What Are The Most Sought After Security Skills?

IT security has become one of the most important focal points in private and public sectors. As the rise of cyber-threats impact the way we protect private data and prevent breaches that can cost into the billions of dollars to fix, the need for qualified IT security professionals is more pressing than ever before.

The demand for skilled professionals has been growing more than 10 percent each year, according to a survey conducted by (ISC)2, a non-profit association of IT professionals based in Clearwater, Florida. And the U.S. Bureau of Labor Statistics expects employment of IT security analysts to grow by almost 40 percent by 2022 – a rate higher than most other high-tech careers.

Eddie Schwarz, international vice president of the ISACA, has almost 30 years of experience in the IT world. He’s watched as the industry has converted to wireless, evolved into mobile and faced unique challenges in communicating between the back office and boardroom, In recent years, one of the most pressing issues he’s had to face is how to educate the next generation of IT analysts in up-to-date security compliance.

“Over the last seven years, we’ve seen advanced threats increase,” said Schwarz, who admits that many hackers have moved from more traditional types of crime to cyber-crime. “Cyber-terrorism isn’t going away. It’s actually getting worse and will continue to get worse in the foreseeable future. It affects everyone.”

According to Schwarz, the rate at which technology advances has a lot to do with the rise of the most devastating cyber-threats, particularly as the mobile industry skyrockets. “Everything is Internet-connected now,” says Schwarz, “which opens a lot of questions as tech marches faster and faster ahead.”

Some of these questions IT pros should be asking: How can I protect our mobile data? And what skills will I need to secure information as cyber-terrorism becomes an even bigger threat?

“We need people with the knowledge, skills and capabilities to feel safe and secure,” Schwarz explains. “But there’s a gap in knowledge and skills showing that there aren’t enough people that are experts in this field.”

Here’s What You Need to Know

Asher DeMetz of Sungard AS, an IT company with headquarters in Wayne, Pennsylvania, contributed a column to Forbes magazine about the most critical IT security skills needed on the corporate level today. “Lack of security is an issue in every corporation,” DeMetz said. “You want to build a targeted security strategy. To do so requires having a specific security skill-set.” He says that these skills may be found in-house or through a managed service provider.

The most important skill for any IT security pro right now is being able to set up a successful security program. As corporate leaders are becoming more aware of the need to bulk up security measures, they will inevitably look to a security manager to develop programs designed to reduce risks based on a customized environment. Because not every company is the same, the approach one takes to developing a security plan will not be the same either.

A theoretical approach to security may sound great in the boardroom, but it will only goes so far in protecting important data. A security pro, in addition to having a plan, also needs to be able to implement programs company-wide. In some ways, this can be the most challenging step in any security measure; as it can be difficult having longtime employees change the way they operate in traditional settings.

But everyone must be on board with a security plan, which should include not only hardware and networks within the office but also handhelds and mobile devices that are linked to the company, but exist outside of the network. A security manager must also be able to get the program set up and to manage it on a continual basis.

DeMetz said that in addition to day-to-day operations, being able to audit the system is critical to ensuring that it works. Not only are there compliance laws to consider, regular testing of the system will let the team know if the protocols are working and if there are any areas that need improvement.

In this case, ethical hacking could mean the difference between a risking a breach or staving off an attack. So, in addition to understanding how to keep data safe, a security expert should also be able to try and penetrate the system. Ethical hacking can indicate areas that could be at risk before a breach even happens.

In a worst-case scenario, a professional also needs to be able to respond to an attack immediately. “You’ll need to have the skills available to immediately address and remediate the problem,” says DeMetz. There is no waiting when a data breach occurs.

More Demand, More Money

Schwarz said IT professionals with these skills will be among the best-paid, most sought after analysts in the industry. “Cybersecurity is one of the hot fields today,” he says. Interestingly, he said that while a background in computer science helps to move into the field, it’s not necessary. He personally sees more and more professionals rising in the ranks from diverse educational backgrounds.

More than having a degree in computer science, employers are looking for people who can show they’ve gone through performance-based testing and exercised skills, said Schwarz, who was actually a fine art major before moving into IT. “They want to see that if the company is getting hacked, that you know what to do,” he said. “It also requires a desire to figure out what’s going on and understand why things are going wrong and what can be done to fix it.”

He said that for many years, the IT world was focused on a single generalized skill-set that may not always fit the bill when it comes to preventing cyber-terrorism. In fact, having more diversified skills may actually be a bonus for thinking outside the box and anticipating how to prevent hacking at some of the most respected organizations around the world.

