<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>JeffBolden.net</title>
	
	<link>http://www.jeffbolden.net</link>
	<description>Ramblings from a Information Security Professional</description>
	<pubDate>Mon, 19 May 2008 20:46:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Jeffboldennet" type="application/rss+xml" /><item>
		<title>What a difference a month makes…</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/293754622/</link>
		<comments>http://www.jeffbolden.net/2008/05/19/what-a-difference-a-month-makes/#comments</comments>
		<pubDate>Mon, 19 May 2008 20:46:49 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<category><![CDATA[Stuff]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/?p=20</guid>
		<description>Sorry for the lack of updates the past month or so, and it&amp;#8217;s not for lack of events to share. In fact, it&amp;#8217;s been quite the opposite and I&amp;#8217;ve just been too busy to check in. It&amp;#8217;s funny how fast time moves by when you have a lot going on. =)
So, the big news for [...]</description>
			<content:encoded><![CDATA[<p>Sorry for the lack of updates the past month or so, and it&#8217;s not for lack of events to share. In fact, it&#8217;s been quite the opposite and I&#8217;ve just been too busy to check in. It&#8217;s funny how fast time moves by when you have a lot going on. =)</p>
<p>So, the big news for me is on the career front. As it turns out, about 4-5 weeks ago I left my glamorous jetsetting (ahh, sweet sweet sarcasm&#8230;) Internal IT Auditor position for some real RockStar status. I can hear all of you asking, &#8220;Jeff, what could possibly make me want to leave the excitement and thrills of internal IT audit?&#8221; Seriously though, the past 4 months or so I&#8217;ve been really examining my career and taking a long hard look at what I like and dislike in my day to day grind and came to the conclusion that being an auditor was not the direction I wanted to continue in. Add that to the fact that after working in the banking/finance industry now for almost 8 years I was quickly reaching the point of complete and utter PCI/GLBA/FFIEC burnout, and I could see the writing on the wall.</p>
<p>I like to keep my hands &#8220;dirty&#8221; so to speak and not being able to directly solve the security and IT problems I see on a daily basis was just too much for me. Quite frankly, I&#8217;m an ops guy, I like getting in and actually working on the tech. I knew that already, but sometimes it takes me longer to figure things out than others. =)</p>
<p>So, during this period of realization one day in April, I just happened to stumbled across my &#8220;dream opportunity&#8221;. I&#8217;ve always wanted to find a position where I could get in to a small startup on the ground floor and build a world-class IT dept/infrastructure from the beginning. Someplace small and nimble yet with the same IT needs and issues as the big boys. Someplace I could go that I didn&#8217;t have to worry about what FFIEC says, but how things really should be. Not &#8220;security for regulatory&#8217;s sake&#8221;, but real, common-sense security. After years of shaking my head at the PHB&#8217;s stupid IT decisions I wanted to go someplace I could &#8220;put my money where my mouth was&#8221; (so to speak) and see if I could do it better. Careful what you wish for&#8230; =)</p>
<p>So, the opportunity presented itself and things moved extremely quickly from there. Suddenly I&#8217;m no longer in banking, and I&#8217;ve had more fun in the past 4 weeks then I have in the previous 4 years! It&#8217;s been hectic and challenging as I shake off the rust on some of my technical skills, but I have not had this much enjoyment going to work in years.</p>
