<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>cissp CISSP training Certified Information Systems Security Professional</title>
<link>http://www.cccure.org</link>
<description>Knowledge Sharing and Giving Back to the community</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2010-03-13T07:51:53-05:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2010-03-13T07:51:53-05:00</sy:updateBase>

<item>
<title>Viruses and Digital Signatures</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1462</link>
<description><![CDATA[<div>Recently, Symantec received some malicious files which appeared to be signed by &#8220;Adobe Systems Incorporated&#8221;. On closer inspection, however, it was seen that the signature was just a ruse used by the malware author to give an air of legitimacy to the files. Virus writers are getting smarter and going that extra mile to digitally sign their files. Using this technique the malware authors could, for example, penetrate an environment where only signed files are allowed but the authenticity of the signature is not checked.</div>
<div>&#160;</div>
<div>Although the files are signed, they are signed using an unauthenticated CA (Certificate Authority) which is masquerading as Verisign. A CA is a trusted third party that issues and signs the certificate and vouches for the authenticity of the file. Each CA should be registered and therefore recognized globally as a trusted signer. The signature on the certificate is verified by the signer&#8217;s public key.</div>
<div>&#160;</div>
<div>What the malware authors have tried here is to create their own CA and attempt to use it to sign these malicious files. They chose a misleading name for their CA, namely "Verisign", but their private key used for signing will obviously be different from the authentic Verisign CA key. Therefore this renders their CA untrustworthy so that, while the file still has a valid signature, it is not from the real Verisign CA.</div>
<div>&#160;</div>
<div>Also, although the file is correctly signed by a company called "Adobe Systems Incorporated," that company has been certified by their fake Verisign CA and therefore has no meaning or relation to the real "Adobe Systems Incorporated."</div>
<div>&#160;</div>
<div>Shown below are the real and fake Verisign CA signed files. On the left you can see that the certificate chain is not trusted all the way to the root where as on the right side (a real Adobe file) the certification chain is trusted up to the root.</div>
<div>&#160;</div>
<div>&#160;<br> <br> &#160;</div>
<p style="text-align: center;"><img class="ibimage" src="http://www.symantec.com/connect/imagebrowser/view/image/1225531/_original" alt="certificates.jpg" hspace="5" vspace="5" width="500" height="425"></p>
<p style="text-align: center;"><img class="ibimage" src="http://www.symantec.com/connect/imagebrowser/view/image/1225541/_original" alt="path.jpg" hspace="5" vspace="5" width="500" height="268"></p>
<div>On Windows machines with User Access Control enabled, a warning similar to the one shown below will be displayed (warning that the publisher is unknown).</div>
<div>&#160;</div>
<div>&#160;</div>
<p style="text-align: center;"><img class="ibimage" src="http://www.symantec.com/connect/imagebrowser/view/image/1225551/_original" alt="warning_1a.jpg" hspace="5" vspace="5" width="413" height="227"></p>
<div>&#160;</div>
<div>So, in a nutshell, creating &#8220;authentic-looking&#8221; certificates to make malicious files look legitimate is a trick which virus writers are employing to challenge today&#8217;s sophisticated security mechanisms. We have written about certificates being abused previously. The following blog article has more information: <a href="http://www.symantec.com/connect/blogs/phishing-toolkit-attacks-are-abusing-ssl-certificates">Phishing Toolkits Attacks are Abusing SSL Certificates</a>.&#160;</div>
<div>&#160;</div>
<div>So, play safe, and check the authenticity of the signature whenever one is present.</div>
<div><br></div>
<div>See original article on the Symantec Blog at:&#160; http://www.symantec.com/connect/blogs/viruses-and-digital-signatures<br></div>]]></description>
<guid isPermaLink="false">1462@http://www.cccure.org</guid>
<dc:subject>Virus</dc:subject>
<dc:date>2010-03-06T08:29:21-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>SQL Injection and Parameter Manipulation video clips</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1461</link>
<description><![CDATA[<p>&#160;</p>
