Jerell’s Graduation

We had a lovely time joining our family to celebrate Jerell’s graduation. He’s going to go do great things!

 

The majority of this group is family

 

left to right: Hector Jr, Henry Senior, Amelia, Hazel, Helena, and Hethel

Posted in life | Comments Off on Jerell’s Graduation

Merry Christmas (Information Security Comics)

Some pictures I found on the Internet

Posted in Security Blog | Tagged , , | Comments Off on Merry Christmas (Information Security Comics)

2016 San Francisco CISO Executive Summit

I had the privilege of attending the 2016 CISO Executive Summit in San Francisco on Monday the 5th. I went with a great group of people!

There was a lot of good discussions regarding leadership, insider threats, third party management, challenging the status quo, and effective security awareness. One of the biggest realizations that I had, was that we all have common overlapping problems despite our level of maturity within those domains.

  • We purchase products that are top right in the Gartner magic quadrant, normally because it comes with process and maturity… We are attracted to those products because we normally lack internal (products) process and maturity to face up to those risks.
  • We lack a clear definition of insider threats and less than 1% of attendees is proactive in sorting them out.
  • We put our money, at least $20 billion annually as an industry, into perimeter devices and fancy technologies though the threats have changed attack strategy and have targeted users directly through social engineering.
  • Less than 5% of attendees have a person or more dedicated to awareness of social engineering.

Riddle me this… When will we shift focus and migrate from product to process and people, despite more than a decade of publicly announced compromise via social engineering? This to me is a leadership/psychological/behavioral problem.

Here is a great write-up on insider threats.

There are a number of precursors of insider attacks that can help to identify and prevent them:

Deliberate markers – These are signs which attackers leave intentionally. They can be very obvious or very subtle, but they all aim to make a statement. Being able to identify the smaller, less obvious markers can help prevent the “big attack.”
Meaningful errors – Skilled attackers tend to try and cover their tracks by deleting log files but error logs are often overlooked.
Preparatory behavior – Collecting information, such as testing countermeasures or permissions, is the starting point of any social engineering attack.
Correlated usage patterns – It is worthwhile to invest in investigating the patterns of computer usage across different systems. This can reveal a systematic attempt to collect information or test boundaries.
Verbal behavior – Collecting information or voicing dissatisfaction about the current working conditions may be considered one of the precursors of an insider attack.
Personality traits – A history of rule violation, drug or alcohol addiction, or inappropriate social skills may contribute to the propensity of committing an insider attack.
Security professionals should understand that attackers are people too, who differ in resources, motivation, ability and risk propensity.

Posted in Security Blog | Tagged , , , , , , , , , | Comments Off on 2016 San Francisco CISO Executive Summit

Auntie Gloria

It’s with a heavy heart to announce that my Auntie Gloria lost her fight against cancer.

Posted in life | Comments Off on Auntie Gloria

Victor’s 5th Birthday

It’s amazing how big this guy is getting!

Posted in life | Comments Off on Victor’s 5th Birthday

Ukulele Christmas Concert at Sam Ash 2016

Posted in life | Comments Off on Ukulele Christmas Concert at Sam Ash 2016

Tom’s Birthday

Posted in life | Comments Off on Tom’s Birthday

Glendale Glitters 2016

We met up with Rob’s family and took them to Glendale Glitters with Karie tonight. It was a great time!

img_0658-2

img_0659-2

img_0664-2

img_0666-2

img_0680-2

img_0683-2

img_0691-2

img_0693-2

Posted in Event, life | Tagged , , , , , , | Comments Off on Glendale Glitters 2016

Thanksgiving 2016

Today was Jaime’s birthday! Happy birthday baby!

img_0547

Brandee’s cooking is so good, I ate until I hated myself!

img_0555

15129446_1342522545771443_919649996307454797_o

Posted in life | Comments Off on Thanksgiving 2016

President-Elect Trump on 100 Day Transition Plan

Trump’s plan includes asking the Department of Defense and the Chairman of the Joint Chiefs of Staff to create plan to protect our infrastructure against Cyber Attacks.

screenshot-from-2016-11-23-06-32-23

Click to watch on Youtube

How this will modify the Cybersecurity National Action Plan that was published under Obama in February of 2016 (likely as a result of the OPM breach which was predicted in 2005, under Bush, by the OPM Inspector General).

Are we still on track to invest over $19 billion for cybersecurity as part of the President’s Fiscal Year (FY) 2017 Budget?

Posted in Security Blog | Tagged , , , , , | Comments Off on President-Elect Trump on 100 Day Transition Plan