<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure Today &#187; CISSP</title>
	<atom:link href="http://www.securetoday.net/category/cissp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securetoday.net</link>
	<description>Protecting your own for the future</description>
	<lastBuildDate>Thu, 25 Feb 2010 16:25:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CISSP &#8211; Free trainings</title>
		<link>http://www.securetoday.net/2009/07/cissp-free-trainings/</link>
		<comments>http://www.securetoday.net/2009/07/cissp-free-trainings/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 00:04:07 +0000</pubDate>
		<dc:creator>Zarex dela Cruz, CISSP</dc:creator>
				<category><![CDATA[CISSP]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.securetoday.net/?p=139</guid>
		<description><![CDATA[Studying to get your Certified Information System Security (CISSP) from ISC2 is not a walk in the park. It requires that you have many years of experience in the world of Information Security. 
It&#8217;s prerequisites includes a possession of minimum five years of professional experience in the information security field or four years plus a [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-140" title="cissp" src="http://www.securetoday.net/wp-content/uploads/2009/11/cissp-150x150.jpg" alt="cissp" width="150" height="150" /><strong>S</strong>tudying to get your Certified Information System Security (CISSP) from <a href="http://www.isc2.org">ISC2</a> is not a walk in the park. It requires that you have many years of experience in the world of Information Security. </p>
<p>It&#8217;s prerequisites includes a possession of minimum five years of professional experience in the information security field or four years plus a college degree. Or, an Advanced Degree in Information Security from a National Center of Excellence or the regional equivalent can substitute for one year towards the five-year requirement. Then after passing the 250-item exam in six hours and complying with ISC2 Code of Ethics, you still have to be Endorsed. Please visit ISC2 website for more information.</p>
<p>I posted this because I want to share some useful links for you professionals out there, who are thinking or studying for CISSP. SearchSecurity with Shon Harris go over the ten Common Body of Knowledge (CBK) domains for the CISSP in the following webcasts. Be sure to read through all the useful information and try their 10-free quizzes.</p>
<p><a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1328285_mem1,00.html" target="_blank">Domain 1: Security Management Practices</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1323052,00.html" target="_blank">Domain 2: Access Control</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1328960,00.html" target="_blank">Domain 3: Cryptography</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1328985,00.html" target="_blank">Domain 4: Security Models and Architecture</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1329221_mem1,00.html" target="_blank">Domain 5: Telecommunications and Networking</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1329573,00.html" target="_blank">Domain 6: Application and System Development</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1329596,00.html" target="_blank">Domain 7: Business Continuity &#038; Disaster Recovery</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1329632,00.html" target="_blank">Domain 8: Law, Investigations and Ethics</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1057452,00.html" target="_blank">Domain 9: Physical Security</a><br />
<a href="http://searchsecurity.techtarget.com/generic/0,295582,sid14_gci1064650,00.html" target="_blank">Domain 10: Operations Security</a></p>
<p>Good luck!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securetoday.net/2009/07/cissp-free-trainings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CPTED &#8211; Physical Security</title>
		<link>http://www.securetoday.net/2009/05/cpted-physical-security/</link>
		<comments>http://www.securetoday.net/2009/05/cpted-physical-security/#comments</comments>
		<pubDate>Mon, 11 May 2009 00:49:53 +0000</pubDate>
		<dc:creator>Zarex dela Cruz, CISSP</dc:creator>
				<category><![CDATA[CISSP]]></category>
		<category><![CDATA[General Security]]></category>
		<category><![CDATA[CPTED]]></category>
		<category><![CDATA[physical security]]></category>

		<guid isPermaLink="false">http://www.securetoday.net/?p=114</guid>
		<description><![CDATA[This month, I&#8217;d like to discuss a topic that is somewhat being set aside when talking about security &#8211; Physical Security. We all know and agree that the physical aspect of security is as important as any facets of security, be it technical or logical, and administrative.
