For many years many people complain about learning so many things for the CISSP exam that they would never use in their life. When I was preparing for the exam a few years ago, I also had the same perspective as others. People also have the belief that they are required to understand security through (ISC)2’s view for this exam, which is so detached from reality. The contention of these statements is that someone would have to memorize bits and pieces and other trivial facts for the exam that are not helpful in their career – thus a waste of time. Again, I was also in the same boat when I prepared and took the exam ages ago. Now I see it completely differently.
I have found that since I have authored books and taught for many years CISSP training classes, I have a greater understanding of the material than I would have if I just studied and took the test and moved on with life.
The things that people are complaining about learning (Bell Lapadula, Biba, Clark-Wilson, etc.) will be of much benefit to a comprehensive understanding of security in a holistic manner instead of just focusing on their original thought of what makes up security. A lot of the technical guys are of the belief that learning anything above technology is a waste of their time. This thinking is common to these people because they think of anyone who does not understand technology like they do as inferior. But companies are not in business to just have software and networks in place. The software, network, and systems are just some of the tools the company utilizes to manage and grow their business. So understanding things that are above technology, commonly referred to as soft skills, are actually more critical in the world of business – which is where we all live and work.
Although I am pretty disappointed with the manner that the questions on the CISSP exam are worded (confusing, vague, subjective), I have greater appreciation of the actual Common Body of Knowledge CBK. I was a security consultant before I took the exam, and then I wrote books, and taught CISSP – and I am still a security consultant, but my view on security as against my knowledgebase has significantly changed.
I, like most people, focused on what security topics I was to perform in my specific job. At the time on-line banking was coming out of the market (yes I am that old) and I worked with programmers, software architects, project managers, analysts, and end customers – all doing on-line banking . To be honest at that time I was the least interested in the different types of fire suppression, access control models, trusted computing base or anything outside of my domain of topics that I lived, worked and breathed in.
By: Shon Harris
Archive for September, 2009
Cissp Exam – Understanding Security in a Holistic Manner and Learning Above Technology
September 29th, 2009Business Success and the Art of Networking
September 28th, 2009Networking is about creating a support system for your business. It can help you raise money attract employees or partners and even offer a fresh perspective.
Networking is a non- starter if you start with the end in mind. This is even true when one thinks of networking in the business context. Business networking is not merely about exchanging cards and few laughs over dinner, its about looking for ways to help each other grow symbiotically. It is a process which helps to build relationships and develop the support system for the entrepreneur and his business.
Any successful entrepreneur will tell you that a network of contacts can add value only if you know how to add value to each one of them. If you want to know the secret to building the network which will help you, you have to learn to understand other peoples problems and challenges first. You have to be ready to give first and demand later.
The art of networking is not an easy one. Most young entrepreneurs find that it is easier to build upon an idea than to develop a network of contacts. The best bet for young entrepreneurs is to participate in forums that are provided by business networking professionals like Business Networking International (BNI), The Indus Entrepreneurs, and even online networking sites like Ryze and LinkedIn. These have regular mixer meets- where new entrepreneurs have an opportunity to interact with more experienced entrepreneurs and take the concept of organised networking very seriously.
Such forums result in a place where business supply and demand have a command ground. For eg: people who require funds can connect with people who want to invest funds, and there is always the possibility of finding a new business.
It is an opportunity for new entrants to gain an insight into the minds of biggest and the best in business. Its not just a platform to help entrepreneurs interact but also a responsibility to educate and inspire them. Entrepreneurs have to be realistic about what they can get from networking opportunities.
Essentials of Networking:
1. Look at building relationships, not a database.
2. Networking events are not always buyer- seller meets.
3. Aviod western rules for networking. India and Indians have a different approach.
4. Learn to give, seek the giver’s gain.
5. Listen and understand others business first.
6. Look at ways of growing your network through giving
7. Learn to distinguish between networking and fund raising events.
8. Networking events should be informal.
9. Follow up with people or suggestion for people you meet at an event.
10. Do not just collect visiting cards, get to know people.
By: Madhur Bajaj
What is the Relation With Data Communications and Networks?
