SDISSA http://www.sdissa.org San Diego ISSA Chapter admin@sdissa.org admin@sdissa.org Copyright 2010 SDISSA glFusion Thu, 11 Mar 2010 13:49:40 -0800 en-gb Holistic Information Security Practitioner (HISP) Certification Course to be held at SAIC-San Diego March 15-19, 2010 http://www.sdissa.org/article.php?story=Holistic_Information_Security_Prac http://www.sdissa.org/article.php?story=Holistic_Information_Security_Prac Sat, 06 Mar 2010 00:01:18 -0800 http://www.sdissa.org/article.php?story=Holistic_Information_Security_Prac#comments Local Events <p><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;">The&nbsp; public Holistic Information Security Practitioner (HISP) Certification </span></span></span></p><p><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;">course </span></span></span><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;">will be </span></span></span><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;"> </span></span></span><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;">held at SAIC in&nbsp;San Diego, CA:</span></span></span><br /><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;">&nbsp;</span></span></span><span style="font-size: small;"><span style="font-family: Arial;"><span style="color: black;"><br /></span></span></span></p><p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Arial;"><strong><span style="color: black;">DATE:</span></strong> &nbsp; </span></span><span style="font-size: small;"><span style="font-family: Arial;">March 15-19, 2010</span></span><span style="font-size: small;"><span style="font-family: Arial;"><br /></span></span></p><p class="MsoNormal"><strong><span style="font-size: small;"><span style="font-family: Arial;">TIME:&nbsp;&nbsp;&nbsp; </span></span></strong><span style="font-family: Arial;"><span style="font-size: small;">8:30 AM - 5:30 PM (Mon - Thurs) <br /></span></span></p><p><span style="font-family: Arial;"> <span><span style="font-size: small;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; &nbsp; and 8:30 AM - 3:00 PM (Friday)</span></span></span></p><p class="MsoNormal"><span style="font-size: small;"><span style="font-family: Arial;"><strong><span style="color: black;">LOCATION</span></strong><span style="color: black;">:&nbsp;</span></span></span><span style="font-family: Arial;"><span style="color: black;">SAIC - Campus Point Facility </span><br /></span></p><p class="MsoNormal"><span style="font-family: Arial;"><span style="color: black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<strong> </strong>Building E - Room 2200</span> </span></p><p class="MsoNormal" style="margin-left: 0.5in;">&nbsp;<span style="font-family: Arial;"><span style="color: black;">&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 10260 Campus Point Drive</span></span></p><p class="MsoNormal" style="margin-left: 0.5in;"><span style="font-family: Arial;"><span style="color: black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; San Diego, CA 92121-1578</span></span></p><p class="MsoNormal"><span style="font-size: 10pt; font-family: &quot;sans-serif&quot;; color: black;">&nbsp;</span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-family: Arial;"><span style="font-size: small;"><i><span style="color: rgb(31, 73, 125);">&quot;....</span></i></span><i><span style="color: rgb(31, 73, 125);">T</span>he Holistic Information Security Practitioner (HISP) Certification course is one of the fastest growing information security certifications for <span style="background: none repeat scroll 0% 0% transparent; cursor: pointer; -moz-background-inline-policy: continuous;" class="yshortcuts" id="lw_1267990370_10">Information Security Practitioners</span>, Managers and Officers. In the current global economic recession, a recent </i></span><i><span style="font-family: &quot;sans-serif&quot;;"><a rel="nofollow" target="_blank" href="http://www.careerbuilder.com/Article/CB-829-Who-is-Hiring-Is-Your-Job-Recession-Proof/?ArticleID=829&amp;cbRecursionCnt=1&amp;cbsid=5dbc14180e0b49c2bb54ee25c66ed8c7-291063740-wq-6&amp;ns_siteid=ns_us_g_recession_proof_jobs__"><span style="font-family: Arial;"><span class="yshortcuts" id="lw_1267990370_11">CareerBuilder.com report</span></span></a></span></i><span style="font-family: Arial;"><i>&nbsp; indicates that the Information <span class="yshortcuts" id="lw_1267990370_12">Security Manager job</span> is one of the 5 recession proof jobs....</i></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><i><span style="font-family: &quot;sans-serif&quot;;">&nbsp;</span></i><span style="font-size: small;"><span style="font-family: Arial;">This is the only integration course that provides practical education on the integration of best practices for Information Security Management, Information Systems Auditing and multiple <span style="background: none repeat scroll 0% 0% transparent; cursor: pointer; -moz-background-inline-policy: continuous;" class="yshortcuts" id="lw_1267990370_13">Regulatory Compliance requirements</span> and how to map multiple regulatory requirements to the internationally accepted best practices framework of ISO/IEC 27002:2005 and the ISO/IEC 27001:2005 standard &ndash; a globally accepted standard that can help implement a holistic, comprehensive and effective <span style="border-bottom: 1px dashed rgb(0, 102, 204); cursor: pointer;" class="yshortcuts" id="lw_1267990370_14">information