Welcome to cissp CISSP training Certified Information Systems Security Professional
Search
Nickname Password Security Code Security Code Type Security Code  

You are certified but are your qualified?  Become qualified today.


Rated #1 Training

Surveys

Where do you find the best price for books?

Amazon.Com
Bookpool.Com
The ISC2 webstore
CISSPS.COM
Cheapbooks.com
Ecampus.com
Other (Please leave a comment with name of site)



Results
Polls

Votes: 1272
Comments: 33

Who's Online

There are currently, 100 guest(s) and 26 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

Training Classes Calendar

Test of Widget

 

The CCCure Family of Portals is strictly supported by our Sponsors below and Donations.

Core Impact your compliance best friend Top Training for Top Results, delivered by Security University

Advertise Now

Home of CORE Impact
Click
Here to visit.
List of Classes
Register for a class
CLICK HERE
to get more details

Clement, Nathalie, and Alain the Portals administrators wishes you a warm welcome.

Great supplements to help you reach your certification goals


Upcoming Classes and Events

<< February 2010 >>

S M T W T F S
  123456
78910111213
14151617181920
21222324252627
28           
02/22• CISSP Class Reston, VA
03/08• CISSP, Dublin, Ireland
03/22• Q/EH® Qualified/ Ethical Hacker Class
03/22• CISSP Class, Reston, VA Delivered by Cleme...
03/29• Security+ Boot Camp, Reston, VA
04/19• CISSP Boot Camp, Reston, VA
04/19• CISSP, Rome, Italy delivered by Clement Du...
05/01• CISSP Class, Dubai, UAE delivered by Cleme...
05/08• CISSP Class, Doha, Qatar delivered by Clem...

Official (ISC)2 Guide to the CISSP CBK, Second Edition
Posted by boss on Thursday, 04 February 2010 @ 21:23:44 EST (66 reads)
Topic CISSP Books

cdupuis writes "

NOTE FROM CLEMENT:

The long awaited update to the Official ISC2 Study Guidewas finally released at the beginning of 2010.  The first edition was severely criticized due to the many errors, contradiction, and mistakes that were in the book.  It seems this version went through a lot more thorough Technical Editing process where CISSP's and the different authors have scrutinized each of the chapters to ensure accuracy.   The book has gained more pages as well.  The previous edition was filled with a lot of fluff such as appendixes, glossaries, etc...     This one seems to be content oriented.  I have not read through the whole book yet.  If you did read through the whole book I would be VERY interested in getting your feedback.  If you do find any errors, mistakes, or contradictions, I have created a new forum to post them and discuss them with others as well. 

Visit the link below to give us feedback about the new book:

https://www.cccure.org/forum-6.html

If you do find any mistakes, visit the link below to contribute them to the forum reserved for that purpose:

https://www.cccure.org/forum-74.html

Product Description

With each new advance in connectivity and convenience comes a new wave of threats to privacy and security capable of destroying a company’s reputation, violating a consumer’s privacy, compromising intellectual property, and in some cases endangering personal safety. This is why it is essential for information security professionals to stay up to date with the latest advances in technology and the new security threats they create.

Recognized as one of the best tools available for the information security professional and especially for candidates studying for the (ISC)2 CISSP examination, the Official (ISC)2® Guide to the CISSP® CBK®, Second Edition has been updated and revised to reflect the latest developments in this ever-changing field. Endorsed by the (ISC)2, this book provides unrivaled preparation for the certification exam that is both up to date and authoritative. Compiled and reviewed by CISSPs and (ISC)2 members, the text provides an exhaustive review of the 10 current domains of the CBK—and the high-level topics contained in each domain.

Unique and exceptionally thorough, this edition includes a CD with over 200 sample questions, sample exams, and a full test simulation that provides the same number and types of questions with the same allotment of time allowed in the actual exam. It will even grade the exam, provide the correct answers, and identify areas where more study is needed.

Earning your CISSP is a deserving achievement that makes you a member of an elite network of professionals. This book not only provides you with the tools to effectively study for the exam, but also supplies you with ready access to best practices for implementing new technologies, dealing with current threats, incorporating new security tools, and managing the human factor of security—that will serve you well into your career.