<p><strong>NOTE FROM CLEMENT:<br>These two videos are very nice videos that demonstrate in simple terms what SQL Injections are and also what is Parameter Tampering.&#160; It is not for the purpose to learn everything there is to know about the subject,&#160; that would take weeks,&#160; the goal is to educate people and developers on the issue.&#160;&#160; They are great because of their short length and I like the animations as well. &#160; One picture is worth a thousand words they say.&#160; In this case on minute of video clip is worth 10 minutes of talks. &#160;&#160; I will most certainly use them in some of my classes.&#160; Job well done.&#160;&#160; Clement</strong></p>
<p>One of the biggest challenges of the security community is to build true SDLC (Secure development Life Cycle).</p>
<p>The biggest obstacle is that application developers at large lack the know-how and motivation to address application risk.&#160; <br><br> At Checkmarx labs we thought that a new approach to application developers might help them cross the barrier.<br> We have developed as a pilot including two short animated clips that should help developers understand security flaws, how they can be detected and consequently prevented.</p>
<p>We built one clip for SQL Injection and another for Parameter Tampering - limited up to 5 minutes each.<br> <br> We would appreciate feedback from the OWASP community whether the effort is meaningful and should it be extended.<br><br> Please feel free to use the clips freely.<br> <br> The clips can be found at:<br> <br>SQL Injection :<strong> <a href="http://www.youtube.com/watch?v=vjDrseRLyuA&#38;hd=1">http://www.youtube.com/watch?v=vjDrseRLyuA&#38;hd=1</a></strong><br> <br>Parameter Tampering: <strong><a href="http://www.youtube.com/watch?v=l5LCDEDn7FY&#38;hd=1">http://www.youtube.com/watch?v=l5LCDEDn7FY&#38;hd=1</a></strong><br> <br> Yours,<br> <br> Maty Siman, CISSP<br> CTO<br> Checkmarx</p>
<p>&#160;</p>]]></description>
<guid isPermaLink="false">1461@http://www.cccure.org</guid>
<dc:subject>Awareness</dc:subject>
<dc:date>2010-03-03T11:17:55-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>NATO CISSP Study Group in Brussels</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1460</link>
<description><![CDATA[<p>We are starting a NATO-wide CISSP Study Group at NATO HQ in Brussels, Belgium.</p>
<p>Anybody interested in joining needs to be able to access the HQ compound.</p>
<p><em><em>If you are interested,  please respond to smortimer (at) magiansystems (dot) com.<br></em></em></p>]]></description>
<guid isPermaLink="false">1460@http://www.cccure.org</guid>
<dc:subject>Study_Group</dc:subject>
<dc:date>2010-02-23T19:20:02-05:00</dc:date>
<dc:creator>Posted by magian</dc:creator>
</item>

<item>
<title>Anyone studying in Kansas City for the Aug 7th test?</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1459</link>
<description><![CDATA[<p>I am looking for study partners for the&#160;CISSP Exam in&#160;Kansas City,&#160;&#160;Kansas City,&#160;&#160;KS&#160;&#160;on&#160;Aug 07, 2010.&#160;&#160;I have a full time job, so this would need to be done in the evening or weekends. We could possibly meet by phone weekly or bi-weekly.&#160; If you are interested, please respond to <a href="mailto:wpeterson@techie.com">wpeterson@techie.com</a>.&#160;<br><br>Thanks, <br>Wendy</p>]]></description>
<guid isPermaLink="false">1459@http://www.cccure.org</guid>
<dc:subject>Study_Group</dc:subject>
<dc:date>2010-02-18T20:18:19-05:00</dc:date>
<dc:creator>Posted by wpeterson</dc:creator>
</item>

<item>
<title>Join SecurityVibes and exchange information with your peers!</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1458</link>
<description><![CDATA[<p>&#160;</p>
<p><strong>DLP, Cybercrime, Vulnerabilities, Malware, Compliance, Cloud Security...&#160;How does this relate to you? Want to share your opinion? Interested in knowing what your peers have experienced?&#160;</strong></p>
<p>Easy, <a href="http://www.securityvibes.com/request_invite.php">ask for an invite</a> today and join SecurityVibes!</p>
<p>Security Vibes is an online community for CSOs to exchange information, share thoughts and opinions and learn from your peers. &#160;With 100 existing UK members, as well as similar active communities in France and the US, we are looking to increase the number of participants by inviting CIO and CSO level executives to join this exclusive community. &#160;Security Vibes is the first closed community dedicated to infosec professionals. It operates under strict Chatham House rules and a strict no-vendors policy, which means that members can share views and insights amongst those with similar interests and concerns in complete confidence. &#160;</p>
