38
MVHS Career Night 2015 Information Security

MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Embed Size (px)

Citation preview

Page 1: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

MVHS Career Night 2015

Information Security

Page 2: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Agenda

• What is Information and Security.• Industry Standards• Job Profiles• Certifications• Tips

Page 3: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

What a person wants in life

• Money • Fame • Nirvana

We will talk about first 2

Page 4: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

How to be wealthy ?

Have Rich ParentsMarry a Rich SpouseWin the LotteryBecome a Successful Black Hat Hacker (Live

life underground)Work as a White Hat (this presentation)YOU WILL MAKE YOUR OWN CAREER!Others may help, but it’s ALL ON YOU!

Page 5: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Do I have your attention now.

Page 6: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Why Information Security?

• Increasing regulatory compliance• Requires organizations to adopt security standards

and frameworks for long-term approach to mitigating risk

• Evolving and emerging threats and attacks• Continual learning of new skills and techniques• Convergence of physical and information security• Accountability between information security

professionals and management falls on several key executives to manage growing risk exposures

Page 7: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

What Is Information?

• Information is collection of useful DATA.• Information could be – Your personal details– Your corporate details.– Future plan’s

Page 8: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

What is Information Security?1) Access Controls 2) Telecommunications and Network Security 3) Information Security and Risk Management 4) Application Security 5) Cryptography 6) Security Architecture and Design 7) Operations Security 8) Business Continuity and Disaster Recovery Planning 9) Legal, Regulations, Compliance and Investigations 10) Physical (Environmental) Security

Page 9: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

What Next

Page 10: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Explore : – Industry Standard

• Knowledge – nothing beats core concept understanding

• Certification – helps in proving your exposure as fresher.

Page 11: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Explore : Types of Info-Sec jobs

• Ethical Hacker– Vulnerability Assessment– Penetration Tester

• Forensic Investigator• Security Governance– Auditor

• Security Administrator• Secure Developer

Page 12: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Explore : Type of certification

• Security Analyst – CEH, ECSA, OSCP• Development – SCJP, MCSE• Server Security – RHCSS• Auditor – ISO 27000 lead auditor

Page 13: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Information Security

Page 14: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Information Security

• keep the bad guys out• let the trusted guys in• give trusted guys access to what they are

authorized to access

Page 15: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Security Triad

Page 16: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Security Triad

Page 17: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Secure Developer

• A Developer who is aware about security issues.

• Developers now are classified In 3 major category– Thick Client Developer– Thin Client Developer.– Kernel or driver developer.

• If you can exploit it you need to patch it.

Page 18: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Security Administrator

• Server Administrator with background into Security.

• Skills Required– Server Hardening.– Firewall configuration.

Page 19: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Vulnerability Assessment

• It is the process of finding possible exploitable situation in a given target.

• Target could be Desktop/ Laptop, Network, Web Application, literally any device with a processor and motive to achieve

• Skill Set– understanding of target architecture.– Eye for details and thinking of an exploiter.– (Optional) Programming for nessus plugin.

Page 20: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Penetration Testing

• Next Step to vulnerability assessment.• Here the target is actually evaluated against a

live attack.

• Skills Required:– Programming : C / C++ , Python, Perl , Ruby– Understanding of an exploitation framework.• Metasploit• Core impact

Page 21: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Forensic Expert

• The post – mortem specialist for IT• Responsible for after incident evaluation of a

target.

• Skills– All that’s needed for VA/PT.– Understanding of forensic concepts not limited to

data recovery, log evaluation etc.

Page 22: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Clarify : Auditor

• Reviews the systems and networks and related security policies with regards to Industrial standards.

• Skills Required– Understanding of compliance policies• HIPPA, ISO 27001, PCI DSS, SOX and many more.

– Understanding of ethical hacking concepts and application.

Page 23: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Commit : How to gain Knowledge

Spend first few years mastering fundamentals• Get involved in as many systems, apps, platforms,languages, etc. as you can• Key technologies and areas• Relevant security experience• Compliance/regulatory/risk management• Encryption• Firewalls• Policy• IDS/IPS• Programming and scripting

Page 24: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Commit : Technical Skills Required

• LEARN the Operating System• LEARN the Coding Language• LEARN Assembler & Shell Coding• Learn Metasploit• Learn Nessus• Learn Writing exploit for Metasploit• Learn writing scanning plug-in for Nessus.

Page 25: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Commit : Soft Skills Required

• Learn Presentation skills.• Learn business language. Management likes to

hear that.

Page 26: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Commit : how to gain certificate

• Attend Training• Learn, understand and apply the concepts in a

controlled environment.• Take exam when you have confidence.

Page 27: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Commit : how to practice

• Set up a lab at home.– Physical Lab (best)– Virtual Lab (second Best)

• Keep yourself updated subscribe to Vulnerability DB.– Practice regularly on a secured home lab.

Page 28: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Commit : First job

• Lower rungs of the tech ladder• Unpaid Overtime is Expected• When offered company training – take it• Expect to make Mistakes– Learn from them

Page 29: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

THINGS TO REMEMBER

Page 30: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Things to Remember

• Learn to Question Everything.• Keep yourself up-to-date. • Be expert in one field however, security

specialist are more on advantage if they develop generalist skills.

• Security is extension of business needs and should support it.

• Form group of like minded people.

Page 31: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

HACKER GOT HACKED

• Keep your system and network secure first.• Avoid publicizing about being “HACKER” till

you have practiced enough and feel confident.• Self proclaimers are not seen with good eyes

in security communities.• Your work should speak and not your mouth.

Page 32: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Work and personal Life

Page 33: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

CERTIFICATIONS

Page 34: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Why Certification is good

• Nothing beats the first hand Job Exposure.However• When you hit roadblock, certifications helps

Page 35: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

More on Certification

• Passing a Certification exam says that:– You have the minimum knowledge to be considered for

certification (at the time of the test) OR

– You are very good at taking tests.

Page 36: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Industry Certifications

• EC-Council– CEH, ECSA, CHFI ,ECSP and More

• ISC2

– CISSP• Offensive Security– OSCP

• ISACA– CISA and CISM

Page 37: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips
Page 38: MVHS Career Night 2015 Information Security. Agenda What is Information and Security. Industry Standards Job Profiles Certifications Tips

Any Questions