<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7270622623494104816</id><updated>2012-01-14T09:29:38.754-08:00</updated><category term='ºº'/><title type='text'>CISSP Certification</title><subtitle type='html'>CISSP Certification exam preparation notes, is a hard exam, is about computer security seen from different ten domains, but it's not much deep in each domain.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-1187529523918357579</id><published>2010-10-13T08:32:00.000-07:00</published><updated>2010-10-13T08:54:19.479-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ºº'/><title type='text'>Buguroo CISSP Training</title><content type='html'>Buguroo team helps you to get the CISSP certifiaction, this company is very expert on several CISSP Domains.&lt;br /&gt;&lt;br /&gt;Our trainment is based on experience, and will help you to pass the hard CISSP exam.&lt;br /&gt;&lt;br /&gt;The Buguroo Software Factory is specialized on Applications Security domain, they have the best application code automatic auditor of the market, BugScout. And has an advanced I+D+i labs where develop custom exploits and reverse binary files.&lt;br /&gt;&lt;br /&gt;More information at:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.buguroo.com"&gt;Buguroo offensive security Software Factory &amp; Services&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-1187529523918357579?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/1187529523918357579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=1187529523918357579' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/1187529523918357579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/1187529523918357579'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2010/10/buguroo-security-software-factory.html' title='Buguroo CISSP Training'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-4997833115084686465</id><published>2008-05-06T10:24:00.000-07:00</published><updated>2008-05-06T12:47:26.117-07:00</updated><title type='text'>WIFI Security</title><content type='html'>*IEEE&lt;br /&gt;802.11a 5GHz 52Mbps OFDM (ortogonal multiplexing) low distance  (hight frequency, lower distance)&lt;br /&gt;802.11b 2,4GHz 5MHz*14channels  DSSS (spreaded spectrum) (ch14 only used in Japan)&lt;br /&gt;802.11g 2.4GHz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;*Open System Authentication&lt;br /&gt;The only "security" check is the ESSID&lt;br /&gt;&lt;br /&gt;*Shared Key authentication&lt;br /&gt;&lt;br /&gt;WEP -&gt; CRC32 + RC4 (the same all the communication) -&gt; weak security&lt;br /&gt;WPA -&gt; TKIP  + RC4 (different every time)&lt;br /&gt;WPA2-&gt; AES   + EAP -&gt; strong security&lt;br /&gt;&lt;br /&gt;*Bluetooth attacks&lt;br /&gt;- bluejack send spam anonymously to victyms.&lt;br /&gt;- bluebof exploit overflows in services remotelly.&lt;br /&gt;- bluebug use AT commands on victims cell phone.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-4997833115084686465?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/4997833115084686465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=4997833115084686465' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/4997833115084686465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/4997833115084686465'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/wifi-security.html' title='WIFI Security'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-2072937542134156635</id><published>2008-05-04T01:21:00.000-07:00</published><updated>2008-05-04T01:32:18.144-07:00</updated><title type='text'>Trusted Computer Base and Reference Monitor</title><content type='html'>Te Orange Book (Department of Defense Trusted Computer System Evaluation Criteria)&lt;br /&gt;defines the trusted computer base (TCB) as the combination of all hardware, firmware and software responsible for enforcing the security policy.&lt;br /&gt;&lt;br /&gt;The Reference Monitor also defined at Orange Book, and refers to an abstract machine that mediates all accesses to objects by subjects.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-2072937542134156635?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/2072937542134156635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=2072937542134156635' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2072937542134156635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2072937542134156635'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/trusted-computer-base-and-reference.html' title='Trusted Computer Base and Reference Monitor'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-8312644568247656203</id><published>2008-05-03T06:53:00.000-07:00</published><updated>2008-05-04T01:21:13.104-07:00</updated><title type='text'>Security Models</title><content type='html'>The main security models are: lattice, state machine, research, Bell-Lapadula (BLP), Biba, Clark-Wilson, access control matrix, information flow models, Graham-Denning, Harrison-Ruzzo-Ullman and Brewer-Nash (chinese wall).&lt;br /&gt;&lt;br /&gt;* Latice&lt;br /&gt;- one way information flow&lt;br /&gt;- confidentiality and integrity&lt;br /&gt;- security labels to all objects&lt;br /&gt;- this model is used by (Bell-lapadula, biba, chinese wall)&lt;br /&gt;&lt;br /&gt;* State machine&lt;br /&gt;- The policy define the points the secure state can change.&lt;br /&gt;- Check if current state is secure state.&lt;br /&gt;- check the state of the automated information system (AIS)&lt;br /&gt;- Go the one secure state to other secure state. &lt;br /&gt;&lt;br /&gt;* Non interference models&lt;br /&gt;- is a research model&lt;br /&gt;- the inputs (high-level actions) don't determine what outputs (low-level actions) can see.&lt;br /&gt;- Restricted flows between inputs and outputs.&lt;br /&gt;- Activities are separated in security levels to reduce leaks.&lt;br /&gt;- Higher security level can not interfere in lowerlevel&lt;br /&gt;- Lower level cannot get any information from higher level.&lt;br /&gt;&lt;br /&gt;* Information flow models&lt;br /&gt;- research model&lt;br /&gt;- labeled with security classes&lt;br /&gt;- it could flow upward or at the same level if allowed.