Logo

    isc2

    Explore "isc2" with insightful episodes like "RCRE 014 - CISSP Exam Questions (Domain 4)", "RCRE 013 - CISSP Exam Questions (Domain 4)", "RCR 046: Logging and Monitoring Activities (Domain 7)", "RCRE 012: CISSP Exam Questions (Domain 3)" and "RCRE 011: CISSP Exam Questions (Domain 3)" from podcasts like ""Reduce Cyber Risk Podcast - Cybersecurity Made Simple", "Reduce Cyber Risk Podcast - Cybersecurity Made Simple", "Reduce Cyber Risk Podcast - Cybersecurity Made Simple", "Reduce Cyber Risk Podcast - Cybersecurity Made Simple" and "Reduce Cyber Risk Podcast - Cybersecurity Made Simple"" and more!

    Episodes (61)

    RCRE 014 - CISSP Exam Questions (Domain 4)

    RCRE 014 - CISSP Exam Questions (Domain 4)

    Description:

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

    In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 4 (Communication and Network Security) of the ISC2 CISSP Exam. 

    BTW - Get access to all my CISSP Training Courses here at: 

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCRE 013 - CISSP Exam Questions (Domain 4)

    RCRE 013 - CISSP Exam Questions (Domain 4)

    Description:

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 4 (Communication and Network Security) of the ISC2 CISSP Exam. 

     

    BTW - Get access to all my CISSP Training Courses here at: 

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCR 046: Logging and Monitoring Activities (Domain 7)

    RCR 046: Logging and Monitoring Activities (Domain 7)

    Description:

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will talk about the following items that are included within Domain 7 (Security Operations) of the CISSP Exam:

     

    • CISSP / Cybersecurity Integration – Logging and Monitoring Overview
    • CISSP Training –  Logging and Monitoring Activities (Domain 7)
    • CISSP Exam Question – Logging and Monitoring / Data Life Cycle (Domain 7)

     

    BTW - Get access to all my CISSP Training Courses here at:   http://www.shongerber.com/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

     

    LINKS: 

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCRE 012: CISSP Exam Questions (Domain 3)

    RCRE 012: CISSP Exam Questions (Domain 3)

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam. 

     

    BTW - Get access to all my CISSP Training Courses here at:  http://reducecyberrisk.com/cissp-training/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCRE 011: CISSP Exam Questions (Domain 3)

    RCRE 011: CISSP Exam Questions (Domain 3)

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam. 

     

    BTW - Get access to all my CISSP Training Courses here at:  http://reducecyberrisk.com/cissp-training/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCR 045: Conduct security control testing (CISSP Domain 6)

    RCR 045: Conduct security control testing (CISSP Domain 6)

    Description:

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will talk about the following items that are included within Domain 6 (Security Assessment and Testing) of the CISSP Exam:

     

    • CISSP / Cybersecurity Integration – Disaster Recovery and Business Continuity
    • CISSP Training –  Conduct security control testing (Domain 6)
    • CISSP Exam Question – CVSS / Scanning Tools

     

    BTW - Get access to all my CISSP Training Courses here at:  http://reducecyberrisk.com/cissp-training/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

     

    LINKS: 

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCRE 010: CISSP Exam Questions (Domain 3)

    RCRE 010: CISSP Exam Questions (Domain 3)

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam. 

     

    BTW - Get access to all my CISSP Training Courses here at:  http://reducecyberrisk.com/cissp-training/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCRE 009: CISSP Exam Questions (Domain 3)

    RCRE 009: CISSP Exam Questions (Domain 3)

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam. 

     

    BTW - Get access to all my CISSP Training Courses here at:  http://reducecyberrisk.com/cissp-training/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCR 044: Identity and access provisioning lifecycle (CISSP Domain 5)

    RCR 044: Identity and access provisioning lifecycle (CISSP Domain 5)

     

    Description:

    Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

     

    In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam:

     

    • CISSP / Cybersecurity Integration – Identity Governance
    • CISSP Training –  Manage the identity and access provisioning lifecycle (Domain 5)
    • CISSP Exam Question – Username-Password / Preventative Controls

     

    BTW - Get access to all my CISSP Training Courses here at:  http://reducecyberrisk.com/cissp-training/

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

     

    LINKS: 

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    Cybersecurity Workforce Gap - Business Security Weekly #130

    Cybersecurity Workforce Gap - Business Security Weekly #130

    John McCumber is the Director, Cybersecurity Advocacy at (ISC)2. John will cover the statistics behind the cybersecurity workforce gap, and explain why what we perceive anecdotally isn't what we see in the media. Learn what is really taking place in cybersecurity hiring, training, and education. Find new opportunities in this data for your personal career growth.

