Showing posts with label IT training. Show all posts
Showing posts with label IT training. Show all posts

Wednesday, June 25, 2014

Real-time Monitoring your Organization Against Threats

Overview: Monitoring traffic is crucial and is often mandatory (e.g.: NERCii). Filtering and blocking malicious traffics is often optional, but I usually suggest IPS to detect and block threats in incoming/outgoing traffics from boundaries of critical perimeters (e.g.: Internet to Intranet, Intranet to critical perimeter gateways), but never in electronic security perimeters (ESP) where blocking valid traffics could lead to various operational disaster scenarios. Real-time monitoring of firewalls and other security sensors is required to rapidly detect and initiate response to cyber incidents. 

Security and Compliance involve by default: exception, justification and compensatory measures. In all organizations, there are situations where it is considered more secured with reason to not apply any changes to a specific system (ex.: a HSM bank system remain usually unchanged, mainframes and Unix systems are other examples, especially in industrial organizations (ex.: in the energy sector, Technical Feasibility Exceptions (TFE) can justify the exemption of running a protective control such as an anti-malware or applying any update like system or firmware update, etc.).

Security Paradigm 

Despite it is usually considered unsecured to keep a system unchanged, as previously explained, it is sometimes the only way to keep it to an acceptable security posture considering the potential impacts of loss, especially when systems are isolated and very critical. In those situations, a justification (e.g.: ticket, derogation, statement of applicability, etc.) must be provided in order to document the reasons and duration of the exception in time.

An organization can be compliant and secure while system are unchanged during a long period of time (e.g.: years) and it is important to understand this reality in large corporations conducting critical activities. Not all systems can remain secured while unchanged, usually systems isolated in restricted networks or not interconnected to a computer network are valid examples.

Why should you attend: All organizations are facing various types of threats. Threats can come from inside, outside your organization or from both. This article focus on monitoring informational resources against all types of threats threatening your critical functions supported by electronic assets such as servers, desktops, switches, routers, firewalls, etc. Organizations are getting more and more interconnected and thinking that the obscurity can be considered as a security control is similar to me to ignoring the new reality of Interconnected Networks and the risk surrounding the Internet.

Areas Covered in the Session:

  • Layer 2 and Layer 3 monitoring
  • Technical difference between internal and external threats
  • Real life example of a man in-the-middle attack on Internal network demonstrated
  • Capture internal traffic with packet sniffer
  • Steal username and password on the network
  • Traffic redirection and routing hijacking on internal network
  • Example of solution to detect and correct ARP table while poisoned on a critical system

Who Will Benefit:

  • Architect
  • System Administrator
  • Threats & Vulnerabilities Director
  • Risk Management Specialists
  • Risk Advisors
  • Auditor
  • Security Specialists

Monday, June 16, 2014

What is Agile Methodology?

Agile Methodology is considered a ground-breaking practice in project management. Tied closely with software development, Agile Methodology is essentially a practice that helps project management anticipate and counter unpredictability and vulnerability. The quintessential aim of the Agile Methodology is to help avoid project delays and overruns by addressing bottlenecks at all stages of the project development. This goes a long way in cutting the costs and other problems associated with keeping all these activities towards the end of the project, by when it could be either too expensive or impractical to carry out these critical changes.

Deeply related to software project management
As the discipline of software grew, it spawned and spanned several technologies, as well as business requirements, which had to accommodate the new changes. This necessitated the development of a flexible system or model of software development, the culmination of which resulted in the Agile Methodology.
Agile Methodology did not come into effect out of the blue. It took persistent effort from the IT community to arrive at a model of project management that addressed their needs in a comprehensive manner.

Agile Methodology is not a standalone
The term 'Agile' is a comprehensive term with which several models used for agile development –Scrum being the primary one among them –are identified.

