{"id":177,"date":"2014-03-12T18:29:50","date_gmt":"2014-03-13T00:29:50","guid":{"rendered":"http:\/\/cybersecurity.bellevue.edu\/?p=177"},"modified":"2021-08-30T13:12:50","modified_gmt":"2021-08-30T19:12:50","slug":"my-tweets-from-the-2014-rsa-conference","status":"publish","type":"post","link":"https:\/\/cybersecurity.bellevue.edu\/index.php\/2014\/03\/12\/my-tweets-from-the-2014-rsa-conference\/","title":{"rendered":"My Tweets from the 2014 RSA Conference"},"content":{"rendered":"<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">The RSA 2014 Conference took place in San Francisco February 24-28.<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>It\u2019s the top gathering of information security and risk professionals in the world with over 25,000 attendees.<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>I had the privilege to attend (and <a href=\"http:\/\/www.rsaconference.com\/events\/us14\/agenda\/sessions\/1036\/surviving-a-security-firestorm-tales-from-those\">lead a CISO panel<\/a>).<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>While I was there, I used twitter (<a href=\"https:\/\/twitter.com\/RonW123\">@ronw123<\/a>) to record my thoughts of <a href=\"http:\/\/www.rsaconference.com\/events\/us14\/agenda\/sessions\">the sessions<\/a> and <a href=\"http:\/\/www.rsaconference.com\/events\/us14\/downloads-and-media\/video-index\">events<\/a>.<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>Below is a snapshot with commentary:<\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">Security Awareness and education was a common theme throughout the conference.<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>The industry is finally realizing it\u2019s about the humans and people will always be the weakest security link<\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\">\u201c<a href=\"https:\/\/twitter.com\/ddkirsch\"><s>@<\/s><b>ddkirsch<\/b><\/a>: Heard at #<span style=\"mso-bidi-font-weight: bold;\">RSAC<\/span> \u2014 Even my Mom knows that <s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">HTTPS<\/span> isn&#8217;t a plural of HTTP. <a href=\"https:\/\/twitter.com\/search?q=%23ITsecurity&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><b>ITsecurity<\/b><\/a>\u201d &lt; too bad<br \/>\nso many moms, dads, &amp; kids don&#8217;t<\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">Chris Hadnagy (<a href=\"https:\/\/twitter.com\/humanhacker\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">humanhacker<\/span><\/a> &amp; <a href=\"http:\/\/www.social-engineer.org\/\">Social-Engineer.org<\/a>) talked about, \u201c<a href=\"http:\/\/www.rsaconference.com\/events\/us14\/agenda\/sessions\/980\/social-engineering-when-the-phone-is-more-dangerous\">Social Engineering: When the Phone is More Dangerous than Malware<\/a>.\u201d <span style=\"mso-spacerun: yes;\">\u00a0<\/span><\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman';\">Wow! Even<\/span><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\"> <a href=\"https:\/\/twitter.com\/humanhacker\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">humanhacker<\/span><\/a> <\/span><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman';\">got caught w\/ phishing. It can happen to you. There are no stupid users, just uneducated<br \/>\nones. <\/span><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\"><a href=\"https:\/\/twitter.com\/SocEngineerInc\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">SocEngineerInc<\/span><\/a> <\/span><\/p>\n<p class=\"js-tweet-text\" style=\"margin-left: .5in;\"><a href=\"https:\/\/twitter.com\/humanhacker\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">humanhacker<\/span><\/a> <a href=\"https:\/\/twitter.com\/SocEngineerInc\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">SocEngineerInc<\/span><\/a> showing stats from <span class=\"invisible\"><span style=\"text-decoration: underline;\"><span style=\"color: blue;\"><a href=\"http:\/\/hackmageddon.com\/\" data-expanded-url=\"http:\/\/hackmageddon.com\">http:\/\/hackmageddon.com<\/a><\/span><\/span><\/span>. Scary. But there&#8217;s hope. \ud83d\ude42<\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">Jack Jones (<a href=\"https:\/\/twitter.com\/JonesFAIRiq\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">JonesFAIRiq<\/span><\/a>) had a great presentation titled, \u201c<a href=\"http:\/\/www.rsaconference.com\/events\/us14\/agenda\/sessions\/960\/ending-risk-management-groundhog-day\">Ending Risk Management Groundhog Day<\/a>.\u201d<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>He didn\u2019t even realize that there was a running panel from 2008-2010 that I was on with the name \u201cSecurity Groundhog Day\u201d (<a href=\"http:\/\/emcrsa.hosted.jivesoftware.com\/docs\/DOC-1722\">2008<\/a>, <a href=\"http:\/\/emcrsa.hosted.jivesoftware.com\/docs\/DOC-2254\/version\/1\">2009<\/a>, <a href=\"http:\/\/castroller.com\/podcasts\/RsaConferencePodcast\/2187083\">2010<\/a>). <span style=\"mso-spacerun: yes;\">\u00a0<\/span>Jack is the father of <a href=\"http:\/\/fairwiki.riskmanagementinsight.com\/\">FAIR<\/a> and provides great ideas for proactively using risk management practices to manage security. <\/span><\/p>\n<p class=\"js-tweet-text\" style=\"margin-left: .5in;\">Get off the &#8220;Hamster Wheel of Pain.