security management</span> system. </span></span></p><p class="MsoBodyText2"><span style="font-size: small;"><span style="font-family: Arial;">&nbsp;</span></span><span style="font-size: small;"><span style="font-family: Arial;">The course covers the mapping of ISO/IEC 27002:2005 with COBIT, COSO and ITIL then explains a methodology to map regulations such as PCI Data Security (Visa CISP), Canadian Bill C-198, OSFI, PIPEDA, PIPA, PHIPA, UK Data Protection Act, EU Directive on Privacy, <span class="yshortcuts" id="lw_1267990370_15">California</span> SB-1386, HIPAA Security, FFIEC, GLB Act, FISMA (NIST 800-53/FIPS 200), <span class="yshortcuts" id="lw_1267990370_16">Sarbanes-Oxley Act</span> (Security), <span class="yshortcuts" id="lw_1267990370_17">FACT Act</span> to the ISO 27002:2005 framework. </span></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-size: small;"><span style="font-family: Arial;">This course addresses the most pressing issues <span style="background: none repeat scroll 0% 0% transparent; cursor: pointer; -moz-background-inline-policy: continuous;" class="yshortcuts" id="lw_1267990370_18">Information Security Practitioners</span> face worldwide, which is safeguarding sensitive information with a balanced focus on People, Process and Technology whilst meeting legal, contractual and <span class="yshortcuts" id="lw_1267990370_19">regulatory compliance requirements</span>.</span></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-size: small;"><span style="font-family: Arial;">&nbsp;</span></span><span style="font-family: Arial;">A number of Fortune 500 and Global 2000 companies such as <span style="background: none repeat scroll 0% 0% transparent; cursor: pointer; -moz-background-inline-policy: continuous;" class="yshortcuts" id="lw_1267990370_20">Microsoft Corporation</span>, <span class="yshortcuts" id="lw_1267990370_21">Cisco Systems</span>, <span style="border-bottom: 1px dashed rgb(0, 102, 204); cursor: pointer;" class="yshortcuts" id="lw_1267990370_22">Sempra Energy</span>, United Airlines and Verizon Business have each trained from between 10 to 60 of their Information Security &amp; Compliance specialists through the HISP public and private onsite classes.</span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-family: &quot;sans-serif&quot;;"> </span></p><p><span style="font-size: small;"><span style="font-family: Arial;"> <strong>COST:&nbsp;</strong><span style="color: black;">HISP Certification course with Examination - </span>&#36;2995 (<strong><span style="color: rgb(255, 0, 0);">before ISSA/ISACA/ASIS 15% discount</span></strong>)</span></span></p><p><span style="font-family: Arial;"> &nbsp; </span><span style="font-size: small;"><span style="font-family: Arial;"> &nbsp; </span><span style="font-family: Arial;"> </span></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-family: Arial;"><span style="color: rgb(0, 0, 255);"><strong>(</strong>NOTE:There is a 15% discount for ISSA, ISACA and ASIS members <b><span style="text-decoration: underline;">in good standing</span></b> for these classes, this discount is approximately &#36;450 which almost covers the examination fee of &#36;499)</span></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><strong><span style="color: rgb(0, 0, 0);"><span style="font-size: small;"><span style="font-family: Arial;"><span>REGISTRATION URL: <a href="https://www.compliancehealthcheck.com/secure/classregister.htm" target="_blank">https://www.compliancehealthcheck.com/secure/classregister.htm</a><br /></span></span></span></span></strong></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-family: Arial;"><b><span style="color: red;">When registering online using the above URL, please enter &ldquo;Sean Lewis&rdquo; </span></b><b><span style="color: red;">in the Registration Form field &ldquo;Referral Source&rdquo;,</span></b><b><span style="color: red;"> to enable eFortresses to grant you the 15% discounted price and to track your registration.</span></b></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><strong>REGISTRATION EMAIL:&nbsp; </strong><span style="text-decoration: underline;"><a href="mailto:training@eFortresses.com?subject=Requestt%20For%20Registration%20-%20HISP%20Training" rel="nofollow"><span style="font-size: small;"><span style="font-family: Arial;"><span style="text-decoration: underline;"><span style="color: blue;">training@eFortresses.com</span></span></span></span></a></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;"><span style="font-family: Arial;"><b><span style="color: red;">When registering online using the above email address, please enter &ldquo;REFERENCE: Sean Lewis&rdquo; in the email &quot;Subject&quot; area, to enable eFortresses to grant you the 15% discount and to track your registratio</span><span style="color: red;">n.