&lt;br /&gt;- similar than BLP&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* Bell-LaPadula model (BLP)&lt;br /&gt;- Confidentiality model&lt;br /&gt;- Described in the orange book and TCSEC&lt;br /&gt;- Is a state machine&lt;br /&gt;- Mandatory access control&lt;br /&gt;- The MAC is based on labeling both objects and (with classifications) and subjects (with their clearances)&lt;br /&gt;- The system (Reference Monitor) only allows access if the clearance is equal to or higher than the classification.&lt;br /&gt;- Uses latice and matrix.&lt;br /&gt;- simple security -&gt; read down -&gt; subject of lower clearance cannot read an object of higher classification.&lt;br /&gt;- *(star) property -&gt; write/append up -&gt; hight level subject cannot send missages to lower-level object.&lt;br /&gt;&lt;br /&gt;* Biba&lt;br /&gt;- Integrity model&lt;br /&gt;- complement to BLP&lt;br /&gt;- simple integrity -&gt;  subject  read access to object only if subject level &lt;= object level &lt;br /&gt;(absurd but true)&lt;br /&gt;- the integrity * property -&gt;subject have write access to object only if subject level =&gt; object level&lt;br /&gt;- no information from a subject can be passed on to an object in higher security level.&lt;br /&gt;&lt;br /&gt;* Clark-Wilson&lt;br /&gt;- Integrity  by controlling changes&lt;br /&gt;- Suitable for transaction systems&lt;br /&gt;- CORBA is based on Clark-Wilson, it creates relations between objects.&lt;br /&gt;- no changes by unauthorized subjects, no unauthorized changes by unauthorized subjects.&lt;br /&gt;- subject-program-object binding.&lt;br /&gt;- subject authentication and identification&lt;br /&gt;- only a set of programs can access objects&lt;br /&gt;- users can run only a set of programs&lt;br /&gt;- External consistency -&gt; The system is doing what is expected to do.&lt;br /&gt;- Internal consistency -&gt; The data  being consistent and similar to real world.&lt;br /&gt;- CDI -&gt; Constrained data item -&gt; integrity protected.&lt;br /&gt;- UCDI -&gt; Unconstrained data item -&gt; data not controlled by Clark-Wilson.&lt;br /&gt;- IVP -&gt; Integrity verification procedure -&gt; Procedure scanning, data and confirming its integrity.&lt;br /&gt;- Transformation procedures -&gt; Procedures allowed only to change a cconstrained data item.&lt;br /&gt;&lt;br /&gt;* Access control matrix&lt;br /&gt;- Users, groups and roles down the left hand side.&lt;br /&gt;- All the resources a functions across the top.&lt;br /&gt;- Subjects are listed in rows.&lt;br /&gt;- Objects are listed in columns.&lt;br /&gt;&lt;br /&gt;* Graham-Denning&lt;br /&gt;- set of objects, set of subjects, set of rights.&lt;br /&gt;- subjects have process and a domain&lt;br /&gt;- Eight primitive protection:&lt;br /&gt;1. Create object &lt;br /&gt;2. Create subject&lt;br /&gt;3. Delete object&lt;br /&gt;4. Delete subject&lt;br /&gt;5. Read access right&lt;br /&gt;6. Grant access right&lt;br /&gt;7. Delete access right&lt;br /&gt;8. Transfer access right&lt;br /&gt;&lt;br /&gt;* Brewer-Nash (chinese wall)&lt;br /&gt;- Prevent conflict of interest. &lt;br /&gt;- Access control rules change user behavior.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-8312644568247656203?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/8312644568247656203/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=8312644568247656203' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/8312644568247656203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/8312644568247656203'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/security-models.html' title='Security Models'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-4463854914523332488</id><published>2008-05-03T05:15:00.000-07:00</published><updated>2008-05-03T05:30:31.880-07:00</updated><title type='text'>Security Frameworks</title><content type='html'>* ISO/IEC 17799:2005 &lt;br /&gt;Is a security best practices. It has a great scope: Business continuiti management, access control, system development security controls, physical and environmental security, civil laws compliance, RRHH security, Information security, comunications and operations management, assent management, security policy and incident management.&lt;br /&gt;&lt;br /&gt;* ISO 27001&lt;br /&gt;Information security management specification. Is a complement for the ISO 17799.&lt;br /&gt;Defines an information security management system and creates a framework for the design implementation, management and maintenance of IS processes throughout an organization. Will replace the BS 7799.&lt;br /&gt;Is not a code of practice as 17799, defines the information management system itself.&lt;br /&gt;&lt;br /&gt;* BS 7799&lt;br /&gt;Will be replaced by ISO 27001.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-4463854914523332488?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/4463854914523332488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=4463854914523332488' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/4463854914523332488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/4463854914523332488'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/security-frameworks.html' title='Security Frameworks'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-8479513431606145782</id><published>2008-05-03T05:10:00.001-07:00</published><updated>2008-05-03T05:13:19.043-07:00</updated><title type='text'>SEI-CMMI</title><content type='html'>SEI-CMMI means: Software Engineering Institute's Capability Maturity Model Integration&lt;br /&gt;SEI is an I+D center contracted to advance software engineering practices.&lt;br /&gt;CMMI ratings help customers determine trustworthy and low-risk vendors of software products and services.&lt;br /&gt;A CMMI level 5 means than organization can prove successful application of government and industry vest practices.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-8479513431606145782?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/8479513431606145782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=8479513431606145782' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/8479513431606145782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/8479513431606145782'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/sei-cmmi.html' title='SEI-CMMI'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-6645821509221083112</id><published>2008-05-03T04:50:00.001-07:00</published><updated>2008-05-03T05:09:56.790-07:00</updated><title type='text'>Common Criteria</title><content type='html'>Common criteria is an ISO standard product evaluation which includes ITSEC and TCSEC.