<p>The new position? Director of IT for an up and coming startup here in Portland called <a href="http://www.iterasi.net">Iterasi</a>. We&#8217;ve just gone beta, so be sure to check it out.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2008/05/19/what-a-difference-a-month-makes/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2008/05/19/what-a-difference-a-month-makes/</feedburner:origLink></item>
		<item>
		<title>Wireshark v1.0 released</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/261512336/</link>
		<comments>http://www.jeffbolden.net/2008/03/31/wireshark-v10-released/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 20:58:46 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Audit]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2008/03/31/wireshark-v10-released/</guid>
		<description>After a short 10 year build time (I kid&amp;#8230;), one of the best security tools out has reached the v1.0 milestone. Wireshark 1.0.0. was released this weekend! You can read more about it in this news item as well as grabbing the file from the Wireshark site. I&amp;#8217;ve used Ethereal since the early days and [...]</description>
			<content:encoded><![CDATA[<p><a href="http://www.jeffbolden.net/wp-content/uploads/2008/03/wireshark.JPG" title="wireshark.JPG"><img src="http://www.jeffbolden.net/wp-content/uploads/2008/03/wireshark.JPG" alt="Wireshark" /></a></p>
<p>After a short 10 year build time (I kid&#8230;), one of the best security tools out has reached the v1.0 milestone. <a href="http://www.wireshark.org/docs/relnotes/wireshark-1.0.0.html">Wireshark 1.0.0</a>. was released this weekend! You can read more about it in this <a href="http://www.wireshark.org/news/20080331.html">news item</a> as well as grabbing the file from the <a href="http://www.wireshark.org/">Wireshark</a> site. I&#8217;ve used Ethereal since the early days and it&#8217;s always been one of my staple network/security tools. I big congrats to the team! Here&#8217;s the news release:</p>
<blockquote><p>I&#8217;m proud to announce the release of Wireshark 1.0. This is the culmination of nearly ten years of hard work by a team of brilliant and talented developers. It is an honor to be able to work with these people.<br />
On behalf of the development team, I would like to thank Wireshark&#8217;s user community for all of your enthusiasm and support over the years. Wireshark development will continue, and we have lots of great features to offer in the coming years.</p>
<h4>In this release</h4>
<p>Security-related vulnerabilities in the X.509sat, Roofnet, LDAP, and SCCP dissectors have been fixed. See the <a href="http://www.wireshark.org/security/wnpa-sec-2008-02.html">advisory</a> for details.<br />
This release includes an experimental package for Mac OSX Intel. For a complete list of changes, please refer to the <a href="http://www.wireshark.org/docs/relnotes/wireshark-1.0.0.html">1.0.0 release notes</a>.<br />
Official releases are available right now from the <a href="http://www.wireshark.org/download.html">download page</a>.</p></blockquote>
<pre></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2008/03/31/wireshark-v10-released/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2008/03/31/wireshark-v10-released/</feedburner:origLink></item>
		<item>
		<title>You mean I’ve been wasting my time?!!</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/231188824/</link>
		<comments>http://www.jeffbolden.net/2008/02/07/you-mean-ive-been-wasting-my-time/#comments</comments>
		<pubDate>Thu, 07 Feb 2008 20:38:07 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2008/02/07/you-mean-ive-been-wasting-my-time/</guid>
		<description>During my daily RSS scan this morning I noticed this article on DarkReading that is sure to spark a lot of debate over the next few days.

Computer Forensics Show 2008 &amp;#8212; Peter Tippett thinks it&amp;#8217;s time for security  professionals to wake up and stop wasting their energy. 