</span></b></span></p><p class="MsoNormal" style="margin-right: 0in; margin-bottom: 5pt; margin-left: 0in; text-align: justify;">Additional San Diego HISP course dates are:</p><ul> <li><span style="color: rgb(0, 0, 0);">June 7-11, 2010</span></li> <li><span style="color: rgb(0, 0, 0);">September 13-17, 2010</span></li> <li><span style="color: rgb(0, 0, 0);">December 13-17, 2010</span></li></ul><p style="margin-bottom: 5pt;" class="MsoNormal"><span style="font-family: Arial;"><span style="color: rgb(0, 0, 0);">For more <strong>general</strong> information regarding the HISP Certification Course, please visit&nbsp;</span> <a href="http://www.hispcertification.org/" target="_blank" rel="nofollow"><span style="text-decoration: underline;"><span style="color: blue;">http://www.hispcertification.org</span></span></a> </span></p><p style="margin-bottom: 5pt;" class="MsoNormal"><span style="font-family: Arial;"><span style="color: rgb(0, 0, 0);">For more <strong>genereral</strong> information regarding the HISP Institute &amp; <span id="lw_1267993438_22" class="yshortcuts" style="background: none repeat scroll 0% 0% transparent; cursor: pointer; -moz-background-inline-policy: continuous;">Certification</span>, please visit</span> </span><span style="font-family: &quot;sans-serif&quot;;"><a href="http://www.hispi.org/" target="_blank" rel="nofollow"><span style="font-family: Arial;"><span style="text-decoration: underline;"><span style="color: blue;">http://www.hispi.org</span></span></span></a><b> </b></span></p><p style="" class="MsoNormal"><span style="color: rgb(31, 73, 125);">&nbsp;</span></p><hr /><p>&nbsp;</p> http://www.sdissa.org/trackback.php?id=Holistic_Information_Security_Prac FBI Computer Scientist Position http://www.sdissa.org/article.php?story=20080804120503123 http://www.sdissa.org/article.php?story=20080804120503123 Mon, 04 Aug 2008 09:05:03 -0700 Careers <font face="Arial"><div><strong>Company: </strong>FBI, San Diego, CA</div><div><strong>Contact: </strong>CS Jennifer Kolde - FBI San Diego Division <span></span></div><div><strong>Status:</strong> Position Open</div><div><strong>Type: </strong>Full Time</div></font> <p class="MsoNormal"><span>The FBI, San Diego Field Office, National Security Cyber Squad, will post a position for a Computer Scientist in the near future.&nbsp; The Computer Scientist (CS) is responsible for providing technical support and subject matter expertise to FBI Special Agents and Intelligence Analysts related to sensitive computer network intrusions and intelligence matters.&nbsp; While the CS will perform a variety of duties, his/her primary responsibility is identifying computer network attacks and data compromise using techniques such as malware analysis, forensic analysis, log file analysis, large-scale data analysis (correlation / trending), network traffic analysis, and the development of tools and / or programs to assist with or automate the same.&nbsp; </span></p><p class="MsoNormal"><span>The CS will work in a team environment in the production of relevant written reporting and briefings within the FBI and other U.S. Government entities.&nbsp; As such, strong written and oral communications skills are essential.&nbsp; In addition, as a subject matter expert, the CS is expected to monitor and provide insight into trends in the security community (vulnerabilities, threats, exploits, changing techniques, risks, etc.). </span></p><p class="MsoNormal"><span>The position will be at the GS13 or GS14 level with an adjustment for San Diego locality pay.&nbsp; The salary grade and step are determined from the selected candidate&rsquo;s experience and prior employment.&nbsp; </span></p><p class="MsoNormal"><span>Interested candidates must meet the following minimum requirements to apply:</span></p><ul> <li><span>US Citizen<br /> </span></li> <li><span>Ability to obtain a Top Secret-SCI clearance</span></li> <li><span>Completion of a four-year course of study at an accredited college or university (e.g., Bachelor's degree or higher)</span></li> <li><span>Minimum of 30 semester hours of mathematics, statistics, and computer science</span></li></ul><p class="MsoNormal"><span>Once posted, the position will be open to applicants for only a short window of time (usually 10 days).&nbsp; As such, we encourage you to forward this information to anyone who may be interested in applying so that interested candidates can become familiar with the hiring process, especially the need to apply immediately and completely when the position is posted.&nbsp; The application process requires submission of a current resume, official college / university transcripts, and completion of an online application (to include a set of multiple choice / essay questions describing the candidate's relevant experience).&nbsp; Interested candidates are strongly encouraged to visit the FBI Jobs web site (<a href="http://www.fbijobs.gov/">http://www.fbijobs.gov</a>) to register and review the application process.&nbsp; </span></p><p class="MsoNormal"><span>Additional information about employment with the Federal Bureau of Investigation can be found on the following web sites:</span></p><p class="MsoNormal"><span>1. FBIJobs:&nbsp; <a href="http://www.fbijobs.gov/">www.fbijobs.gov</a></span></p><p class="MsoNormal"><span>&nbsp;&nbsp; - Job posting and application web site.</span></p><p class="MsoNormal"><span>2. Office of Personnel Management:&nbsp; <a href="http://www.opm.gov/">www.opm.gov</a></span></p><p class="MsoNormal"><span>&nbsp;&nbsp; - Salary, benefits, and other information related to Government employment</span></p><p class="MsoNormal"><span>3.&nbsp; FBI:&nbsp; <a href="http://www.fbi.gov/">www.fbi.gov</a></span></p><p class="MsoNormal"><span>&nbsp;&nbsp; - FBI web site</span></p><p class="MsoNormal"><span>Candidates who are interested in applying for the position should register on the FBIJobs web site, and sign up for email notification to receive an alert when the position is posted.