorized access to the user’s account because he/she didn’t follow the rules, then the user is accountable.  They are guilty until they can prove themselves innocent.  If someone (like the CEO) wants to share their account, they can as long as they realize that’s it’s them who will be held responsible for any actions taken by the other party.

With so many passwords to remember, people need to write them down.  Telling people not to just isn’t realistic.  Some use a password vault application.  Others use a piece of paper.  Both are fine as long as it’s rigorously protected.  It’s fine for people to write down their passwords as long as they store it in a very safe location.  My mom has a piece of paper with all of her passwords on it in a desk drawer in her apartment.  I’m fine with it, since I may need it one day as her power of attorney.  Her apartment is in a secure facility, so the risk is minimal.  There’s a lot bigger risk of her becoming incapacitated and me not having access to her accounts.

That’s what it comes down to: understanding RISK and establishing Accountability.  What are the risks associated with the actions?  Who’s responsible?  Answer those and you make a cognitive decision that’s both realistic and enforceable.

Careers, Security Education

Cybersecurity Degree vs. Certification

What’s best for your career – a Cybersecurity certification or a degree in Information Technology (IT) security?
[Guest Author: Laura Linhart]

A few years ago, this question would not have been as relevant as it is today.  The CISSP® (Certified Information Systems Security Professional) sponsored by the International Information systems Security Certification Consortium (ISC2) first offered as a security certification in 1994, was the first information security certification to meet ISO standards.[1]  Since then, the number and types of information or Cybersecurity certifications and professional organizations that offer these certifications has proliferated.

The growth and evolution of information or Cybersecurity as a degree unto itself has also been significant in recent years.  Today, many colleges or universities offer it is a field or major unto itself, offered as both undergraduate and graduate degrees.  In previous years it was only available as a subset of another major such as data processing, computer networking or computer science.

From a career or professional perspective, information security appears to be a stable and growing profession[2] .  As the profession continues to grow and evolve, the question of which is more relevant – a degree or certifications is now a consideration.   As with most things in life, the best answer is “it depends”.  Where you are at in your career, life’s journey (i.e., age) and your own ambitions are things to consider.

Degree – to expand or gain knowledge.  On the positive side, a degree is forever, and does not require any upkeep.  It will get you in the HR screening process door if an IT degree is a particular job requirement.  It indicates that you have the work ethic to complete something.

Certification – to establish your credibility.  Require continuing care and feeding (continuing certification requirements).  Most also require years of experience in the specific area of certification.   It indicates that you have the subject matter expertise.

Another variable to consider is practical experience.  In some situations, practical experience means the most.  It indicates that you have the ability, and can apply and expand on what you know.

The bottom line is that there is no one answer that fits all.  It depends on your particular circumstances.

In reality, you will probably need both a degree and certification(s).

 

Security Education

What do you need? Security Education or Training

As you’re looking to improve yourself as a Cybersecurity citizen, you often need help from an outside source to increase your knowledge and/or abilities.   Security is a broad topic encompassing many disciplines and Cybersecurity is no different.  There are technical, procedural, and managerial aspects to be considered to grow what you know about Cybersecurity.  There are often many, different ways to solve the same security problem. Knowing what to do and how to do it requires both knowledge and experience.  How do you gain it though?

The answer is Cybersecurity training and education.  There’s often a question as to which you need: training or education.  There is a difference between the two, which I’ll explain below. You need to be aware of your needs, wants, and goals before proceeding, or there’s a chance you won’t meet them.

Cybersecurity education provides a more general background on the philosophies and concepts behind Cybersecurity.  It allows you to understand the context for security tools, techniques, and technologies. With security education, you understand why it’s important to have particular protection methodologies in place and is at the strategic level of thinking.  Cybersecurity education emphasizes principles of risk management and how security fits into an organizational culture and structure. Education is long term taking many months if not years to acquire. Finally, education teaches critical thinking and allows the student to learn how to learn, which is crucial for new subjects or technologies.

In contrast, Cybersecurity training is more specific to a technology, procedure, or skill.  It’s tactical or operational, rather than strategic. Training emphasizes the building of explicit skills and applying what you know to a particular situation.  When you attend cyber training, you are learning about a specific technology or practice that can meet an immediate need. Lastly, training is short term and can often be accomplished in days or weeks.