Features of Agile Methodology
1.      The overwhelming emphasis that the Agile Methodology focuses on is that the whole team should be tightly knit. It takes everyone and all aspects, be it quality assurance, developers, the customer, as well as project management itself, in the loop.
2.      Since coordination and integration of such complex parts is integral to project management; the Agile Methodology attaches a high degree of importance to frequent communication. The frequency of these meetings is best determined by the team based on its convenience, but meeting at least once a day is considered an acceptable frequency to discuss and take action on the progress made, so that oversights can be spotted and rectified then and there.
3.      Agile Methodology also has what are called sprints. These are delivery cycles. These sprints are designed keeping in mind the fact that there could be short-term deliveries, ranging from one to four weeks.
4.      The Agile Methodology facilitates very open communication techniques and tools. Everyone in the team –the customer included –is encouraged to express views and offer feedback in an open and transparent manner. When the software is being implemented; these are considered seriously.
References:

Wednesday, May 14, 2014

Moving to the 3rd IT Platform and Beyond - Challenges and Opportunities

Overview: According to IDC the 3rd IT Platform is comprised of Cloud, Mobile, Social, and Big Data. Mobile and Social originated in the consumer market and have been driven into enterprise IT by users, while Cloud and Big Data were typically driven by businesses looking to create a new computing paradigm and break the traditional bottlenecks in processing vast information. Forward looking IT organizations are now gearing up to utilize 3rd IT Platform technologies across most of their projects, and to move beyond, using new technologies such as Web APIs and BYOT (Bring Your Own Technology). 

This presentation will discuss the four pillars of the 3rd IT Platform and illustrate the challenges and opportunities to advance them for greater business value. 

Why should you attend:: Are you still deploying 2nd platform applications while your competition is moving full steam ahead onto the 3rd platform? The new technologies - cloud, mobile, social, big data - are compelling, but what is the best way to exploit them; how can you build the new generation of applications that appeals to your customers and connect them to the systems of record, without compromising the integrity of those systems?

Areas Covered in the Session:

  • The 3rd IT platform defined and redefined
  • How does IT consumerization impact the Enterprise?
  • Cloud 2.0: hybrid clouds, legacy migration, and a new application development paradigm
  • Moving Beyond BYOD - the impact of BYOT and the Internet of Things
  • How Web APIs enable the digital business
  • How can IT meet the challenges and stay relevant to the business
Speaker Profile: Max Dolgicer
is Senior Consultant at International System Group (ISG), Inc a leading consulting firm that specializes in IT Strategy, development and integration of large-scale applications, Service-Oriented Architecture, and Cloud Computing. For over 25 years Mr. Dolgicer has held many senior IT Management and Technical positions including engagements for companies like 3M, Carey International, United States Patent Office (USPTO), New York Stock Exchange (NYSE), Credit Suisse, Federal Reserve, Allstate Insurance, Financial Times Interactive, MetLife, Principal Financial Group, Cigna, Citi Group, Morgan Stanley, Delta Airlines, Goldman Sachs, McKenzie Financial Corporation. In addition to end-user companies, Mr. Dolgicer has worked closely for many established software vendors as well as various stage start-ups. Most of his work focused on product roadmap and strategy, competitive analysis as well as product positioning. 
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539

Data Compression Methods and Compression Performance Metrics

Overview: The webinar covers the foundations of data compression in the context of the broader subject of information theory. The learner will gain valuable insight into how lossless compression works and why the techniques are robust and trustworthy. In the historical perspective, data compression concepts have arrived in a timely manner to aid the expanding data storage and wireless communication needs of the modern era. The measure of information is defined probabilistically, it is formally defined as entropy, a term that Claude Shannon borrowed from quantum mechanics. 

Why should you Attend:The information age continues to yield more and more data. The Internet, Big Data, Cloud Computing, and data storage requirements are measured in ever-increasing scales of Terabytes, Petabytes, Exabytes, and Zettabytes. Does data compression provide a solution to stem this ever-expanding flood? Can you trust data compression? Doesn't it put your data “at risk”? Are some types of data more compressible than other data? How do the methods of lossless data compression (covered) differ from lossy data compression? Take away from this session a meaningful understanding of lossless compression, its limitations, and the tradeoffs between storage reduction and increased processing required to compact and re-expand data. 