&lt;br /&gt;CC evaluates the protection profiles (PPs) and security targets.&lt;br /&gt;&lt;br /&gt;Assurance levels:&lt;br /&gt;&lt;br /&gt;EAL 1 Functionally tested, all the threats to security are not seen as serious.&lt;br /&gt;EAL 2 Structurally tested, low to moderate level of independently guaranteed security..&lt;br /&gt;EAL 3 Methodically tested and checked, moderate level of independently ensured security.&lt;br /&gt;EAL 4 Methodically designed, tested and reviewed. Developers or users require a moderate to high level of independntly ensured security.&lt;br /&gt;EAL 5 Semiformally designed and tested, the requirement is hight level of independently ensured security.&lt;br /&gt;EAL 6 Semiformally verified, designed and tested, for hight risk situations.&lt;br /&gt;EAL 7 Formally verified, designed and tested, for extremelly high risk situations.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-6645821509221083112?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/6645821509221083112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=6645821509221083112' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/6645821509221083112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/6645821509221083112'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/common-criteria.html' title='Common Criteria'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-6826785168393689397</id><published>2008-05-03T04:46:00.000-07:00</published><updated>2008-05-03T04:49:39.639-07:00</updated><title type='text'>Trusted Computer Security Evaluation Criteria</title><content type='html'>TCSEC only adress with confidenciality, and is published at the Orange Book.&lt;br /&gt;&lt;br /&gt;Levels:&lt;br /&gt;&lt;br /&gt;A Verified protection&lt;br /&gt;A1 Verified design&lt;br /&gt;&lt;br /&gt;B Mandatory protection&lt;br /&gt;B3 Labeled security&lt;br /&gt;B2 Structured protection&lt;br /&gt;B1 Labeled security&lt;br /&gt;&lt;br /&gt;C Discretionary protection&lt;br /&gt;C2 Discretionary protection&lt;br /&gt;C1 Controlled access&lt;br /&gt;&lt;br /&gt;D Minimal Security&lt;br /&gt;&lt;br /&gt;Common criteria has replaced TCSEC and ITSEC.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-6826785168393689397?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/6826785168393689397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=6826785168393689397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/6826785168393689397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/6826785168393689397'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/trusted-computer-security-evaluation.html' title='Trusted Computer Security Evaluation Criteria'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-2988421564534414676</id><published>2008-05-03T03:14:00.000-07:00</published><updated>2008-05-03T04:50:03.169-07:00</updated><title type='text'>Information TEchnology Security Evaluation Criteria</title><content type='html'>ITSEC is product or system evaluation criteria, is primarily used in Europe and addresses the CIA triad.&lt;br /&gt;The target to be evaluated is the TOE (target of evaluation)&lt;br /&gt;There are two ratings, functionality rating (F1 to F10) and assurance rating (E0 to E6)&lt;br /&gt;&lt;br /&gt;Common criteria has replaced ITSEC and TCSEC.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-2988421564534414676?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/2988421564534414676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=2988421564534414676' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2988421564534414676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2988421564534414676'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/05/information-technology-security.html' title='Information TEchnology Security Evaluation Criteria'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-342991385102637823</id><published>2008-04-23T22:53:00.000-07:00</published><updated>2008-04-23T23:44:10.231-07:00</updated><title type='text'>Centralized Remote Access</title><content type='html'>The main protocols that centralize the remote access are:&lt;br /&gt;&lt;br /&gt;A good Centralized Remote Access must support the following protocols:&lt;br /&gt;    * CHAP&lt;br /&gt;    * PAP&lt;br /&gt;    * Unix Login&lt;br /&gt;    * SecureID&lt;br /&gt;    * Novell NDS&lt;br /&gt;    * Microsoft domain authentication systems&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;RADIUS&lt;/h2&gt;&lt;br /&gt;Remote Authentication and Dial-In User Service.&lt;br /&gt;Radius is a networking protocol that uses access servers to provide centralized management of access to large networks. RADIUS is commonly used by ISPs and corporations managing access to the internet or internal networks employing a variety of networking technologies, including modems, DSL, wireless and VPNs.&lt;br /&gt;RFC: 2138&lt;br /&gt;Port: 1813/udp&lt;br /&gt;RADIUS uses a challenge/response method for authentication. It uses the MD-5 encryption method to encrypt password information.&lt;br /&gt;The primary purpose of this data is that the user can be billed accordingly; the data is also commonly used for statistical purposes and for general network monitoring.&lt;br /&gt;realms like: somedomain.com\username@anotherdomain.com&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;TACACS&lt;/h2&gt;&lt;br /&gt;Terminal Access Controller Access Control System.&lt;br /&gt;Multi-factor authentication.&lt;br /&gt;Extended TACACS (XTACACS) adds more intelligence in the server.&lt;br /&gt;TACACS+ adds encryption to all transmissions and a challenge/response option. &lt;br /&gt;Unlike RADIUS, TACACS+ stores all server options and authentication information in a single file. Some improvements from RADIUS are:&lt;br /&gt;    * The shared secret key and accounting information are specified in the configuration file.&lt;br /&gt;    * Site-specific extensions are supported by customizable variable length parameter data. &lt;br /&gt;    * TCP ensures reliable delivery. &lt;br /&gt;&lt;br /&gt;&lt;h2&gt;DIAMETER&lt;/h2&gt;&lt;br /&gt;It builds on the strengths of RADIUS while improving encryption, authentication, authorization, accounting, and the ability to connect to multiple service providers.