The US State Department cracked a vexing cybersecurity problem through continuous monitoring and a focus on the 20 critical controls (the most important defenses based on actual attack data compiled by NSA and other agencies). Result: measurable, major improvement of security while lowering the cost. Justifying the transformation: State had paid for 95,000 pages of certification & accreditation and follow-up reports at a cost of $1,400 per page, totaling $130 million over six years, and much of the data was outdated by the time it is printed.
-http://gcn.com/articles/2009/11/12/state-department-it-security-pilot.aspx
[Editor's Note (Paller): This is the cyber equivalent of the 1983 expose of the $605 toilet seat. Shifting some of the $1.3 billion per C&A cycle to continuous automated monitoring is a great way for the federal government to lead by example and make huge improvements security while saving hundreds of millions of dollars. ]
Building and Maintaining a "Certifiable" Workforce
By Robert J. Mavretich
How Can You Build and Leverage SNORT IDS Metrics to Reduce Risk?
By Tim Proffitt
Daisy Chain Authentication
By Courtney Imbert
NEW #SANS Survey: Security Analytics & Intelligence 2nd [...]
October 1, 2013 - 6:30 PM
Tips on how to convince your boss to let you train online wi [...]
October 1, 2013 - 6:23 PM
#2 Tip on how 2 convince your boss 2 let u train online: Fle [...]
October 1, 2013 - 3:00 PM
(301) 654-SANS (7267)
Mon-Fri 9am - 8pm EST/EDT
info@sans.org
"As a security professional, this info is foundational to do a competent job, let alone be successful."
- Michael Foster, Providence Health & Security
"Because of the use of real-world examples it's easier to apply what you learn."
- Danny Hill, Friedkin Companies, Inc.
"The perfect balance of theory and hands-on experience."
- James D. Perry II, University of Tennessee