<p>Membership is by invitation only and benefits of membership include: online discussion forums, access to cutting edge multi-media content and analysis such as videos, podcasts as well as real life networking events, called CSO Interchanges, where members can meet in person and swap ideas and learn from each other and hear from industry experts and fellow members.&#160;</p>
<p>CISSPs belonging to Security Vibes can also earn CPE credits for their significant SecurityVibes content contributions. In line with (ISC)2&#8217;s CPE Guidelines, CISSPs earn 10 CPE credits for their first published article and one additional credit for every subsequent hour spent posting content to the SecurityVibes.com site.</p>
<p>If you&#8217;d like to find out more about joining please visit the website at: <a href="http://www.securityvibes.com">http://www.securityvibes.com</a> or to apply for membership at <a href="http://www.securityvibes.com/request_invite.php">http://www.securityvibes.com/request_invite.php</a></p>
<p>&#160;</p>]]></description>
<guid isPermaLink="false">1458@http://www.cccure.org</guid>
<dc:subject>Awareness</dc:subject>
<dc:date>2010-02-16T09:44:44-05:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>The Rugged Software Manifesto</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1457</link>
<description><![CDATA[<p>The three authors of the manifesto are Josh Corman, an analyst with The 451 Group; David Rice, formerly with the National Security Agency and author of <em>Geekonomics</em>, a book about the real cost of insecure software; and Jeff Williams, the chairman of OWASP, an organization focused on Web    application security. The trio announced the project at the SANS Institure AppSec Conferenc in San Francisco Monday.</p>
<p><strong>The Rugged Software Manifesto </strong></p>
<ul>
<li>I am rugged... and more  importantly, my code is rugged. </li>
<li>I recognize that software has become  a foundation of our modern world.</li>
<li>I recognize the awesome  responsibility that comes with this foundational role.</li>
<li>I recognize that my code will be used in ways I cannot anticipate, in ways it was not designed, and for longer than it was ever intended.</li>
<li>I recognize that my code will be attacked by talented and persistent adversaries who threaten our physical, economic, and national security.</li>
<li>I recognize these things - and I  choose to be rugged.</li>
<li>I am rugged because I refuse to be  a source of vulnerability or weakness.</li>
<li>I am rugged because I assure my  code will support its mission. </li>
<li>I am rugged because my code can  face these challenges and persist in spite of them.</li>
<li>I am rugged, not because it is  easy, but because it is necessary... and I am up for the challenge.<br> </li>
</ul>
<p><strong>Official Announcement Document</strong> - <a href="http://www.owasp.org/images/b/bd/Rugged_Software_Development_20100205.pdf"><img src="http://www.ruggedsoftware.org/images/PDF_Logo.jpg" alt height="32"></a></p>
<p><strong></strong></p>
<p>&#160;</p>
<p>If you want Rugged Software, join us and help define the principles, and technologies that will help others become Rugged too. Our first project is to define how people and organizations can know if they are Rugged.</p>
<p>Visit their website at:&#160; <a href="http://www.ruggedsoftware.org/"><strong>http://www.ruggedsoftware.org/</strong></a></p>]]></description>
<guid isPermaLink="false">1457@http://www.cccure.org</guid>
<dc:subject>CISSP</dc:subject>
<dc:date>2010-02-10T08:43:31-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Job Opportunity in Dubai for a Senior Incident Response Investigator</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1456</link>
<description><![CDATA[<table border="0" cellspacing="0" cellpadding="0">

<tr>
Subject: 
<td>[htcia] Job Opportunity - Dubai</td>
</tr>
<tr>
Date: 
<td>Tue, 9 Feb 2010 11:34:36 -0500</td>
</tr>
<tr>
From: 
<td>
<a href="mailto:sanson@forwarddiscovery.com">sanson@forwarddiscovery.com</a>
</td>
</tr>

</table>