</span></p> The Admiral Baker Clubhouse http://www.sdissa.org/article.php?story=admiral_baker_clubhouse http://www.sdissa.org/article.php?story=admiral_baker_clubhouse Wed, 04 Jun 2008 06:15:50 -0700 http://www.sdissa.org/article.php?story=admiral_baker_clubhouse#comments General News <div><span><strong>MEETING LOCATION</strong></span><br />Located just East of Friar's Road and Highway 15<br /><br /><strong>The Admiral Baker Clubhouse</strong><br />At 2400 Admiral Baker Rd,&nbsp; San Diego, CA 92120<br />(619) 487-0090</div><p><br />Take Friars road east until Santo Road, take a left and very soon veer right onto the Admiral Baker Clubhouse.&nbsp; Then stay left and follow the road around to the clubhouse.&nbsp; No base sticker or government badge is needed.<br /><br />You&rsquo;re going to love the setting, ambiance, and history of the place!<br /><br /><strong>Driving Directions from Highway 15:</strong><br /><br />1) Take Friars Road exit East. Pass through the first stoplight (Rancho Mission).<br />2) Turn left at the second light (Santo Road).<br />3) Make an immediate right turn onto Admiral Baker Road.<br />4) Follow the road to its end at the golf course clubhouse.<br /><br /><img width="442" height="462" src="http://www.sdissa.org/images/library/Image/images/admiral_baker_clubhouse.jpg" alt="" /></p> http://www.sdissa.org/trackback.php?id=admiral_baker_clubhouse IA/Security resources, references, guides http://www.sdissa.org/article.php?story=20071217151212844 http://www.sdissa.org/article.php?story=20071217151212844 Mon, 17 Dec 2007 12:12:12 -0800 Education <div><strong>Useful web sites&nbsp;&nbsp;&nbsp; (Main ones) </strong></div><div><a href="https://infosec.navy.mil/docs/index.jsp">https://infosec.navy.mil/docs/index.jsp</a></div><div><a href="http://iase.disa.mil/techguid/index.html">http://iase.disa.mil/techguid/index.html</a></div><div>&nbsp;</div><div><strong>&nbsp;And these others</strong></div><div><a href="http://www.sse-cmm.org/lib/lib.asp">http://www.sse-cmm.org/lib/lib.asp</a></div><div><a href="https://www.fleetforces.navy.mil/netwarcom/navycanda">https://www.fleetforces.navy.mil/netwarcom/navycanda</a></div><div><a href="https://www.us.army.mil/suite/portal/index.jsp">https://www.us.army.mil/suite/portal/index.jsp</a></div><div><a href="http://csrc.nist.gov/">http://csrc.nist.gov/</a></div><div><a href="http://www.nsa.gov/ia/index.cfm">http://www.nsa.gov/ia/index.cfm</a></div><div><a href="http://www.iatf.net/">http://www.iatf.net/</a></div><div><a href="void(0);/*1197933050781*/">http://www.cert.org/</a></div><div><a href="http://www.commoncriteriaportal.org/ ">http://www.commoncriteriaportal.org/ </a></div><div><a href="http://www.amc.army.mil/amc/ci/matrix/policy/policy_new.htm">http://www.amc.army.mil/amc/ci/matrix/policy/policy_new.htm</a> </div><div><a href="https://www.sans.org/about/sans.php">https://www.sans.org/about/sans.php</a></div><div><a href="http://iac.dtic.mil/iatac/">http://iac.dtic.mil/iatac/</a></div><div><a href="http://www.cerias.purdue.edu/">http://www.cerias.purdue.edu/</a></div><div><a href="http://security.sdsc.edu/">http://security.sdsc.edu/</a></div> <div><div><strong>Main Statues / Directives / Guidance</strong></div><ul style="MARGIN-TOP: 0in"> <li>Clinger-Cohen Act (CCA), 1996 </li> <li>Government Information Security Reform Act (GISRA), 2000 </li> <li>Federal Information Security Management Act (FISMA), 2002 </li> <li>OMB Circular A-130, 2000 </li> <li>DoDD 8500.01E -&nbsp;Information Assurance (IA), April 2007 (changed from 8500.1) </li> <li>DoDI 8500.2 - IA Implementation, Feb 03 </li> <li>DoDI 8580.1 - IA in the Defense Acquisition System, July 04 </li> <li>Information Assurance Technical Framework (IATF), Sep 2000 (www.iatf.net) </li> <li>GIG IA Architecture, ICD (6 Mar 06) &nbsp;and Strategy &nbsp;(and related GIAP artifacts, plans, priorities) </li> <li>NSTISSP 11 - National Security Telecommunications&nbsp;and Information Systems Security </li> <li>DoDI 8510.bb - DoD Information Assurance Certification and Accreditation Process (DIACAP) </li></ul><div>&nbsp;</div><div>&nbsp;</div><div>&nbsp;</div><div><strong>Also see:</strong></div><div>- DoDD 5000.1 - The Defense Acquisition System, May 03</div><div>- DoDI 5000.2 - Operation of the Defense Acquisition System, May 03</div><div>-&nbsp;&nbsp;&nbsp; Section 2224 of title 10, US Code &ldquo;Defense Information Assurance Program&rdquo;</div><div><strong><span>http://iase.disa.mil/policy-guidance/index.html#DoD</span></strong></div><div>&nbsp;</div></div><span><br /></span><div><strong>Preferred Product Lists (PPL)</strong> -&nbsp;Generally programs should still to using PPL devices / processes in building their systems. Other than the type-1 COMSEC devices, which require individual certification letters held by the companies, the list below is probably the 90% solution without getting industry groups such as ICSA labs.</div><div>&nbsp;</div><div>NIST FIPS 140 certifications: http://csrc.nist.gov/groups/STM/cmvp/index.html</div><div>NIST algorithm certifications: http://csrc.nist.gov/groups/STM/cavp/index.html</div><div>NIAP/Common Criteria: http://niap.bahialab.com/cc-scheme/</div><div>DISA IASE: http://iase.disa.mil/index2.html</div><div>NSA IAD: http://www.nsa.gov/ia/index.cfm</div><div>&nbsp;</div><div>NOTE - A PPL list can range from algorithms to specific equipment configurations. For example, one radio might have FIPS approval when ordered using model number 123 and an NSA type-1 certification when ordered using model number 456.