JeffBolden.net Ramblings from a IT Professional and NetSec Geek

30Oct/090

BoldTech Solutions

BoldTech Solutions

Just wanted to put in a quick plug for my current endeavor. BoldTech Solutions is a small Technology Consulting and Managed Services practice serving the needs of the SMB market in the Portland/Vancouver area. We provide innovative solutions to your small business IT problems and help you keep your focus on your business, not your technology.

Filed under: Personal, Stuff No Comments
25Mar/090

Where did you learn that word?!

So, I'm perusing the job sites the other day and my 13-year old son walks in, looks at the screen and says "Why is the S-word on there?!" I didn't catch it until he pointed it out, at which point I busted up laughing.

jobsummary3

Pretty much sums up the job market at the moment...

Tagged as: No Comments
27Sep/070

SANS2007 Day 3/4 Recap

Tuesday and Wednesday were both full days for me, covering the ISO27002 controls as well as hitting lunch and learns, some great after-hours talks, and a trip or two down the strip as well. The highlight of the past 2 days was a couple of excellent talks on bluetooth eavesdropping as well as a talk on VM Escape issues.

Josh Wright's Wednesday evening talk on bluetooth eavesdropping was excellent (as usual, great talk Josh!) and showed just how bad bluetooth security is. He has a great YouTube video up showing the issues as well as a great paper on Dispelling Common Bluetooth Misconceptions that he just released. I highly recommend taking a look at both. Also, be sure to check out his website www.willhackforsushi.com for lots more wireless info.

Tonight is the PaulDotCom security podcast live here at SANS and I'll be dropping in for that. It's only fitting since I was lucky enough to be at their first podcast at SANS 2005 in LA. They've come a long way since then! =) They will be running a live stream as well as taking questions over IRC, so be sure to jump over to their site and get the info, then join us tonight!

Filed under: Personal, SANS No Comments
24Sep/070

SANS2007 Day 2 Recap

It's been a funĀ  couple of days down here at Vegas! I flew down Saturday night and got to Caesars around 8pm and got settled in. A nice surprise was getting bumped up to a nicer room in the Augustus Tower, with a great view of the Bellagio Fountain right out my window. It's been awhile since I've been to Vegas, and man the strip sure has changed! After class yesterday I managed to get out and do a little exploring, then went down to the Hilton and checked out the Star Trek Experience. I have to say it was pretty cool, but I was ready to hit the sack after all the wandering around.

I'm heading down to check out the vendors, pick up some swag, and mingle with the security elite. =) Also on the agenda for after-hours Wednesday night is a talk from Josh Wright on Bluetooth Headset eavesdropping, as well as a presentation from Ed Skoudis on VM Escape. I'm also going to try to get over to the PaulDotCom sec podcast on Thursday.

Filed under: Personal, SANS No Comments
7Sep/070

SANS2007, Vegas-style!

102.jpg

SANS Network Security 2007 is almost upon us! It's been over 18 months since I've been to SANS so I'm really looking forward to going to the Vegas conference this year, even if it is a management track. I'll be doing the MGMT411 track this time, covering the ISO 17799/27001. It's a good overview to refresh my memory on the "official" security framework in my new role, but I would be much more excited about the malware or forensics tracks. I guess it can't alway be fun and games... =)

If anyone reading this (all 2 of you...) is going to the Vegas conference and would like to get together, be sure to drop me a line and we can schedule a night. I always like meeting fellow netsec geeks for food and fun!

Filed under: Personal, SANS No Comments
4Aug/075

CISA Results are in…

The summer is flying by so fast I had almost forgot about my CISA test and that I was still waiting for results. It had been weeks since I last thought about it, so I was pleasantly surprised to get an email from ISACA on Thursday with the results. Long story short, I passed with flying colors! I'm glad, as I did not relish the thought of having to study and retake the test in December during the holiday season.

All in all, this was one of the more interesting (read stressful) certification tests I've taken. Now that I can look back at it knowing I passed, it was a test that I probably worried more than I needed to, but one I had to prepare for the most due to it covering areas that I did not have as much experience in as I've had with other certification subjects in the past.

Now comes the fun part, filling out the application and documenting my past security experience so I can claim a new set of letters to add behind my name. All of which really means nothing in the grand scheme of things... =)

Filed under: Audit, Personal 5 Comments
18Jun/070

CISA test over – Now the wait begins…

After a month or two of pretty regular study I finally got my Certified Information Systems Auditor (CISA) test done a week ago and then promptly took a much-deserved week off for vacation. Now comes the 10-week wait for the results. You would think in this day and age they could get you the results a little faster, but such is life I guess. :)

The test itself was one of the more difficult ones I've taken due to the subjectivity of the questions. There were too many questions where you had to make a decision on the "most right" answer, and it seemed to me like it tests your ability to decide what ISACA wants you to say more than your actual knowledge of the material. I've yet to fail a cert test, but I'm really unsure as to my success on this one.

As an FYI, I used the Sybex CISA Study guide and found it to be an excellent guide of the material. I also used the official ISACA CISA Test Question CD for review.