All,<br><br>Forward Discovery has an immediate opening in&#160;Dubai, UAE for a Senior<br>Incident Response Investigator. The position requires thorough<br>knowledge of network technology as it relates to the response and<br>investigation of computer network incidents. &#160;Candidates should<br>possess a thorough and current knowledge of network threats and attack<br>vectors. Candidates should also possess current skills in computer<br>forensic analysis as it relates to network investigation and incident<br>response.<br><br>Additional skills and experience required include:<br><br>&#183; &#160; &#160; Malware analysis<br><br>&#183; &#160; &#160; CERT or Incident Response policy and procedure development<br><br>&#183; &#160; &#160; Excellent written and oral communication skills<br><br>&#183; &#160; &#160; Four-year degree, preferably in a related field<br><br>&#183; &#160; &#160; Experience with Windows, Unix and Linux operating systems<br><br>&#183; &#160; &#160; Experience in managing people and projects<br><br>&#183; &#160; &#160; Log analysis in the detection and investigation of intrusions<br><br>&#183; &#160; &#160; Experience working for telecommunications companies preferred<br><br>&#183; &#160; &#160; Computer programming skills are preferred<br><br>&#183; &#160; &#160; Certification in computer forensics is preferred<br><br><br>Compensation package will be dependent upon relevant experience but<br>will range from $100,000 to $150,000 plus housing allowance.<br><br>The POC for this position is&#160;Steve Anson at:<br><a href="mailto:sanson@forwarddiscovery.com">sanson@forwarddiscovery.com</a><br>]]></description>
<guid isPermaLink="false">1456@http://www.cccure.org</guid>
<dc:subject>JOBS</dc:subject>
<dc:date>2010-02-09T20:50:41-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>More evidence of value of security certification -- Part 2 of 5</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1455</link>
<description><![CDATA[<p>This story appeared on Network World at<br> http://www.networkworld.com/news/2010/020810-security-certification.html</p>
<p>&#160;</p>
<p>More evidence of value of security certification</p>
<div id="article_author">By        M. E. Kabay, Network World <br> February 08, 2010 12:04 AM ET</div>
<div id="article_copy">
<div id="imu" style="float: right;">&#160;</div>
<p class="first">This is the second of five articles discussing the benefits (if any) of security certifications in the job market. In the    <a href="http://www.networkworld.com/newsletters/sec/2010/020110sec2.html">first article</a>, a number of studies suggested that certifications do indeed improve prospects for hiring and higher salaries.</p>
<p>In this article, I conclude the review of recent studies and surveys with yet more encouraging news for holders of security    certifications.</p>
<p>* * *</p>
<p>In June 2008, NetworkWorld writer Jon Brodkin pointed out that "Overall, the value of 164 IT certifications measured by Foote dropped 4.9% the past two years and 1.6% in the six-month period ending April 1 [2008]." However, Brodkin wrote, "Some certifications are bucking the trend and rising in value.<strong> IT security certifications rose 3.1% in value over the past two years and 1.2% in value in the last six months.</strong> Certain types of security skills are seeing dramatic growth. A 27% rise in value was measured for the Certified Information Security Manager designation, just in the past six months. In second place with a 25% rise in the last six months was the <a href="http://www.networkworld.com/newsletters/edu/2008/060208ed1.html">GIAC Security Expert cert</a>."</p>
<p>In a follow-up article, Brodkin reported on a <a href="http://www.isc2.org/uploadedFiles/Industry_Resources/2008_Global_WF_Study.pdf">survey</a> carried out for the International Information Systems Security Certification Consortium, (<a href="http://www.isc2.org/">ISC</a>)^2, which showed "that holders of the CISSP, SSCP or CAP certifications who work in the Americas and have at least five years    experience earn [an average of] $102,376 per year &#8211; more than $21,000 higher than IT pros who also have five years experience    but lack the <a href="http://www.networkworld.com/newsletters/edu/2008/060908ed1.html">certifications</a>."</p>
<p>Reporting on the popularity of security certifications, Joan Goodchild of <em>CSO Magazine</em> wrote about a CompTIA survey that came out in late October 2009. The study of more than 1,500 IT workers found that many    of them planned to pass certifications in security, ethical hacking and <a href="http://www.networkworld.com/news/2009/110509-survey-security-certifications-hot-among.html">digital forensics</a>.&#160;</p>
