Building Elegant Security Dashboards for your NOC or SOC & CISSP Domain 1 Security & Risk Management

May 15, 2019 by John Nash

Monday June 3rd, 2019 / 6 PM – 9 PM

WHO: Southwest CyberSec Forum WHEN: 1st Monday of each month 6:00 PM – 9:00 PM WHERE: UAT theater at 2625 W Baseline Rd, Tempe, AZ 85283 WHY: To stay current with new cyber threats, explore new security technologies, and network with your peers.

FREE: No membership fees, no RSVP’s, food and drinks provided by our sponsors.

Sponsorship by Oracle

Sponsor Contact:

Dan Krpata dan.krpata@oracle.com Security and Management Specialist 602-549-5197

Cyber Threat Rundown with Erik Graham

We have video of our presentations on YouTube!

Presentation 1: Building Security Dashboards from Elasticsearch Log Data (7:00-7:45 PM)

by Dean Moore and John Nash of Phreedom Technologies

We have video of our presentations on YouTube!

John R. Nash

With the relentless increase in speed and capacity of networks and systems, the logs that are generated can exceed thousands of events per second or more!  Is there any hope for an understaffed security team to keep up with the constant flow of user activity and system events, and hope to make any sense out of it?

John and Dean will show how to build sophisticated security dashboards, sourced from firewall and windows event log data stored in Elasticsearch.  The focus will be on the use of open source tools to build time series histograms and heat maps to identify important data that will highlight how your infrastructure is operating and quickly identify patterns and anomalies that may require further investigation.

Examples:

Firewall session for most active users over a 2 day period

ISP Daily Bandwidth by Netblock Owner (ASN)

Daily Heat map of Firewall Policy Events

Presentation 2: CISSP Domain 1 Security & Risk Management presented by Tim Hoffman (7:45-8:00 PM)

We have video of our presentations on YouTube!

Tim Hoffman

The security & risk management domain is a complex domains that accounts for a total of 16% of the score on the examination. This domain often confuses the more technical personnel because it speaks to business. The intent of the domain puts focus directly on business executives and security personnel who must work together to agree on the proper security activities to perform to achieve optimum governance. The Board and Executive Management will involve themselves with providing strategic direction and making decisions based on risk – then managing risks appropriately while concurrently verifying that the enterprise’s resources are used responsibly.

Mr. Timothy Hoffman is a Healthcare Cybersecurity Executive with an extensive US Navy cryptologic background, a serial entrepreneur, and Founder of Tim Hoffman & Associates, LLC. His professional credentials include an MS from Central Michigan University and certifications including: CISSP, GCIH, CCSK, Security+(CE), Network+(CE), ITIL v3, ISO 27001, C|EH, CNDA, Expert Rating PM, ISP, and many others.

Mr. Hoffman’s strength is found in alignment of technology solutions to business needs so as to support business through risk management. His team translates technical speak into everyday language that is easy to understand and has won praise for security program creation, policy & procedure writing, Cloud system design, and network architecture.

Notable career accomplishments include 5 books, radio show host in Italy & US, multiple language facility with fluency in Italian, and platform training to thousands of students on IT & cybersecurity topics for nearly 30 years. He is a competitive level dancer on the global UCWDC scale placing 4th in 2016 and 8th at a higher level in 2019.

Back to top