Thoughts on the CISM exam

So I took the CISM exam in June 12th. I have not received the results back yet, it generally takes 6-8 weeks. The test was tough and I thought the practice database from ISACA was a good representation of the type of questions to expect. I do think though that they could reduce the number of questions from 200. There were many repetitive questions and for only 5 domains they should either add more unique questions or reduce the number.

Preparing for the CISM exam

I have decided to sit for the CISM exam. The exam is scheduled for June 12th. ISACA only offers the exam two times per year so I figured this was the best time to take it. The CISM is growing in popularity and is becoming more common in job requirements, although it is still not as popular as the CISSP. The CISM is more focused to those in management positions around Information Security and requires three years of actual management experience in Information Security.

The exam is 200 questions and you can take up to 4 hours to complete. It is considered very rigorous and at least as difficult as the CISSP. I am very excited to take this exam and will post some information in subsequent posts. More information on the CISM exam can be found below.

http://bit.ly/a2Xclj

Symantec to purchase PGP and GuardianEdge

While not related directly to IPS it is still news worthy. Symantec announce today they are buying PGP and GuardianEdge for $370 million dollars! Symantec has somewhat languished over the last few years without alot of truly innovative security products. This now places Symantec as a major player in the encryption space. They can now compete with other companies such as Mcaffe, Sophos and Checkpoint in the encryption space.

Interesting note: Mcafee previously owned PGP and sold it. They then later purchased Safeboot and now Symantec owns PGP. I guess Mcafee should have just kept PGP. :-)

http://www.theregister.co.uk/2010/04/29/symantec_buys_pgp/

Virtual IPS vs. Virtualized IPS

Virtualization is a top priority for most organizations today. Security of these virtualized environments should also be a top priority and in the Intrusion Prevention market most vendors are developing or have developed virtual or virtualized solutions.

The terms virtual IPS and virtualized IPS have different meanings and I want to take some time to attempt to differentiate these terms. Most vendors have had virtual IPS for many years. Virtual IPS is the ability to apply different polices to certain types of traffic. This could be done using VLAN tags or physical interfaces. IBM does this using the Protection Domains feature which allows a different policy to be deployed to different VLAN’s. Mcafee does this by allowing different policies to be assigned to physical interfaces and can also support policies to be applied based no VLAN tags.

Virtualized IPS is what most of us think of today when we discuss virtualization. Virtualized IPS is an IPS appliance that runs in a virtual environment such as VmWare, Zen or Microsoft’s Hyper-V. The IPS is installed as a virtual server and can be configured so that all server to server traffic inside and outside the virtual environment can be monitored by an IPS.

It is important to be clear on these differences in terminology because not all vendors have virtualized IPS and most sales people will not know enough to properly answer the question, Do you support virtualization? Most will say yes, because they have heard their support teams talk about virtual IPS not virtualized IPS. Virtualized IPS will continue to grow in importance and eventually all the major Intrusion Prevention vendors will have these offerings. Until then do your homework and hold the vendors accountable.

Intrusion Prevention Cabling

As a follow up on my previous post on cabling an IPS I have attached an example that I have seen successful.This example is specific to a Mcafee M2750 device and assumes interfaces that are hard set. Note that the actual firewall and LAN switch are using Straight cables and not cross-over. The only cross-over is placed between the Fail-open kit and the IPS.

Added Fortinet Visio Stencils

I have added Fortinet Visio Stencils. Fortinet is a company of great interest. (more…)

Page 2 of 6«123456»