|
jason
|
 |
« on: September 05, 2012, 09:26:32 AM » |
|
I'm putting together a list of column topics for next year. Keeping in mind that I'm staying roughly in the area of general information security, what would you all be interested in reading about?
|
|
|
|
|
Logged
|
|
|
|
|
tturner
|
 |
« Reply #1 on: September 05, 2012, 12:52:02 PM » |
|
Hacking web services and/or mobile apps.  Oh you said general information security... How about - metrics that don't suck?
|
|
|
|
|
Logged
|
Certifications: CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP WIP: OSWP, GSSP-JAVA, GXPN Udacity on hold, again. I suck. http://sentinel24.com/blog @tonylturner http://bsidesorlando.org
|
|
|
|
jason
|
 |
« Reply #2 on: September 05, 2012, 02:03:40 PM » |
|
Metrics to measure anything in particular?
|
|
|
|
|
Logged
|
|
|
|
|
m0wgli
|
 |
« Reply #3 on: September 05, 2012, 02:47:29 PM » |
|
Trying to keep within the remit of general information security. I'd be interested in reading about how to respond to incidents and what can subsequently be learnt from them, and, how to deal with insider threats.
|
|
|
|
|
Logged
|
Security + | OSWP | eCPPT | CSTA
|
|
|
|
jason
|
 |
« Reply #4 on: September 05, 2012, 02:54:52 PM » |
|
Ok, so far we have:
Metrics Incident response Insider threats
What else?
|
|
|
|
|
Logged
|
|
|
|
|
tturner
|
 |
« Reply #5 on: September 05, 2012, 03:12:03 PM » |
|
Metrics to measure the effectiveness of security program. For instance I find the number of spams blocked to be a poor metric that's more about big numbers in a chart than any meaningful representation of how the organization is reducing risk or saving money. Good metrics are things like measuring number of incidents detected internally vs by customers, attack vectors, time to respond to incident, time to close out incident, lag time for remediating vulnerabilities, etc.
|
|
|
|
|
Logged
|
Certifications: CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP WIP: OSWP, GSSP-JAVA, GXPN Udacity on hold, again. I suck. http://sentinel24.com/blog @tonylturner http://bsidesorlando.org
|
|
|
|
jason
|
 |
« Reply #6 on: September 05, 2012, 03:50:13 PM » |
|
Roger that. On the list.
|
|
|
|
|
Logged
|
|
|
|
|