The ISC2 Guide to the CISSP CBK Second Edition

The Official ISC2 Guide to the CISSP CBK Second Edition
Click Here to get your copy or more details

"

(comments? | Score: 0)


IEEE Computing Now magazine -- Special issue on Biometric
Posted by boss on Wednesday, 03 February 2010 @ 17:28:44 EST (47 reads)
Topic Awareness Info

cdupuis writes "

IEEE COMPUTING NOW SPECIAL ISSUE ON BIOMETRICS

Learn about biometric technology, what's next for traditional techniques such as fingerprint and iris recognition, and new modalities that could soon be available commercially.—Ron Vetter and Karl Ricanek Jr., Guest Editors

Iris Recognition: The Path Forward
By Arun Ross

Fingerprint Matching
By Anil K. Jain, Jianjiang Feng, and Karthik Nandakumar

Face Recognition by Computers and Humans
By Rama Chellappa, Pawan Sinha, and P. Jonathon Phillips

Unconstrained Biometric Identification: Emerging Technologies
By Karl Ricanek Jr., Marios Savvides, Damon L. Woodard, and Gerry Dozier

News
Biometrics Could Streamline Border Crossings
By Greg Goth

Evaluating Biometric Systems
The Biometric Menagerie
By Neil Yager and Ted Dunstone

"

(comments? | Score: 0)


CISSP for Dummies 3rd Edition by Peter Gregory
Posted by boss on Tuesday, 02 February 2010 @ 14:31:47 EST (68 reads)
Topic CISSP Books

cdupuis writes "

NOTE FROM CLEMENT:

This book has no fluff and is to the point.  This is a great book if you have dozen of years of experience and you do not want to read through the thousand of pages offered within some of the other books.   It is also a great resource for a last minute review of the ten domains.  It can help you identify key points rapidly and it has a bit of humour which makes this easier to read.  Peter Gregory has done a fantastic job in this book and I HIGHLY recommend it for your studies.   Do not be deceived by the title, it is all the opposite,  you would be dum not to get it.

The bestselling guide to CISSP certification – now fully updated for the latest exam!

The CISSP for DUMMIES third editon by Peter Gregory

There are currently over 75,000 CISSP certified people out there and thousands take this exam each year. The topics covered in the exam include: network security, security management, systems development, cryptography, disaster recovery, law, and physical security. CISSP For Dummies, 3rd Edition is the bestselling guide that covers the CISSP exam and helps prepare those wanting to take this security exam.

The 3rd Edition features 200 additional pages of new content to provide thorough coverage and reflect changes to the exam. Written by security experts and well-known Dummies authors, Peter Gregory and Larry Miller, this book is the perfect, no-nonsense guide to the CISSP certification, offering test-taking tips, resources, and self-assessment tools.

  • Fully updated with 200 pages of new content for more thorough coverage and to reflect all exam changes
  • Security experts Peter Gregory and Larry Miller bring practical real-world security expertise
  • CD-ROM includes hundreds of randomly generated test questions for readers to practice taking the test with both timed and untimed versions

 

Visit the link below to give us feedback about the new book:

https://www.cccure.org/forum-6.html

If you do find any mistakes, visit the link below to contribute them to the forum reserved for that purpose:

https://www.cccure.org/forum-74.html

CISSP For Dummies, 3rd Edition can lead you down the rough road to certification success!

Get all the details at:

https://www.amazon.com/CISSP for Dummies 3rd edition by Peter Gregory

"

(comments? | Score: 0)


Where can I get the best price for the CISSP All In One 5th Edition?
Posted by boss on Tuesday, 02 February 2010 @ 13:55:22 EST (37 reads)
Topic CISSP Books

cdupuis writes "

Lately I have received many emails from site visitors and members asking me WHY I am no longer selling the CISSP All In One 5th Edition book within my webstore at http://www.cccure.com.   The reason is very simple:  I cannot compete with large retailers and I will not sell you a book for $20 more just for the sake of taking away your money.   I prefer to refer you directly to Amazon or other source where the price is a lot lower, below you will find some of the prices advertised on leading book retailers sites and CISSP related sites as of the publication of this article.

The list price on McGraw Hill is: $79.99.  

As you can see below you MUST shop when you buy your book.  There is significant differences in the pricing being used by different vendors.  Let's face it, it is the exact same book for all of the vendors listed below, you may as well save significant amount of money by buying it directly from Amazon as they are offering service, fair price, quick shipping, and they are reputable as well.

CISSP.COM          $74.99

Logical Security    $65.00

Buy.com              $47.99

WallMart              $47.00

Amazon.com        $46.79

The WINNER is:  AMAZON.COM -- CLICK HERE TO GET YOUR COPY FROM AMAZON.COM

"

(comments? | Score: 0)


Get FREE copies of Hakin9 Magazine in PDF format
Posted by boss on Tuesday, 02 February 2010 @ 09:53:14 EST (106 reads)
Topic Hackers

cdupuis writes "

NOTE FROM CLEMENT:

Below you have a few copies of Hakin9 that you can download for free from the Hakin9 web site.  On the same page as the magazine you will also find dozens of great articles that you can look at.  They are all in PDF Format.