In this discussion, I’m trying not to sway your though as to which is better, because both are important for expanding your Cybersecurity knowledge and abilities. You need to decide for yourself the method you want to take in order to meet your goals. The important thing to consider is that you keep growing and increasing your knowledge.  Feel free to comment below on your views of education versus training. Don’t stop learning!

Security Education, Security Management

National Center of Academic Excellence in Information Assurance Education

In April 2012, the National Information Assurance Education and Training Program (NIETP) office under the authority of the U.S. National Security Agency (NSA) and Department of Homeland Security (DHS) announced that Bellevue University is designated as a National Center of Academic Excellence in Information Assurance Education (CAE-IAE) for the academic years 2012-2017. This is a great accomplishment for the University and demonstrates our continued dedication to not only Cybersecurity Education, but also to the security community. 

The CAE-IAE application, submitted earlier this year passed a rigorous review that was evaluated against a stringent criteria, demonstrating its competency and commitment to academic excellence in Information Assurance education and security practices. The letter received by the University with the announcement demonstrates the quality of our program.  “One reviewer remarked that Bellevue’s submission, ‘demonstrated fine curriculum, expert faculty and noteworthy outreach.’  You are to be commended for submitting such an exemplary application.  Your ability to meet the increasing demands of the program criteria will serve the nation well in contributing to the protection of the National Information Infrastructure. “

Mary Hawkins, the Bellevue University President will be receiving the official certificate of designation signed by the Director, NSA, the IA Director, NSA and the Cybersecurity Assistant Secretary, DHS, at the 16th Colloquium for Information Systems Security Education (CISSE) in June.

An official press release and announcement is forthcoming.

Human Aspects, Online Safety Tips, Security Education

Happy Safer Internet Day

Tuesday, February 7, 2012 is Safer Internet Day (SID).  It’s an international event organized to promote safer and more responsible use of online technology and mobile phones, especially amongst the younger generation. We have so many netizens who are unaware of the dangers in the new Internet age.  The only solution is constant and consistent education.

Some of the statistics provided  on the website are telling:

  • 26 per cent of children report having a public social networking profile.
  • Children of all ages are lacking digital skills –confidence is often not matched by skill!
  • 12 per cent of European 9-16 year olds say they have been bothered or upset by something on the internet…
  • …however, 56 per cent of parents whose child has received nasty or hurtful messages online are not aware of this.
  • One in eight parents don’t seem to mediate their children’s online activities…
  • …while 56 per cent of parents take positive steps such as suggesting to their children how to behave towards others online.
  • 44 per cent of children think that parental mediation limits what they do online, 11 per cent say it limits their activities a lot.

One aspect that I find fascinating is that this is a global problem.  Kids worldwide are encountering the same problems that we see here in the United States.  Wesites like SaferInternetDay.org and StaySafeOnline.org provide a large amount of useful information to help folks be secure online.  It’s all free and readily available for anyone who wants it.

It’s great to see a worldwide effort like this. I just wonder how we can better spread the word and educate not only our kids, but everyone.

Careers, Security Education

Bellevue University Cybersecurity Skill Valuation Survey

A request for your help:

I would like to ask you for your advice as we develop a new academic program in Cybersecurity.   Here at Bellevue University and the College of Information Technology, we periodically review whether our academic programs are meeting the expectations of students and employers.   As a leader in your business area, we value your views on the skills you would expect of an employee with a Bachelor of Science degree in Cybersecurity.  Conceptually, this would be an employee with a current (or future) role in your organization who would be responsible for various operational aspects of securing your information systems.  Below is a link to a short survey which will record your views about the skills you would expect of such a graduate / employee.    

http://www.surveymonkey.com/s/2SJF76Z

It will be most beneficial if you could complete the survey by Feb 14, 2012.  I sincerely appreciate you taking a few moments to complete the survey and provide us with your valuable advice on this matter as we strive to improve our programs for the benefit of both students and employers. 

We will publish a summary of the results of this survey after its completion.

Online Safety Tips, Security Education

Staying off of the suspect list

Often, we’re our own worst enemy.  We do things that make us a likely target for blame.  In other words, we’re on the suspect list.  We receive the blame when something goes wrong because of our actions or the access we maintain.

The idea is to keep yourself and other off of that list.  First of all, it disrupts the investigation in finding the true source of the problem.  Second, it causes others to distrust those on the suspect list, even if their innocent.  The best way to prove innocence is to have a clear name from the onset.