&lt;br /&gt;Operates in a peer-to-peer operation instead of a client/server.&lt;br /&gt;Is capable of supporting any number of connection, authentication, authorization, and account types.&lt;br /&gt;Is made up of a base protocol and extension modules.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-342991385102637823?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/342991385102637823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=342991385102637823' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/342991385102637823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/342991385102637823'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/centralized-remote-access.html' title='Centralized Remote Access'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-2006781677241511552</id><published>2008-04-23T12:43:00.000-07:00</published><updated>2008-04-23T12:55:59.963-07:00</updated><title type='text'>Network Media</title><content type='html'>The common problems on the Network Media are:&lt;br /&gt;    *  Attenuation is signal degradation due to capacitance, conductance, and resistance over distance.&lt;br /&gt;    * Crosstalk occurs when the signal from one cable affects the signal on a nearby cable.&lt;br /&gt;    * Noise is erroneous signal that is present on the media.&lt;br /&gt;    * Eavesdropping is a security problem that happens when data signals are intercepted. &lt;br /&gt;&lt;br /&gt;The most dangerous to the less dangerous mediums are:&lt;br /&gt;    * Wireless&lt;br /&gt;    * UTP&lt;br /&gt;    * STP&lt;br /&gt;    * Coaxial&lt;br /&gt;    * Fiber optics &lt;br /&gt;&lt;br /&gt;Countermeasures:&lt;br /&gt;    * Shielding&lt;br /&gt;    * Padding&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Wireless&lt;/h2&gt;&lt;br /&gt;Is highly susceptible to attenuation, crosstalk, and noise.&lt;br /&gt;Is highly vulnerable to eavesdropping. You must encrypt wireless traffic to protect it from interception.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Coaxial&lt;/h2&gt;&lt;br /&gt;Is not suitable for ring or star topologies because the ends of the cable must be terminated.&lt;br /&gt;Are rarely used in modern networks. Coaxial is difficult to install and maintain.&lt;br /&gt;Types: 10Base5 (ThickNet) and 10Base2 or (ThinNet).&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Twisted Pair&lt;/h2&gt;&lt;br /&gt;Shielded Twisted Pair (STP) has a grounded outer copper shield (or foil) around the bundle of twisted pairs or around each pair. This provides added protection against EMI.&lt;br /&gt;&lt;br /&gt;Unshielded Twisted Pair (UTP) does not have a grounded outer copper shield. UTP cables are easier to work with and are less expensive than shielded cables. &lt;br /&gt;&lt;br /&gt;Cat 2 is used with 4 megabit Ethernet.&lt;br /&gt;Cat 3 is used with 10 megabit Ethernet or 16 megabit Token Ring.&lt;br /&gt;Cat 4 is used with 16 megabits Token Ring or token bus.&lt;br /&gt;Cat 5 is used with 100 megabit and 1 Gigabit Ethernet and ATM networking.&lt;br /&gt;Cat 5e is similar to Cat 5 but provides better EMI protection. Cat 5e supports 1 and 10 Gigabit Ethernet (Gigabit connections require the use of all four twisted pairs).&lt;br /&gt;Cat 6 is designed for high-bandwidth, broadband communications such as full-motion video.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Fiber Optic&lt;/h2&gt;&lt;br /&gt;It is made of plastic or glass.&lt;br /&gt;    * he core carries the signal. It is made of plastic or glass.&lt;br /&gt;    * The cladding maintains the signal in the center of the core as the cable bends.&lt;br /&gt;    * The sheathing protects the cladding and the core. &lt;br /&gt;&lt;br /&gt;Fiber optic cables are classified as one of two types:&lt;br /&gt;&lt;br /&gt;    * Single mode cables use a single light ray. The core diameter is around 10 microns. Cable lengths can extend a great distance (less attenuation).&lt;br /&gt;    * Multi-mode cables use multiple light rays in a single cable. The core diameter is around 50 to 100 microns. Cable lengths are limited in distance (higher attenuation). &lt;br /&gt;&lt;br /&gt;Fiber optic cables:&lt;br /&gt;&lt;br /&gt;    * Allow for very high speeds and high bandwidth.&lt;br /&gt;    * Are immune from crosstalk and noise.&lt;br /&gt;    * Allow for greater distances than wireless or other wired media.&lt;br /&gt;    * Require specialized equipment to tap, making eavesdropping difficult.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-2006781677241511552?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/2006781677241511552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=2006781677241511552' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2006781677241511552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2006781677241511552'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/network-media.html' title='Network Media'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-7420747293379386701</id><published>2008-04-13T23:12:00.000-07:00</published><updated>2008-04-16T02:11:28.999-07:00</updated><title type='text'>Data classification</title><content type='html'>The reason to classify data is to organize it according to its sensitivity to loss or disclosure, indicating the level of confidentiality, integrity and availability required.&lt;br /&gt;&lt;br /&gt;Data classification helps ensure that the data is protected in the most cost-effective manner.&lt;br /&gt;&lt;br /&gt;The classification is different in every company, but in general there are two man groups:&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Private Business&lt;/h2&gt;&lt;br /&gt;Normally the availability is the main thing, if the service is down, or if data becomes lost, implies  a monetary loss and image loss.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Government and military&lt;/h2&gt;&lt;br /&gt;In Government and military, the confidentiality is the main thing, integrity is the second and availability (normally) is the less important. Because there are secrets to keep, and the money don't come from the data or a service.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The information can be:&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Public&lt;/h2&gt;&lt;br /&gt;Disclosure is not welcome, but it would not impact on the company.&lt;br /&gt;-&gt;Business&lt;br /&gt;&lt;h2&gt;Proprietary&lt;/h2&gt;&lt;br /&gt;If disclosed could reduce competitive edge.