As some of you will no doubt know I do a lot of networking on LinkedIn. I'm always interested in what's growing, what's moving and how to advance the story of our lives here in America. Many of my professional connections are on LinkedIn and I am thrilled that I can reach into the resource from time to time seek the advice and opinions that they willingly provide.
This post is about exposing a resource whose time has come. The need is here and people should pay attention to the depth and breathe of posts. Its about helping others who may really be in a bind due to the downturn (self imposed) of our economy during this pandemic. As we press forward and reopen our economy the endless opportunities will slowly give rise to America's unlimited potential which should be great news for everyone involved.
In the meantime, Andrew Seaman does a segment on LinkedIn called #Gethired and provides some tremendous resources that I have found to be just terrific and incredibly helpful. Andrew is a great writer and inserts into his posts another resource of LinkedIn called LinkedIn Learning. I have viewed many of the videos and taken a number of these courses and found the quality to be top notch. He quotes experts from the field and links them in his posts for additional value. I call that bonus points.
A take away from the resume course is in the table I'm inserting below. Within a few minutes you can brighten your day and freshen up that resume with color and relevance.
Keywords
Tell a story
Contrast/Compare
Never give up
I was also interested in what LinkedIn was saying on its blog. Yes, if you didn't know it LinkedIn has a blog and this is another terrific resource for all involved. LinkedIn has managed to pull together a great team of individuals on its platform who do one terrific job of communicating. That can not be understated.
That's what this post is all about. Take a look at your LinkedIn account and drive some attention to the posts and resources that LinkedIn personnel and contactors have so handsomely put together in one place for your use.
Zoom, the video conferencing software maker learned a lot of lessons this past month as a result of legions of new visitors who stopped by and signed up as new customers. The software company literally exploded with new customers during Mid March 2020 as a result of the COVID -19. However a number of security incidents started happening and with that a fire hose of commentary poured into their email boxes, security blogs, conference calls and forums. Security professionals came on strong. One security practitioner commented that the right out of the box the default settings needed serious review and the general public was at the point of the spear - buyer beware. Waiting rooms, passwords, and many other enhancements all focused on security and reducing risk were heard from all quarters.
To the credit of Zoom, now known as that easy, cheap video conferencing software have made the changes to improve security (change to many of the default settings, like requiring password as a default for all meetings, establishing a waiting room so you can verify participants and sprinkling of the message not to share passwords, etc) and reduce the risks to many of its users. Zoom has taken it on the chin for many in this functional area: "Video Conferencing Brands" while the rest of the pack gets the opportunity to take another look at security. Zoom brought on a security professional and kinder days seem to be in the future. Zoom also has a HIPAA compliant application separate from what general users get to use. See the photo above for the last known update from Zoom. Zoom is growing and has been sending out improvements as they become available.
Video Conference Software:
Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms
Here are some additional products for consideration:
GoToMeeting
Webex Teams
Skype for business
Google Hangouts
Join.Me LogMeIn
Amazon Chime
Microsoft Teams
Cisco Webex Meetings
Updox
Vsee
Zoom for healthcare
Spruce health care messenger
Apple Face Time
Doxy.me
Face Book Messenger Chat
Blue Jeans - recently purchased by Verizon
Check out each of these products and note well during a declared national emergency many if not all maybe used without compliance penalty. However, after the emergency is over please do use HIPPA compliant software. See shorturl.at/fijHL for future updates at U.S. H.H.S. dot gov.
Today 4/25/20 I reviewed an article from Dr Eric Cole, Secure Anchor Consulting. These are some of his thoughts:
Zooming now household
word
Due to pandemic
March/April 2020 video conferencing increases 1000 fold. "Zooming" takes on a life of its own for all brands of video conference calling software.
ZOOM BOMBING: DEFINED
Is where a person
joins into Zoom video conferencing calls uninvited and either 1.) listens in,
2.) gathers important info to use at a later time or 3.) become disruptive to
your meeting or event.
How do you protect a Zoom call?
Remember you
are a target, 2. Cyber security is your business, 3. Make sure your
software is up to date.
Make sure your computer
operating system is up to date
Make sure your Zoom app is
up to date and other apps as well
Make sure you are using
anti-virus software and its up to date
On a conference call today. Discussion of fat client verses thin client again for VT software (for the young at heart this seems to reoccur every 5-10 years), functionality services were discussed (I think more of what you are used to using drives the most favorite product discussion) and end to end encryption took place. Zoom came up and given that it is slowly improving its security posture some note it is moving into the "pack" of other VT implementations given that it will become less of a pick up and use utility because of security concerns. Those with more security concerns and less functionality can look here: https://www.infosecnews.org/national-security-agency-releases-guide-to-secure-video-conferencing
A few weeks ago there was a lot in the news about ZOOM Bombing.
So ZOOM took action and set up some default security to 'appease the masses'.
But here's the thing... they did too little, too late AND ZOOM meetings are
still being targeted.
It's not over! The adversary is still on the prowl and creating
havoc.
I recorded a quick video for you to share with your organization
to help keep the awareness around how to protect against ZOOM Bombing.
Have you ever wondered where to start in securing your computer operations? Its natural to be concerned and to suffer from some anxiety. Careful what you wish for because when some people apply for CSO, CISO jobs they may suddenly find that they got what they wished for. Now what? Where do I start, what comes first, yikes I need priorities, but where?
Integris Security LLC with the help of some of our friends from the NY InfraGard Thursday Conference Call came up with some great resources which you should become familiar with. We also discussed at some length ISO 27001. It was the conclusion of the of the callers that the ISO standards are written to be very broad and do not focus the security professional on what needs to be done with any given priority. The ISO standard could lead you down a road unfocused and without clear priorities of what's really important for your organization.
Here are some focused security and risk management resources:
Security professionals need to have a full understanding of the environment which they are securing. These men and women need to be able to explain to others why we need this control, that defensive tool, etc... The security professional needs to be intimately involved with the infrastructure and provide a solid understanding of every facet of the operation. This work takes dedication - endless time and energy that becomes the life and work product of a CSO/CISO.
CSO's and CISO's would do well to build a set of books which would consist of the environment that they have been hired to protect. In these books should be the SANS twenty controls. Each control should be explained in detail and record of examination clearly maintained so that each fresh security face looking at the systems will not have to hunt for the documentation. This is part of your audit trail.
Why SANS? The SANS organization has distinguished itself as an expensive but outstanding security organization from which excellence is derived from. The SANS top 20 security controls are maintained and updated so that security professionals can be assured they are addressing the top known threats.
How can a true security professional even begin to contemplate securing an organizations assets without knowing the environment inside / out? It is impossible. If your organization needs assistance in understanding these and other security issues, give Integris Security a call and let's get started today.
Trust is at the core of Integris Security. We can be counted upon to provide you with the services and intelligence to keep your information, systems and institution secure. Call us and let's get to work on improving your security/risk posture.