All that is required to access the downloads is to join their mailing list.  You will immediately receive through email a confirmation link with instruction on how to access the files.  Do read the past issues, you will see that coverage is very thorough and most of the content would still be applicable today with minor changes.  Hakin9 is a magazine that I like very much and it always contains great articles and howto.  The printed magazine comes with a bootable version of Backtrack plus many commercial utilities with license to use.  The best way to really appreciate if it is for you or not is by downloading some of the copies below and see for yourself.

MY ERP GOT HACKED!  Release Date: 2009-07

04_2009-1_free

Issue_contents
  • Nokia’s Vow of Silence
  • Phishing
  • Print Your Shell
  • My ERP Got Hacked – An Introduction to Computer Forensics
  • Attacks On Music and Video Files
  • The Strings Decoding Process
  • Hacking Through Wild Cards
  • Create a Self-Signed Digital Certificate with OpenSSL
  • Automating Malware Analysis

FREE ISSUE: My ERP Got hacked! 04/2009  Download pdf


Breaking Client-Side Certificate Protection   Release Date: 2009-03

Hakin9_3_2009_en

Issue_contents
  • Brute Force Attack
  • Exporting Nonexportable Certificates
  • User Enumeration with Burp Suite
  • More Thoughts on Defeating AntiVirus
  • A New Era for Buffer Overflow
  • Automating Malware Analysis
  • Anatomy of Malicious PDF Documents
  • Analyzing Malware Packed Executables
  • Bootleggers and the Internet
  • Interview with Nicholas J. Percoco
  • Self exposure with…

    FREE ISSUE: Breaking Client-Side Certificate Protection 03/2009   Download pdf

 

The Real World Clickjacking  Release Date: 2009-02

Hakin9_2_2009_en

Issue_contents
  • Metasploit Alternate Uses for a Penetration Test
  • Backdooring Frameworks
  • The Real World Clickjacking
  • Apple Super Drive. Set It Free
  • Mapping HTTP Interface Embedded Devices
  • How Does Your Benchmark of Physical Security Affect Your Environment?
  • iPhone Forensics
  • Safer 6.1
  • Making Open Security Research Sustainable
  • Interview with Raffael Marty
  • Self exposure with…
  • ENGARDE SECURE LINUX
  • Analyzing Malware

    FREE ISSUE: The Real World Clickjacking 02/2009    Download pdf

 


Hacking Instant Messenger    Release Date: 2001-01

Hakin9_1_2009_en

Issue_contents
  • Metasploit Alternate Uses for a Penetration Test
  • Backdooring Frameworks
  • The Real World Clickjacking
  • Apple Super Drive. Set It Free
  • Mapping HTTP Interface Embedded Devices
  • How Does Your Benchmark of Physical Security Affect Your Environment?
  • iPhone Forensics
  • Safer 6.1
  • Making Open Security Research Sustainable
  • Interview with Raffael Marty
  • Self exposure with…
  • ENGARDE SECURE LINUX
  • Analyzing Malware

FREE ISSUE: Hacking Instant Messenger 01/2009  Download pdf

 

"

(comments? | Score: 0)


Researchers criticise 3D Secure credit card authentication
Posted by boss on Monday, 01 February 2010 @ 06:48:42 EST (63 reads)
Topic Awareness Info

cdupuis writes "
26 January 2010, 19:01


An example of 3DS phishing sites Researchers at the University of Cambridge Computer Laboratory, say the 3D Secure (3DS) authentications system branded as the "Verified by Visa" and "MasterCard SecureCode" schemes are "a text book example of how not to design an authentication protocol". The researchers, Steven J Murdoch and Ross Anderson, make their criticisms in a paper[1]PDF being presented today at the Financial Cryptography and Data Security '10 (FC10) conference. It examines the failings of the credit card verification scheme which was introduced by banks as a response to the rise in fraud for card-not-present transactions.

In the paper, they identify a number of weaknesses, for example, the mechanism used to display the 3DS form is embedded within an iframe or pop-up with no address bar, so there us no indication of where the form has come from. This goes against banks advice to their customers to avoid phishing sites by only entering bank passwords into sites they can identify as the bank's own site. When one of the researchers initially encountered 3DS, he found the content was being served by securesite.co.uk and contacted his bank who informed him that this was a phishing site. In fact, securesite.co.uk belongs to Cyota, who are owned by RSA and handles the 3DS authentication process for many UK banks.