“There’s no universal formula,” Schwarz said. But top IT pros should seek out companies and organizations where IT security is taken seriously. In banking, for example, as much as 15 percent of budgets are often directed toward cyber-security. “If an organization has a reliance on information – and most do at this point – and they don’t take cybersecurity seriously they have their heads in the sand.”

Click here to learn about the CompTIA Security+ certification and here to learn about the CompTIA Advanced Security Practitioner certification.

Natalie Hope McDonald is a writer and editor based in Philadelphia.

[CompTIA]

Preventing Cyber-War: CASP Guards Against Global Cybersecurity Threats

F-22 Raptor stealth fighters tore across the tranquil, picturesque desert sky of Hill Air Force Base in northern Utah as Patrick Lane, senior manager of product management at CompTIA, prepared to discuss high-level IT security with a conference room full of information assurance workers. He took in the sights, awed by the planes’ high-tech acrobatics; they flew at what seemed like impossibly slow speeds, then impossibly fast ones, banked and turned on a dime over the mountain-ringed valley abutting the Great Salt Lake. It was breathtaking, all the more so because of the danger involved. Hill Air Force Base is one of the few live-fire Air Force training ranges in the country.

But what brought Lane to Hill Air Force Base was a facet of national security more intangible than such impressive machines. Invited to speak on behalf of the Armed Forces Communications and Electronics Association, he was there to present on unauthorized network entry, newly evolving malware threats and the tools an advance IT pro can use to fight both.

Lane’s visit to Hill Air Force Base’s is but one of the steps he’s taken to increase the nation’s level of cybersecurity preparedness, a critical goal given disconcerting news about both the increasing sophistication of malware and its increasingly invasive uses. For Lane, there is only one solution to the growing problem – the CompTIA Advanced Security Practitioner (CASP) certification.

Lane said, “If [someone has] a CASP certification, they can be hired by a state – hopefully by the U.S. – to fight the fight that’s going on all around us.”

So what, exactly, is that fight? While there has been no out-and-out declaration of cyber-war by one state against another, there has nevertheless been a proliferation of hacking cases targeting both state and corporate enterprises suspected to have been ​executed by nation-state actors. The spate of point-of-sale malware attacks that plagued U.S. retail enterprises over the past few years seems to have, according to Lane, given way to espionage malware focused on gaining access to and harvesting intellectual property and state secrets.

Recent headlines reflect this. The hack of Sony’s email servers, which led to the theft and public release of private emails between Sony employees, celebrities and others, was eventually attributed to North Korea – though North Korea denies involvement. More recently, some have pointed the finger at China regarding a breach at the U.S. Office of Personnel Management (OPM) that resulted in the personal data of at least four million current, prospective and former federal employees – possibly up to 18 million people – being compromised. The attack appears to have been under way for a protracted period of time and the fallout from it remains to be seen.

The obvious similarity between these two attacks is the alleged involvement of state actors. But these attacks also both used a specific type of technology. The espionage malware used in both attacks represents a newer, more sophisticated form of cyber-attack known as an advanced persistent threat (APT). APTs are adept at infiltrating, then residing undetected on networks. They can hide themselves in the essential APIs of a system, quietly sending information back to a command-and-control server.

“Whereas it used to be [hackers would] walk up, break the window, walk in and leave, now it’s almost as if someone broke into your house and is waiting in the cabinet,” Lane said.

Lane sees hope, though, for the government wrapping its mind around this malware model. That’s where CASP comes in.

Unlike some other certifications, CASP is meant to assess – in addition to the knowledge of specific tools – experience. It tests the sort of deductions an IT professional with 10 years of overall IT experience or five years of security experience should be able to make.

“[CASP] is unique because we’re focusing on the people [who] are actually going to have to sit there and figure out the problem and try to fix it,” Lane said. “Our certification is built to assess workers [who] have a chance of defeating these attacks or at least scattering them.”

Lane is similarly confident that cyberattacks on government infrastructure, like what occurred with OPM, could be limited with widespread CASP certification.

“What you’re trying to defend against is the hacker’s ability to extract targeted information,” Lane said. “In theory, if you had a bunch of CASP guys there [in the case of OPM], they would have been using CASP ideas. They would have understood that users are the biggest problem as far as launching malware into networks. So you would hope that the attack would have been detected and stopped before the breach took place.”

The U.S. military sees the importance of having a certification that assesses an IT professional’s ability to identify and combat advanced persistent threats. CASP was developed at the request of the U.S. Navy and since then it has been adopted by the broader Department of Defense for Directive 8570.01-M.

