Come Join the Discussion

Add your comments to any of these postings or comments

Thursday, January 31, 2013


The Los Angeles Chapter of the Information Systems Security Association (ISSA-LA) invites you to partner with us at our Fifth Annual Information Security Summit, “The Growing Cyber Threat: Protect Your Business!”  The Summit is the premier Information Security event in Southern California. Last year we drew 500 people, and our goal for this year is 700.
 
The Summit offers information systems and information security vendors a very high-value marketing opportunity. By taking advantage of Summit and meeting sponsorships, your products and services get associated in the marketplace with ISSA-LA’s leadership; this enhances the market’s perception of you as an industry leader in the 18th largest economy in the world — Los Angeles County. 
 
We have many different sponsorship levels designed for every type of budget, including a set of premier sponsorships that include the full Summit attendee list. The top level sponsorships also bring with them an opportunity to address the full audience.
 
To register to be a Summit V Sponsor, please visit our Registration Page:
 
For more information about the Summit, including speakers, please visit our Summit website:
 
For more information about sponsorship, please visit:
 
OR
 
Contact our Vendor Director, Richard Greenberg, at:
 
We hope to see you there!

Friday, January 25, 2013

Government in bed with Communications Corporations

It is now illegal for wireless customers to purchase and unlock their cell phones! We know that George Orwell's and Aldus Huxley's visions of the future have unfortunately come to pass, but this is getting ridiculous and outrageous. http://tinyurl.com/ahpzo67

Wednesday, January 23, 2013

Oracle, what the hell are you doing to us with Java? Be merciful, and hire some really good analysts. This cannot continue. And, what is the deal with trying to sneak the Ask Toolbar into our Java updates? You're acting like rogue software companies. Enough is enough!

Tuesday, January 22, 2013


OWASP Monthly Meeting - January 23, 2013

  • 900 Corporate Pointe , Culver CityCA
    owaspla.org
    • Top Ten Web Defenses
    We cannot “firewall” or “patch” our way to secure websites. In the past, security professionals thought firewalls, Secure Sockets Layer (SSL), patching, and privacy policies were enough. Today, however, these methods are outdated and ineffective, as attacks on prominent, well-protected websites are occurring every day. Website developers must learn to code in a secure fashion to have any chance of providing organizations with proper defenses in the current threat-scape. The session will provide specific tips and guidelines to make website code both low risk and less vulnerable.
    • Bio: Jim Manico
    Jim is the VP of Security Architecture for WhiteHat Security. Jim is also the host of the OWASP Podcast Series, is the committee chair of the OWASP Connections Committee, is the project manager of the OWASP Cheatsheet series, and is a significant contributor to several additional OWASP projects. Jim provides secure coding and developer awareness training for WhiteHat Security using his 8+ years of experience delivering developer-training courses for SANS, Aspect Security and others. He brings 16 years of database-driven Web software development and analysis experience to WhiteHat and OWASP as well. Jim works on the beautiful island of Kauai, Hawaii where he lives with his wife Tracey.

    • Sponsor: WhiteHat Security
    Founded in 2001 and headquartered in Santa Clara, California, WhiteHat Security provides end-to-end solutions for Web security. The company's cloud technology platform and leading security engineers turn verified security intelligence into actionable insights for customers. Through a combination of core products and strategic partnerships, WhiteHat Security provides complete Web security at a scale unmatched in the industry. WhiteHat Sentinel, the company's flagship product line, manages thousands of websites -- including sites in the most regulated industries as well as top ecommerce, finance and healthcare companies.

Monday, February 20, 2012

Portable Device Security

Theft of tablets, laptops, smart phones, and other portable devices is on the rise. Originally stolen for their street value, these devices are becoming more and more a target for the information they carry. As these devices become smaller and lighter, they become more vulnerable to theft.

Common high risk areas of concern continue to be:

• airport security checkpoints
• airport curbsides, ticket counters, and gates
• airplane overhead compartments
• hotel rooms, and
• inside cars.

Losing a laptop is not just the loss of money: it is a significant loss in productivity and resources, especially if the data contained on it is not backed up. Even more serious is the loss of potentially sensitive information.

