<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: toastmasters]]></title>
    <link>http://securityratty.com/tag/toastmasters</link>
    <description></description>
    <pubDate>Tue, 15 Jan 2008 19:22:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[CISSPs Lend me your ears]]></title>
      <link>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</link>
      <guid>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</guid>
      <description><![CDATA[Art of Information Security endorses Dan Houser for(ISC)²Board of Directors
The CISSP isundoubtablyone of the most, if not the most, important professional certifications in Information Security....]]></description>
      <content:encoded><![CDATA[<p><strong>Art of Information Security endorses Dan Houser for (ISC)² Board of Directors</strong></p>
<p>The CISSP is undoubtably one of the most, if not the most, important professional certifications in Information Security. Many organizations and practitioners rely on it as evidence of a solid foundation and track record in Information Security. But the CISSP is only one of the many ways that the (ISC)² attempts to fulfill its mission of developing the Information Security profession.</p>
<p>Board membership is a role of governance, guidance, and passion. Let&#8217;s briefly explore how Dan&#8217;s track record and past contributions demonstrate his qualification for this post, and possibly your vote.</p>
<p><strong>Passion</strong></p>
<p>Dan is someone who has a passion for promoting and developing the talent needed to continue to grow and mature our profession. Anyone who has seen Dan speak at conferences, local chapter meetings, or in one of his classes knows how passionate Dan is! But anyone who takes the time to approach him knows that he is no ideologue or zealot; Dan is always interested in improving his own understanding, and then sharing that knowledge with others.</p>
<p>Dan has a long track record as a contributor - as a &#8220;giver&#8221; - to the profession. In addition to teaching over a dozen CISSP review courses, he has also served on multiple (ISC)² committees, is one of the authors of the ISSAP Body of Knowledge (cryptography), and has published primary research on professional certifications. He is also the founder of the monthly Columbus, Ohio Information Security MBA (Masters of Beer Appreciation) meeting - a professional roundtable that attracts practitioners from across the state.</p>
<p><strong>Governance and Guidance <br />
</strong></p>
<p>In addition to past experience serving on (ISC)² committees, which I assume led to the current board&#8217;s nomination, Dan has served on numerous Boards of Directors including local and regional community organizations, ISSA chapters,and several Toastmasters clubs. </p>
<p><strong>Personal Experiences</strong></p>
<p>I have known Dan for almost three yeas. Dan and I have collaborated on a number or projects, including a half-day Cryptographic Controls Seminar and a full-day Identity Management Architecture class. It is my feeling that when you collaborate, work closely, and travel with someone, you really get to know them. You get to do more than hear about their College Sweethearts (which, for Dan, is Rebecca, his wife of 21 years), but you also get to understand their ethics, how they really conduct themselves, how they deal with stress, etc.</p>
<p>Given the entire picture, the understanding that I have of Dan Houser, I can think of no one better suited to representing, guiding and developing the (ISC)². I have voted for Dan, and I hope that you will consider doing the same.</p>
<p>Here is the voting link for (ISC)²: <a href="https://webportal.isc2.org/custom/votenow.aspx%20" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://webportal.isc2.org/custom/votenow.aspx%20');" target="_blank">https://webportal.isc2.org/custom/votenow.aspx</a></p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/105/cissps-lend-me-your-ears/" >CISSPs&#8230; Lend me your ears&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/456765137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/dan houser">dan houser</category>
      <category domain="http://securityratty.com/tag/dan foralmostthree yeas">dan foralmostthree yeas</category>
      <category domain="http://securityratty.com/tag/dans track record">dans track record</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/track record">track record</category>
      <category domain="http://securityratty.com/tag/information security profession">information security profession</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/profession">profession</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/456765137/">CISSPs Lend me your ears</source>
    </item>
    <item>