&#8221; Stop repeating past errors. <a href=\"https:\/\/twitter.com\/JonesFAIRiq\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">JonesFAIRiq<\/span><\/a> <a href=\"https:\/\/twitter.com\/alexhutton\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">alexhutton<\/span><\/a> [Note: I\u2019ve learned<br \/>\nthat this comes from \u201c<a href=\"http:\/\/itrevolution.com\/books\/phoenix-project-devops-book\/\">The Phoenix Project<\/a>\u201d]<\/p>\n<p class=\"js-tweet-text\" style=\"margin-left: .5in;\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">JonesFAIRiq<\/span> &#8220;Policies need to be clear, concise, and useful&#8230; &amp; written to a 9th grade level.&#8221;<\/p>\n<p class=\"js-tweet-text\" style=\"margin-left: .5in;\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">JonesFAIRiq<\/span> &#8220;We&#8217;re really good at fixing symptoms, but not root causes.&#8221; <s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">1problem <\/span>is asking the right questions about risk.<\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif'; mso-fareast-font-family: 'Times New Roman';\">Info Risk Mgmt Groundhog Day. Dude&#8230; Really&#8230; Again. It&#8217;s d\u00e9j\u00e0 Vu all over again. <\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">Presentations on risks and threats are now commonplace at the RSA Conference. Here are thoughts on talks by Adam Shostack (<a href=\"https:\/\/twitter.com\/adamshostack\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">adamshostack<\/span><\/a>), Pete Lindstrom (<a href=\"https:\/\/twitter.com\/SpireSec\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">SpireSec<\/span><\/a>), and Andy Ellis (<a href=\"https:\/\/twitter.com\/csoandy\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">csoandy<\/span><\/a>). <\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\"><a href=\"https:\/\/twitter.com\/adamshostack\"><s>@<\/s><b>adamshostack<\/b><\/a> talking <a href=\"http:\/\/www.rsaconference.com\/events\/us14\/agenda\/sessions\/1035\/new-foundations-for-threat-modeling\">New Foundations of Threat Modeling<\/a>. Asking &amp; answering 4 questions about threat modeling and the right ways to find good threats. [Note: He has a new book out on Threat Modeling.]<\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\"><a href=\"https:\/\/twitter.com\/SpireSec\"><s>@<\/s><b>SpireSec <\/b><\/a>just mentioned the Hand Rule (see <a title=\"http:\/\/en.wikipedia.org\/wiki\/Calculus_of_negligence\" href=\"http:\/\/t.co\/69IVejlMXr\" target=\"_blank\" data-expanded-url=\"http:\/\/en.wikipedia.org\/wiki\/Calculus_of_negligence\" rel=\"noopener\"><span class=\"invisible\">http:\/\/<\/span><span class=\"js-display-url\">en.wikipedia.org\/wiki\/Calculus_<\/span><span class=\"invisible\">of_negligence\u00a0<\/span><span class=\"tco-ellipsis\">\u2026<\/span><\/a>).<br \/>\nSo few security \/ risk professionals know anything about it.<\/span><\/p>\n<p class=\"js-tweet-text\" style=\"margin-left: .5in;\"><a href=\"https:\/\/twitter.com\/SpireSec\"><s>@<\/s><b>SpireSec<\/b><\/a> &#8211; Being a contrarian in security makes you normal. Meaning we seek the truth even if it may hurt.<\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\">\u201c<a href=\"https:\/\/twitter.com\/csoandy\"><s>@<\/s><b>csoandy<\/b><\/a>: The true problem of a Prisoner\u2019s Dilemma Scenario is that it disregards the Game Manager.\u201d &lt; tying Game Theory to security<\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">NIST released the first version of the <a href=\"http:\/\/www.nist.gov\/cyberframework\/upload\/cybersecurity-framework-021214-final.pdf\">Framework for Improving Critical Infrastructure Cybersecurity<\/a> on February 12, 2014.<span style=\"mso-spacerun: yes;\">\u00a0 <\/span>Of course, this generated a few comments:<\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\">The NIST Cybersecurity Framework, Here we are *again* writes <s><a href=\"@georgevhulme\">@<b><span style=\"text-decoration: none underline; text-line-through: none;\"><span style=\"text-decoration: none underline; text-line-through: none;\">georgevhulme<\/span><\/span><\/b><\/a><\/s>, Engage <span class=\"invisible\"><span style=\"text-decoration: underline;\"><span style=\"color: blue;\"><a href=\"http:\/\/bit.ly\/1ffzuMY\u00a0\" data-expanded-url=\"http:\/\/bit.ly\/1ffzuMY\">http:\/\/bit.ly\/1ffzuMY\u00a0<\/a><\/span><\/span><\/span><br \/>\n<a href=\"https:\/\/twitter.com\/search?q=%23infosec&amp;src=hash\" data-query-source=\"hashtag_click\"><s><span style=\"text-decoration: none line-through; text-underline: none;\">#<\/span><\/s><span style=\"mso-bidi-font-weight: bold; text-decoration: none; text-underline: none;\">infosec<\/span><\/a><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\">News from <s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">RSAC<\/span> &#8211; DHS working with MS-ISAC on offering managed security services to state\/local gov&#8217;t who adopt Cybersecurity framework.