<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Job Interview &#187; Security</title>
	<atom:link href="http://www.it-job-interview.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.it-job-interview.com</link>
	<description>Face IT, Answer IT, Get IT!</description>
	<lastBuildDate>Thu, 18 Nov 2010 16:35:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Why Your Network May Get Denial-of-Service Attacks, and How Can You Recover from the Attack?</title>
		<link>http://www.it-job-interview.com/network-denial-of-service-attack.html</link>
		<comments>http://www.it-job-interview.com/network-denial-of-service-attack.html#comments</comments>
		<pubDate>Thu, 06 Aug 2009 17:18:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Network Questions]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.it-job-interview.com/?p=57</guid>
		<description><![CDATA[This question is asked to network administrators and security officers in order to test insight of the candidates’ overall knowledge of the various attacks that may affect the organization. You’d better have some real life network security experience to giving a perfect answer. However, if you never dealt with denial-of-service attack and recovery, you can [...]]]></description>
			<content:encoded><![CDATA[<p>This question is asked to network administrators and security officers in order to test insight of the candidates’ overall knowledge of the various attacks that may affect the organization.  You’d better have some real life network security experience to giving a perfect answer.  However, if you never dealt with denial-of-service attack and recovery, you can still make yourself familiar with the concept and describe the general process.  An example answer could be like:</p>
<p>“Our network could get denial-of-service attack because someone wanted to crash our system or make it perform so poorly and become unusable.  Hackers may also want to install Trojan or a root kit through the attack.  When a denial-of-service attack is identified, the first thing I would do is to reboot the system.  In general I would also need to reprogram the switches and routers in order to drop the offending traffic.  I would implement certain security features provided by the vendors to within the system to protect the network from this type of attack.  With a Windows server system for example, I can invoke IPSec policies that allow me to limit or forbid traffic from certain hosts.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-job-interview.com/network-denial-of-service-attack.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISSP &#8211; Certified Information Systems Security Professional Certification</title>
		<link>http://www.it-job-interview.com/cissp-certified-information-systems-security-professional-certification.html</link>
		<comments>http://www.it-job-interview.com/cissp-certified-information-systems-security-professional-certification.html#comments</comments>
		<pubDate>Mon, 18 Aug 2008 17:41:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Career insight]]></category>
		<category><![CDATA[Certifications]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.itcareersuccess.com/?p=55</guid>
		<description><![CDATA[The International Information Systems Security Certifications Consortium [(ISC)2] offers Certified Information Systems Security Professional Certification (CISSP) which is a high level certification program for IT professionals in security field. CISSP Certification was designed to recognize mastery of an international standard for information security and understanding of a Common Body of Knowledge (CBK). CISSP Certification can [...]]]></description>
			<content:encoded><![CDATA[<p>The International Information Systems Security Certifications Consortium [(ISC)2] offers Certified Information Systems Security Professional Certification (CISSP) which is a high level certification program for IT professionals in security field.  CISSP Certification was designed to recognize mastery of an international standard for information security and understanding of a Common Body of Knowledge (CBK).<span id="more-188"></span></p>
<p>CISSP Certification can enhance a professional’s career and provide added IS credibility.  Obtaining CISSP certification is a matter of both personal and professional commitment, and on-going dedication to excellence in the information security [IS] industry.  Since there is a growing demand on security professionals, there are many reasons to achieve a CISSP certification:</p>
<p>- Become an expert in the hottest field in IT industry.<br />
- Enhance your knowledge of security concepts and practices.<br />
- Increase you marketability and competitive advantage.<br />
- Secure your current job by offering security expertise.<br />
- Increase salary in current job or in new opportunities.</p>
<h2>CISSP Exam</h2>
<p>The CISSP Certification examination consists of 250 multiple-choice questions. Candidates have up to 6 hours to complete the examination. Ten CISSP information systems security test domains are covered in the examination pertaining to the Common Body of Knowledge (CBK):</p>
<p><strong>Access Control Systems &amp; Methodology</strong><br />
Controlling access to critical system resources that require protection from unauthorized modificaton or disclosure.  Topics include two factor authenticaiton, single sign-on, biometrics, etc.</p>