In a presentation here yesterday, Tippett &amp;#8212; [...]</description>
			<content:encoded><![CDATA[<p>During my daily RSS scan this morning I noticed <a href="http://www.darkreading.com/document.asp?doc_id=145224&amp;print=true" target="_blank">this article on DarkReading</a> that is sure to spark a lot of debate over the next few days.</p>
<p><cite></cite></p>
<blockquote><p><font>Computer Forensics Show 2008 &#8212; Peter Tippett thinks it&#8217;s time for security  professionals to wake up and stop wasting their energy. </font></p>
<p><font>In a presentation here yesterday, Tippett &#8212; who is vice president of risk  intelligence for Verizon Business, chief scientist at ICSA Labs, and the  inventor of the program that became Norton AntiVirus &#8212; said that about one  third of today&#8217;s security practices are based on outmoded or outdated concepts  that don&#8217;t apply to today&#8217;s computing environments.</font></p></blockquote>
<p>Once you get past the incendiary statements, it seems to me like Peter is discussing getting back to basics with our security thinking. Nothing is 100% safe, but in the rush to try and secure everything, many tend to forget about the basics. It seems the past two years many companies (and many in the netsec field) have gone overboard in trying to manage every risk to the point of CYA insanity, instead of using a more holistic approach of basic security best-practice and prudent risk assessment/management. As anyone that has worked in the security field knows, we netsec folk have to get a million things right to keep the bad guys out, but the bad guys only have to get one thing right to get in. Of course, that&#8217;s why the argument for defense-in-depth is so important.</p>
<p>Yet, while I do agree with most of the points Peter brings up, we can&#8217;t just throw up our hands and give up. We still have to approach security with due diligence as one of the goals.</p>
<p>There is a <a href="http://it.slashdot.org/article.pl?sid=08/02/07/1534220" target="_blank">good discussion on the article</a> over at Slashdot. Put on your fire-retardant suit before clicking the link&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2008/02/07/you-mean-ive-been-wasting-my-time/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2008/02/07/you-mean-ive-been-wasting-my-time/</feedburner:origLink></item>
		<item>
		<title>UK to make security/hacking tools illegal?</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/210746833/</link>
		<comments>http://www.jeffbolden.net/2008/01/03/uk-to-make-securityhacking-tools-illegal/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 21:38:06 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2008/01/03/uk-to-make-securityhacking-tools-illegal/</guid>
		<description>Utter madness&amp;#8230;.
The Register reports on a new UK guideline that makes it illegal to create or distribute so-called hacking&amp;#8221; security tools.
The controversial measure is among amendments to the Computer Misuse Act included in the Police and Justice Act 2006. However, the ban along with measures to increase the maximum penalty for hacking offences to ten [...]</description>
			<content:encoded><![CDATA[<p><a href="http://www.theregister.co.uk/2008/01/02/hacker_toll_ban_guidance/" target="_blank">Utter madness&#8230;.</a></p>
<p>The Register reports on a new UK guideline that makes it illegal to create or distribute so-called hacking&#8221; security tools.</p>
<blockquote><p><quote>The <a href="http://www.theregister.co.uk/2006/01/26/uk_computer_crime_revamp" target="_blank">controversial measure</a> is among amendments to the Computer Misuse Act included in the Police and Justice Act 2006. However, the ban along with measures to increase the maximum penalty for hacking offences to ten years and make denial of service offences clearly illegal, are still <a href="http://www.lightbluetouchpaper.org/2007/06/19/hacking-tools-are-legal-for-a-little-longer" target="_blank">not in force</a> and probably won&#8217;t be until May 2008 in order not to create overlap with the Serious Crime Bill, currently making its way through the House of Commons.</quote></p></blockquote>
<p>I was amazed when the German  computer crime laws came into effect in August 2007, but it looks like the insanity is spreading to other parts of Europe as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2008/01/03/uk-to-make-securityhacking-tools-illegal/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2008/01/03/uk-to-make-securityhacking-tools-illegal/</feedburner:origLink></item>
