Dept of State CISO to Speak at NoVA ISSA Chapter Meeting

If you happen to be near northern Virginia on 16 Sept 2010, you can catch the US Department of State’s CISO – John Streufert – speak at the Northern Virginia ISSA chapter meeting. John Streufert is interesting because he and his team are one of the first to break ranks with FISMA and create what they call a “continuous monitoring” security metrics program instead.I look forward to this presentation.References:http://www.issa-nova.org/default.aspxemail: david @ sharpesecurity.com website: http://www.sharpesecurity.com/Twitter: twitter.com/sharpesecurity


Poke in the Eye to SANS and CISSPs in Defcon 18 CTF Announcement

From the Defcon 18 CTF contest announcement at https://forum.defcon.org/showthread.php?p=112359#post112359:”This isn’t CTF like your mama used to make. Level 1 questions make CISSPs turn red, Level 2 make SANS Fellows cry in frustration, Level 3 are typically only answerable by sheep of above average barnyard intelligence, you get the idea.”and”Those with SANS certs need not apply. CISSPs are right out”.Two things spring to mind:1). The organization putting on Defcon 18’s CTF is “Defense Diutinus Technologies Corp (ddtek)”. My understanding is that ddtek is really Chris Eagle’s Naval Postgraduate School … Continue Reading