    To learn more about ISC2, visit: https://securityweekly.com/isc2

    Full Show Notes: https://wiki.securityweekly.com/BSWEpisode130

    The Same Problem - Business Security Weekly #130

    The Same Problem - Business Security Weekly #130

    This week, we welcome John McCumber, Director of Cybersecurity Advocacy at (ISC)2, to talk about the statistics behind the cybersecurity workforce gap! In our second segment, we air a pre recorded interview with Andrew Hollister, Chief Architect and Product Manager at LogRhythm, discussing how to measure the effectiveness of your SOC!

     

    To learn more about ISC2, visit: https://securityweekly.com/isc2

    To learn more about LogRhythm, visit: https://securityweekly.com/logrhythm

    Full Show Notes: https://wiki.securityweekly.com/BSWEpisode130

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

     

    Visit our website: https://www.securityweekly.com

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

    The Same Problem - Business Security Weekly #130

    The Same Problem - Business Security Weekly #130

    This week, we welcome John McCumber, Director of Cybersecurity Advocacy at (ISC)2, to talk about the statistics behind the cybersecurity workforce gap! In our second segment, we air a pre recorded interview with Andrew Hollister, Chief Architect and Product Manager at LogRhythm, discussing how to measure the effectiveness of your SOC!

     

    To learn more about ISC2, visit: https://securityweekly.com/isc2

    To learn more about LogRhythm, visit: https://securityweekly.com/logrhythm

    Full Show Notes: https://wiki.securityweekly.com/BSWEpisode130

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

     

    Visit our website: https://www.securityweekly.com

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

    Cybersecurity Workforce Gap - Business Security Weekly #130

    Cybersecurity Workforce Gap - Business Security Weekly #130

    John McCumber is the Director, Cybersecurity Advocacy at (ISC)2. John will cover the statistics behind the cybersecurity workforce gap, and explain why what we perceive anecdotally isn't what we see in the media. Learn what is really taking place in cybersecurity hiring, training, and education. Find new opportunities in this data for your personal career growth.

    To learn more about ISC2, visit: https://securityweekly.com/isc2

    Full Show Notes: https://wiki.securityweekly.com/BSWEpisode130

    RCR 024: Security News and Cyber Awareness Training - Part I

    RCR 024: Security News and Cyber Awareness Training - Part I

    Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk.  Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.   

    In this episode, Shon will talk about recent security news: Big Trouble Down Under - Password Resets; Four signs you need a CISO; US Lawmakers looking at foreign VPN usage; PWC corporate director survey.  In addition, Shon will be providing Part I of his training Cyber Awareness Training and what you can do to implement within your organization.  Some of the content will include:  Methods to present training, content reviews, metrics, program evaluations, and the differences between security education, awareness and training...much, much more.  

     

    As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.  

     

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    RCR 023: Security News and Cybersecurity Frameworks - Part II

    RCR 023: Security News and Cybersecurity Frameworks - Part II

    Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk.  Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.   

     

    In this episode, Shon will talk about recent security news: NERC (CIP); Execs in Cybersecurity; Webstresers going to Jail.  In addition, Shon will be providing Part II of his training on the understanding of Cybersecurity Frameworks and their importance in protecting your business or for your CISSP certification.   Some of the content will include PCI-DSS, ISO 27001, Cybersecurity Framework, and so much more. 

     

    As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.  

     

    Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    ReduceCyberRisk.com - https://reducecyberrisk.com/

    Facebook - https://www.facebook.com/CyberRiskReduced/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free. 

    2017-009-Dave Kennedy talks about CIAs 'Vault7', ISC2, and Derbycon updates!

    2017-009-Dave Kennedy talks about CIAs 'Vault7', ISC2, and Derbycon updates!

    Wikileaks published a cache of documents and information from what appears to be a wiki from the Central Intelligence Agency (CIA).

    This week, we discuss the details of the leak (as of 11Mar 2017), and how damaging it is to blue teamers.

    To help us, we asked Mr. Dave Kennedy  (@hackingDave) to sit down with us and discuss what he found, and his opinions of the data that was leaked. Mr. Kennedy is always a great interview, and his insights are now regularly seen on Fox Business News, CNN, and MSNBC.

    Dave isn't one to rest on his laurels. For many of you, you know him as the co-organizer of #derbycon, as well as a board member of #ISC2.  We ask him about initiatives going on with ISC2, and how you (whether or not you're a ISC2 cert holder). You can help with various committees and helping to improve the certification landscape. We talk about how to get involved.