The researchers also criticise the initial password entry process which occurs the first time a card holder uses a 3DS enabled card to shop online. The user is asked to enter a new password as part of the process of making the purchase, which the researchers feel is a bad time to ask for the password as the user is probably more interested in shopping and more likely to choose a weak password. They also note that the process of entering the new password also signs the user up to new terms and conditions which shift liability onto the customer despite the bank having made "many poor security choices". Other problems included inconsistent authentication methods, weak mutual authentication with a memorable phrase having to be chosen when a new password is entered and concerns about privacy.

The paper concludes that the "single sign-on" model that the 3DS system implements is the wrong model and that what should replace it is a transaction authentication system where, for example, a user would receive an SMS message saying "You are about to pay $X to Merchant Y" and requesting an authorisation code from the customer, at least as a stop-gap until a more trustworthy payment device could be brought into use. The motivation for this, the researchers feel, should come from regulators intervening on behalf of consumers.


URL of this Article:
http://www.h-online.com/security/news/item/Researchers-criticise-3D-Secure-credit-card-authentication-914144.html

Links in this Article:
  [1] http://www.cl.cam.ac.uk/~rja14/Papers/fc10vbvsecurecode.pdf

"

(comments? | Score: 0)


New logo for the CCCure Family of Portals
Posted by boss on Friday, 29 January 2010 @ 23:15:05 EST (58 reads)
Topic CISSP OSG INFO

cdupuis writes "

Today I am happy to present our new logo:

The CCCure Family of Portals

Our new logo represent very well the mission of CCCure and it's family of portals.

It shows that our mission is Education, Information System Security, helping people worldwide.

Every month we have people from more than 125 countries that are making use of our portals.  That's over 100,000 unique visitors overall.  We are proud today to show our new identity,  the next time you see it you will know it is not a clone, a rogue, or a fake.  It is the real thing.

Thanks to all who supported us over the past ten years.

Best regards

Clement, Nathalie, and Alain
Site Owners and Maintainers

 

"

(comments? | Score: 0)


CISSP All In One FIFTH EDITION book has been released
Posted by boss on Thursday, 21 January 2010 @ 22:49:04 EST (233 reads)
Topic CISSP Books

cdupuis writes "

Get all the details at:

https://www.cccure.com/cart/products/CISSP-ALL-IN-ONE-FIFTH-EDITION-from-Shon-Harris.html

Just Released January 15, 2010 

A comprehensive, up-to-date revision of the market-leading CISSP training resource 

cissp_large.jpg



Written by the bestselling author and a respected IT security trainer Shon Harris, this exam guide offers complete coverage of all the material on the Certified Information Systems Security Professional (CISSP) exam. With full treatment of all the 10 exam domains, as developed by the International Information Systems Security Certification Consortium (ISC2), this definitive tool contains learning objectives at the beginning of each chapter, sidebars with in-depth technical explanations, practice questions, and real-world scenarios.

Detailed and authoritative, Shon Harris' CISSP All-in-One Exam Guide, Fifth Edition serves as both a comprehensive certification study guide and student work book, and a fundamental on-the-job reference. The CD-ROM includes more than 800 simulated practice questions in a Windows-based test engine, an electronic book, and video training from the author.

Book Details
Harcover:
1008 pages
Dimensions (in inches):
2.25 x 9.25 x 7.50
Publisher:
McGraw-Hill Osborne Media; 5th edition (February 8, 2010)
Language:
English
ISBN:

0071602178 (OR) 978-0071602174

 


Shon Harris, CISSP, MCSE, is a security consultant, a former engineer in the Air Force Information Warfare Unit, an instructor, an author, and President of Logical Security.  

She has written two best selling CISSP books, and co-authored Hacker's Challenge and Gray Hat Hacking. Shon has developed a new security book series, being published by McGraw-Hill, which will be sold to corporations, universities, colleges, and professionals throughout the world. This series will set the new standards in security training, education, and industry practices.

She is an active contributor for Information Security Magazine and Windows 2000 Magazine. Shon has taught computer and information security to a wide range of clients including RSA, Department of Defense, Department of Energy, National Security Agency (NSA), Bank of America, Defense Information Systems Agency (DISA), BMC, and more.

Shon was recently recognized by Information Security Magazine as one of the top 25 women technologists, researchers and executives reshaping information security today.