As a security professional, we should be very aware [...]]]></description>
			<content:encoded><![CDATA[<p><strong>T</strong>his month, I&#8217;d like to discuss a topic that is somewhat being set aside when talking about security &#8211; Physical Security. We all know and agree that the physical aspect of security is as important as any facets of security, be it technical or logical, and administrative.</p>
<p>As a security professional, we should be very aware and concerned that the security we protect, such as critcal data and confidential information through the technology like firewall, DLP, IDP, and the like can as easily be compromised as someone stealing the physical server, damaged by natural or environmental calamities, or broken by infrastructure faults. So, physical security must not be ignored and should also be incorporated in the security policies as well as included in any security discussions.</p>
<p>Physical security must be implemented based on the model of a <strong>layered defense</strong>. The idea is, before unauthorized entity can access the valuable asset, they should go through layers of layers of physical barriers before reaching the spot. If one of the layers fails, the others will protect the asset. So layers of defense should move from the perimeter towards the asset.</p>
<p>I am a firm believer that security should not be a patched-approach, rather, it should be part of the architecture. Similar to software applications, I believe that one of the best ways to stay secure is to develop the program as error-, flaw-free. This way, we don&#8217;t have to worry about patching it and afraid of getting compromised by its vulnerabilities. Of course, it is not a perfect world, and that is why as much as we can, security should begin at the very start of the design.</p>
<p>Physical security is not exempted. The <strong>CPTED (Crime Prevention Through Environmental Design)</strong> is a discipline that structures the proper architectural design of a physical environment to reduce crime by directly affecting human behaviors and activities. The CPTED concept has been around since the 1960s. It provides guidance in loss and crime prevention through proper construction of buildings and the arrangement of environmental components.</p>
<p style="text-align: left;">
<div id="attachment_117" class="wp-caption aligncenter" style="width: 493px"><img class="size-full wp-image-117" title="CPTED" src="http://www.securetoday.net/wp-content/uploads/2009/10/CPTED.gif" alt="CPTED elements" width="483" height="536" /><p class="wp-caption-text">CPTED Key Concepts</p></div>
<p style="text-align: left;">So the idea of CPTED is before even the construction of a facility, it then address the landscaping, entrances, exits, neighborhood layouts, access roads and freeways, lightnings, and traffic patterns. It also puts into consideration the placement of offices, lobby, restrooms, campuses surrounding, and even up to the scale of the wider scope of the city. As you can imagine, before a facility is built, the security is already put in consideration. Putting the proper landscaping should deter intruders, or building the right height of fence or correct placement of lightnings should stop unauthorized people. Another good example is to architect the built of a data center to be located at the center of the facility so that the walls will protect it from any damages from outside.</p>
<p style="text-align: left;"><span id="more-114"></span></p>
<p style="text-align: left;">There are several components to consider when implementing CPTED as shown from the figure above. The best approach is usually to build an environment from a CPTED approach and then apply these components on top of the design where it is needed. The following target-hardening components are derived from Moffat (1983, p.23):</p>
<ul>
<li>Access Control</li>
<li>Natural Surveillance</li>
<li>Territoriality</li>
<li>Defensible Space</li>
<li>Activity Programme</li>
<li>Formal Organized Surveillance</li>
</ul>
<p><strong>Access Control</strong> (Natural) &#8211; this is the guidance of placing of fences, doors, lightnings, and landscaping to address the flow of people going in and out of a location.</p>
<p><strong>Surveillance</strong> (Natural and Formal)- is the components that address the placements of CCTV, security guards, and natural strategies such as line of sight, raised entrances, bollards, etc.)</p>
<p><strong>Territoriality</strong> &#8211; addresses the concepts of security zones. It can be implemented through the use of physical barriers such as walls, dividers, fences, flags, to clearly marked your dedicated scope of coverage or jurisdiction.</p>
<p><strong>Defensible Space</strong> &#8211; this is similar to Territorial Reinforcement (above), in that the environment or community being designed incorporates sense of ownership. Good examples are the physical fences or logical borders of jurisdiction where you defend of which you own.</p>
<p><strong>Activity Programme </strong>- or activity support involves the use of design to encourage intended patterns of usage of public space. This concept aims to protects community by encouraging safe activities and practices in the surrounding environment to deter any unsafe activities from happening. This approach also includes access control, surveillance, and territoriality.</p>
<p>The CPTED discipline adds value in security as it starts where it needs to be. And although as IT Security professionals, our involvement in the construction of facilities and implementation of CPTED is rare, it is a good knowledge to know and it is there. The CPTED is a security concept that if it is implemented correctly, it will benefit everybody.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securetoday.net/2009/05/cpted-physical-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