    We finish up asking about the latest updates to DerbyCon, as well as the dates of tickets, and we talk about our CTF for a free ticket to DerbyCon.

     

    Direct Link: http://traffic.libsyn.com/brakeingsecurity/2017-009-dave_kennedy_vault7_isc2_derbycon_update.mp3

    Youtube:  https://www.youtube.com/watch?v=lqXGGg7-BlM

    iTunes: https://itunes.apple.com/us/podcast/2017-009-dave-kennedy-talks-abotu-cias-vault7-isc2/id799131292?i=1000382638971&mt=2

     

    #Bsides #London is accepting Call for Papers (#CFP) starting 14 Febuary 2017, as well as a Call for Workshops. Tickets are sold out currently, but will be other chances for tickets. Follow @bsidesLondon for more information. You can find out more information at https://www.securitybsides.org.uk/   

    CFP closes 27 march 2017

    ------

    HITB announcement:

    “Tickets are on sale, And entering special code 'brakeingsecurity' at checkout gets you a 10% discount". Brakeing Down Security thanks #Sebastian Paul #Avarvarei and all the organizers of #Hack In The Box (#HITB) for this opportunity! You can follow them on Twitter @HITBSecConf. Hack In the Box will be held from 10-14 April 2017. Find out more information here: http://conference.hitb.org/hitbsecconf2017ams/

    ---------

    Join our #Slack Channel! Sign up at https://brakesec.signup.team

    #RSS: http://www.brakeingsecurity.com/rss

    #Google Play Store: https://play.google.com/music/m/Ifp5boyverbo4yywxnbydtzljcy?t=Brakeing_Down_Security_podcast

    iHeartRadio App:  https://www.iheart.com/show/263-Brakeing-Down-Securi/

    SoundCloud: https://www.soundcloud.com/bryan-brake

    Comments, Questions, Feedback: bds.podcast@gmail.com

    Support Brakeing Down Security Podcast on #Patreon: https://www.patreon.com/bds_podcast

    #Twitter: @brakesec @boettcherpwned @bryanbrake

    #Player.FM : https://player.fm/series/brakeing-down-security-podcast

    #Stitcher Network: http://www.stitcher.com/s?fid=80546&refid=stpr

    #TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/

     

     

    --show notes--

    http://www.bbc.com/news/world-us-canada-10758578

     

    WL: “CIA ‘hoarded’ vulnerabilities or ‘cyber-weapons’

        Should they not have tools that allow them to infiltrate systems of ‘bad’ people?

        Promises to share information with manufacturers

            BrBr- Manufacturers and devs are the reason the CIA has ‘cyber-weapons’

                Shit code, poor software design/architecture

                Security wonks aren’t without blame here either

     

    http://www.bbc.com/news/technology-39218393  -RAND report

            Report suggested stockpiling is ‘good’

                “On the other hand, publicly disclosing a vulnerability that isn't known by one's adversaries gives them the upper hand, because the adversary could then protect against any attack using that vulnerability, while still keeping an inventory of vulnerabilities of which only it is aware of in reserve.”

     

    Encryption does still work, in many cases… as it appears they are having to intercept the data before it makes it into secure messaging systems…  

    http://abcnews.go.com/Technology/wireStory/cia-wikileaks-dump-tells-us-encryption-works-46045668

     

    (somewhat relevant? Not sure if you want to touch on https://twitter.com/bradheath/status/837846963471122432/photo/1)

     

    Wikileaks - more harm than good?

        Guess that depends on what side you’re on

        What side is Assange on? (his own side?)

        Media creates FUD because they don’t understand

            Secure messaging apps busted (fud inferred by WL)

                In fact, data is circumvented before encryption is applied.

    Some of the docs make you wonder about the need for ‘over-classification’


    Vulnerabilities uncovered

     

    Samsung Smart TVs “Fake-Off”

    Tools to exfil data off of iDevices

        BrBr- Cellbrite has sold that for years to the FBI

            CIA appears to only have up to iOS 9 (according to docs released)

    Car hacking tech

    Sandbox detection (notices mouse clicks or the lack of them)

        Reported by eEye: https://wikileaks.org/ciav7p1/cms/page_2621847.html

    Technique: Process Hollowing: https://wikileaks.org/ciav7p1/cms/page_3375167.html

        Not new: https://attack.mitre.org/wiki/Technique/T1093

    **anything Mr. Kennedy feels is important to mention**

     

    What can blue teamers do to protect themselves?

        Take an accounting of ‘smart devices’ in your workplace

            Educate users on not bringing smart devices to work

                And at home (if they are remote)

                    Alexa,

            Restrict smart devices in sensitive areas

                SCIFs, conference rooms, even in ‘open workplace’ areas

               

        Segment possibly affected systems from the internet

        Keep proper inventories of software used in your environment

        Modify IR exercises to allow for this type of scenario?