Basic common sense steps can be taken to help protect these now ubiquitous targets.
• Do not check your laptop with the rest of your baggage. It may become damaged, lost, or stolen.
• Keep your laptop in sight. When going through security checkpoints, do not place your laptop on the belt until the checkpoint is clear for you to walk through. Be especially careful when using the restroom or making a phone call. It takes a thief only a moment to walk off with your belongings. On the plane, if not using the laptop, stow it under the seat in front of you, not in an overhead compartment.
• Do not rest your laptop on top of a rolling luggage carrier.
• Keep your laptop with you on a train instead of putting it in the luggage compartment near the exit, where thieves have easy access.
• Don't leave your laptop or briefcase inside a car. If you must, store it inside the trunk, out of view.
• Never leave your laptop unsecured in a hotel. Use the hotel safe or a locking cable, or hide the laptop. Do not assume that your laptop is safe just because you are staying in a reputable hotel. Consider leaving the TV on at a moderate volume and placing a "Do Not Disturb" sign on the door when leaving the room so potential thieves will think the room is occupied.
• Avoid temperature extremes. To avoid damaging your laptop and data, don't start the computer when it is extremely cold or warm. Manufacturers recommend ambient temperatures of 45-95 degrees Fahrenheit. Allow your laptop to come to room temperature before powering it on.
Protecting the Information
• Ensure current antivirus protection. Connecting from a hotel or other travel site puts you outside the protection provided by the County's firewall, so be sure your laptop's virus definitions are up-to-date before traveling. Virus definitions are normally automatically updated on PCs managed by the company, when connected to the Internet.
• Never store a password on the computer or in the computer bag. A stolen laptop with a stored password provides easy entry to a company’s network.

A Strategic Approach to Vulnerabilities at the Application Layer

Most organizations spend large amounts of time and money to protect their networks and infrastructure from attacks and threats. But, no matter how good a defense may be, it usually falls short in addressing security vulnerabilities inside the network at the application layer.

A number of research findings indicate that organizations' applications are one of the highest-risk areas and where the most damage can be done. As example, look at the amount of confidential and personal information that is stolen each year.

In sharp contrast with ISO/IEC 9126 - Software Quality Standard, all current software development methodologies (agile, waterfall, MSF, and others) hardly mention the word security. In fact, the use of these methodologies has not resulted in a measurable reduction of security related defects, which is evident by the fact that CERT tracking of security attacks continue to grow.

With exceptions, most companies' applications can be targeted, from the outside and from within, with a multitude of attack methodologies, including SQL injection, Cross Site Scripting (XSS) and Cross Site request Forgery (CSRF) vulnerabilities, which can be used to perpetrate various scams, purportedly compromising vast amounts of sensitive and personal information.

Companies need to embark on a "Security Development Lifecycle" (SDL) for all custom application development. One of the needs to support this type of methodology and fulfill this security process is an application security management solution that can test, correlate and manage application security vulnerabilities. The first component is a static scanner that is used with application development that scans source code, alerting development management and developers of security problems within that code as it's being developed. The second component is a dynamic scanner that scans newly developed applications in a staging environment, as well as applications currently in production, to detect security vulnerabilities so they can be quickly addressed by Application Development or, in the case of COTS applications, by the vendor. The third component is an application vulnerability correlation and management application that correlates information gathered by static and dynamic application scanners, network scanners, eliminates false positives and duplicates, and allows escalation of issues to the responsible team based on the vulnerability found (application development or sys admin).

A full and thoughtful approach is necessary to ensure protection of companies' most important assets, their information.

Friday, May 27, 2011

ISSA International 2011 Elections

Hi,

I'm Richard Greenberg, CISSP, and I'm running for the ISSA International Board of Directors. I'm currently the Information Security Officer for the Los Angeles County Department of Public Health. Prior to this appointment, I was the first to hold the same position for the County's Department of Health Services.

I bring over 25 years of management experience and have been a strategic and thought leader in IT and Information Security for both the private and public sectors. My Project Management, Security Operations, and Policy and Compliance experience have helped shape my broad perspective on creating and implementing Information Security Programs in organizations.

I am actively involved in the Information Security community, serving on the Boards of the Los Angeles Chapters of both ISSA and OWASP. I also have been a member of the ISSA CISO Executive Program, where I have collaborated with other Information Security Officers from around the country.

I was recently was awarded Senior Member standing in ISSA by the Fellow Selection Committee. I also served on the ISSA International Conference - Attendee Development Committee and the CISO Forum - Planning Committee.

I currently serve on the OWASP Global Conference Committee, and co-chaired the highly successful OWASP Global AppSec USA 2010 Conference. I am a member of the IANS Pacific Security Forum Steering Committee and the CISO Executive Summit Governing Body in Southern California.

I have been a published author in the ISSA Journal, and have spoken on Information Security, most recently at the OWASP Global AppSec USA 2010 Conference. Besides my CISSP, I have achieved CNA and ITIL Foundation certifications.