<p><strong>Applications &amp; Systems Development</strong><br />
The integration and unity of the controls within the application design, databse security models, implementation of multi-level security.</p>
<p><strong>Business Continuity Planning</strong><br />
Planning issues used to address catastrophic system failure, natural disasters, and other severe network service interruptions.</p>
<p><strong>Cryptography</strong><br />
Mathematics, techniques, and infrastructure required to provide confidentiality, data integrity, non-repudiation, and other cryptographic functions.</p>
<p><strong>Law, Investigation &amp; Ethics</strong><br />
Legal issues surrounding computer security.  Topics include computer forensics, chain of evidence, computer surveillance, privacy, anonymity, netiquette.</p>
<p><strong>Operations Security</strong><br />
Protection issues that occur during the operation of the networked systems.  Covers Java and mobile code security issurs, hacker threats, penetration testing.</p>
<p><strong>Physical Security</strong><br />
The real world security issues that sites must address to be secure.  Topics includes facility issues, fences, guards, lighting, etc.</p>
<p><strong>Security Architecture &amp; Models</strong><br />
Topics concerning desktop and network security issues.  Covers desktop security policies, physical security of desktop and laptop systems, desktop and network data backup security issues, viruses, secure remote access.</p>
<p><strong>Security Management Practices</strong><br />
People and organization issues.  Security awareness, enterprise security architecture, risk assessment.</p>
<p><strong>Telecommunications, Network &amp; Internet Security</strong><br />
Communications protocols, network services, and their vulnerabilities.  Covers firewalls perimeter security, extranet access control, Internet based attack, application layer, network layer, and transport layer security, security of communication protocols.</p>
<p>To qualify to take the CISSP exam, you must have three years of direct work experience in one or more of the ten domains that make up the CBK.</p>
<p>The CISSP exam is made up of 250 multiple-choice questions and you are given up to six hours to complete it.  Each question has four choices with only one right answer.</p>
<p>Recertification is also required every 3 years, with on-going requirements for maintaining your credentials in good standing.</p>
<p>The exam registration fee is $450.</p>
<h2>Resources</h2>
<p>(ISC)2 and CISSP&#8217;s offical home page</p>
<p>https://www.isc2.org/</p>
<p>CISSP and SSCP open study guides website</p>
<p>http://www.cccure.org/</p>
<p>The web portal for CISSP</p>
<p>http://www.cissps.com/</p>
<p>Computer Security Instutite CISSP page</p>
<p>http://www.gocsi.com/cissp.htm</p>
<p>Boson&#8217;s Practice Tests for CISSP exams</p>
<p>http://www.boson.com/tests/secure.htm</p>
<p>Yahoo! Groups HIPAA-CISSP</p>
<p>http://groups.yahoo.com/group/HIPAA-CISSP/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-job-interview.com/cissp-certified-information-systems-security-professional-certification.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Career Track on IT Security with Cisco</title>
		<link>http://www.it-job-interview.com/it-security-with-cisco.html</link>
		<comments>http://www.it-job-interview.com/it-security-with-cisco.html#comments</comments>
		<pubDate>Thu, 17 Jul 2008 00:31:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Career insight]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.it-job-interview.com/?p=24</guid>
		<description><![CDATA[Several years ago, network security was simply a specialization implemented by system administrators. Today, security has gone beyond network and played major roles in IT industry. Due to all these sweeping changes we experienced in recent years, we are all sure that security will stay as the No.1 priority in IT system implementation, and the [...]]]></description>
			<content:encoded><![CDATA[<p>Several years ago, network security was simply a specialization implemented by system administrators.  Today, security has gone beyond network and played major roles in IT industry.</p>
<p>Due to all these sweeping changes we experienced in recent years, we are all sure that security will stay as the No.1 priority in IT system implementation, and the demand for security professionals will never die.  Security is definitely the growth sector of the day.  Thus, the security career track can be a highly remunerative direction.<span id="more-24"></span></p>
<p>Because Cisco dominates the network kingdom, anything related to network, such as security, can be influenced by Cisco in a big way.  For an individual professional planning career on security field, Cisco security technology is the right choice.</p>
<p>Here&#8217;s is a common rule in IT career, &#8211; what ever you do, get certified.  If you decide to put your career on focus of Cisco security, obtain Cisco security certifications.  Cisco certification provides professional-level recognition in designing and implementing Cisco security solutions.</p>