 

 

Chapter 1: Reasons to Becoming a CISSP Chapter 2: Security Trends Chapter 3: Security Management Practices Chapter 4: Access Control Chapter 5: Security Architecture and Models Chapter 6: Physical Security Chapter 7: Telecommunications and Network Security Chapter 8: Cryptography Chapter 9: Business Continuity Planning and Disaster Recovery Chapter 10: Laws, Investigations, and Ethics Chapter 11: Applications and Systems Development Security Chapter 12: Operations Security Appendix: About the CD-ROM Index

Visit the link below to give us feedback about the new book:

https://www.cccure.org/forum-6.html

If you do find any mistakes, visit the link below to contribute them to the forum reserved for that purpose:

https://www.cccure.org/forum-74.html

Get all the details at:

https://www.cccure.com/cart/products/CISSP-ALL-IN-ONE-FIFTH-EDITION-from-Shon-Harris.html

"

(comments? | Score: 0)


CPE = CONTINUOUS PAYMENT EXPECTED
Posted by boss on Thursday, 21 January 2010 @ 20:45:21 EST (185 reads)
Topic CISSP OSG INFO

cdupuis writes "

NOTE FROM CLEMENT:

CompTIA has joined the rank of certification body who will require CPE's to keep our A+, Network+, and Security+ certification current as well as imposing an expiry date or renewal cycle every 3 years like other certification body are doing.

If the whole CPE things was done properly it would be great.  However in most case this is use as a way of making more money by offering seminars and other cheesy training to make CPE's.  When will people get serious about providing skills and knowledge as a priority.

See the announcement below from CompTIA:

CompTIA Certification Renewal Policy

CompTIA A+, CompTIA Network+ or CompTIA Security+ certifications are now valid for three years from the date the candidate is certified. The change brings the CompTIA certifications in line with the practice of other major providers of certifications for IT professionals, such as Cisco, Microsoft and Oracle.

The renewal policy also is required for these three certifications to maintain their accreditation and compliance with internationally accepted standards for assessing personnel certification programs (ANSI/ISO/IEC 17024). CompTIA A+, CompTIA Network+ and CompTIA Security+ certifications earned the ISO 17024 accreditation from the International Organization for Standardization (ISO) in 2008. ISO requires that individuals have a way to renew the currency of their certification on a regular basis. In CompTIA’s case, renewal will occur every three years.

The new certification renewal policy is applicable to all individuals who hold CompTIA A+, CompTIA Network+ or CompTIA Security+ certifications, regardless of the date they were certified. Other CompTIA certifications are not affected at this time.

Beginning January 1, 2010, a “Valid Through” date appears on all certificates and certificate holder ID cards for individuals who earn CompTIA A+, CompTIA Network+ or CompTIA Security+. The date is three years from the date of certification.

Certification renewal will ensure that individuals have the most up-to-date skills and knowledge to deal with the fast-changing IT environment.

In conjunction, CompTIA is introducing a continuing education program for individuals with multiple ways to earn continuing education credits to maintain their active certifications.

Among activities that will qualify for continuing education credits are passing a “bridge” exam or the most current exam for their CompTIA certification; teaching, lecturing or presenting on relevant industry topics; participating in non-degree courses or computer-based training; attending relevant industry conferences and events; participating in a CompTIA exam development workshop; publishing articles, whitepapers, blogs or books on relevant topics; obtaining other industry certifications; or completing industry-related college courses from degree-granting institutions.

Enrollment in the certification renewal program is expected to be available in mid-2010.

"

(Read More... | 2 comments | Score: 0)


ISACA Announces New CRISC Certification for Risk Professionals
Posted by boss on Sunday, 17 January 2010 @ 18:26:29 EST (132 reads)
Topic ISACA

cdupuis writes "

Rolling Meadows, IL, USA (13 January 2010)—ISACA, a global association of 86,000 IT audit, risk, governance and security professionals, is responding to market demand by introducing a new risk-related certification. The Certified in Risk and Information Systems Control (CRISC) designation is for IT professionals who identify and manage risks through the development, implementation and maintenance of information systems (IS) controls. These professionals help enterprises accomplish business objectives such as effective and efficient operations, reliable financial reporting, and compliance with regulatory requirements.

A grandfathering program, through which experienced professionals can earn the certification without passing an exam, will open in April. The first CRISC exam will be administered in 2011.

ISACA established CRISC (pronounced “see risk”) to recognize IT professionals with skills and abilities related to:

  • Risk identification, assessment and evaluation
  • Risk response
  • Risk monitoring
  • IS control design and implementation
  • IS control monitoring and maintenance

“The CRISC designation will demonstrate to employers that the certification holder is able to identify and evaluate the risks unique to their specific organization and help the enterprise accomplish its business objectives by designing, implementing, monitoring and maintaining risk-based, efficient and effective IS controls,” said Urs Fischer, chair of ISACA’s CRISC Task Force. “We conducted an extensive amount of research globally and found that enterprises are becoming more risk-aware and are looking to identify professionals who possess the skills to help them protect their assets and enhance their businesses. CRISC fills a gap that currently exists in the marketplace.”