&lt;br /&gt;(technical specifications of a product)&lt;br /&gt;-&gt;Business&lt;br /&gt;&lt;h2&gt;Confidential&lt;/h2&gt;&lt;br /&gt;Disclosure seriously affect a company.&lt;br /&gt;(trade secrets, code)&lt;br /&gt;-&gt;Business &amp; Military&lt;br /&gt;&lt;h2&gt;Sensitive&lt;/h2&gt;&lt;br /&gt;Special precaution in the integrity.&lt;br /&gt;-&gt;Business&lt;br /&gt;&lt;h2&gt;Secret&lt;/h2&gt;&lt;br /&gt;If disclosed could cause serious damage or national security.&lt;br /&gt;(military plans)&lt;br /&gt;-&gt;Military&lt;br /&gt;&lt;h2&gt;Top secret&lt;/h2&gt;&lt;br /&gt;If disclosed, it could cause grave damage to a national security &lt;br /&gt;(spy satellite)&lt;br /&gt;-&gt;Military&lt;br /&gt;&lt;h2&gt;Sensitive but unclassified (SBU)&lt;/h2&gt;&lt;br /&gt;Minor secret.&lt;br /&gt;(medical data)&lt;br /&gt;-&gt;Government&lt;br /&gt;&lt;h2&gt;Unclassified&lt;/h2&gt;&lt;br /&gt;Data not sensible or classified.&lt;br /&gt;-&gt;Military&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The sensitivity level:&lt;br /&gt;1. Top secret&lt;br /&gt;2. Secret&lt;br /&gt;3. Confidential&lt;br /&gt;4. SBU&lt;br /&gt;5. Unclasified&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Data Classification Procedures&lt;/h2&gt;&lt;br /&gt;1. Identify custodian responsible for maintaining data and its security level&lt;br /&gt;2. Criteria how is classified&lt;br /&gt;3. The owner set the classification&lt;br /&gt;4. Security controls required&lt;br /&gt;5. Document exceptions&lt;br /&gt;6. Methods to transfer the custody to a different data owner&lt;br /&gt;7. Procedures to declassifying the data&lt;br /&gt;8. Security awareness program&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Responsibilities&lt;/h2&gt;&lt;br /&gt;Senior management, and other levels of management, understand the vision of the company, the business goals and objectives. &lt;br /&gt;The next layer is functional management, who understand their departments and how security affects their department.&lt;br /&gt;The next layers are operational management managers and staff, understand the techniques and procedures.&lt;br /&gt;&lt;br /&gt;The data owner is a member of senior management, he is responsible for negligent acts and decide the classification.&lt;br /&gt;&lt;br /&gt;The data custodian maintain and protect the data, for ex. system administrator.&lt;br /&gt;&lt;br /&gt;The data user, who routinely uses the data.&lt;br /&gt;&lt;br /&gt;The chief information officer (CIO) should work with senior to define procedures.&lt;br /&gt;&lt;br /&gt;Business managers determine the level of protection needed, and are involved in the selection of safeguards.&lt;br /&gt;&lt;br /&gt;Auditor examines the practices.&lt;br /&gt;&lt;br /&gt;Security professional, is responsible for security and carry out the senior manager's directives.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;DoD Data Classification&lt;/h2&gt;&lt;br /&gt;- Top Secret&lt;br /&gt;- Secret&lt;br /&gt;- Confidential&lt;br /&gt;- Unclassified&lt;br /&gt;&lt;br /&gt;Data classification is done in mandatory access controls.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-7420747293379386701?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/7420747293379386701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=7420747293379386701' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/7420747293379386701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/7420747293379386701'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/data-classification.html' title='Data classification'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-5074667119048094678</id><published>2008-04-09T12:03:00.000-07:00</published><updated>2008-05-02T13:20:44.129-07:00</updated><title type='text'>Policies, Procedures, Standards, Baselines and Guidelines</title><content type='html'>The senior manager has to protect the computers and information  the most cost-effective manner possible by a Risk Management.&lt;br /&gt;He defines the scope of security, what is expected from employees and the consequences of noncompliance will be.&lt;br /&gt;A security program includes: Policies, Procedures, Standards, Baselines and Guidelines&lt;br /&gt;&lt;br /&gt;The Policies are the strategy and procedures, standards, baselines and guidelines the tactics. Procedures are the lowest level in the policy chain&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Security Policy&lt;/h2&gt;&lt;br /&gt;The policy provides the fundation, procedures, standards, baselines and guidelines are the security framework.&lt;br /&gt;&lt;br /&gt;There are thre categories or types of policies:&lt;br /&gt;&lt;h3&gt;Regulatory&lt;/h3&gt;&lt;br /&gt;Ensures that organization is following the standards by a specific industry or law.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Advisory&lt;/h3&gt;&lt;br /&gt;Strongly suggest certain types of behaviors and activities.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Informative&lt;/h3&gt;&lt;br /&gt;Inform about some topics, is not enforceable policy but is to teach people.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The security policies are:&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Organizational Security Policy&lt;/h3&gt;&lt;br /&gt;- How security progam will be set up.&lt;br /&gt;- program's goals&lt;br /&gt;- assigns responsibilities&lt;br /&gt;- strategic and tactical value of security&lt;br /&gt;- how enforcement should be carried.&lt;br /&gt;&lt;br /&gt;Organizational security policy provides scope an direction for all future security activities within the organization and define the amount of risk the senior management is willing to accept.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Issue-specific policies&lt;/h3&gt;&lt;br /&gt;This policies are more detailed, because policies provide direction and structure for the staff.&lt;br /&gt;&lt;br /&gt;For example:  email security policy&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;System-specific policy&lt;/h3&gt;&lt;br /&gt;System policies includes: Computers, Networks, Application and Data.&lt;br /&gt;&lt;br /&gt;- approved software list.&lt;br /&gt;- how to configure firewalls.&lt;br /&gt;- how databases have to be protected.&lt;br /&gt;and o on.