<p>Cisco created this career path through the security certification program because the demand is high and Cisco has a great interest in securing the networks of their clients. With Cisco ranking among the top certification paths for great salaries and job stability, having the security path as part of your resume may prove to be one of the best decisions any IT professional could ever make.</p>
<p>To approach this path, you can check out Cisco certification&#8217;s requirements and find out what knowledge and skills are needed to work on the job, and then, do whatever you can to get these knowledge and skills as effectively as possible.  Your goal is not only getting the certification credential, but also obtain the real skills.  You can reach both goals by self-study, through training, and on-job practicing.</p>
<p>Cisco&#8217;s professional-level certifications provide a clear career path in the IT security market.  They offer IT professionals the knowledge, skills, and credentials necessary for designing and implementing end-to-end security solutions.  Cisco certification program offers one flagship certification and three focused certifications in the  security track:</p>
<p>Cisco Certified Security Professional (CCSP)</p>
<p>Cisco Firewall Specialist</p>
<p>Cisco VPN Specialist and</p>
<p>Cisco IDS Specialist</p>
<p>The security certifications meet heightened customer and channel partner demand for knowledgeable network professionals who can design, build, and implement security solutions that include Cisco Secure networks. They are also part of Cisco&#8217;s security strategy to embed security throughout the network, making it a transparent, scalable, and manageable aspect of any business infrastructure.</p>
<p>The Cisco Certified Security Professional certification (CCSP) prepares an individual for a career in the IT security market.  This certification provides network professionals with professional level recognition in designing and implementing Cisco secure networks.  CCSP covers key areas of network security, including identity, firewalls, VPNs, intrusion-prevention systems and security management.  CCSP certification is valid for three years.</p>
<p>CCSP recognizes the increased importance placed on today&#8217;s IT professionals who are responsible for developing business solutions and integrating security devices with the underlying network architectures.  CCSP holders are actively involved in developing business solutions and designing and delivering multiple levels of security departments.</p>
<p>As a CCSP you will understand major networking protocols, procedures and how to integrate security devices with the underlying network.  By obtaining all the knowledge and skills required for CCSP certification, you should be fully prepared to design and implement fully secure networks that will thoroughly protect any organization&#8217;s IT infrastructure.</p>
<p>The three focused certifications concentrate on the needs of individuals who want to pursue skills in specific areas of network security.  These certifications enable individuals to achieve the highest level of technical knowledge and expertise in Cisco specific security technologies and solutions including intrusion detection, firewall and VPN.  The focused certifications are valid for two years.</p>
<p>Cisco security professionals are required to demonstrate sound fundamental knowledge and skills on network systems.  In fact, in order to obtain these certifications, you must have a valid CCNA (Cisco Certified Network Associate) first in addition to taking and passing the corresponding exams.</p>
<p>In the workplace, you as a Cisco security professional are actively involved in designing comprehensive security solutions for businesses of all sizes.  You must demonstrate your ability to secure a network using Cisco IOS Software, ACS, Cisco PIX Firewalls, the Cisco VPN 3000 Series Concentrator, IDS technologies and CiscoWorks VMS.  You must be flexible to work within various environments, including IT department, enterprise security, or simply as a consultant.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-job-interview.com/it-security-with-cisco.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IT Security Specialist Job Description</title>
		<link>http://www.it-job-interview.com/security-specialist-job-description.html</link>
		<comments>http://www.it-job-interview.com/security-specialist-job-description.html#comments</comments>
		<pubDate>Fri, 30 Mar 2007 20:40:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Job Descriptions]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.itcareersuccess.com/?p=138</guid>
		<description><![CDATA[IT Security Specialist is responsible for performing multiple security risk and vulnerability assessments, as well as operational projects and functions including monitoring of the network intrusion detection system. Primary Responsibilities 1) Assess risk, evaluate security , identify vulnerabilities and corrective actions, and review for compliance with security policies and practices. 2) Assist in monitoring and [...]]]></description>
			<content:encoded><![CDATA[<p>IT Security Specialist is responsible for performing multiple security risk and vulnerability assessments, as well as operational projects and functions including monitoring of the network intrusion detection system.<span id="more-271"></span></p>