CRISC complements ISACA’s three existing certifications: Certified Information Systems Auditor (CISA), established in 1978 and earned by more than 70,000 professionals since its inception; Certified Information Security Manager (CISM), earned by more than 12,000 professionals since it was launched in 2002; and the newer Certified in the Governance of Enterprise IT (CGEIT), earned by more than 4,000 professionals since it was developed in 2006:

  • CISA is designed for IT professionals who perform independent reviews of control design and operational effectiveness; CRISC is for IT and business professionals who design, implement and maintain IS controls.
  • CISM is for individuals who manage, design, oversee and/or assess an enterprise’s information security, including the identification and management of information security risks; CRISC is for IT professionals whose roles also encompass operational and compliance considerations.
  • CGEIT is for IT and business professionals who have a significant management, advisory or assurance role relating to the governance of IT, including risk management; CRISC is for IT and business professionals who are engaged at an operational level to mitigate risk.

Additional information about the CRISC certification is available at www.isaca.org/crisc.

About ISACA®

With more than 86,000 constituents in more than 160 countries, ISACA® (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems assurance and security, enterprise governance of IT, and IT-related risk and compliance. Founded in 1969, ISACA sponsors international conferences, publishes the ISACA® Journal, and develops international information systems auditing and control standards. It also administers the globally respected Certified Information Systems Auditor™ (CISA®), Certified Information Security Manager® (CISM®) and Certified in the Governance of Enterprise IT® (CGEIT®) and Certified in Risk and Information Systems Control™ (CRISC™) designations.

ISACA developed and continually updates the COBIT®, Val IT™ and Risk IT frameworks, which help IT professionals and enterprise leaders fulfill their IT governance responsibilities and deliver value to the business.

Media Contacts:

Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org
Deborah Vohasek, +1.847.660.5566, dvohasek@isaca.org
Joanne Duffer, +1.847.660.5564, jduffer@isaca.org

ISACA
3701 Algonquin Road, Suite 1010
Rolling Meadows, IL 60008
USA

"

(comments? | Score: 0)


10 valuable advices to land a job in 2010
Posted by boss on Friday, 15 January 2010 @ 14:56:59 EST (123 reads)
Topic JOBS

cdupuis writes "

So, here we are: 2010 is here already! Several good thoughts and hopes of a better future flooded our minds during these past couple of days, so now it’s time to kick off and make all our wishes to realize. For many of us, 2010 renovates the perspective of finding a job if unemployed, or a better job in case you strive for different horizons. Regardless of what drives you, finding a new job sounds like a daunting task if you’re not prepared. So what about having a little help to give you the edge and make the hunting a bit easier?

Below I share a bit of my personal experience (and also of my close colleagues) that should help you put together your personal strategy to land a job. So get yourself ready, leave your comfort zone and let’s make our career resolutions come true!

See the whole article at: 

http://www.myinfosecjob.com/2010/01/10-valuable-advices-to-land-a-job-in-2010/#more-438

"

(comments? | Score: 0)


2010: A Good Time to Start an Information Security Career
Posted by boss on Friday, 15 January 2010 @ 14:50:46 EST (156 reads)
Topic JOBS

cdupuis writes "

Another great article published on the BankInfoSecurity web site:

January 8, 2010 - Tom Field

 

Tom Field
With the global recession barely in the rearview mirror, you hear a lot of people saying one of two things: "I'm lucky to even have a job" or "This is a lousy time to be looking for work."

I hear that latter statement, especially, and think to myself "Man, not if you're in information security!"

This year and next year, bar none, security is the smart place to be in IT. - David Foote 
For a lot of reasons, now is a very good time to be looking for work if your talent is protecting other people's data.

First of all, from the president on down, this nation is all about cybersecurity these days. It's one of the three hottest topics in Washington, D.C., and as my colleague Eric Chabrow says, you're likely to see some major cybersecurity policy at least discussed in 2010. Government agencies are eager to hire new, skilled security professionals.

The second hot topic in D.C. is healthcare. In 2009, the federal government gave healthcare organizations a boatload of money to create electronic records, and in 2010 it's going to enforce new regulations to help protect those records. Think this initiative won't call for additional personnel skilled in risk management, privacy and incident response? Good time to be an information security professional in healthcare. And stay tuned, please, for further discussion on this subject.