		<item>
		<title>SANS2007 Day 3/4 Recap</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/162136837/</link>
		<comments>http://www.jeffbolden.net/2007/09/27/sans2007-day-34-recap/#comments</comments>
		<pubDate>Thu, 27 Sep 2007 20:00:38 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2007/09/27/sans2007-day-34-recap/</guid>
		<description>Tuesday and Wednesday were both full days for me, covering the ISO27002 controls as well as hitting  lunch and learns, some great after-hours talks, and a trip or two down the strip as well. The highlight of the past 2 days was a couple of excellent talks on bluetooth eavesdropping as well as a [...]</description>
			<content:encoded><![CDATA[<p>Tuesday and Wednesday were both full days for me, covering the ISO27002 controls as well as hitting  lunch and learns, some great after-hours talks, and a trip or two down the strip as well. The highlight of the past 2 days was a couple of excellent talks on bluetooth eavesdropping as well as a talk on VM Escape issues.</p>
<p>Josh Wright&#8217;s Wednesday evening talk on bluetooth eavesdropping was excellent (as usual, great talk Josh!) and showed just how bad bluetooth security is. He has a great <a href="http://www.youtube.com/watch?v=1c-jzYAH2gw" target="_blank">YouTube video</a> up showing the issues as well as a great paper on <a href="http://www.sans.edu/resources/securitylab/bluetooth.php" target="_blank">Dispelling Common Bluetooth Misconceptions</a> that he just released. I highly recommend taking a look at both. Also, be sure to check out his website <a href="http://www.willhackforsushi.com" target="_blank">www.willhackforsushi.com</a> for lots more wireless info.</p>
<div width="425" height="350">
<div name="movie" value="http://www.youtube.com/v/1c-jzYAH2gw"></div>
<div name="wmode" value="transparent"></div>
<div style="text-align: center"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" width="425" height="350"><param name="width" value="425" /><param name="height" value="350" /><param name="wmode" value="transparent" /><param name="src" value="http://www.youtube.com/v/1c-jzYAH2gw" /><embed type="application/x-shockwave-flash" width="425" height="350" wmode="transparent" src="http://www.youtube.com/v/1c-jzYAH2gw"></embed></object></div>
<div style="text-align: center" align="left"></div>
<div style="text-align: center" align="left"></div>
</div>
<p>Tonight is the PaulDotCom security podcast live here at SANS and I&#8217;ll be dropping in for that. It&#8217;s only fitting since I was lucky enough to be at their first podcast at SANS 2005 in LA. They&#8217;ve come a long way since then! =) They will be running a live stream as well as taking questions over IRC, so be sure to <a href="http://www.pauldotcom.com/2007/09/26/recording_and_stream_notice_ep_11.html" target="_blank">jump over to their site</a> and get the info, then join us tonight!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2007/09/27/sans2007-day-34-recap/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2007/09/27/sans2007-day-34-recap/</feedburner:origLink></item>
		<item>
		<title>SANS2007 Day 2 Recap</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/160831345/</link>
		<comments>http://www.jeffbolden.net/2007/09/24/sans2007-day-2-recap/#comments</comments>
		<pubDate>Tue, 25 Sep 2007 00:04:38 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2007/09/24/sans2007-day-2-recap/</guid>
		<description>It&amp;#8217;s been a fun  couple of days down here at Vegas! I flew down Saturday night and got to Caesars around 8pm and got settled in. A nice surprise was getting bumped up to a nicer room in the Augustus Tower, with a great view of the Bellagio Fountain right out my window. It&amp;#8217;s been [...]</description>
			<content:encoded><![CDATA[<p>It&#8217;s been a fun  couple of days down here at Vegas! I flew down Saturday night and got to Caesars around 8pm and got settled in. A nice surprise was getting bumped up to a nicer room in the Augustus Tower, with a great view of the Bellagio Fountain right out my window. It&#8217;s been awhile since I&#8217;ve been to Vegas, and man the strip sure has changed! After class yesterday I managed to get out and do a little exploring, then went down to the Hilton and checked out the Star Trek Experience. I have to say it was pretty cool, but I was ready to hit the sack after all the wandering around.</p>