September 27th, 2009Data communications and networks make use of an approach that is totally focused on the Internet and was designed to tackle the issues of communicating system design. In order to get to the data communications and networks, a certain integrated approach is taken. The way that this is done is by an emphasis that will begin right at the top level of the obligations and will work downwards from there; while explaining just how the requirements are completed by the lower layers of the broadcasting chain. Data communications and networks are very important when it comes to services like VoIP, as they make up some of the service.
When one talks about data communications they are referring to equipment that was specially designed to give and gather information that is capable of communicating with other similar equipment and systems. Data communications are the tools that are used to make certain adjustments within the network. A simple example of data communications would be connecting two computers together when they are 100 feet away from one another. A cable can be used to plug into each computer and they will then be connected, creating data communications. There are different factors that have to be taken into consideration when trying to determine how data communication will work. For example, some factors in this case might include security, distance, signaling, topology and protocol.
In another equally simple case, a data communication could be the connection of your computer to the internet through a modem. If you have done this, you have established a steady connection between your computer and the World Wide Web. Every time you click on a link from a website you are requesting certain information from that website and it is given to you in the form of data, whether it is in color, letters or graphics. Data communications and networks are needed in an Internet connection. It makes the connection, and therefore it has to be present at all times.
A network is made up of two or more computers that are joined in order for them to share certain resources such as CD-ROM’s, printers or fax machines. They can allow the exchange of files and they may also allow different forms of electronic communications. These computers can be joined by infrared light beams, cables, satellites, telephone lines or radio waves. There are two major types of networks; these are Local Area network (LAN) and Wide Area Network (WAN). Networks are important when it comes to computers and the communications with other computer networks. You need to know and understand networks in order to be able to use them to their optimum capability.
The Internet is the main example that can be used when one talks about data communications and networks. There are numerous modern connection options and services that can be used and these include ADSL, Voice over Internet Protocol and mobile radio. When it comes to current systems and the importance of them, the aspects that are more traditional such as circuit switching still exist and are available.
By: Derek Rogers
Efficient Network Design & Installation Ensures Smooth Business Growth
September 26th, 2009Every business is aimed towards growth, and network support is amongst those many factors leading to the progress of a business
Today, the IT sector has expanded a great deal, which means that businesses will surely benefit from installing and understanding the latest technology. An efficient computer network raises business outcome, reduces unnecessary costs and increases business efficiency—making Network installation and computer maintenance the two most important aspects of a business.
To have a robust network support, you first need an appropriate computer network installation. Computer network design and installation can be scary but don’t let that worry you. Follow the tips given below and give your business the reliability and efficiency it needs:
Network Planning:
Planning is the initial step in your network installation process. Business growth is greatly dependent on efficient network design and network installation services, which are again dependent on effective network planning. Planning includes defining your needs, establishing strategies and policies to achieve your goals, visioning the probable growth of business, and identifying any security threats.
Network Requirements
Once you’re done with planning, the next stage involves deciding the types of computer devices required for your network in question. These may include things like back-up devices, UPS (uninterruptible power supply), printers, switches, scanners, servers, cables etc.
Network Usage
A part of network design and installation is to identify the number of people using a specific network, how it will be used, and the number of people that will use it locally or remotely. Also design and install LAN (Local Area Network) and WAN (Wide Area Network) to connect people within and outside the organizational premises.
Network Security
Security measures should be the first concern of your network installation service. Important business data and information may be exposed to security threats like viruses, spyware, malware, hackers, or other unauthorized access to the data. Therefore, your network should be designed and installed in such a way that it maintains high levels of protection against all such menaces.
Network Monitoring
Regular monitoring and checkup of network system is essential to recognize the successful installation of your network. Remove any issues that crop up during the network reviewing stage, and this will ensure you have a maximum network uptime, boosting your business growth.
A quick, safe and seamless network design and installation is what your business requires in order to flourish and grow rapidly, and the above given points will tell you exactly how you can efficiently design and install a successful network.
About Author:
Bryan Williams has closely worked with small and medium businesses in analysis, planning & management. If you’re looking for advice regarding IT support, especially Business IT support, network support, network installation and or choosing right network installation services you can always ask Bryan.
By: Bryan Williamz