      <title><![CDATA[Hacker Safe? Not so much.]]></title>
      <link>http://securityratty.com/article/bf319fc9e1a9dcb0e60c2720e7611bbe</link>
      <guid>http://securityratty.com/article/bf319fc9e1a9dcb0e60c2720e7611bbe</guid>
      <description><![CDATA[Likely you've all read about Hacker Safe certified Geeks.com being hacked . ScanAlert, recently bought by McAfee, says that &quot;research indicates sites remotely scanned for known vulnerabilities on a...]]></description>
      <content:encoded><![CDATA[Likely you've all read about Hacker Safe certified Geeks.com being <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=205600099">hacked</a>. ScanAlert, recently bought by McAfee, says that "research indicates sites remotely scanned for known vulnerabilities on a daily basis, such as those earning 'Hacker Safe' certification, can prevent over 99% of hacker crime." <br />I agree...but here comes strike two.<br />I was happily bouncing about the internet looking for things that should be fixed,  when what did I see at <a href="http://www.toastmasters.org">Toastmasters International</a> but a McAfee Hacker Safe certificate. Ever the skeptic, I said to myself "Prove it." But, of course, because my white hat and professional values require it, I remembered that <span style="font-style:italic;">first, do no harm</span> are words to live by. But a wee script test in a form field can't hurt, right? <br />There's video of this <a href="http://holisticinfosec.org/video/tm_HackerSafe.html">here</a> if you prefer.<br />Let's begin.<br />Here's the Advanced Search page, note the McAfee Hacker Safe tag in the lower right:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://holisticinfosec.org/images/hackersafe/AdvancedSearch.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px;" src="http://holisticinfosec.org/images/hackersafe/SimpleScript.png" border="0" alt="" /></a><br />Then, said little test script about to be submitted to the Advanced Search page:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://holisticinfosec.org/images/hackersafe/SimpleScript.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px;" src="http://holisticinfosec.org/images/hackersafe/SimpleScript.png" border="0" alt="" /></a><br /></p><br />Ruh roh, Rastro. Can you say XSS?<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://holisticinfosec.org/images/hackersafe/NotSoMuch.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px;" src="http://holisticinfosec.org/images/hackersafe/NotSoMuch.png" border="0" alt="" /></a><br /><br />Man, that's not good, so let's try a bit more trickery.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://holisticinfosec.org/images/hackersafe/iFrame.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px;" src="http://holisticinfosec.org/images/hackersafe/iFrame.png" border="0" alt="" /></a><br /><br /><a href="http://www.xssed.com/about">XSSed</a> indeed.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://holisticinfosec.org/images/hackersafe/xssed.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px;" src="http://holisticinfosec.org/images/hackersafe/xssed.png" border="0" alt="" /></a><br /><br />Something tells me the McAfee Hacker Safe service offering would do well to dig a little deeper before certifying a site.<br />Meanwhile, sanitizing input might not be a bad idea for our Toastmasters friends.<br />Play nice until Toastmasters gets a chance to fix it, please. I've already let them know.<br />Cheers.<br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/01/hacker-safe-not-so-much.html&title=Hacker%20Safe%20Not%20So%20Much" title="Hacker Safe not so much del.icio.us">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/01/hacker-safe-not-so-much.html" title="Hacker Safe not so much ">digg</a>]]></content:encoded>
      <pubDate>Tue, 15 Jan 2008 19:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hacker safe">hacker safe</category>
      <category domain="http://securityratty.com/tag/mcafee hacker safe">mcafee hacker safe</category>
      <category domain="http://securityratty.com/tag/toastmasters">toastmasters</category>
      <category domain="http://securityratty.com/tag/toastmasters friends">toastmasters friends</category>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/toastmasters international">toastmasters international</category>
      <category domain="http://securityratty.com/tag/wee script test">wee script test</category>
      <category domain="http://securityratty.com/tag/professional values require">professional values require</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <source url="http://holisticinfosec.blogspot.com/2008/01/hacker-safe-not-so-much.html">Hacker Safe? Not so much.</source>
    </item>
  </channel>
</rss>
