Thursday, April 14, 2005

April's ISSA-Denver Meeting

Yesterday afternoon the local ISSA chapter hosted a very interesting speaker. The speaker was Patti Titus, the current Chief Information Security Officer, Transportation Security Administration DHS. I was going to link to her bio but it appears to not exist anywhere so I will just copy it and then go into my notes about her discussion.

Patricia Titus currently reports to the Chief Information Officer at Transportation Security Administration in Washington, DC, in the capacity of the Chief Information Security Officer and Director of IT Security. Her duties have been to develop and implement a new IT Security Office for TSA. She also reports and works for the CISO at the Department of Homeland Security. Prior to joining TSA in April 2002, Ms. Titus was assigned as a Technical Advisor to the Deputy CIO at the Department of Treasury. Since joining public service in March 2000, Ms. Titus has been assigned to various emerging technology projects and has worked extensively on the enterprise network security projects. Prior to public server Ms. Titus worked in small start up companies within the DC metropolitan area as Vice President of Sales and Marketing. She spent several years in the Information Technology industry in various capacities. Prior to this she spent 13 years living overseas on duty with the US State Department, Department of Defense and Swiss Government.

Okay so now you know who she is - here's what she had to say:

Patti had several points she wanted to convey to the crowd, anong the points she touched on
were Homeland Security Presidential Directive/Hspd-12, a policy for a Common Identification Standard for Federal Employees and Contractor. Basically the problem has come to light that there exist "Wide variations in the quality and security of forms of identification used to gain access to secure Federal and other facilities where there is potential for terrorist attacks need to be eliminated. Therefore, it is the policy of the United States to enhance security, increase Government efficiency, reduce identity fraud, and protect personal privacy by establishing a mandatory, Government-wide standard for secure and reliable forms of identification issued by the Federal Government to its employees and contractors (including contractor employees). " Patti discussed the need for implementation of better biometeric solutions, PKI infrasturcture etc. She however did not comment on where the money was going to come from to finance these cool new gadgets for the government.

As previous user of biometrics this intrigues me - during a normal week I encountered no less than 20 false readings for a simple finger print scanner that allowed access to the lab I worked in. If we are going to utilize this technology in the government we really need to make things work - the common worker will not tolerate having to scan their finger 3 or 4 times every time they try to enter a room.

There was a brief discussion concerning IPSonar, an enterprise software consists of several interrelated discovery processes that find routes and routers, hosts, servers, wireless access points, operating system information, unauthorized connections or hosts, and perimeter leaks. This included how an intern was the one who actually deployed the initial testing launch of this program and how the resulting report of holes lead to the report being labeled - TOP SECRET - ONLY THOSE AT THE TOP CAN SEE THIS -

This is discouraging news to me. I would hope that our government would be running toolsets by now that allow them to accurately discover and gauge the risk that their network has to the outside world. To have an intern (Hats of to her for pointing out the silliness) come in and throw a product on the network that so accurately describes where water is pouring from the damn is not a building confidence for those security geeks who pay attention to these things.

We learned some interesting things about the TSA's luggage machines - no wonder I get yanked all the time - I must be getting the guy who isn't punching the threat button fast enough.

Patti discussed the convergence of CIO and CISO positions in the enterprise market. I agree with her on this one - the CISO position had little chance of survival in my eyes, typically you are stepping on the CIO/CTO's toes and something has to give. I will be curious to see whether we actually see the CISO blend with the CFO position. The advent of SOX puts the financial department on the hook for non-compliancy, with jail sentences following quickly behind that.

Patti left with a few thoughts, reminding us that We Do Not Negotiate with Terrorists, Cyber or Real! She also said something that made me wonder how soon till we see someone hunt down a "cracker" and put a bullet in him for cracking their systems.

All and all a very interesting speaker - I had an opportunity to have dinner with her the night before her speech and was happy to meet some one who was candid about her role within the current administration, the political appointees and what was right and wrong with our current behaviors.

Tuesday, March 08, 2005

Things....

Location:

So I am sitting in Fado's - Chicago. It's an Irish pub that has free wireless, so I can sit and work all while drinking a pint of Guinness. Very few things can get better than that in my opinion. If you happen to be in the neighborhood of a Fado, I would recommend the the Guiness Stew - good home cooking, and to wrap things up, you guessed it Guinness Ice Cream.

If you get a chance look try to end up in Brie's section - she doesn't own a computer but she really digs bloggers. Yes, I used dig and no, I didn't ask for her number my wife doesn't share well with other children

Now on to other things...

I registered for my CISA exam recently. This should be interesting. If I pass, and I plan to, I will have what the industry is considering the top two certifications going: CISSP and CISA. The next thing I have to figure out is what I want to be when I grow up. If you have any ideas let me know. Registering for the exam cost me a quick 500 dollars and then another 250 for study materials - somewhere I hear warning bells going off. The test is offered once a year, so I had better pass or suffer the abuse for the next twelve months.

And in other news...

Commwarrior.A
Finally we have a virus for mobile phones. Uses bluetooth and MMS messages to replicate itself. I wondered how long this would take, ever since I started using the Audiovox 5600 (the same phone Scoble and crew love so much - side note i had mine before Scoble got his - nanner nanner). It is based on Windows SmartPhone so I know it will be the next platform for attack.

Firewalls' False Sense of Security
I have argued for both sides of this issue. A majority of the time I find that the deployment team behind the firewall believe that they have mitigated all future damage because of their firewall deployment. Conversations then lead to IDS, IPS - I have no idea where it will end - I do know that every time a new stop is added someone will look for a new way to get over the bump.

Now back to my regulary consumed beer.

Thursday, March 03, 2005

Squaw - what I would change?

Just got back from an extended weekend at Squaw valley. The resort's village is currently being operated by Intrawest, the same guys who did Whistler.

It was a great trip - a yearly 'boys' trip that has several interesting characters, including: Rick aka 'the Founder', Chuck aka 'Chuckles/Chuckalafucas', Andrew aka 'the Scotsman', Chris aka 'Mr. Goodlookin' and myself Ward aka 'Big Daddy'.

We had a wonderful time, there was good snow - nothing fresh - that didn't show till the last night and we got 7 inches of fresh powder - wanted to extend the trip by one more day for some pow pow but instead I got on the plane and flew back to Denver.

Squaw's new village - looks very similar to Whistler (why change a good thing?) - could use some help. As I said I was there for 5 days - while the mouse is away from the kitty he can play with other mice. We stayed exactly 22 feet from the Squaw one lift, and about 100 feet from the closest bar - yet - the nightlife was horrid.

I have lived in ski towns before - I remember the 1 woman to 12 guy ratio, and this was expected but I grew up in a more lively town smack in the middle of the bible belt - one bar closed at 9 pm on Sunday night. The drive thru liquor store the next county over in North Carolina would have still been open. Needless to say - the experience was repeated night after night for the entire weekend.

So I say to the intrawest guys - figure out beyond copying the buildings, how to create the same nightlife experience you have at Whistler or start preparing yourself for continued disappointment at Squaw.

On a side note - the little breakfast place at the end of the village - two wonderful waitresses (Bunny and ????) and one great owner (Lisa) made the week a little better.