Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: World

» Topic:  SANS unveils IT security degrees

» Added by:  contractoruk.com

» Date:  14.12.2005

  The SANS Institute is opening its doors to equip the 'next-generation of cyber security leaders' by offering two 'extremely challenging' graduate degree courses.

Based in the US, the college-run programs in Information Security Management and Information Security Engineering are offered to IT pros ready to achieve the highest level of mastery.

Both degrees are open to IT applicants from a range of countries, including the UK, though each candidate must have trained at an accredited college (or equivalent) as a minimum requirement.

Speaking to Contractor UK, SANS said contracted IT professionals would gain a “unique advantage” opting for either course, especially MSc Engineering, which is the more skill-centric of the two.

The Institute's Alan Paller said the courses are 'not for everyone,' adding that the ideal candidate will be the professional currently being groomed as the future security leader of their organisation.

Industry professionals who expect to guide and manage security and networking personnel, with a view to becoming a company's IT security leader should opt for the MSc in Information Security Engineering.

Today, these budding security leaders might be eyeing roles like technical director, networking security manager and even assistant CIO for security, SANS said.

A spokesman added: 'It's true that contractors are more interested in being able to clearly show proof of competency in particular skills. And is one of the advantages of both programs, but the engineering program in particular is skills-based.'

Pointing to the Engineering degree content - available here - the spokesman said: 'Completion of this program would provide the contractor credentials for Security Policy; the ability to create and deliver a Security Awareness program; IDS with emphasis on Snort.

'Our Hacker techniques [course] is more focused to incident handling and response than penetration testing, technical auditing, project management, which ideally prepares the student to achieve a PMI certification which we encourage, and then two other skills at the 500 level.'

The Engineering and Security Management degree, designed to train up tomorrow's chief information security officers, both include coursework projects that examine real-world IT problems.

Besides thea core curriculum, each degree will train IT workers to become masters of communication, project management, educating, mentoring and persuasion – the latter an essential for managers to gain boardroom support.

The Institute explains demand for IT security professionals is at a premium, fuelled by the growing menace of cyber crime and terrorism, which insists on the need to develop IT units to counter the threat.

To highlight the problem, SANS pointed to warnings from the UK National Infrastructure Security Coordination Centre, which recognises both degrees.

Director Roger Cumming says a new series of attacks against government systems and infrastructure is unprecedented on such “an industrial scale.”

According to US giant Northrup Grumman, demand for security professionals with the right mix of business and technical skills has led to IT-centric workers being laid off.

Art Ehuan, who managed the organisation’s CSIOs, commented: “In upgrading the staff and hiring new people for security management positions, the most difficult problem we face is finding technical security people who also have good management and business and communication skills.

'The success of our security programs depends on our finding those people. I have had to remove purely technical security people from management roles because they had never learned how to make the business case in language business leaders can understand.'

Cue the two new degree courses at SANS, which proudly declares: 'The SANS promise is that you will be able to apply our training the day you get back to the office.'

Both degrees are designed to support the working professional by allowing them to stay in employment, while embarking on one of the part-time courses, allowing them to hone their business skills.

Alan Paller explained: 'The new SANS degree programs are designed to take people from the workforce and build on their current skills until they have both the management and technical skills to come back ready to take on substantial management responsibilities in cyber warfare or defence against cyber crime.'

Entries to SANS are now being accepted for course commencement in February, with prices for the two-year part-time course approximated at $28,000(£15,800).

'I think this [the Engineering degree] would give a contractor a unique advantage,' a spokesman at the Institute said.

'If you are trying to show credentials in a particular skill area, you bring a prospective client’s attention to the Certificate. If you are trying to show overall qualifications, you can point to the degree.'

Source: contractoruk.com



Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.