The most trusted source for computer security training, certification and research.



select a course
Virginia Beach, VA - August 22 - 29, 2008
Global Information Assurance Certification

Wow! It's an incident handler's Christmas morning, tools, tools, tools. Very Applicable!
-Todd Davis, Symantec

Special Events

SANS Virginia Beach 08

Welcome To SANS Talk - General Session
- Dr. Eric Cole
- Sunday, August 24, 2008 * 8:15am-8:45am

GIAC Brief
- John Strand
- Tuesday, August 26, 2008 * 7:15pm-8:15pm

SANS Technology Institute Brief
- President Stephen Northcutt
- Wednesday, August 27, 2008 * 7:00pm-8:00pm

SANS Technology Institute

SANS Technology Institute Master of Science degree programs offer candidates an unparalleled opportunity to excel in the two aspects of security that are most important to the success of their employer and their own careers: management skills and technical mastery.

Over the next 20 years, information technology will become so central to all aspects of our lives, from recreation to warfare, that information security will rise in importance and scale. It will become a profession with more than 500,000, and perhaps 1,000,000 people employed in positions in which they have significant roles in shaping the security of their employers' systems. Those people need managers - technical directors and chief information security officers who are deeply skilled in the technology and who have excellent management skills.

If you aspire to help lead your organization's or your country's information security program, and you have the qualifications, organizational backing, and personal drive to excel in these challenging degree programs, we will welcome you into the program.

The following SANS Technology Institute (STI) master's student will be making the following presentation as part of his graduation requirements:

Security Awareness Training Using an Actual Incident
- Russell Meyer
- Thursday, August 28, 2008 * 7:00pm-7:40pm
- Cape Charles

Companies practice evacuations in case of fire, disaster recovery simulations, and testing of generators in case of power failure; so why not also practice security incident handling?

In this talk you will learn how information security awareness training can be delivered to IT staff like developers, management and helpdesk personnel. The staff will work in teams to investigate an actual compromised system recreated on a VMware image. Using this hands-on approach, the teams will examine the system, find the vulnerabilities, the hidden folders and files, and practice cleaning up the system and removing the vulnerabilities -- all the while documenting their findings and following the proper incident handling procedures. Attendees will learn how a hands-on approach in a lab setting can be an effective learning tool.

Bio:
Russell Meyer has over 15 years experience in compliance, network security, programming and project implementations. He holds several GIAC certifications as well as the CISSP, MCSE, MCNE. He is currently a SANS Technology Institute Master of Science degree candidate.