Areas Covered in the Session:
  • Entropy as the measure of information
  • Shannon's Source Coding Theorem
  • Huffman Trees and Huffman Coding
  • Arithmetic coding
  • Dictionary methods
  • Transform methods
  • Data deduplication
  • Implementation considerations, Open Source software, Hardware compression chips
  • Performance
Speaker Profile: Raymond Moberly
is a consulting subject matter expert in the field of Information Theory, knowledgeable about principles of error correction, cryptography, and data compression. He has worked extensively in the field of software defined radio. He has lead development efforts for embedded software and firmware on microcontrollers, digital signal processors, and field programmable gate arrays. He has extensive experience in the verification and validation of systems through all development phases including formal qualification testing. He enjoys profiling software in order to to analyze and better optimize code code performance. Raymond holds a bachelor's degree in engineering from Caltech, masters in applied mathematics from San Diego State University, and a doctorate in computational science from the Claremont Graduate University.
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539

Maximizing Your Enterprise Architecture Effort by Increasing Stakeholder Involvement

Overview: More Enterprise Architecture projects fail due to poor stakeholder participation than any other reason. Your EA team, like most, may have difficulty engaging your stakeholders and keeping them engaged. What do TOGAF and ArchiMate have offer to help us in the essential area? 

Areas Covered in the Session:
  • Why poor stakeholder engagement leads to EA project failure
  • Isn't stakeholder management a PMO responsibility?
  • How does TOGAF help us engage stakeholders?
    • Understanding your stakeholders
    • Building a stakeholder map
    • Solution Concept Diagram
  • What does ArchiMate offer us for engaging stakeholders?
    • How do models help?
    • Motivation Viewpoint
    • Stakeholder Viewpoint
    • Introductory Viewpoint
    • Goal Contribution Viewpoint
    • Goal Realization Viewpoint
  • Summary

Who Will Benefit:

  • Enterprise Architects
  • IT Architects
  • Solution Architects
  • IT Project Managers
Speaker Profile: John Polgreen
 is a TOGAF® 9 and ArchiMate® 2 certified Enterprise Architect with twenty years of Information Technology industry experience. John has a wealth of Enterprise Architecture and general IT experience. His achievements have included leading the enterprise architecture efforts for the Foreign Agriculture Service of the United States Department of Agriculture, and preparing the business architecture and service component architecture portions of the Federal Student Aid's annual EA assessment. John is trained to use IBM Systems Architect and the Rational Unified Process, and has worked with major EA frameworks including TOGAF®, Zachman, DoDAF and FEA. He has worked in Microsoft, Java and mixed platform environments.
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539

Best Practices for Securing Active Directory - Webinar By EITAGlobal

Why should you attend: This Webinar is helpful for Active Directory administrators. It teaches them how to properly secure the Active Directory Domain Controllers. A vast majority of servers in the world are running Microsoft Windows operating system. This makes them a favorite target of bad guys. In this Webinar you will learn some of the best practices for securing your Active Directory environment. 

Areas Covered in the Session:
  • 10 immutable laws of security
  • Minimizing known security threats to Active Directory
  • Identifying sources of threat
  • Securing various administrative accounts
  • Minimizing attacks on Domain Controllers from 16-bit apps
  • Deciding which services are necessary to run on Domain Controllers
  • Reducing Active Directory attack surface
  • Dealing with local administrator accounts
  • Understanding the protected accounts and groups in Active Directory
  • Group Policy settings for securing Active Directory
Speaker Profile: Zubair Alexander
is a Microsoft MVP, a Microsoft Certified Trainer, and the founder of SeattlePro Enterprises, LLC, an IT training and consulting company. He holds more than 25 industry certifications including MCT, MCSE, MCSA, MCDST, MCITP, MCTS, MCP+I, MCSA 2000/2003: Security, MCSE 2000/2003: Security, CNA, A+, Network+, Security+, CTT+ and CIW. His experience covers a wide range of spectrum: trainer, consultant, systems administrator, security architect, network engineer, author, technical editor, college instructor and public speaker. 
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539