<p>I&#8217;m heading down to check out the vendors, pick up some swag, and mingle with the security elite. =) Also on the agenda for after-hours Wednesday night is a talk from Josh Wright on Bluetooth Headset eavesdropping, as well as a presentation from Ed Skoudis on VM Escape. I&#8217;m also going to try to get over to the PaulDotCom sec podcast on Thursday.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2007/09/24/sans2007-day-2-recap/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2007/09/24/sans2007-day-2-recap/</feedburner:origLink></item>
		<item>
		<title>SANS2007, Vegas-style!</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/153518725/</link>
		<comments>http://www.jeffbolden.net/2007/09/07/sans2007-vegas-style/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 16:57:47 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2007/09/07/sans2007-vegas-style/</guid>
		<description>SANS Network Security 2007 is almost upon us! It&amp;#8217;s been over 18 months since I&amp;#8217;ve been to SANS so I&amp;#8217;m really looking forward to going to the Vegas conference this year, even if it is a management track. I&amp;#8217;ll be doing the MGMT411 track this time, covering the ISO 17799/27001. It&amp;#8217;s a good overview to [...]</description>
			<content:encoded><![CDATA[<p><a href="http://www.sans.org/ns2007/description.php?tid=1537&amp;portal=b636f2df573e5f8e3f4082a36071e408" target="_blank"></a></p>
<div style="text-align: center"><a href="http://www.sans.org/ns2007/description.php?tid=1537&amp;portal=b636f2df573e5f8e3f4082a36071e408" target="_blank"><img src="http://www.jeffbolden.net/wp-content/uploads/2007/09/102.jpg" title="SANS2007" alt="102.jpg" border="0" /></a></div>
<p><a href="http://www.sans.org/info/15026?portal=56c9a7ea8a61da510b0e34c4814bbb65" target="_blank"></a></p>
<p><a href="http://www.sans.org/info/15026?portal=56c9a7ea8a61da510b0e34c4814bbb65" target="_blank">SANS Network Security 2007</a> is almost upon us! It&#8217;s been over 18 months since I&#8217;ve been to SANS so I&#8217;m really looking forward to going to the Vegas conference this year, even if it is a management track. I&#8217;ll be doing the <a href="http://www.sans.org/ns2007/description.php?tid=1537&amp;portal=b636f2df573e5f8e3f4082a36071e408" target="_blank">MGMT411</a> track this time, covering the ISO 17799/27001. It&#8217;s a good overview to refresh my memory on the &#8220;official&#8221; security framework in my new role, but I would be much more excited about the malware or forensics tracks. I guess it can&#8217;t alway be fun and games&#8230; =)</p>
<p>If anyone reading this (all 2 of you&#8230;) is going to the Vegas conference and would like to get together, be sure to drop me a line and we can schedule a night. I always like meeting fellow netsec geeks for food and fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2007/09/07/sans2007-vegas-style/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2007/09/07/sans2007-vegas-style/</feedburner:origLink></item>
		<item>
		<title>Security Certs: Oh How I Love/Loath Thee…</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/153503109/</link>
		<comments>http://www.jeffbolden.net/2007/09/07/security-certs-oh-how-i-loveloath-thee/#comments</comments>
		<pubDate>Fri, 07 Sep 2007 16:18:35 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Certs]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2007/09/07/security-certs-oh-how-i-loveloath-thee/</guid>
		<description>With my recent focus on career, job search and subsequent employer change the past few months, I&amp;#8217;ve been wanting to post some of my recent thoughts on certifications but just haven&amp;#8217;t had the time. So it was with interest (and some amusement) that I was following the recent comments between Daniel Miessler (original post and [...]</description>
			<content:encoded><![CDATA[<p>With my recent focus on career, job search and subsequent employer change the past few months, I&#8217;ve been wanting to post some of my recent thoughts on certifications but just haven&#8217;t had the time. So it was with interest (and some amusement) that I was following the recent comments between Daniel Miessler (<a href="http://dmiessler.com/blogarchive/information-security-comparing-the-cissp-and-gsec-certifications" target="_blank">original post</a> and <a href="http://dmiessler.com/blogarchive/why-cissps-do-need-to-be-decently-versed-in-technology" target="_blank">followup</a>) and Marty McKeay (<a href="http://www.mckeay.net/secure/2007/08/repeat_after_me_the_cissp_is_n.html" target="_blank">here</a> and <a href="http://www.mckeay.net/secure/2007/09/only_testing_for_10_domains.html" target="_blank">here</a>) in regards to the comparisons/differences between the CISSP and GSEC. They have some opposing viewpoints on the subject, although I think they are closer than they think and sum up my thoughts pretty succinctly. Some of my favorite quotes from the discussion:</p>