<span>&nbsp;&nbsp; Same is true for a router, IPS,...&nbsp;&nbsp;&nbsp;&nbsp; Yet even if a device has a CC EAL-4 certification, you still need to ensure that the protection profile used and the security target meets your specific application.</span></div><div><strong>&nbsp;</strong></div><div><strong>&nbsp;</strong></div><div><strong><em>DoDD 8500.01E, October 24, 2002</em></strong><em>&nbsp;&nbsp; &nbsp;&nbsp;(</em> ENCLOSURE 1, REFERENCES (Continued))</div><div>(e) DoD CIO Memorandum 6-8510, &quot;Guidance and Policy for Department of Defense Global Information Grid Information Assurance,&quot; June 16, 2000 (<em><span>hereby canceled</span></em>)</div><div>(f) DoD 5025.1-M, &quot;DoD Directives System Procedures,&quot; <em>March 5, 2003</em></div><div>(g) Executive Order 12333, &quot;United States Intelligence Activities,&quot; December 4, 1981</div><div>(h) DoD Directive <em>5144.1, &ldquo;Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer (ASD(NII)/DoD CIO),&rdquo; May 2, 2005</em></div><div>(i) National Security Telecommunications and Information Systems Security Instruction (NSTISSI) No. 4009, &quot;National Information Systems Security Glossary,&quot; September 20002</div><div>(j) OMB Circular A-130, &quot;Management of Federal Information Resources, Transmittal 4,&quot; November 30, 2000</div><div>(k) DoD Directive 5000.1, &quot;The Defense Acquisition System,&quot; <em>May 12, 2003</em></div><div>(l) Sections 1423 and 1451 of title 40, United States Code, &quot;Division E of the Clinger-Cohen Act of 1996&quot;</div><div>(m) DoD Directive O-8530.1, &quot;Computer Network Defense,&quot; January 8, 2001</div><div>(n) DoD 5200.2-R, &quot;DoD Personnel Security Program,&quot; <em>December 16, 1986</em></div><div>(o) DoD 5200.1-R, &quot;DoD Information Security Program Regulation,&quot; January 14, 1997</div><div>(p) DoD Directive 5230.11, &quot;Disclosure of Classified Military Information to Foreign Governments and International Organizations,&quot; June 16, 1992</div><div>(q) DoD Directive 5230.20<em>E</em>, &quot;Visits <em>and </em>Assignments of Foreign Nationals,&quot; <em>June 22, 2005</em></div><div>(r) DoD Instruction 5230.27, &quot;Presentation of DoD-Related Scientific and Technical Papers at Meetings,&quot; October 6, 1987</div><div>(s) DoD Directive 5230.9, &quot;Clearance of DoD Information for Public Release,&quot; April 9, 1996</div><div>(t) DoD Instruction 5230.29, &quot;Security and Policy Review of DoD Information for Public Release,&quot; August 6, 1999</div><div>(u) DoD Instruction 5200.40, &quot;DoD Information Technology Security Certification and Accreditation (C&amp;A) Process (DITSCAP),&quot; December 30, 1997</div><div>(v) DoD Directive C-5200.5, &quot;Communications Security (COMSEC),&quot; (U) April 21, 1990</div><div>(w) National Security Telecommunications and Information Systems Security Policy (NSTISSP) No. 11, &quot;National Policy Governing the Acquisition of Information Assurance (IA) and IA-enabled Information Technology Products,&quot; January 2000</div><div>(x) DoD Directive <em>3020.40, &ldquo;Defense Critical Infrastructure Program (DCIP),&rdquo; August 19, 2005</em></div><div>(y) DoD 5220.22-M, &quot;National Industrial Security Program Operating Manual,&quot; January 1995 and &quot;National Industrial Security Program Operating Manual Supplement,&quot; February 1995</div><div>&nbsp;</div><div><strong>&nbsp;</strong></div><div><strong>&nbsp;</strong></div><div><strong>****&nbsp;<a name="OLE_LINK1">CJSCSI 6510.1E, </a>Information Assurance And Computer Network Defense</strong>.</div><div>a. Joint Pub 1-02 Series, &ldquo;Department of Defense Dictionary of Military and Associated Terms&rdquo;</div><div>b. CNSS Instruction No. 4009 Series, &ldquo;National Information Assurance (IA) Glossary&rdquo;</div><div>c. DOD Directive 8500.1 Series, &ldquo;Information Assurance (IA)&rdquo;</div><div>d. DOD Directive O-8530.1 Series, &ldquo;Computer Network Defense (CND)&rdquo;</div><div>e. DOD Instruction 8500.2 Series, &ldquo;Information Assurance (IA) Implementation&rdquo;</div><div>f. DOD Instruction O-8530.2, 9 March 2001, &ldquo;Support to Computer Network Defense (CND)&rdquo;</div><div>g. CJCSM 6510.01 Series, &ldquo;Defense-in-Depth: Information Assurance (IA) and Computer Network Defense (CND)&rdquo;</div><div>h. DOD Directive 8100.1 Series, &ldquo;Global Information Grid (GIG) Overarching Policy&rdquo;</div><div>i. DOD CIO Memorandum, 6 July 2006, &rdquo;Department of Defense (DoD) Information Assurance (IA) and Certification and Accreditation (C&amp;A) Process Guidance&rdquo;</div><div>j. DOD Instruction 8551.1 Series, &ldquo;Ports, Protocols and Services Management (PPSM)&rdquo;</div><div>k. CJCSI 6211.02 Series, &ldquo;Defense Information System Network (DISN): Policy, Responsibilities and Processes&rdquo;</div><div>l. CNSSP-1 Series, &ldquo;National Policy for Safeguarding and Control of Communications Security Materials&rdquo;</div><div>m. DOD Regulation 5200.1-R Series, &ldquo;Information Security Program&rdquo;</div><div>n. National Security Agency, 2003/2004, &ldquo;Information