&lt;br /&gt;&lt;br /&gt;More granularity is needed in this kind of policies.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Standards&lt;/h2&gt;&lt;br /&gt;Mandatory rules.&lt;br /&gt;Standards and baselines achieve consistency in security implementation. &lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Baselines&lt;/h2&gt;&lt;br /&gt;Provide the minimum security level necessary throughout the organization, &lt;br /&gt;for ex: At all workstations of the company, at least C2 level is required.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Guidelines&lt;/h2&gt;&lt;br /&gt;Recommended actions and operations to the staff and users when a specific standard doesn't apply.&lt;br /&gt;Guidelines are flexible.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Procedures&lt;/h2&gt;&lt;br /&gt;Tasks detailed step by step to achieve certain goal.&lt;br /&gt;Procedures spell out how the policy, standards, and guidelines will actually be implemented.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-5074667119048094678?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/5074667119048094678/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=5074667119048094678' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/5074667119048094678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/5074667119048094678'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/policies-procedures-standards-baselines.html' title='Policies, Procedures, Standards, Baselines and Guidelines'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-7508275442991458685</id><published>2008-04-08T14:14:00.000-07:00</published><updated>2008-04-09T12:19:23.634-07:00</updated><title type='text'>Risk Management</title><content type='html'>There are 3 steps in risk management:&lt;br /&gt;&lt;br /&gt;1. Asset identification and Value Assignment&lt;br /&gt;2. Quantitative/Qualitative Risk Analysis and assessment&lt;br /&gt;3. Countermeasure and implementation&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Asset identification and Value Assignment&lt;/h2&gt;&lt;br /&gt;&lt;br /&gt;Delphy technique consists in make a group, and anonimously, everybody put a value for some risks&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Quantitative Risk Analysis&lt;/h2&gt;&lt;br /&gt;&lt;br /&gt;AV asset value&lt;br /&gt;EF exposure factor&lt;br /&gt;SLE single loss expectanci&lt;br /&gt;ARO anualized rate of occurrence&lt;br /&gt;ALE anualized loss expectancy&lt;br /&gt;residual risk -&gt; risk reduced by safeguards (risk never is reduced to 0)&lt;br /&gt;total risk -&gt; we have total risk if don't implement the safeguards.&lt;br /&gt;&lt;br /&gt;AV * EF = SLE&lt;br /&gt;&lt;br /&gt;SLE * ARO = ALE&lt;br /&gt;&lt;br /&gt;Coefficients are in range 0-1 with 2 decimals.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Qualitative Risk Analysis&lt;/h2&gt;&lt;br /&gt;&lt;br /&gt;Some levels may be defined, like: dangerous, very dangerous, not dangerous.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Handling Risks&lt;/h2&gt;&lt;br /&gt;&lt;br /&gt;There are 4 options for each risk:&lt;br /&gt;&lt;br /&gt;transfer the risk (ex. insurance)&lt;br /&gt;reduce the risk (ex. countermeasures)&lt;br /&gt;rejecting the risk (ex. ignore the risk)&lt;br /&gt;accept the risk (ex. cost of countermeasures outweights the potential loss value AV)&lt;br /&gt;&lt;br /&gt;Countermeasure costs:&lt;br /&gt;Product cost &lt;br /&gt;Design/planning cost&lt;br /&gt;Implementation cost&lt;br /&gt;Environment modifications &lt;br /&gt;Compatibility with other countermeasures&lt;br /&gt;Maintenance requirements&lt;br /&gt;Testing requirements&lt;br /&gt;Repair, replace, or update costs&lt;br /&gt;Operating and support costs&lt;br /&gt;Effects on productivity&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-7508275442991458685?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/7508275442991458685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=7508275442991458685' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/7508275442991458685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/7508275442991458685'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/risk-management.html' title='Risk Management'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-7502773273659948225</id><published>2008-04-08T12:10:00.000-07:00</published><updated>2008-05-03T03:12:58.129-07:00</updated><title type='text'>Cryptograpy</title><content type='html'>Caesar Cipher is a substitution algorithm&lt;br /&gt;Asymetric key are easy to distribute, this is a big advantage versus symetric ones.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.secguru.com/link/cissp_domain_5_cryptography_presentation_ppt"&gt;online ppt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;DES - Digital Encryption System&lt;/h2&gt;&lt;br /&gt;IMB developed DES on 1972, but never was approved by national security, but is a standard for unclassified government data.&lt;br /&gt;&lt;br /&gt;Is a symetric private key algorithm that does 16 rounds of transpositions and substitutions.&lt;br /&gt;blocksize 64bits, plain cyphertext.&lt;br /&gt;keysize 56bit - 8bit of parity&lt;br /&gt;&lt;br /&gt;Exists HW implementations of DES.&lt;br /&gt;&lt;br /&gt;Double DES: key 112bits&lt;br /&gt;Triple DES: very secure, encrypt first key, decrypt second key, encrypt first key.&lt;br /&gt;&lt;br /&gt;El Gamal: Extends Diffie-Helman, enabling the encryption and the digital key management.&lt;br /&gt;&lt;br /&gt;The only cipher system said to be unbreakable by brute force is one-time pad.&lt;br /&gt;&lt;br /&gt;Electronic Code Book (ECB) is a cryptographic tool vulnerable to frequency analysis.&lt;br /&gt;According to Bruce Schneier and Niels Ferguson, the best mode to select for a product would be CTR (counter) but failure to randomize the nonce, and preventing nonce reuse will decrease the security of CTR mode.&lt;br /&gt;&lt;br /&gt;The running key cipher is based on modular arithmetic.&lt;br /&gt;&lt;br /&gt;Cryptosystem attacks can be: timing, chosen plaintext an differential. But not Rubber hose which is used to attack the user and not the system.&lt;br /&gt;&lt;br /&gt;Polyalphabetic ciphers are used for mitigating frequency analysis attack.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-7502773273659948225?