        Reduce ‘smart’ devices

            Grab that drill and modify the TV in the conference room

            Cover the cameras on TV

                Is that too paranoid?

            Don’t setup networking on smart devices or use cloud services on ‘smart’ devices

        Remind devs that unpatched or crap code can become the next ‘cyber-weapon’ ;)

    2015-054: Dave Kennedy

    2015-054: Dave Kennedy

    Dave Kennedy does a lot for the infosec community. As owner/operator of 2 companies (Binary Defense Systems and Trusted Security), he also is an organizer of #DerbyCon and active contributor to the Social Engineering ToolKit (#SET).  You can also find him discussing the latest hacking attempts and breaches on Fox News and other mainstream media outlets.

    But this time, we interview Dave Kennedy because he has been elected to the ISC2 board. He will be serving a 3 year term with Wim Remes (who we interviewed a couple of weeks ago) and others to improve #ISC2 processes, and to make #CISSP and other certs more competitive in the #infosec/IT community.

    And yes... we find out about what is going on with DerbyCon and get some updates with what will happen in the next DerbyCon.

     

    iTunes Link: https://itunes.apple.com/us/podcast/2015-054-dave-kennedy/id799131292?i=359677576&mt=2

    TuneIn Radio App: http://tunein.com/r…/Brakeing-Down-Security-Podcast-p801582/

    BrakeSec Podcast Twitter: http://www.twitter.com/brakesec

    Join our Patreon!: https://www.patreon.com/bds_podcast

    Comments, Questions, Feedback: bds.podcast@gmail.com

    2015-052: Wim Remes-ISC2 board member

    2015-052: Wim Remes-ISC2 board member

    I got a hold of Mr. Wim Remes, because he was elected to the ISC board in November 2015.  Recent changes to the CISSP included changing the long-standing 10 domains down to 8 domains, plus a major revamp to all of them.

    I wanted to know what Mr. Remes' plans were for the coming term, how the board works, and how organizations like ISC2 drive change in the industry. I also asked Wim how he is trying to ensure that CISSP and the other certs are going to remain current and competitive.

    This is a great interview if you're looking to get your #CISSP or any other ISC2 cert, or you currently have an #ISC2 #certification and want to get knowledge of the workings of ISC2 and the board.

     

    Mr. #Remes' Twitter: @wimremes

    ISC2 official site: http://www.isc2.org

     

    Direct Link: http://traffic.libsyn.com/brakeingsecurity/2015-052-wim_remes-isc2.mp3

    iTunes: https://itunes.apple.com/us/podcast/2015-052-wim-remes-isc2-board/id799131292?i=359103338&mt=2

    TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/

    BrakeSec Podcast Twitter: http://www.twitter.com/brakesec

    Join our Patreon!: https://www.patreon.com/bds_podcast

    Comments, Questions, Feedback: bds.podcast@gmail.com

    DtSR Episode 144 - Insights from the ISC2 2015 Survey

    DtSR Episode 144 - Insights from the ISC2 2015 Survey

    In this episode...

    • David Shearer, Executive Director for ISC2 joins us to talk about the results of the ISC2 2015 Information Security Workforce Study
    • We ask David to highlight some of the results
    • We discuss how malware and application security were identified as top threats 3 years in a row -- and what's to be done about this
    • We discuss the major discrepancy between priorities from this survey and recent CIO surveys
    • We discuss the importance of communication skills (identified in the survey) while leadership and business management are far down the scale
    • We discuss with David how under his leadership ISC2 can build a much tighter alignment to business -- not just more security certifications

    Guest

    • David Shearer - David Shearer has more than 27 years of business experience including the chief operating officer for (ISC)², associate chief information officer for International Technology Services at the U.S. Department of Agriculture, the deputy chief information officer at the U.S. Department of the Interior, and the executive for architecture, engineering and technical services at the U.S. Patent and Trademark Office. Shearer has been responsible for managing and providing services via international IT infrastructures, and he has implemented large-scale SAP Enterprise Resource Planning (ERP) projects. Shearer holds a B.S. from Park College, a M.S. from Syracuse University, management and technical certificates from the U.S. National Defense University, and he is a U.S. federal executive presidential rank award recipient. As (ISC)² Executive Director, Shearer is responsible for the overall direction and management of the organization.

       

    Support the show

    >>> If you're reading this, consider clicking the link above to support the show!
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
    YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
    LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
    X/Twitter: https://twitter.com/dtsr_podcast

    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io