Thursday, April 3, 2014

2-day In-person Seminar: Security & Compliance by Objects using UML and SysML (PCI DSS, NERC,...) By Marc Andre Heroux


"The International Association of Privacy Professionals (IAPP) has approved "Security & Compliance by Objects using UML and SysML (PCI DSS, NERC,...)" seminar for 12 CPE credits"






Areas Covered in the Session:



  • Governance objects
  • Compliance by objects
  • Security Controls Definition and Implementation
  • UML/SysML - Object Management Group (OMG)
  • PCI DSS, NERC, etc.










Who Will Benefit:


  • Chief (CEO, CTO, CSO, etc.)
  • Senior Director
  • IT Manager
  • Project Control Officer (PCO)
  • Project Manager
  • Technological/Security Architect
  • Security Advisor
  • Auditor





















































































































































































































































































































































































































































  Why should you attend :


Many organizations have short delay to get their information system compliant to standards such as PCI DSS, NERC or any other standards.


This seminar will guide you in the application of a Compliance Object Model approach to evaluate the risk, determine gaps and implement security controls. 


This seminar will focus on how to apply Unified Modeling Language (UML) concepts from the Object Management Group (OMG) such as communication/collaboration diagrams and activity diagrams.
                                
                                 We will explore the SysML approach to elaborate system architectures and engineering model. During the seminar, we will design a Data Leak Prevention System using UML and SysML. The output diagram will present the functional and technical requirements (ex.: Diagram of the Security Controls for a Data Leak Prevention System). 

  Day 1 –Agenda

LectureAgenda Content
Lectur 1:
During the first day, we will explain the following:
  • What is UML?
  • What is SysML?
  • What are the relations between objects, compliances and security
  • We will enumerate the various elements and basics concepts to understand prior going forward with a real example
  • We will evaluate potential organizational data losses and the impact of loss
  • We will explain what are the requirements in order to apply the method: "Security & Compliance by Objects using UML and SysML"

 Day 2 –Agenda

LectureAgenda Content
Lecture 1:The second day, we will work with objects. We will evaluate the gaps between the current situation of an organization with the acceptable situation based on a "Risk Profile".
Lecture 2:We will design the security controls using UML and SysML. The final output will be the technological architecture to be implemented by the operational team.
Lecture 3:We will cover strategic aspects of the PCI DSS standard and NERC CIP to explain how we can quickly define tactical security controls and how we can collaborate the operational team regarding the implementation of each security control.
Lecture 4:After this seminar, you will be able to use the Compliance Object Model to quickly resolve security issues on a daily basis or apply the method for larger compliance project.
Lecture 5:Finally, you will be comfortable with many UML concepts of the Object Management Group (OMG) and will better armed to manage security and compliance in your organization.

About Speaker
speakerMarc Andre Heroux
Senior Security Advisor, GRCSI

Mr. Heroux cumulates over 16 years of experience in Governance, Risk Management, Compliance, Security & IT consulting.

Marc been involved in many Linux, Security & SaaS/Cloud Computing Projects. He has a solid technical background.

Since 2000, he especially acted as a security, compliance & risk management specialist. Marc leaded many critical security projects such as: AS2 certification with the AAFES (US Army and Air Force Exchange Service), compliance of Sears Canada and GE Commercial Finance transactions, ASC X12.58 encryption and architecture analysis for Banks, US Custom Border EDI integration and SOX compliance.

He also worked on compliance projects against ISO 27000, COBIT, ANSI, NIST standards, Basel II, SAS 70 (SSAE no. 16), PCI, CICA 5970, Article 17 Directive 95/46/EC & NERC.



Contact Information: 



Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539