<p>Goodchild added &#8230;[M]ore companies are requiring IT security certification&#8230;. [T]he number of organizations where IT security certification is required has increased by half and is continuing to grow; 32% of employees were required to have certifications in 2008, compared to 20% in 2006.</p>
<p><a href="http://www.footepartners.com/">Foote Partners</a> maintains a database with constant updates to produce its annual "IT Skills and Certifications Pay Index." The latest edition (as of this writing in the first week of January 2010) includes "data collected through January 1, 2010." A 55-page PDF sample of the $2,500, 305 page quarterly report ($9,750 for a year's worth of reports) is available <a href="http://www.footepartners.com/SamplePages2010HTSCPI_Rev2.pdf">free online</a> to illustrate the format of the report (most of the charts have been redacted to blanks).</p>
<p>Among the 201 specializations studied by Foote Partners, 34 certifications specifically involve security, auditing, forensics    or penetration testing.</p>
<p>Founder David Foote, who also serves as Foote Partners' CEO &#38; Chief Research Officer, was quoted in a Dec. 31, 2009 interview in a Bank Information Security <a href="http://www.bankinfosecurity.com/podcasts.php?podcastID=404">podcast</a> as saying that "Information security is the hot career option for professionals in 2010 and beyond." He was also interviewed    back in August 2009 by Carolyn Gibney of <a href="http://itknowledgeexchange.techtarget.com/security-wire-weekly/security-job-market-heating-up/">SearchSecurity</a> and said much the same thing: "Foote says there's reason for those in the security industry to be optimistic."</p>
<p>The Jan. 5, 2010 issue of the System Administration and Network Security (<a href="http://www.sans.org/">SANS</a>) <a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=12&#38;issue=1">NewsBites</a> started with the following assertion in an advertisement for the organization's courses:</p>
<p>The hottest security skills employers are seeking for 2010:</p>
<p>1. Red teaming/penetration testing (systems/networks and applications)<br>2. Forensics<br>3. Security essentials<br>4. Reverse engineering malware<br>5. Auditing networks and systems (hands-on testing)<br>6. Intrusion detection<br>7. Security management and leadership<br>8. Securing virtual systems<br>9. CISSP certification</p>
<p>Plus: Effective presentation skills for security professionals.</p>
<p>This last point is important: in addition to technical skills, communications and management skills are valuable to IA professionals. Recently <a href="http://uk.linkedin.com/in/pauldorey">Paul Dorey</a>, chairman of the <a href="https://www.instisp.org/SSLPage.aspx?pid=183">Institute of Information Security Professionals</a> in Britain, was <a href="http://searchsecurity.techtarget.co.uk/news/article/0,289142,sid180_gci1355122,00.html">quoted</a> as follows:</p>
<p>"We are entering a time when IT security people are going to have to move from being merely advisers to the business to real professionals whose views are listened to," he said. As IT supports every aspect of life, security breaches become potentially life-threatening or disastrous for their organisations. Just as bridge designers and structural engineers work to common and consistent standards and are therefore respected, he said, so security professionals should command the same level of respect.</p>
<p>For that to happen, security professionals need to communicate effectively with a wide range of disciplines &#8211; including audit, risk assessment and compliance, IT and engineering. "They need to be like chameleons to fit into those disciplines," he said. "You may not become an expert in them all, but you must at least don the facade. ... Get some mentoring to help you understand them."</p>
<p>In the next article in this five-part series, I'll look at the wider context of certification and licensing for a range of professionals in the United States and point to the efforts beginning in the early 2000s to force certification for IA officers in the U.S. Department of Defense.</p>
<p><a href="http://www.networkworld.com/topics/security.html">Read more about security</a> in Network World's Security section.</p>
<p>All contents copyright 1995-2010 Network World, Inc. <a href="http://www.networkworld.com/">http://www.networkworld.com</a></p>
</div>]]></description>
<guid isPermaLink="false">1455@http://www.cccure.org</guid>
<dc:subject>Docteur Kabay</dc:subject>
<dc:date>2010-02-09T17:33:03-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Stupid rebates for Stupid Clients</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1454</link>