The CompTIA advisory committee for CASP, which is constantly revising the requirements for the certification to make sure its skills assessment remains on the cutting edge, features some of the biggest names in technology, business and government. Target, RICOH, the U.S. Navy Center for Information Dominance and the U.S. Department of Veterans Affairs are only a few of the names on the list. These organizations contribute their hands-on cybersecurity expertise to the CASP exam.

And so, despite cyberattacks growing in target size and technical sophistication, according to Lane, it’s possible to stay ahead of these threats. If these attacks can be understood as acts of quiet aggression in a pervasive, decentralized cyber war, Lane believes that CASP will play a big role in making sure it’s a war we can win.

“To tell you the truth, the stuff that they’re doing isn’t difficult to stop, necessarily,” Lane said. “You just have to figure out what they’re doing.”

Matthew Stern is a freelance writer based in Chicago who covers information technology, retail and various other topics and industries.

[CompTIA]

Consumer IoT Security Impacts

Within the CSA Internet of Things (IoT) Working Group, we are researching various topics related to securing IoT implementations within an enterprise. One of the more interesting aspects to consider on this subject is the role that consumer IoT devices play in regards to enterprise security.

News of exploits against consumer IoT devices is common, and research into vulnerabilities related to poor development and configuration choices continues. Rapid7 recently published a significant research report on baby monitor exposure and vulnerabilities, which showed that many leading brands are still highly vulnerable. Download their report.

Another interesting aspect of consumer IoT security is the apparent inability to rely upon the consumer to safeguard the underlying network that IoT devices use to communicate. Consumers are often proponents of usability over security, and in the past some consumer IoT device makers have purposefully chosen to value usability over security. This is somewhat understandable, as most people would prefer not to have to configure unique security credentials for each IoT device that operates within their home. Of concern though is that adding new (non-secure) points of connection into the home provides an ability for malicious parties to gain access to other computing resources in the home – potentially leaving sensitive data such as passwords exposed. This is concerning for an enterprise security practitioner because many people choose to use the same passwords to protect both corporate and personal information and application access.

What’s interesting also is that consumer IoT devices do not always stay within the home. A report this year by OpenDNS provided a great deal of data that showed that IoT devices, or the associated applications installed on staff computers, were often found to be communicating with services over the internet from the Corporate network. In some cases, Smart TVs were brought into the enterprise, and these devices were pre-configured to talk with service addresses/ports on the internet. In other cases, fitness trackers were associated with applications that were loaded onto laptops or mobile phones, and then those applications began communication with the manufacturer through the corporate network. Read the OpenDNS report.

At this point, education is likely the best defense against the exposures that consumer IoT devices introduce to the enterprise. Security staff should be educated to identify when inappropriate devices and software is being used on the network, and all staff should be educated on the need to secure their connected home systems as part of a larger effort to keep data secure.

Join the CSA IoT Working Group.

By Brian Russell, Co-Chair, CSA IoT Working Group
Brian Russell is the Chief Engineer/CyberSecurity for Leidos.

[Cloud Security Alliance Blog]

Palo Alto Networks Researcher Discovers Critical IE Vulnerability

Palo Alto Networks researcher Hui Gao was credited with discovery of a new critical Internet Explorer (IE) vulnerability affecting IE versions 6, 7, 8, 9, 10 and 11. CVE-2015-2548 is included in Microsoft’s October 2015 Security Bulletin and documented in Microsoft Security Bulletin MS15-109.

In our continuing commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors. (As of this writing, Microsoft researcher Bo Qu was also credited with critical IE vulnerability discoveries in August and July, acknowledged in revisions to Microsoft Security Bulletins MS15-065 and MS15-079.)

Palo Alto Networks is a regular contributor to vulnerability research. Previous critical IE vulnerability discoveries from the past 18 months included three in September, one in August, three in July (revised from two), three in June, three in May, one in March, five in February (revised from three), three in November 2014, one in October 2014, 15 in September 2014, three in August 2014, 10 in July 2014, and 22 in June 2014 (revised from 21).

By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.

[Palo Alto Networks Blog]

The Value of Shared Threat Intelligence

In a recent column for SecurityWeek, Scott Simkin examines the challenge of sharing threat intelligence among security vendors, but notes how vendors who treat threat intelligence as intellectual property are doing more harm than good when it comes to stopping cyber attacks.

As Scott writes, “When vendors and individuals try to keep threat intelligence private, they limit the ability of the entire group to identify and mitigate new threats as they are developed and launched against organizations.”

Read Scott’s article at SecurityWeek.com here.
Learn about Palo Alto Networks AutoFocus and actionable threat intelligence here.
Learn more about the Cyber Threat Alliance here.

[Palo Alto Networks Blog]

English
Exit mobile version