<p><strong>Primary Responsibilities</strong></p>
<ul>
<li>1) Assess risk, evaluate security , identify vulnerabilities and corrective actions, and review for compliance with security policies and practices.</li>
<li>2) Assist in monitoring and maintaining network and/or host intrusion detection systems, and participate as needed in security event response processes.</li>
<li>3) Review and approve firewall, VPN and other security changes.</li>
<li>4) Participate in the selection and implementation of technologies and security solutions.</li>
<li>5) Coordinate/oversee third party security reviews, penetration testing, and consulting projects as necessary.</li>
</ul>
<p><strong>Required General Skills</strong></p>
<ul>
<li>1) Excellent verbal and written communication skills, including technical/non-technical communication, documentation and presentations.</li>
<li>2) Ability to assess risk and provide innovative solutions balancing security and business requirements.</li>
<li>3) Strong planning, organization and time management skills with the ability to handle multiple projects without direct supervision.</li>
<li>4) Ability to work independently, to follow a work plan, meet project milestones, and interact with various levels of management.</li>
<li>5) Energetic team player with strong initiative, team orientation, and excellent problem solving skills.</li>
</ul>
<p><strong>General Qualifications</strong></p>
<p>Degree Preference: Bachelor&#8217;s or greater degree preferred, emphasis in Information Systems/Computer Science.<br />
Certification Requirement: Network or security -related certifications a plus (ex., CISSP, etc.).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-job-interview.com/security-specialist-job-description.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chief Security Officer (CSO) Job Description</title>
		<link>http://www.it-job-interview.com/cso-job-description.html</link>
		<comments>http://www.it-job-interview.com/cso-job-description.html#comments</comments>
		<pubDate>Thu, 15 Mar 2007 18:57:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Job Descriptions]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.itcareersuccess.com/?p=128</guid>
		<description><![CDATA[Chief Security Officer (CSO) is the top security executive in the company. He or she will report directly to a senior functional executive (CEO, COO, CFO, chief administration officer, head of legal counsel). The CSO will oversee and coordinate security efforts across the company, including information technology, human resources, communications, legal, facilities management and other [...]]]></description>
			<content:encoded><![CDATA[<p>Chief Security Officer (CSO) is the top security executive in the company. He or she will report directly to a senior functional executive (CEO, COO, CFO, chief administration officer, head of legal counsel). The CSO will oversee and coordinate security efforts across the company, including information technology, human resources, communications, legal, facilities management and other groups, and will identify security initiatives and standards. The candidate&#8217;s direct reports will include the chief information security officer and the director of corporate security and safety.<span id="more-261"></span></p>
<p><strong>Responsibilities:</strong></p>
<ul>
<li>Oversee a network of security directors and vendors who safeguard the company&#8217;s assets, intellectual property and computer systems, as well as the physical safety of employees and visitors.</li>
<li>Identify protection goals, objectives and metrics consistent with corporate strategic plan.</li>
<li>Manage the development and implementation of global security policy, standards, guidelines and procedures to ensure ongoing maintenance of security. Physical protection responsibilities will include asset protection, workplace violence prevention, access control systems, video surveillance, and more. Information protection responsibilities will include network security architecture, network access and monitoring policies, employee education and awareness, and more.</li>
<li>Maintain relationships with local, state and federal law enforcement and other related government agencies.</li>
<li>Oversee incident response planning as well as the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary.</li>
<li>Work with outside consultants as appropriate for independent security audits.</li>
</ul>
<p><strong>Qualifications:</strong></p>
<ul>
<li>Must be an intelligent, articulate and persuasive leader who can serve as an effective member of the senior management team and who is able to communicate security-related concepts to a broad range of technical and non-technical staff.</li>
<li>Should have experience with business continuity planning, auditing, and risk management, as well as contract and vendor negotiation.</li>
<li>Must have strong working knowledge of pertinent law and the law enforcement community.</li>
<li>Must have a solid understanding of information technology and information security.</li>
</ul>
<p><a title="CSO" href="http://www.csoonline.com/research/leadership/cso_role.html" target="_blank">More about CSO</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-job-interview.com/cso-job-description.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