Often security professionals and IT managers have access to many systems, applications, or facilities. They believe it’s required because of their position or responsibility.  The problem is that having access puts them on the suspect list.  Many times I’ve been accused when there were network issues.  “Were you running one of your security scans again?” was a common statement aimed at me just because I had the ability to run scans, not that I did.

Often other activities may add us to the “suspect list”, such as browsing the Internet, transferring documents from home to work and vice versa, clicking on links in email, or installing freeware or shareware applications on a work computer. While they’re not bad in and of themselves, these actions do have potentially dangerous consequences.

Here are five things you need to do to keep yourself off of the suspect list:

  • Limit your access.  This is the concept of least privilege.  If you don’t need it or don’t use it every day, disable or delete your access to it.
  • Only use administrator privileges when you administer the system.  If you’re always logged as an admin, then you’re just asking for trouble.
  • Freeware isn’t always free and shareware may mean your sharing more than the program.  Finding programs on the Internet may save money in the short run, but they occasionally contain hidden malware than can take down your system.
  • Think before you click.  Be aware of where you go on the Internet.
  • Keep your secrets secret.  If you allow others to use your login id or badge, then that person is you and you’ll be on the suspect list if something goes wrong. Badges and passwords are like gum, it’s not cool to share once used. 

Security’s objective is to keep people off of the suspect list.  We know that the great majority of our work force wants to do what’s right.  We want to help you.  Like the police, our objective isn’t to get you into trouble, but to keep you out of trouble.  Consider what you should do to keep yourself and others off the suspect list.  It will make your life much easier.

Online Safety Tips, Security Education, Security Management

2012 Webinar Announcement

2012 – The Year of Online Protection

2011 was the year of the breach.  2012 should be the year was get security right and start protecting ourselves, communities, organizations and families online.

To help kick-off the New Year, I’m hosting an online seminar titled, “Protecting yourself and your company from the evils of the internet in 2012.”  It is scheduled for Wednesday, January 25 1-2 p.m. CST and you can see it freely online, once you register.

From our Seminars and Outreach page:

Ron Woerner, Director of Bellevue University’s Master of Science in Cybersecurity program, will discuss the perils of the Internet, how hackers can take over your computer and how they access your private information. It’s not all doom and gloom, though. Woerner will suggest ways to protect yourself and your company in 2012. Come to this online presentation with your questions on online safety and security. You will have the opportunity to participate in a live question and answer session with Woerner following the presentation.

It’s going to be more than just your typical & basic keep yourself safe online talk.  I will be providing detailed tips, tricks, and techniques to keep 2012 from being another Year of The Breach. It will end with a chance for you to ask your questions about online protection to help you focus your security activities in 2012.

Please join in the conversation if you want to learn more about online safety, hear about our Cybersecurity programs, or are just looking for certification credits.

To learn more and register for the event, go here: http://www.bellevue.edu/cybersecurity/.

Security Education

Happy Holidays from the BU CCE!

Happy Holidays from the Bellevue University Center for Cybersecurity Education!

In this holiday season of giving, we are using online merchants more than ever.  They provide an easy and convenient way of finding that perfect present for your loved ones.  Of course, these merchants don’t take cash or check; you must use some type of credit.  To help protect your online financial identity, this blog post provides some simple tips to help you keep your online buying safe.

You can protect yourself online anytime of the year by doing a few very simple things:

  • The best thing you can do as a user is to stop and think about the websites you visit and the business you conduct online.   
  • Don’t click links assuming they are legitimate; always verify where they take you.  Remember, if it is too good to be true, it probably is!
  • Use unique passwords for your accounts.  Ask yourself if you could use those passwords at work.  If you can, those passwords may help provide at least some level of protection.  Change your passwords often and make them different.  These passwords are an attacker’s access to your accounts; protect the passwords as you would protect the keys and title to your car.
  • Check your credit report once a year for free at www.annualcreditreport.com.  Make sure there is nothing appearing that you don’t agree with or know about.
  • Use a credit card or payment service like Paypal.  That greatly limits your liability should your card number or payment be stolen.
  • Secure your personal data on your PC as you would your paper files.

By maintaining a little vigilance, you can save yourself many headaches.  Please help share the word about online safety.  Also, share your tips, so we can all learn.

We hope everyone has a safe and secure holiday season!