<description><![CDATA[<p><strong>Rebates, Rebates, and Rebates.</strong></p>
<p>Are they all great and fantastic for you as a customer?&#160; Not always for sure.&#160; I have received another one in my mailbox today and as I was reading it&#160; I asked myself:&#160; Do they really think that people are that stupid?</p>
<p>When I see advertising where they offer a FREE laptop, a free Kindle, rebate of $500 to the person you refer, or a gift card for referral I am always asking myself how can they offer such freebies?&#160; Then my brain come to it's senses and the response is:&#160; THERE IS NO FREEBIES -- YOU ARE PAYING FOR IT YOURSELF</p>
<p>You the customer have to pay for those freebies.&#160; If you look at the price of the classes associated with those freebies you will quickly realize that many vendors think that you are stupid and you cannot add 1 + 1.&#160; They are simply <strong>overcharging</strong> you and then they give you a gift to make it look OK.</p>
<p>If I overcharge you for my classes then I can offer freebies as well.&#160; However, I think this would be against my ethics.&#160; A company should simply give the best price they can while delivering quality training.&#160;&#160; If the only reason people attend such class is to get a freebie instead of getting great content and outstanding skills and knowledge it means your class does not have much to offer in the first place.</p>
<p>When classes are overpriced, you are the person who pays for those freebies that's for sure.&#160; Do look at the price before the freebie is being offered, the price is so outrageous that they can offer freebies and still charge you more and make more money than most vendors out there.&#160; You will quickly notice that there is no free lunch, you are the one that is paying for the freebie because the class price is way too high in the first place.&#160; There is no SPECIAL at all.</p>
<p>At <a href="http://www.securityuniversity.net/classes_CISSP.php">Security University</a> we currently have an offer for a<strong> two for one</strong>,&#160; our normal class price is already heavily discounted but if you come to the same class with one of your colleague you can split the cost of the class in two.&#160; This gives you an amazing class for a very low price.&#160; Do check it out, you will see that we do not use complicated scheme, we like to keep thing easy and straight forward.&#160; Simply come with a friend of a colleague and you pay half of the normal price which is already lower than most vendors out there.&#160; <a href="http://www.securityuniversity.net/classes_CISSP.php">Check it out </a>and you will not be disappointed.&#160; This is about $1300 per person which is a great deal considering that our faculty has only Security Instructors that are well known and that have dozens of years of experience on average.&#160; We don't hire people who reads slide to you.&#160; We hire the best and only the best.&#160;&#160; If your are really found on having a freebie, we can sell the class to you at $2695 and give you a kindle or a $100 gift card. :-(</p>
<p>At <a href="http://www.securityuniversity.net/classes_CISSP.php">Security University </a>we also believe in being a <strong>responsible community player</strong> as well.&#160; Over the next three CISSP classes we will deliver we have 16 student who had paid for classes with Vigilar Intense School but their money was lost due to the closing of Vigilar Intense School.&#160; We have offered free seats to those students to help them offset the losses they have suffered.&#160; This is what responsible organizations do to help the community.&#160; <strong>Ask the freebie givers out there how many seats they have given for free?</strong></p>
<p>In closing, I just want to say:&#160; Do not be stupid and don't get lured into freebies that you pay yourself.&#160; Who cares about a Kindle that cost you three times the prices when you look at the price fo the class compared with what others are charging.&#160; Get your money worth, train more people, use your training budget adequately.&#160; This is what this is all about.&#160; Not about overprice classes with so called freebies.</p>
<p>Best regards to all</p>
<p>Clement Dupuis<br>Senior Security Instructor and Evangelist at Security University<br>(Very tired of vendors who thinks we are all stupid and hope we will fall pray of stupid rebates)</p>]]></description>
<guid isPermaLink="false">1454@http://www.cccure.org</guid>