The GOALS that I would like to accomplish as a Director on the International Board include:
1. Bring a collaborative approach to the Board
1.1. Leverage my involvement with Global OWASP Committees to encourage engagements with other information security organizations
1.2. Engage ISSA Chapters to share their successes, strategies, and templates to help build strong chapters worldwide
2. Work with other information security organizations to bring more benefits to ISSA membership, such as discounts at InfoSec events around the globe
3. Engage the best and brightest security professionals to be a part of ISSA
4. Ensure the knowledge transfer of threats, technologies, strategies and current regulatory policies to help our members successfully implement strategies at their companies and organizations
5. Support enterprise objectives by educating members on the relationship between IT and the business, business processes and business risks.
6. Advocate for ISSA to have a lead role in helping to build partnerships between private industry and the public sector, to protect critical infrastructure and networks
7. Reach out to achieve more participation from membership
8. Help grow the Cyber Secure Community by reaching out to business leaders
9. Become a better security practitioner from my association with fellow Board members
10. Share my knowledge and experience with fellow Board members

Friday, March 25, 2011

ISSA Web Conference Series - Consumerization of the Workplace

The ISSA Web Conference Series is featuring Consumerization of the Workplace on March 29. Don't miss this free event and opportunity to earn your CPEs.
https://www2.gotomeeting.com/register/558755915

Tuesday, March 01, 2011

ISSA and OWASP Los Angeles Joint Dinner Meeting

Come join us March 16 at 6PM:
Taix French Country Cuisine
1911 W. Sunset Boulevard
Los Angeles, CA 90026
(213) 484-1265

Hear expert talk on Stuxnet

Net Neutrality on Hit list of new republican majority

They are putting a very weird spin on their stance; pure fiction. Back to saying a lie enough times to make it a truth...for some.

Wednesday, January 12, 2011

Application Documentation

Keep operational, system, user, and programmer documentation up to date. For applications developed by contractors the system, user, and programmer documentation should be required deliverables. Current system and programmer documentation are critical to implementing changes accurately and quickly. They should be stored in a secure place. Updated users manuals provide good reference for new users and can provide training support. All of this material is also invaluable during an audit.

Why can't the FCC Defend Equal Distribution of Content?

I want to be able to choose my provider for TV content based on quality, features, reliability, support, and price, not on who can deliver what programs or stations. It's called collusion, and it stinks!

Friday, July 09, 2010

OWASP AppSec USA 2010 is Coming to California!

FOR IMMEDIATE RELEASE:
Open Web Application Security Project (OWASP) announces AppSec USA 2010, the premiere web application security conference in North America

Los Angeles, California – July 9, 2010 - Open Web Application Security Project (OWASP) announces AppSec USA, which will be held from September 7 to 10 at the University of California at Irvine.

The conference consists of two days of in-depth training classes on September 7 and 8, followed by two days of plenary sessions on September 9 and 10. BOF (Birds of Feathers) sessions and panel discussions round out the conference offerings.
Jeff Williams, keynote speaker and Chairman of the OWASP Foundation notes, “Software is simultaneously getting radically more critical, complex, and interconnected. This creates a perfect storm for attackers, who are having a field day with our systems. We will never hack our way secure. Instead, we need to change the way we think about software, build software, and buy software. OWASP's audacious goal is to reach all developers everywhere and help them build rugged code - because our future depends on it”.

Williams continues, “I've attended many OWASP AppSec Conferences, and they truly bring together the leading researchers, innovators, and community leaders to focus on application security in a free and open noncommercial forum. There's a fantastic sense of community and shared purpose. We encourage anyone interested in secure code to come and find out what application security is all about. Our 501(c)(3) not-for-profit status allows us to keep prices extremely low”.

Another keynote speaker, Bill Cheswick, is a well known security researcher with AT&T Research; his very popular book Firewalls and Internet Security has influenced many security practitioners.

The third keynote speaker, David Rice, is an internationally recognized information security professional. Mr. Rice , author of the highly acclaimed book, Geekonomics, which promotes awareness of the true cost of insecure software, made significant contributions to advance the security of our nation’s critical infrastructure.

HD Moore, the final keynote speaker, is widely acclaimed for his creativity and technical skills, and brings a distinct perspective to AppSec. Mr. Moore’s best known contribution to the security community is the Metasploit Project, an open-source project which can be used to find vulnerabilities in computer systems in order to protect or exploit them.

Irvine, located in Southern California, is beautiful year-round and the UC Irvine campus offers famous architecture, a large park, art, and modern facilities in a pleasant environment. Irvine is situated in the heart of Orange County and is next door to Los Angeles, San Diego, and many other attractions.