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/7502773273659948225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=7502773273659948225' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/7502773273659948225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/7502773273659948225'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/cryptograpy.html' title='Cryptograpy'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-1449603690644202547</id><published>2008-04-08T12:07:00.000-07:00</published><updated>2008-04-08T12:10:51.971-07:00</updated><title type='text'>Change Control Management</title><content type='html'>Change control manager ensures that changes are authorized, documented, correct but NOT effective.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-1449603690644202547?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/1449603690644202547/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=1449603690644202547' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/1449603690644202547'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/1449603690644202547'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/change-control-management.html' title='Change Control Management'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-5100748235270937831</id><published>2008-04-08T12:01:00.000-07:00</published><updated>2008-04-08T12:06:25.990-07:00</updated><title type='text'>Code escrow</title><content type='html'>Source source code escrow protects against vendor bankruptcy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-5100748235270937831?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/5100748235270937831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=5100748235270937831' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/5100748235270937831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/5100748235270937831'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/code-escrow.html' title='Code escrow'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-803768265792752912</id><published>2008-04-08T11:50:00.000-07:00</published><updated>2008-04-08T12:00:05.669-07:00</updated><title type='text'>X.509 certificate syntax</title><content type='html'>The current version of X.509 is 3, this are the fields:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;           1. version&lt;br /&gt;           2. serial number&lt;br /&gt;           3. signature algorithm ID&lt;br /&gt;           4. issuer name&lt;br /&gt;           5. validity period&lt;br /&gt;           6. subject (user) name&lt;br /&gt;           7. subject public key information&lt;br /&gt;           8. issuer unique identifier (version 2 and 3 only)&lt;br /&gt;           9. subject unique identifier (version 2 and 3 only)&lt;br /&gt;          10. extensions (version 3 only)&lt;br /&gt;          11. signature on the above fields&lt;br /&gt;&lt;br /&gt;CISSP Exam can ask you about valid/invalid fields.&lt;br /&gt;&lt;br /&gt;X.509 is supported by PEM, PKCS, S-HTTP, SSL, and other protocols&lt;br /&gt;&lt;br /&gt;More info:&lt;br /&gt;http://www.x5.net/faqs/crypto/q165.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-803768265792752912?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/803768265792752912/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=803768265792752912' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/803768265792752912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/803768265792752912'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/04/x509-certificate-syntax.html' title='X.509 certificate syntax'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-2667878560102990204</id><published>2008-02-20T15:00:00.000-08:00</published><updated>2008-05-02T00:11:48.605-07:00</updated><title type='text'>Security Management Introduction</title><content type='html'>The responsibilities of a Security Manager:&lt;br /&gt;&lt;br /&gt;* What data is valuable, and needs to be protected.&lt;br /&gt;* Ho is responsible for protecting it.&lt;br /&gt;* Define actions for the employees, and consequences for non compliance.&lt;br /&gt;* What type of role security will play in the organization.&lt;br /&gt;&lt;br /&gt;Information Security is NOT a technical issue. Is a management issue that may require technical solutions.&lt;br /&gt;&lt;br /&gt;To Create Security -&gt; Planed, Designed, Implemented and Maintained&lt;br /&gt;&lt;br /&gt;Applied in Top-Down.&lt;br /&gt;&lt;br /&gt;The security has to be in line of business objectives.&lt;br /&gt;&lt;br /&gt;If the company is damaged by an attacker, the Security Manager will have the responsibility of giving explanatinons.&lt;br /&gt;&lt;br /&gt;The best security practices implemented at some technical area are:&lt;br /&gt;Policy, change control and configuration management, trainig and awareness.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-2667878560102990204?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/2667878560102990204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=2667878560102990204' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2667878560102990204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/2667878560102990204'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/02/it-management-introduction.html' title='Security Management Introduction'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-811825992836236014</id><published>2008-02-11T23:05:00.000-08:00</published><updated>2008-02-15T07:14:56.903-08:00</updated><title type='text'>CISSP 10 Domains Overview</title><content type='html'>Here you can see the main concepts of each domain.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Access Control Systems and Methodology&lt;/h3&gt;&lt;br /&gt;Mechanisms and methods used to enable administrators and managers to control what subjects can access.&lt;br /&gt;* Identification, Authentication, Authorization, Monitoring.&lt;br /&gt;* Access Control Administration.&lt;br /&gt;* Categories and Controls.&lt;br /&gt;* Control Threats and Measures.&lt;br /&gt;* Dana ownership.&lt;br /&gt;* Attacks to the Access Control.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Telecommunications and Network Security&lt;/h3&gt;&lt;br /&gt;Protocols and devices security.&lt;br /&gt;* OSI.&lt;br /&gt;* LAN, MAN (metropolitan) and WAN technologies.&lt;br /&gt;* Internet, intranet, extranet.&lt;br /&gt;* VPN's, routers, bridges and repeaters.