And then there's banking reform - the third hot topic in D.C. And while it's hard to imagine exactly how the regulatory agencies will be reshuffled when all the dealing is done, it is clear that: 1) There will be increased regulation, especially for non-banking financial institutions; 2) There will be greater consumer advocacy and security standards; 3) All of this regulatory pressure is going to require new bodies inside the institutions to secure critical systems, as well as outside to examine them.

Like I said, a good time to either start or re-start a career in information security.

I caught up recently with David Foote of Foote Partners LLC, a leading IT staffing research firm. He's been tracking technology-related job trends literally for decades now, and his assertion flat-out is: There's never been a better time to be an information security professional. "This year and next year, bar none, security is the smart place to be in IT," says Foote, who in his conversation with me discusses the wave that has driven the surge in security jobs, as well as his predictions for 2010-2012.

I'd be remiss if I didn't mention our recent Information Security Today Career Trends Survey, which looks academic, business and industry objectives for 2010, pointing to risk management, cybersecurity and fraud/forensics as the hottest topics for training in growth.

But what's the career outlook from your perspective? Where do you see the best information security jobs in 2010, and what are you doing to grow your own career?

Indeed, we are all lucky to have jobs these days. But we're even luckier to be in a field that's growing as quickly as information security.

Here's to a prosperous - and secure - 2010.

"

(comments? | Score: 0)


Job Offer Consultant - ISO27001 Implementation & Certification
Posted by boss on Thursday, 14 January 2010 @ 19:15:05 EST (138 reads)
Topic JOBS

cdupuis writes "

Job Title:             Consultant - ISO 27001 Implementation & Certification

Closing Date:     28th Feb, 2009

Location:             Doha, Qatar

Contact:              Balwant Rathore at balwant_rathore@oissg.org

 

Profile:

The consultant should provide a structured programme to assist clients in ISO 27001 implementation for accreditation.

Required competencies:

  • 2-5 yrs of experience in implementation and maintenance of ISO 27001 in medium / large size organizations.
  • In depth knowledge of ISO 27001 standard requirements and end-to-end (from beginning to the end) involved in at least one cycle of ISO 27001 certification process.
  • Good knowledge in policy/procedure development
  • Trained ISO 27001 Internal Auditor and extensive experience in conducting audits

Preferred competencies:

  • Certified ISO 27001Lead Auditor
  • ISO 27001 Training Experience
  • CISSP Training Experience
  • Knowledge / Experience in standards like ISO 20000, ISO 9001 and CMMI

Others:

  • Excellent oral and written communication skills is must
  • Candidate from big 4 consulting firms are preferred

Interview Process:

  • Short listing of profiles
  • Telephonic Interview
  • Schedule a personal interview

 

"

(comments? | Score: 0)


Info for students that lost money due to Vigilar Intense School closing doors
Posted by boss on Thursday, 14 January 2010 @ 18:26:37 EST (177 reads)
Topic CISSP OSG INFO

cdupuis writes "

Hi Everyone,

Today is an exceptionally great day for your clients and students that paid Intense School pre-paid fees for classes. 

I have contacted SCHEV (State Council of Higher Education for Virginia) in VA - the licensing board in the State of VA and they said students can get a portion of their money refunded.

Linda Woodley is the SCHEV Director and has confirmed Intense School class fees may be refunded to the students.   Below is Linda Woodley's contact information to send/email about refunding class fees.

Intense School told SCHEV no student was going to lose class fees from Intense School closing.  She has been advised differently.

Your all welcome to contact Linda and I hope this helps.

Pls let me know how Security University can assist you.  You have my contact info below.

'good luck with working with Linda as she really knows her stuff. ttys SJS:)


Linda H. Woodley, M.Ed.
Director, Private & Out-of-State Postsecondary Education
State Council of Higher Education for Virginia
James Monroe Building
101 N. 14th Street, 9th Floor
Richmond, VA  23219

Office phone: 804-371-2938
Fax phone: 804-786-2027 or 804-225-2604
E-mail: lindawoodley@schev.edu
Website: www.schev.edu


This information was provided by Sondra at Security University.  Sondra has been a sponsor of CCCure for a long time and this is where you can get CISSP classes delivered by Clement Dupuis the owner of the CCCure Family of Portals.  See Sondra's contact info below.  Give her a call to book a seat on one of the many top notch qualified security classes or the world's best CISSP class.

--
Qualified Training for Qualified Results!