<blockquote><p>[MM] When you&#8217;re interviewing for a position, you&#8217;re interviewing a person, not a certificate.  If you&#8217;re interviewing a CISSP to be a router jockey, you better hope they have a couple of other certs to back up their claims of knowledge.  Or you better have some really good questions for them, preferably both.  By definition, the CISSP shows no in depth knowledge of any particular aspect of security.</p></blockquote>
<p>That&#8217;s one of the things that really bugs me about certs in general, the attitude of some (both cert holders and employers) that just because they hold a CISSP or GSEC, they have reached some pinnacle and know all they need to know about security. The attitude always astounds me! =) I&#8217;ve been in IT for about 15 years and yet I feel like I learn something new every day. In fact, that&#8217;s one of the main reasons I love the security field so much, the constant challenge to stay current, to learn and grow. =)</p>
<blockquote><p>[MM] The CISSP certificate is useful setting a baseline of the person&#8217;s overall knowledge of security. And if it&#8217;s treated as nothing more than a simple measuring stick, it works well. But it&#8217;s not meant to measure someone&#8217;s networking knowledge and using it do so won&#8217;t work.</p></blockquote>
<p>Marty pegs it here. Certs are (IMHO) a simple baseline that employers can use to assess that we in the security arena have a minimum &#8220;baseline&#8221; of security knowledge, but it is not the end-all be-all of measuring the skill of a person. We&#8217;ve all met loads of IT people with a bucketful of certs who could not troubleshoot their way out of a wet paper bag. So I thing Marty&#8217;s point is valid here, we cannot assume that a CISSP knows about things not covered in the official study guide. In a perfect world that foundation knowledge would be there, but this is not a perfect world. =) That&#8217;s where Daniel&#8217;s point rings true:</p>
<blockquote><p>[DM] It’s simply absurd to claim that people in “management” roles don’t need to be versed in technology. <strong>Chefs learn about food. Architects learn about the structural integrity of their building materials. Physicists learn math. </strong>Why should information security experts not have to learn the building blocks of their discipline like everyone else?</p></blockquote>
<p>I&#8217;ve held off taking the CISSP for years, but not for the reasons you might suspect. I guess it was the rebel in me, but as someone who was &#8220;in the trenches&#8221; for years I didn&#8217;t see the need to take a cert that did not (IMHO) add much to my knowledge base and was more of a resume checkbox.</p>
<p>This past year I think I&#8217;ve finally made peace with myself on this whole cert subject and have come to the conclusion that it&#8217;s part of the resume game we all must play sooner or later. I&#8217;ve changed the way I look at these certs and have even come to see the advantage of going through the motions, and will even admit to learning a thing or two in studying for the CISSP and CISA tests this year. I guess you can teach an old dog at least a few new tricks&#8230; =)</p>
<p><strong>Update 9/7/07:</strong> This exchange has sparked some great comments around the web this week. Mike Rothman over at <a href="http://securityincite.com/TDI-2007-09-04#TBP2" target="_blank">SecurityIncite.com</a> wrote a great blurb on the issue. Marty also talks more about the issue in <a href="http://media.libsyn.com/media/mckeay/nsp-090407-ep75.mp3" target="_blank">Episode 75</a> of his great podcast.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2007/09/07/security-certs-oh-how-i-loveloath-thee/feed/</wfw:commentRss>
<enclosure url="http://media.libsyn.com/media/mckeay/nsp-090407-ep75.mp3" length="53200973" type="audio/mpeg" />
		<feedburner:origLink>http://www.jeffbolden.net/2007/09/07/security-certs-oh-how-i-loveloath-thee/</feedburner:origLink></item>