Assurance Manual&rdquo;</div><div>o. Title 10, United States Code, Section 2315</div><div>p. NSTISSP No. 11 Revised, June 2003, &ldquo;National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products&rdquo;</div><div>q. Title 15, United States Code, Section 278g-3</div><div>r. ASD(NII) memorandum, 28 May 2003, &quot;Open Source Software in the Department of Defense&quot;</div><div>s. NIST Special Publication 800-59, August 2003, &ldquo;Guidelines for Identifying an Information System as a National Security System&rdquo;</div><div>t. DOD Instruction 8552.01 Series, &quot;Use of Mobile Code Technologies in DoD Information Systems&quot;</div><div>u. NTISSP No. 200, 15 July 1987, &ldquo;National Policy on Controlled Access Protection&rdquo;</div><div>v. DOD Regulation 5200.2-R Series, &ldquo;Personnel Security Program&rdquo;</div><div>w. ASD(C3I) memorandum with amendment, 11 January 2002, &ldquo;Web Site Administration, Policies and Procedures&rdquo;</div><div>x. DOD Directive 5230.9 Series, &ldquo;Clearance of DOD Information for Public Release&rdquo;</div><div>y. DOD Instruction 5230.29 Series, &ldquo;Security and Policy Review of DOD Information for Public Release&rdquo;</div><div>z. DOD CIO Memorandum, 25 April 2006, &quot;Guidance to Facilitate Information Sharing on DoD Information Technology Systems (U)&quot;</div><div>aa. DOD Directive 1035.1 Series, &ldquo;Telework Policy for Department of Defense&rdquo;</div><div>bb. DOD Directive 5200.1 Series, &ldquo;DOD Information Security Program&rdquo;</div><div>cc. DOD Directive 5200.2, 9 April 1999, &ldquo;DOD Personnel Security Program&rdquo;</div><div>dd. CJCSI 3213.01 Series, &ldquo;Joint Operations Security&rdquo;</div><div>ee. NTISSD No. 600, 10 April 1990, &ldquo;Communications Security (COMSEC) Monitoring&rdquo;</div><div>ff. DOD Directive 4640.6, 26 June 1981, &ldquo;Communications Security Telephone Monitoring and Recording&rdquo; </div><div>gg. Title 18, United States Code, Section 2510, et seq.</div><div>hh. Title 50, United States Code, Section 1801, et seq.</div><div>ii. DISA, 4 October 2002, &ldquo;Application Security Developer&rsquo;s Guide, Version 1.0&rdquo;</div><div>jj. ASD(C3I) memorandum, 16 January 1997, &ldquo;Policy on Department of&nbsp;Defense Electronic Notice and Consent Banner&rdquo;</div><div>kk. DOD General Counsel memorandum, 27 March 1997, &ldquo;Communications&nbsp;Security (COMSEC) and Information Systems Monitoring&rdquo;</div><div>ll. DOD Directive 8520.2, 1 April 2004, &ldquo;Public Key Infrastructure (PKI) and Public Key (PK) Enabling&rdquo;</div><div>mm. DOD Directive 8570.1 Series, &quot;Information Assurance Training, Certification, and Workforce Management&quot;</div><div>nn. DOD 8570.01-M Series, &quot;Information Assurance Workforce Improvement Program&quot;</div><div>oo. NSTISSP No. 101, 14 September 1999, &ldquo;National Policy on Securing Voice Communications&rdquo;</div><div>pp. FIPS 140-2, 25 May 2001, &ldquo;Security Requirements for Cryptographic Modules&rdquo;</div><div>qq. DOD CIO memorandum, 3 July 2007, &quot;Encryption of Sensitive Unclassified Data at Rest on Mobile Computing Devices and Removable Storage Media&quot;</div><div>rr. USSTRATCOM, 11 August 2006, &quot;Joint Concept of Operations for Global Information Grid NetOps&quot;</div><div>ss. DOD Directive 3020.40, 19 August 2006, &quot;Defense Critical Infrastructure Program&quot;</div><div>tt. DCID 6/3, 5 June 1999, &ldquo;Protecting Sensitive Compartmented Information Within Information Systems&rdquo;</div><div>uu. CJCSI 3213.01 Series, &quot;Joint Operations Security&quot;</div><div>vv. CJCSI 3121.01 Series, &ldquo;Standing Rules of Engagement/Standing Rules for the Use of Force&rdquo;</div><div>ww. CJCSI 6510.06 Series, &ldquo;Communications Security Releases to Foreign Nations&rdquo;</div><div>xx. CJCSI 6212.01 Series, &ldquo;Interoperability and Supportability of Information Technology and National Security Systems&rdquo;</div><div>yy. CJCSI 3137.01 Series, &ldquo;The Joint Warfighting Capabilities Assessment Process&rdquo;</div><div>zz. CJCSI 3170.01 Series, &ldquo;The Functional Capabilities Board Process&rdquo;</div><div>aaa. ASD(C3I) memorandum, 26 February 2003, &ldquo;Guidance for Computer Network Defense Response Actions&rdquo;</div><div>bbb. DOD Directive 8581.1E Series, &quot;Information Assurance (IA) Policy for Space Systems Used by the Department of Defense &quot;</div><div>ccc. Strategic Command Instruction (SI) 1009-01, 1 August 2006, &quot;Information Assurance (IA) Implementation for Space Systems Used by the Department of Defense&quot;</div><div>ddd. CJCSI 2300.01 Series, &rdquo;International Agreements&rdquo;</div><div>eee. CJCSI 5130.01 Series, &ldquo;Relationships Between Commanders of Combatant Commands and International Commands and Organizations&rdquo;</div><div>fff. CJCSI 5221.01 Series, &ldquo;Delegation of Authority to Commanders of Combatant Commands to Disclose Classified Military Information to Foreign Governments and International Organizations&rdquo;</div><div>ggg. DOD Directive 4630.5, 5 May 2004, &ldquo;Interoperability and Supportability of Information Technology (IT) and National Security Systems (NSS)&rdquo;</div><div>hhh. DOD 000-151-94, 24 May 1994, &ldquo;Department of Defense Intelligence Production Program (DoDIPP)&rdquo;</div><div>iii. DIA message 021727Z JUN 