<dc:subject>CISSP</dc:subject>
<dc:date>2010-02-09T10:17:22-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Official (ISC)2 Guide to the CISSP CBK, Second Edition</title>
<link>http://www.cccure.org/modules.php?name=News&amp;file=article&amp;sid=1453</link>
<description><![CDATA[<p>NOTE FROM CLEMENT:</p>
<p>The long awaited update to the Official ISC2 Study Guidewas finally released at the beginning of 2010.&#160; The first edition was severely criticized due to the many errors, contradiction, and mistakes that were in the book.&#160; It seems this version went through a lot more thorough Technical Editing process where CISSP's and the different authors have scrutinized each of the chapters to ensure accuracy. &#160; The book has gained more pages as well.&#160; The previous edition was filled with a lot of fluff such as appendixes, glossaries, etc...&#160;&#160; &#160; This one seems to be content oriented.&#160; I have not read through the whole book yet.&#160; If you did read through the whole book I would be VERY interested in getting your feedback.&#160; If you do find any errors, mistakes, or contradictions, I have created a new forum to post them and discuss them with others as well.&#160;</p>
<p><strong>Visit the link below to give us feedback about the new book:</strong></p>
<p><a href="https://www.cccure.org/forum-6.html"><strong>https://www.cccure.org/forum-6.html</strong></a></p>
<p><strong>If you do find any mistakes, visit the link below to contribute them to the forum reserved for that purpose:</strong></p>
<p><strong><a href="https://www.cccure.org/forum-74.html">https://www.cccure.org/forum-74.html</a></strong><br> <br> Product Description</p>
<div class="productDescriptionWrapper">
<p>With each new advance in connectivity and convenience comes a new wave of threats to privacy and security capable of destroying a company&#8217;s reputation, violating a consumer&#8217;s privacy, compromising intellectual property, and in some cases endangering personal safety. This is why it is essential for information security professionals to stay up to date with the latest advances in technology and the new security threats they create.</p>
<p>Recognized as one of the best tools available for the information security professional and especially for candidates studying for the (ISC)2 CISSP examination, the <strong>Official (ISC)2&#174; Guide to the CISSP&#174; CBK&#174;, Second Edition</strong> has been updated and revised to reflect the latest developments in this ever-changing field. Endorsed by the (ISC)2, this book provides unrivaled preparation for the certification exam that is both up to date and authoritative. Compiled and reviewed by CISSPs and (ISC)2 members, the text provides an exhaustive review of the 10 current domains of the CBK&#8212;and the high-level topics contained in each domain.</p>
<p>Unique and exceptionally thorough, this edition includes a CD with over 200 sample questions, sample exams, and a full test simulation that provides the same number and types of questions with the same allotment of time allowed in the actual exam. It will even grade the exam, provide the correct answers, and identify areas where more study is needed.</p>
<p>Earning your CISSP is a deserving achievement that makes you a member of an elite network of professionals. This book not only provides you with the tools to effectively study for the exam, but also supplies you with ready access to best practices for implementing new technologies, dealing with current threats, incorporating new security tools, and managing the human factor of security&#8212;that will serve you well into your career.</p>
<p style="text-align: center;"><a href="http://www.amazon.com/gp/product/1439809593?ie=UTF8&#38;tag=thecisspopens-20&#38;linkCode=xm2&#38;camp=1789&#38;creativeASIN=1439809593"><img title="The Best Book bar none" src="https://www.cccure.org/amazon/isc2book.jpg" alt="The ISC2 Guide to the CISSP CBK Second Edition" width="164" height="209"></a></p>
<p style="text-align: center;"><a href="http://www.amazon.com/gp/product/1439809593?ie=UTF8&#38;tag=thecisspopens-20&#38;linkCode=xm2&#38;camp=1789&#38;creativeASIN=1439809593">The Official ISC2 Guide to the CISSP CBK Second Edition<br>Click Here to get your copy or more details</a></p>
</div>]]></description>
<guid isPermaLink="false">1453@http://www.cccure.org</guid>
<dc:subject>CISSPBOOK</dc:subject>
<dc:date>2010-02-04T21:23:44-05:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

</channel>
</rss>