		<item>
		<title>Summer’s a time for change</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/140761652/</link>
		<comments>http://www.jeffbolden.net/2007/08/04/summers-a-time-for-change/#comments</comments>
		<pubDate>Sun, 05 Aug 2007 00:53:25 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2007/08/04/summers-a-time-for-change/</guid>
		<description>What a summer! Time is flying by, and I just noticed it&amp;#8217;s been almost 2 months since I posted. Nothing like starting a blog just to ignore it. It seems like the past few months have been a flurry of work, kid&amp;#8217;s  summer activities and stress over career. I guess the old adage is [...]</description>
			<content:encoded><![CDATA[<p>What a summer! Time is flying by, and I just noticed it&#8217;s been almost 2 months since I posted. Nothing like starting a blog just to ignore it. It seems like the past few months have been a flurry of work, kid&#8217;s  summer activities and stress over career. I guess the old adage is true, the older you get the faster time seems to slip by. =)</p>
<p>On the job front, I have some changes to announce. After a lot of contemplation I decided it was time to move on from my Security Architect role at US Bank, I role I&#8217;ve been at for the past 15 months. I met a lot of great people, learned a few things about myself, but in the end decided the position was just not a good fit for me. I&#8217;m grateful I had a chance to meet some truly talented security people while I was there and made some great friends. It was a tough decision, but I&#8217;m excited about the change.</p>
<p>I&#8217;ve accepted a new position at a great financial software/solution company in downtown Portland that I&#8217;m extremely excited about, and will be starting Monday. It&#8217;s a role I&#8217;ve been resisting for over three years but circumstances seem to keep pushing me in that direction, so after a lot of thought and discussions with my new employer I&#8217;ve decided to accept the inevitable and become an Information Security Auditor.</p>
<p>So for those of you that know me, yes i&#8217;ve moved to the dark side. I can hear you chuckling from here. =)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2007/08/04/summers-a-time-for-change/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2007/08/04/summers-a-time-for-change/</feedburner:origLink></item>
		<item>
		<title>CISA Results are in…</title>
		<link>http://feeds.feedburner.com/~r/Jeffboldennet/~3/140758405/</link>
		<comments>http://www.jeffbolden.net/2007/08/04/cisa-results-are-in/#comments</comments>
		<pubDate>Sun, 05 Aug 2007 00:34:18 +0000</pubDate>
		<dc:creator>Jeff</dc:creator>
		
		<category><![CDATA[Audit]]></category>

		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://www.jeffbolden.net/2007/08/04/cisa-results-are-in/</guid>
		<description>The summer is flying by so fast I had almost forgot about my CISA test and that I was still waiting for results. It had been weeks since I last thought about it, so I was pleasantly surprised to get an email from ISACA on Thursday with the results. Long story short, I passed with [...]</description>
			<content:encoded><![CDATA[<p>The summer is flying by so fast I had almost forgot about my CISA test and that I was still waiting for results. It had been weeks since I last thought about it, so I was pleasantly surprised to get an email from ISACA on Thursday with the results. Long story short, I passed with flying colors! I&#8217;m glad, as I did not relish the thought of having to study and retake the test in December during the holiday season.</p>
<p>All in all, this was one of the more interesting (read stressful) certification tests I&#8217;ve taken. Now that I can look back at it knowing I passed, it was a test that I probably worried more than I needed to, but one I had to prepare for the most due to it covering areas that I did not have as much experience in as I&#8217;ve had with other certification subjects in the past.</p>
<p>Now comes the fun part, filling out the application and documenting my past security experience so I can claim a new set of letters to add behind my name. All of which really means nothing in the grand scheme of things&#8230; =)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jeffbolden.net/2007/08/04/cisa-results-are-in/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.jeffbolden.net/2007/08/04/cisa-results-are-in/</feedburner:origLink></item>
	</channel>
</rss>