98, &ldquo;Indications and Warning for Information&nbsp;Warfare/Information Operations (CNA-WATCHCON)&rdquo;</div><div>jjj. NSD-42, 5 July 1990, &ldquo;National Policy for the Security of National Security Telecommunications and Information Systems&rdquo;</div><div>kkk. Initial Capabilities Document (ICD), 6 March 2006, &quot;Initial Capabilities Document (ICD) for Global Information Grid (GIG) Information Assurance (IA)&quot;</div><div>lll. NSTISSD No. 503, 30 August 1993, &ldquo;Incident Response and Vulnerability Reporting for National Security Systems&rdquo;</div><div>mmm. Strategic Command Directive (SD) 527-1, 27 January 2006, &quot;Department of Defense (DOD) Information Operations Condition (INFOCON) System Procedures&quot;</div><div>nnn. CJCSM 3402.01 Series, &ldquo;Alert System of the Chairman of the Joint Chiefs of Staff&rdquo;</div><div>ooo. Military Extraterritorial Jurisdiction Act of 2000, 18 U.S.C. 3261, et seq.</div><div>ppp. DOD Instruction 3020.41 Series, &ldquo;Contractor Personnel Authorized to Accompany the U.S. Armed Forces.&rdquo;</div><div>qqq. JTF-GNO Technical Bulletin 06-005, 191500Z May 2006, &quot;Coordinating Authorized Scanning Activity Across DOD Networks&quot;</div><div>rrr. CJCSI 3401.01 Series, &ldquo;Chairman&rsquo;s Readiness System&rdquo;</div><div>sss. CJCSI 3401.03 Series, &ldquo;Information Assurance (IA) and Computer Network Defense (CND) Joint Quarterly Readiness Review (JQRR) Metrics&rdquo;</div><div>ttt. CJCSI 6731.01 Series, &ldquo;Global Command and Control System Security Policy&rdquo;</div><div>uuu. Deputy Secretary of Defense memorandum, July 2000, &ldquo;Use and Protection of Portable Computing Devices&rdquo;</div><div>vvv. DOD Directive 8100.2 Series, &quot;Use of Commercial Wireless Devices, Services, and Technologies in the Department of Defense (DOD) Global Information Grid (GIG)&quot;</div><div>www. DOD Directive, C-5200.19, 16 May 1995, &ldquo;Control of Compromising Emanations&rdquo;</div><div>xxx. ASD(NII) memorandum, 2 June 2006, &quot;Use of Commercial Wireless Local-Area Network (LAN) Devices, Systems and Technologies in Department of Defense (DoD) Global Information Grid (GIG)&quot;</div><div>yyy. PL 104-191, 21 August 1996, Health Insurance Portability and Accountability Act of 1996&quot;</div><div>zzz. Title 5, U.S.C., Section 552a, et seq.</div><div>aaaa. DOD Directive C-5200.5 Series, &ldquo;Communications Security (COMSEC)&rdquo;</div><div>bbbb. CJCSI 6510.02 Series, &quot;Cryptographic Modernization Planning&quot;</div><div>cccc. CJCSN 6510 Series, &quot;Information Assurance Cryptographic Equipment Modernization Requirements&quot;</div><div>dddd. Special Publication 800-34 Series, &ldquo;Contingency Planning Guide for Information Technology Systems&rdquo;</div><div>eeee. DOD Directive 5200.8, 25 April 1991, &ldquo;Security of DoD Installations and Resources&rdquo;</div><div>ffff. Title 44, U.S.C. Section 3542, Federal Information Security Management Act of 2002</div><div>gggg. American National Standard for Telecommunications, 28 February 2001, &ldquo;Telecom Glossary&rdquo;</div><div>hhhh. National Military Strategy for Cyberspace Operations, November 2006</div> Information Systems Auditor Sr. http://www.sdissa.org/article.php?story=20071029105647201 http://www.sdissa.org/article.php?story=20071029105647201 Mon, 29 Oct 2007 08:56:00 -0700 Careers <font face="Arial"><div><strong>Company: </strong>Scripps Health, San Diego, CA</div><div><strong>Contact:</strong> <font face="Arial">Human Resources - <a href="mailto:esparza.veronica@scrippshealth.org">esparza.veronica@scrippshealth.org</a></font></div><div><strong>Status:</strong> Position Open</div><div><strong>Type: </strong>Full Time</div></font> <div><div><span>Join a dynamic organization where you will be challenged and grow with a fast-paced, technology driven, leading healthcare organization with over 11,000 employees. </span><span>This position is a key member of a nationally prominent Audit &amp; Compliance Services Department and Information Security Team. Responsibilities will include, but are not limited to: reviews of implemented clinical and business application system controls, IT general controls for key infrastructure components, and new implementation projects.</span></div></div><div>&nbsp;</div><div><font size="2">The position will lead team reviews and oversee activities or other auditors, conduct audits and review processes and safeguards to protect the organization&rsquo;s information system resources and their data confidentiality, integrity, and availability, as well as assess related security system vulnerabilities for: application software systems, operating systems, telecommunication networks, disaster recovery, as well as Scripps policies, Information Technology procedures, and standards. Also, the position will provide support for compliance and investigative audit projects that are part of the annual audit plan or initiated based on new implementation projects, develop plans for remediation of internal control gaps and deficiencies, reducing costs, and or improving operational efficiency and effectiveness.</font></div><div>&nbsp;</div><div><font size="2"><strong>Basic Qualifications:</strong> Bachelor&rsquo;s degree required in Accounting, Management Information Systems, Computer Engineering, Computer Science, or a related discipline.