<\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">The National Cyber Security Alliance (NCSA) held a twitter session where they asked pointed questions on encouraging kids to <a href=\"http:\/\/www.staysafeonline.org\/\">StaySafeOnline<\/a>. <\/span><\/p>\n<p class=\"js-tweet-text\" style=\"margin-left: .5in;\"><a href=\"https:\/\/twitter.com\/StaySafeOnline\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">StaySafeOnline<\/span><\/a> &amp; others are great! The material is there. It&#8217;s getting it out to people who need it the most. <a href=\"https:\/\/twitter.com\/search?q=%23securitychat&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">securitychat<\/span><\/a> <a href=\"https:\/\/twitter.com\/search?q=%23ChatSTC&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">ChatSTC<\/span><\/a><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\">Should there be a license to drive on the Information Superhighway? IOW: Required Education? <a href=\"https:\/\/twitter.com\/search?q=%23securitychat&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">securitychat<\/span><\/a> <a href=\"https:\/\/twitter.com\/search?q=%23ChatSTC&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">ChatSTC<\/span><\/a><\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\">We need to challenge more Cybersecurity professionals to get out and educate. Make it required for certifications? <a href=\"https:\/\/twitter.com\/search?q=%23SecurityChat&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">SecurityChat<\/span><\/a> <a href=\"https:\/\/twitter.com\/search?q=%23ChatSTC&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">ChatSTC<\/span><\/a><\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\"><span style=\"font-size: 12.0pt; font-family: 'Times New Roman','serif';\"><a href=\"https:\/\/twitter.com\/STOPTHNKCONNECT\"><s>@<\/s><span style=\"mso-bidi-font-weight: bold;\">STOPTHNKCONNECT<\/span><\/a> <a href=\"https:\/\/twitter.com\/search?q=%23securitychat&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">securitychat<\/span><\/a> <a href=\"https:\/\/twitter.com\/search?q=%23ChatSTC&amp;src=hash\" data-query-source=\"hashtag_click\"><s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">ChatSTC<\/span><\/a> A7: Reach the kids at their level. Don&#8217;t talk down to them. Challenge them to teach their parents.<\/span><\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">Of course, one of the hot topics was NSA Surveillance:<span style=\"mso-spacerun: yes;\">\u00a0 <\/span><\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\">\u201cUnderstanding NSA Surveillance: The Washington View <s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">RSAC<\/span>\u201d &lt; what&#8217;s legal may not be wise &#8211; said by both Hayden &amp; Clarke<\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\">We need a real debate at <s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">RSAC<\/span> on the NSA, not pontificating and opinions. High School Debate did it last Nov. see <a title=\"http:\/\/bit.ly\/MZJVrQ\" href=\"http:\/\/t.co\/yqYUlwxkIk\" target=\"_blank\" data-expanded-url=\"http:\/\/bit.ly\/MZJVrQ\" rel=\"noopener\"><span class=\"invisible\">http:\/\/<\/span><span class=\"js-display-url\">bit.ly\/MZJVrQ<\/span><\/a>.<\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">Last, but hardly least is my frustration in the opening keynote of attendees spending their time on their devices and not meeting others. <\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin-left: .5in;\">Listen <s>#<\/s><span style=\"mso-bidi-font-weight: bold;\">RSAC<\/span> peeps! Stop playing with your phones and start meeting someone new. The greatest minds in Cybersecurity are<br \/>\nhere.<\/p>\n<p class=\"MsoNormal\"><span style=\"font-size: 12.0pt; font-family: 'Arial','sans-serif';\">These are my quick, but not complete thoughts. No doubt they will lead to many blogs in the future.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The RSA 2014 Conference took place in San Francisco February 24-28.\u00a0 It\u2019s the top gathering of information security and risk professionals in the world with over 25,000 attendees.\u00a0 I had the privilege to attend (and lead a CISO panel).\u00a0 While I was there, I used twitter (@ronw123) to record my thoughts of the sessions and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[11,18,8,3,35],"tags":[],"class_list":["post-177","post","type-post","status-publish","format-standard","hentry","category-human-aspects","category-online-safety-tips","category-security-education","category-security-management","category-threat-modeling"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/comments?post=177"}],"version-history":[{"count":4,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/177\/revisions"}],"predecessor-version":[{"id":996,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/177\/revisions\/996"}],"wp:attachment":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/media?parent=177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/categories?post=177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/tags?post=177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}