Sondra J. Schneider
Founder & CEO, Security University
109 Weed Ave
Stamford CT 06902
work 203.357.7744
cell 203.249.8364
www.securityuniversity.net

"

(Read More... | 1 comment | Score: 0)


Job Opening Penetration Tester "Hacker"
Posted by boss on Wednesday, 13 January 2010 @ 10:31:55 EST (118 reads)
Topic JOBS

Anonymous writes "

Title: Security Engineer (“Penetration Tester & Hacker”)

 

Located in Charlotte, NC for large global leading co. with advancement opportunity. Will relocate the right individual(s).  Multiple openings $75-105k. This client performs a background investigation on all new hires- checking credit history, possible drug screen, etc.

 

The Security Engineer’s role is to ensure the confidentiality, availability and integrity of in-house information systems. Will perform penetration testing and create own “hacking”  resources (proposing new models and innovative strategies),  not just use pre-packaged standard tools.  Ideal candidate will have 3-10 years exp. performing Systems administration, Network administration, Shell scripting and automation, Security testing. Will design and perform audits, recoveries, monitor security performance. Strong hands-on technical knowledge of Firewalls, IDS/IPS, Windows, UNIX, TCP/IP. Support of McAffee and/or PGP products.  Must have strong customer-focused skills, good communication and documentation abilities.

 

 

 

 Cindy Miceli

Recruiter

Alta Associates

8 Bartles Corner Road

Flemington, NJ 08822

908-806-8442

cindy@altaassociates.com

http://www.linkedin.com/in/cindymiceli

www.altaassociates.com

www.ewf-usa.com

"

(comments? | Score: 0)


Login here

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

Our Sponsors

CCCure Supporters

_SP_SUPPORTEDBY

The PST

The Academy

ChicagoCon

[ _SP_BESUPPORTER ]
[ _SP_TITLE ]

Most Active Members

· 1: side_winder
Total points: 11781
· 2: Lopezco
Total points: 8506
· 3: cissp_newbie
Total points: 7593
· 4: cdupuis
Total points: 6332
· 5: mikeyoung_fla
Total points: 5416
· 6: Vladimir
Total points: 4611
· 7: MMM
Total points: 2969
· 8: damoose
Total points: 2172
· 9: educk
Total points: 2155
· 10: vijayu
Total points: 1910

Today's Big Story

There isn't a Biggest Story for Today, yet.

Past Articles

Friday, January 08
· Is your Anti-Virus worth the price you paid for?
· What is YOUR reason for not using the proper tools
Monday, January 04
· Researchers demonstrate brilliant quantum hack
Friday, December 25
· Top 10 Certifications for 2010
Tuesday, December 22
· Vigilar Intense School has closed doors
Monday, December 14
· The Top 20 Critical Security Controls
Thursday, December 10
· For CISSP's: ISC2 launched InterSeC, its very own professional networking
Tuesday, December 08
· ATM Scam Bank ATMs converted to steal bank customer IDs
Saturday, December 05
· After "Open DNS" meet the new "Google Public DNS resolver"
Thursday, December 03
· Special offers to hakin9 magazine subscription for CCCure members and visitors!
Wednesday, December 02
· Certification Magazine’s 2009 Salary Survey By Certification Magazine Editorial
Monday, November 30
· Log Consolidation Tool -- Meet OSSEC and OSSIM
· Security Service Strategies for Small and Medium size firms
Monday, November 16
· Security University has been selected to be added to 8570
Thursday, November 12
· Webcast: “SC Magazine’s 20 Influential Security Products of the Past 20 Years”
Tuesday, November 10
· Microsoft Security Intelligence Report for first half of 2009
Thursday, October 01
· FREE SC World Congress tickets from CCCure and Security University
Tuesday, September 22
· 2-for-1 Security+ Class - Beat the 8570 Deadline!
Friday, September 18
· Security Job Offer
Monday, August 31
· Security Incident Response Team (SIRT) job opening in Dubai

Older Articles

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2007 by CCCure.Org, and the site maintainers Clement Dupuis and Nathalie Lambert. Reuse is strictly prohibited without written permission of CCCure.Org or it's maintainers.

This web site is not associated directly or indirectly with ISC2, the SANS Institute, ISACA, or other certification authority. The GCFW, CISSP, SSCP, ISSEP, ISSMP, CISA, and CISM are all the property of their respecful owners. The content of this site is provided to you freely due to the generosity of our sponsors.


  • Career
  • Magazines
  • Conferences
  • Study Books
  • Certifications
  • Training
  • Tutorials
  • Quizzes
  • Forums

  • Page Generation: 0.59 Seconds