(ISC)² at RSA Conference

In one month, the world will talk security at RSA Conference in San Francisco, CA. The annual information security event will be held at the Moscone Center February 13-17.

(ISC)² team members can be found on the exhibit floor in booth S-342. Stop by to pick up a copy of the March/April issue of InfoSecurity Professional magazine, printed exclusively for RSA Conference. We will also have 2017 member pins, CISSP® t-shirts, lightsabers (yes, that’s right) and more. The times and dates of demonstrations at our booth – including Vulnerability Central sessions – can be viewed online.

(ISC)² members who register for a full-conference pass can save $200 and will gain access to five days of expert-led sessions spanning 22 topics, 550 exhibitors in the Moscone Center, as well as fascinating keynote speakers. Use the code 1U7ISC2XP when registering to receive a free expo pass.

Members who attend RSA Conference can earn up to 35 CPE credits, depending on the pass they register for.

Dan Waddell, (ISC)² regional managing director, North America, will be giving the opening remarks at the CSA Summit on February 13. We are looking forward to hosting a CSA Summit at our next Security Congress in Austin, TX this September, and more details will be announced later this year.

Before the conference kicks off, join us for one of two “2-Day Crash Courses” on either the CCSP® or CISSP. These training courses are fast-paced and in-depth in order to cover all the key domains of each CBK®. Crash course attendees will receive the official (ISC)² student handbook to use during the course and throughout their studies as they prepare for the exams.

The Center for Cyber Safety and Education will also be at RSA Conference. The Center will have a booth in the CyberSafety Village, located in Moscone West, Level 2, adjacent to the classroom session areas. The Center will be hosting an overview of the Safe and Secure Online program, featuring Garfield’s Cyber Safety Adventures, on Wednesday, February 15 from 5:00-6:00 p.m. PST. To register for this session, please send an email with your name and member ID to safeandsecure@isc2.org.

[(ISC)² Blog]

Cloud First, Now What?

Your executive staff has made a strategic decision to move to the cloud, and your team has the seemingly monumental task of executing on this new direction. The journey to the cloud introduces many unknowns, the least of which is determining the applications and data, including precious customer information, that belong in the cloud. Yet your knowledge is limited, and you have little time to immerse yourself in this vast topic.

Key topics that have been left up to you and your team include: where to start; which applications and data should (or can) be moved to the cloud; what are the risk implications; who can help you make the decision; and, more importantly, how can you make the decision process repeatable.

To help you frame a cloud-first implementation methodology, the Cloud Security Alliance will host the Cloud First, Now What” webinar on January 17th. This webinar, sponsored by Palo Alto Networks, will walk you through the following critical topics:

  • Assembling the cloud team: Moving to the cloud may be an edict from the CEO, but there is a team of players who need to make it happen, from risk, compliance and legal, to IT, security and operations, to dev-ops and the business groups.
  • Picking the first set of applications: Which applications are the first to go? Do you start with easy, low-hanging fruit or move the challenging apps first? Do you “lift and shift,” migrating existing applications, or do you start anew?
  • Determining what data can move: Regulations, contractual obligations, and legacy formats are just a few of the data considerations that need to be considered when implementing a cloud-first methodology.

After the event, you should have all the data necessary to frame your own cloud-first methodology.

Register Now: Cloud First, Now What

[Palo Alto Networks Research Center]

There’s No “I” in Secure Network: User-Based Access Policy is a Team Effort

Today’s cyber attackers have proven themselves far more capable and committed, stopping at nothing to access the pools of valuable data that uphold the integrity and reliability of your business. To maintain a strong security posture and prevent cyber breaches, leverage User-ID™, user-based access controls, on your next-generation firewall (NGFW) to safely enable the applications and technologies required to drive your business forward. User-ID significantly improves network visibility by mapping network traffic to specific users, rather than IP address, and offer several features to protect your network and help block potential threats at every stage of the typical attack lifecycle.

  • Access controls can be applied to ensure that only valid, approved users can access necessary assets and data. Note, however, that legitimate users are not threat free. Threat prevention should also be applied to the network to protect systems and application vulnerabilities from exploitation.
  • Leverage User-ID controls to identify and block malicious command and control traffic.
  • In the event of an infection or data breach, control sensitive data exfiltration by ensuring every user, even infected users, can only access a small subset of the network.
  • Leverage user-based reports and breach forensics for a complete, accurate analysis of the breach to help with future policy implementation.

User-based access controls are steadily becoming in integral component of the network security infrastructure and threat prevention measures. However, it’s important to understand that establishing and implementing a user-based security strategy and policy is not a single team’s responsibility, and should be rooted in the business leadership team’s position on cybercrime prevention. Given the recent spate of high-profile cybercrimes, security is now being discussed at the boardroom level. Leverage the heightened security awareness to build a business case for user-based access policy with the leadership team, and work in tandem to create business policies to simplify and reinforce the implementation. The leadership team’s support will be helpful during policy roll out, and when making necessary adjustments, such as denying access to certain websites, or to help ease the minds of less-than-patient users in the face of issues that need to be ironed out.

Beyond the organization’s leadership, User-ID access policy requires coordination and buy-in from several teams to ensure a seamless adoption and execution. Here are a few examples of who should be involved in the planning and implementation of user-based access policy:

IT Architects

The IT architects know the ins and outs of accessibility. They can offer insight regarding which users log in to the network from various office locations, and whether those users require access to resources that may be safeguarded by NGFWs in other locations.

IT & Security Operations

When it’s time to roll out the new user-based access controls and policy created with User-ID, the IT & Security Operations team will be critical to the execution, helping to troubleshoot any issues associated with implementation. Make sure to provide the proper training so that they are equipped to handle the higher-than-average volume of help desk tickets and user accessibility inquiries.

IT Administrators

Administrators are vital in providing user identity information on which to frame user-based access controls and policy around:

  • Network Admins: As device owners, network admins can provide user identity information from Wireless LAN controllers, NAC devices or VPN gateways
  • Directory Admins: Work with directory admins to gain valuable user identity information from directory servers, such as Active Directory
  • Enterprise Services Admins: To define user-based access requirements for enterprise services, like SAP for example, security practitioners must team up with enterprise service admins
  • Endpoint Admins: In addition to traditional VPN remote access and secure connectivity, coordination with endpoint admins is necessary to ensure user-based access controls extend to the mobile workforce

Implementing User-ID access policy on your Palo Alto Networks NGFW, with the participation and buy-in of all appropriate groups, will aide in meeting your organization’s goal to reduce individual users’, and the entire networks’, risk of infection.

To learn more about the benefits of leveraging User-ID, user-based access controls, on your Palo Alto Networks NGFW:

[Palo Alto Networks Research Center]

English
Exit mobile version