34
Information Security Professional UIN - 16 Nov 2011 - @y3dips Wednesday, November 16, 11

Information Security Professional

Embed Size (px)

DESCRIPTION

ITSec Pro - UIN JAKARTA IT Security Seminar

Citation preview

Page 1: Information Security Professional

Information SecurityProfessional

UIN - 16 Nov 2011 - @y3dips

Wednesday, November 16, 11

Page 2: Information Security Professional

• Freelance IT Security Consultant

• More than 9 years in IT Security

• Founder of “ECHO” one of Indonesian Hacker Community, established 2003

• Founder of IDSECCONF - Indonesia Security Conference

@y3dips

y3dips

Wednesday, November 16, 11

Page 3: Information Security Professional

InfoSec

Means protecting information and information systems from unauthorized

access, use, disclosure, disruption, modification, perusal, inspection,

recording or destruction [1]

[1]  h&p://wikipedia.org

Wednesday, November 16, 11

Page 4: Information Security Professional

Information Security• Information : Set or collection of data that has meaning

• Level [2]

• Non-Classified

• Public Information

• Personal Information

• Routine Business Information

• Classified

• Confidential

• Secret

• Top Secret

[2]  h&p://wikipedia.org

Wednesday, November 16, 11

Page 5: Information Security Professional

InfoSec Pro

People Working in Information security

Wednesday, November 16, 11

Page 6: Information Security Professional

InfoSec Pro

Background• Natural Born Hacker

• Formal Education

Wednesday, November 16, 11

Page 7: Information Security Professional

HackersNatural Born Hacker, Gain their InfoSec Knowledge by Hacking; Hack to Learn not

Wednesday, November 16, 11

Page 8: Information Security Professional

Hacker

• Newbie

• Script Kiddie

• Develop Kiddie

• Hacker

• 1337

Wednesday, November 16, 11

Page 9: Information Security Professional

Newbie

A wanna be hacker

Wednesday, November 16, 11

Page 10: Information Security Professional

Script Kiddies

Know the Tools, Able to use the tools;

But, Not how the tool “really” works

Wednesday, November 16, 11

Page 11: Information Security Professional

Develop Kiddies

Able to Create a Tools,

Know how the tool “really” works

But Still lack with attitude

Wednesday, November 16, 11

Page 12: Information Security Professional

Hacker

Know Exactly What they’re Doin and

How to Do it

Wednesday, November 16, 11

Page 13: Information Security Professional

1337

Nobody Know what They are Doing

Wednesday, November 16, 11

Page 14: Information Security Professional

Hacker

[+]

• Proven Skill and Exprerience

• Able to do a proof of concept

[-]

• Lack of Metodhologies

• Lack or Organizations/Managerial

Wednesday, November 16, 11

Page 15: Information Security Professional

!Professional

• Bug Hunter

• OS/App Developer

• Botnet owner (DDOSer)

• Fraudster

Wednesday, November 16, 11

Page 16: Information Security Professional

Wednesday, November 16, 11

Page 17: Information Security Professional

Wednesday, November 16, 11

Page 18: Information Security Professional

InfoSec StudentGain Information Security Knowledge from formal Education, Course, Certification

Wednesday, November 16, 11

Page 19: Information Security Professional

InfoSec Student

[+]

• Strong in Concept and Metodhologies

[-]

• Lack of Skill and Experience

• Unable to do Proof Of concept

Wednesday, November 16, 11

Page 20: Information Security Professional

InfoSec Pro

• IT Security Officer

• IT Security Analyst

• IT Security Auditor

• IT Security Engineer

Wednesday, November 16, 11

Page 21: Information Security Professional

Security Officer

• Security Contact Point for Organization

• Principle Advisor for IT Security

• Ensure Security Program Running ( Security Awareness course, etc)

• Creating Security Policy, Procedures, Hardening guide

Wednesday, November 16, 11

Page 22: Information Security Professional

Security Analyst

• Monitor all type of access to protect confidentiality and integrity

• Provides Direct Support and Advise to the IT Security Manager

• System Security Analyst, Network Security Analyst

Wednesday, November 16, 11

Page 23: Information Security Professional

Security Auditor

• Auditing an Organizations Technology processess and security.

• IT General Controls Reviews

• Application Controls Reviews

• Security Auditor, Penetration Tester

Wednesday, November 16, 11

Page 24: Information Security Professional

Security Engineer

• Maintenance Computer Hardware and Software that comprises a computer Network

• Doing a Security hardening and Configuration

• System Security Engineer, Network Security Engineer

Wednesday, November 16, 11

Page 25: Information Security Professional

Requirements

• Skill

• Experience

• Attitude

• Able to work independent/group

• Certification?

Wednesday, November 16, 11

Page 26: Information Security Professional

Skill

• In depth knowledge of Operating System

• In depth knowledge of Networking

• In depth knowledge of Application

• In defpth knowledge of Programming

• Much more :)

Wednesday, November 16, 11

Page 27: Information Security Professional

Experience

• How long you’ve been in that field

• + the Security afterward.

Wednesday, November 16, 11

Page 28: Information Security Professional

Attitude

With Great Power Comes Great Responsibilities

Wednesday, November 16, 11

Page 29: Information Security Professional

Work

• Able to work Alone (individualist),

• or a Team Player

Wednesday, November 16, 11

Page 30: Information Security Professional

Certification

• In someway, its a [+]

• Is it badly needed?

Wednesday, November 16, 11

Page 31: Information Security Professional

Limitation

• Government Rule : UU ITE

• Organization/company Rule: NDA

Wednesday, November 16, 11

Page 32: Information Security Professional

Failed

• Always Take not Give

• Lack of Attitude

• Kiddies Minded

• Lazy to Improve

Wednesday, November 16, 11

Page 33: Information Security Professional

Wednesday, November 16, 11

Page 34: Information Security Professional

Information SecurityProfessional

UIN - 16 Nov 2011 - @y3dips

Wednesday, November 16, 11