How to manage the computer and network security function

Ranked #12,515 in Computers & Electronics, #260,292 overall

A security manager has to relate to the techies while getting buyin from senior management

It is a fine art. I used to think of the as sandal to tie protocol. My smartest technical people tended to wear Birkenstocks and the business unit managers were in suits and ties and to be effected, I had to relate to all of them. This lens is about that tricky balance. It will also help you understand what is offered in the course I write and teach SANS Security Leadership Essentials:
http://www.sans.org/training/description.php?mid=62

This is where I post new security articles

Loading Fetching RSS feed... please stand by

Please consider attending my course on security leadership

My course is designed to empower advancing managers who want to get up to speed fast on information security issues and terminology. Lecture sections are intense; the most common student comment is that it's like drinking from a fire hose. The diligent manager will learn vital, up-to-date knowledge and skills required to supervise the security component of any information technology project.

Essentials topics covered in this management track include: Network Fundamentals and Applications, Hardware Architecture, Information Assurance Foundations, Computer Security Policies, Contingency and Continuity Planning, Business Impact Analysis, Incident Handling, Web Security, Offensive and Defensive Information Warfare, culminating with Management Practicum. Only SANS top instructors are invited to teach this course and you will be able to put what you learn into practice, the day you get back into the office.

http://www.sans.org/training/description.php?mid=62

These are some of the books I have worked on

Loading

At RSA I was interviewed about SANS, GIAC and STI

Video interview of Stephen Northcutt

Stephen Northcutt on Security Certification, the SANS Top 20
by helpnetsecurity | video info

9 ratings | 5,343 views
curated content from YouTube

New Guestbook

submit

Useful Security Blogs

Just in case you need something to read

There are almost too many security blogs at this point, here are a few I find relevant.
Anton Chuvakin
Anton is becoming the spokesperson for logs and log analysis for our industry. I believe over the next five years we will be doing intrusion detection with logs the same way we did with network IDS a few years back. Sometimes a bit terse, if he makes you made, forgive him :)
OSSEC Blog
If you can believe that detection is really important these days, then you probably should be following the OSSEC Host Based Intrusion Detection folks.

by

StephenNorthcutt

Stephen Northcutt founded the GIAC certification and currently serves as President of the SANS Technology Institute, a post graduate level IT Security... more »

Feeling creative? Create a Lens!