House of Hackers

Information

Security Education

This is a group for educators, professors and teachers in the field of Risk Management, information security and computer security.

Members: 14
Latest Activity: Jul. 12, 2008

Discussion Forum

Daakik

Education or Certification????

Started by Daakik Jul. 12, 2008.

Comment Wall

Add a Comment

You need to be a member of Security Education to add comments!

Marc-Andre Leger Comment by Marc-Andre Leger on June 16, 2008 at 12:36pm
I would like to start a thread to discuss the requirements for a model curriculum for IT security managers and for IT security practitionners. Any takers ?
Marc-Andre Leger Comment by Marc-Andre Leger on June 6, 2008 at 2:00pm
The Organisation for Economic Cooperation and Development (OECD) released a report titled Malicious Software (malware): a Security Threat to the Internet Economy last week on the international state of Internet security: http://www.oecd.org/dataoecd/53/34/40724457.pdf

This report, developed in collaboration with "experts", aims to inform policy makers about malware impacts, growth and evolution, and countermeasures to combat malware. It seeks to analyse some of the main issues associated with malware and to explore how the international community can better work together to address the problem. Highlights include the following:
- Spam has evolved from a nuisance to a vehicle for fraud to a vector for distributing malware. Malware, in the form of botnets, has become a critical part of a self sustaining cyber attack system. The use of malware has become more sophisticated and targeted. Many attacks are smaller and attempt to stay "below the radar" of the security and law enforcement communities.
- The effectiveness of current security technologies and other protections in detecting and containing malware is challenged by the shrinking of the time between the discovery of vulnerabilities in software products and their exploitation.
- The behaviour of market players confronted with malware (whether Internet service providers, e-commerce companies, registrars, software vendors or end users) is influenced by mixed incentives, some working to enhance and some to reduce security. There are many instances in which the costs of malware are externalised by players at one stage of the value chain onto other players in the value chain.
- A wide range of communities and actors – from policy makers to Internet service providers to end users – h as a role to play in combating malware. There is still limited knowledge, understanding, organisation and delineation of roles and responsibilities in this broad community of actors.
- Current response and mitigation are mainly reactive. There is a need for more structured and strategic co-ordination at national and international levels with involvement of all actors to more adequately assess and mitigate the risk of malware.
- No single entity has a global understanding of the scope, trends, development and consequences of malware and thus the overall malware problem is difficult to quantify. Data on malware are not consistent and terminology for cataloguing and measuring the occurrence of malware is not harmonised.
- Although its economic and social impacts may be hard to quantify, malware used directly or indirectly can harm critical information infrastructures, result in financial losses, and plays a role in the erosion of trust and confidence in the Internet economy.
 

Members (14)

Daakik Marc-Andre Leger dev0id 1337hx0r awk CG1980 Brittany King Bangya carlitux E Specter Xasulrev The-Insider kldo
 
 

About

pdp pdp created this Ning Network.
 

© 2009   Created by pdp on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!