Richard Greenberg, Co-Chair of Conference Organizing Committee, says, “If you can only get away from the office for one conference, this is it. We all are aware of the insidious exploits taking advantage of all types of application security vulnerabilities”.

Greenberg continues, “We need to learn from the experts in order to counter the attacks - to build solid and secure applications. The knowledge we pride ourselves of amassing is insufficient to meet the new evolving threats. Only by sharing our collective wisdom and experiences can we realistically expect to protect our assets”.

The conference is still soliciting sponsors of different levels.
For more information on sponsorship, or to register, please visit http://www.AppSecUSA.org or contact Kate Hartmann at kate.hartmann@owasp.org.

Tuesday, February 16, 2010

Know Your Neighbor


Protecting sensitive and confidential information at work is everyone's job. There are usually a vast amount of security protections in place, but there are additional safeguards we can all practice.


Something as simple as knowing who your neighbors are can go a long way towards providing these protections. If you know who should be in the neighboring office or looking at the computer on the next desk, you can help protect information by making sure that the person you observe has a right to be there. If you do not believe that the person has that right, asking the simple questions like, “Who are you?” and, “Why are you here?” can be a tremendous help.  Asking your supervisor if the person has a right to be there is another way to protect information. As supervisors and managers, you must respect and support your subordinates’ inquiries.


It is everyone’s responsibility to look out for and report any suspected Privacy or Security breach. You don’t have to be sure there is a breach, you just have to be observant. If something doesn’t look right, alert the people who have the job of being sure. This responsibility to be observant and report what doesn’t look right can protect more than just information. This is a good practice at any time.


The simple question you need to ask yourself is, “If it was my information being displayed, should this person be looking at it or taking it away? If you don’t like the answer, do the right thing and report the situation in a timely manner, before it can become a security incident. Notify your supervisor or your Help Desk if you think things are not right. It is all of our jobs!

Wednesday, July 08, 2009

Be Careful with Facebook and Other Social Sites

The information you post online could be used by those with malicious intent to conduct social engineering scams and attempt to steal your identity or access your financial data. In addition, the sites are increasingly sources of worms, viruses and other malicious code. You may be prompted to click on a video on someone's page, which could bring you to a malicious website, for example. If you are accessing a site that has malicious code your machine could become infected. For examples of some common social networking scams, visit the Council of Better Business Bureaus.

It's also important to realize that information you post can be viewed by a broad audience, and could have lasting implications. College admissions officers and school administrators, for example, do visit these sites and in some cases, admissions have been denied to applicants, or disciplinary actions have been taken because of information or photos posted online. Employers also review these sites for information about potential job applicants.

What can you do to protect yourself?
1) Make sure your computer is protected before visiting sites - make sure you have a firewall and anti-virus software on your computer and that it is up-to-date. Keep your operating system up-to-date as well.
2) Do not assume you are in a trusted environment - just because you are on someone's page you know, it is still prudent to use caution when navigating pages and clicking on links or photos, because links, images or other content contained on the pages may include malicious code.
3) Be cautious in how much sensitive and/or personal information you provide - remember that the more information you post, the easier it may be for an attacker to use that information to steal your identity or access your data. Never post confidential information.
4) Use common sense when communicating with users you DO know - confirm electronic requests for loans or donations from your social networking friends and associates. The communications could be from someone who has stolen the credentials of the person you know with the intent of scamming as many people as possible.
5) Use common sense when communicating with users you DON'T know - be cautious about whom you allow to contact you or how much and what type of information you share with strangers online.
6) Understand what information is collected and shared - pay attention to the policies and terms of the sites; they may be sharing your email address or other details with other companies.
7) Make sure you know what sites your child is visiting - be involved in your child's activities and know with whom he/she is communicating and what information is being posted by them or about them by others.
8) Be aware of any expectations or limitations on your presence as an official government employee (e.g., conducted during non-business hours versus business hours, providing personal versus official department opinions, etc.).

For additional information on social networking tips visit:
Cyber Safety for Children: www.cybersafety.ca.gov
US-CERT: http://www.us-cert.gov/cas/tips/ST06-003.html
Stay Safe Online: http://www.staysafeonline.info/content/social-networking
Cyber Smart:, http://cybersmartcurriculum.org/safetysecurity/networking/
GetNetWise: http://kids.getnetwise.org/safetyguide/technology/socialnetworking
OnGuard Online: http://www.onguardonline.gov/topics/social-networking-sites.aspx and http://www.onguardonline.gov/topics/safety-tips-tweens-teens.aspx
TechMission, Inc. Safe Families: http://www.safefamilies.org/socialnetworking.php