&lt;br /&gt;* topologies.&lt;br /&gt;* Network Attacks.&lt;br /&gt;* Network Security Concepts and Risks.&lt;br /&gt;* Business Goals and Network Security.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Security Management Practices&lt;/h3&gt;&lt;br /&gt;Company assets to determine the level of protection required, in order to reducing threats and monetary loss.&lt;br /&gt;* Data classification.&lt;br /&gt;* Policies, procedures, standards and guidelines.&lt;br /&gt;* Risk assessment and management.&lt;br /&gt;* Personal security and awareness.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Applications and Systems Development Security&lt;/h3&gt;&lt;br /&gt;* Data mining and data warehousing.&lt;br /&gt;* Development practices.&lt;br /&gt;* System storage.&lt;br /&gt;* Malicious code.&lt;br /&gt;* Software Based Controls.&lt;br /&gt;* Software Development Lifecyle and Principles.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Cryptography&lt;/h3&gt;&lt;br /&gt;Cryptographic technologies, and attacks to the cryptography.&lt;br /&gt;* Basic Concepts and Algorithms.&lt;br /&gt;* Symetric vs Asymetric algorithms.&lt;br /&gt;* Signatures and Certification.&lt;br /&gt;* Cryptanalysis.&lt;br /&gt;* PKI.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Security Architecture and Models&lt;/h3&gt;&lt;br /&gt;Concepts, Principles and Standards for designing and implementing secure applications.&lt;br /&gt;* SO states, kernel functions and memory mapping.&lt;br /&gt;* Security models.&lt;br /&gt;* TCSSE Trusted Computer Security Evaluations (evaluation criteria)&lt;br /&gt;* Common Criteria and ITSEC&lt;br /&gt;* Common flaws in applications and systems.&lt;br /&gt;* Principles and Benefits&lt;br /&gt;* Trusted Systems and Computing Base.&lt;br /&gt;* System and Enterprise Architecture.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Operations Security&lt;/h3&gt;&lt;br /&gt;Controls over personnel, hardware, systems, auditing and monitoring.&lt;br /&gt;* Administrative responsibilities to personnel and jobs.&lt;br /&gt;* Maintenance concepts. (AV,FW,auditing)&lt;br /&gt;* Preventive, corrective, and recovery controls.&lt;br /&gt;* Standards.&lt;br /&gt;* Media, Backups and Change Control Management.&lt;br /&gt;* Controls Categories.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Business Continuity Planning and Disaster Recovery Planning&lt;/h3&gt;&lt;br /&gt;Preservation of business activities when faced with disruptions or disasters.&lt;br /&gt;* Resource identification and value.&lt;br /&gt;* Risk assessment.&lt;br /&gt;* Crisis management.&lt;br /&gt;* Response and Recovery Plans.&lt;br /&gt;* Restoration Activities.&lt;br /&gt;* Plan development, implementation and maintenance.&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Laws Investigations and Ethics&lt;/h3&gt;&lt;br /&gt;* Laws, regulations and crimes.&lt;br /&gt;* Licensing and software privacy.&lt;br /&gt;* Export and import laws and issues.&lt;br /&gt;* Evidence types and admissibility into court.&lt;br /&gt;* Incident handling, and forensics.&lt;br /&gt;* Major Legal Systems&lt;br /&gt;* Common and Civil Law&lt;br /&gt;* Regulations, Laws and Information Security&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Physical Security&lt;/h3&gt;&lt;br /&gt;Threats, risks and contra measures to protect: facilities,hardware,data,media and personnel.&lt;br /&gt;* Restricted areas, authorization methods and controls.&lt;br /&gt;* Sensors and alarms.&lt;br /&gt;* Intrusion detection.&lt;br /&gt;* Fire detection, prevention and suppression.&lt;br /&gt;* Fencing security guards, and security badge types.&lt;br /&gt;* Layered Physical Defense and Entry Points.&lt;br /&gt;* Site Location Principle.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-811825992836236014?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/811825992836236014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=811825992836236014' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/811825992836236014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/811825992836236014'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/02/cissp-10-domains-overview.html' title='CISSP 10 Domains Overview'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7270622623494104816.post-5174843212468466039</id><published>2008-02-11T15:17:00.000-08:00</published><updated>2008-02-12T10:27:48.178-08:00</updated><title type='text'>How to study CISSP</title><content type='html'>CISSP Has many domains (10), but it has not much deepening at every domain,"inch deep and a mile wide"&lt;br /&gt;&lt;br /&gt;so, is more important to know all domains than getting deeper in few domains.&lt;br /&gt;In all certifications, the most important is to get testing exams, and secondary to study.&lt;br /&gt;You must take notes about every domain, and don't loose much time with the domains where you work every day.&lt;br /&gt;I don't recommend to read only a book, especially if it is not updated.&lt;br /&gt;&lt;br /&gt;The exam:&lt;br /&gt;* 250 questions 4 choices and only 1 correct&lt;br /&gt;* 6h I'm slow with exams, and I did it in 5h20'&lt;br /&gt;* 225 scored and 25 questions for research purpose.&lt;br /&gt;* You have to score 700 points.&lt;br /&gt;&lt;br /&gt;The trick is to learn concepts like word/phrase -&gt; meaning then it will be easier, for example:&lt;br /&gt;(ISC)2  -&gt; International Information Systems Security Certification Consortium&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7270622623494104816-5174843212468466039?l=cisspeasy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cisspeasy.blogspot.com/feeds/5174843212468466039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7270622623494104816&amp;postID=5174843212468466039' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/5174843212468466039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7270622623494104816/posts/default/5174843212468466039'/><link rel='alternate' type='text/html' href='http://cisspeasy.blogspot.com/2008/02/whow-to-study-cissp.html' title='How to study CISSP'/><author><name>Jesús</name><uri>http://www.blogger.com/profile/08849754854640967545</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://4.bp.blogspot.com/_YDjJDsk93g0/S0jQPH6thiI/AAAAAAAAAGA/PgXsaHv0oEM/S220/mi+foto.jpg'/></author><thr:total>1</thr:total></entry></feed>