&nbsp;At least two of the certifications of CISA, CIA, and CPA designations in good standing at the time of hire are required or successful active pursuit of these designations within 12 months of hire. Required experience/Specialized Skills:&nbsp;Ability to evaluate and audit complex information systems and related information security safeguards.&nbsp;Technical knowledge of information security concepts, information technology internal controls and safeguards, technologies, system vulnerabilities, and applicable rules and regulations.&nbsp;Understanding of key clinical information systems and processes in an integrated healthcare delivery environment.&nbsp;Knowledge of the IIA professional auditing standards, as well as internal and information security control frameworks and principles. Demonstrated effective interpersonal, written, and verbal communication skills.&nbsp;High level of personal accountability for accuracy, attention to detail, task prioritization, and timely completion.&nbsp;Ability to work independently under conditions of changing priorities due to investigations and special requests; important deadlines; and rapid response to security incidents.&nbsp;Strong technical skills and ability to learn and deploy computer assisted audit techniques (CAAT) through ACL audit software and other tools. </font></div><div>&nbsp;</div><div><font size="2"><strong>Preferred Qualifications:</strong> Master's preferred.</font></div><div>&nbsp;</div><div><font size="2">Please send your resume together with your salary requirements. Initial salary will be commensurate with experience and qualifications. The position will remain open until filled. To apply, visit us online at: </font></div><div><strong><font size="2">Website: </font><a href="http://www.scripps.org/"><span><font size="2">www.scripps.org</font></span></a></strong></div><div>&nbsp;</div><div><font size="2">For further information, please contact:</font></div><div><strong><a href="mailto:esparza.veronica@scrippshealth.org"><span><font size="2">esparza.veronica@scrippshealth.org</font></span></a><font size="2"> &ndash; Human Resources</font></strong></div><div><strong><font size="2">Address: Scripps Health-CP2</font></strong></div><div><font size="2"><strong>4275 Campus Point Court</strong></font></div><div><font size="2"><strong>San Diego</strong><strong>, CA 92121</strong></font></div><div><strong><font size="2">EEO/ AA</font></strong></div><div>&nbsp;</div> Where do I get a copy of the presentation from last month?s meeting? http://www.sdissa.org/article.php?story=20070921082531585 http://www.sdissa.org/article.php?story=20070921082531585 Fri, 21 Sep 2007 05:25:31 -0700 General News <ul> <li><span style="font-family: Arial;">Did you attend last month&rsquo;s meeting and wish you had gotten a copy of the PowerPoint presentation?</span></li> <li><span style="font-family: Arial;">Are you looking to network with other local security professionals and peers?</span></li> <li><span style="font-family: Arial;">Are you looking to improve your own career opportunities or are trying to fill a security position within your department?</span></li> <li><span style="font-family: Arial;">Do you want to get a discount at the next annual security conference?</span></li> <li><span style="font-family: Arial;">Would you like a forum to discuss with your peers the latest trends in technology, Information Assurance, governance, and risk management?&nbsp;</span>&nbsp;</li></ul><p><span style="font-family: Arial;">These are all reasons why you should consider joining the San Diego Chapter of the ISSA.&nbsp; There are of course lots more benefits, so what we&rsquo;ve listed here only scratches the surface.&nbsp; Once you become a member, you can receive a logon access to the secure portion of our chapter website where you can have full access to all of the resources described in the questions above.&nbsp; <a href="http://www.sdissa.org/staticpages/index.php?page=membership">Click here</a> to get more information about becoming a member.</span></p> Security Engineer http://www.sdissa.org/article.php?story=20070920165149641 http://www.sdissa.org/article.php?story=20070920165149641 Thu, 20 Sep 2007 13:51:00 -0700 Careers <p><strong>Company:</strong> Network Vigilence<br /><strong>Contact:</strong> Network Vigilence Human Relations <a href="mailto:hr@netvig.com?subject=Security%20Engineer%20position%20posted%20at%20SDISSA.org">hr@netvig.com</a><br /><strong>Status:</strong>&nbsp; Position OPEN</p> <div><strong><span>Title: &nbsp;Security Engineer - Step Up your Career into Network Security</span></strong></div><div>&nbsp;</div><div><span>Do you want to step up your career into one of the most challenging and rapidly growing IT professions?&nbsp;</span></div><div>&nbsp;</div><div><span>Are you an experienced Network Engineer that understands how to be consultative and personable with clients? </span></div><div>&nbsp;</div><div><span>Can work under a time crunch, figure just about anything out, and quickly learn new technologies even if it means doing it on your own time?</span></div><div>&nbsp;</div><div><span>Have you been looking for that perfect career growth opportunity that will allow you to go to the next level, building upon your solid network experience with security expertise?&nbsp;</span></div><div>&nbsp;</div><div><span>Do you have a deep interest in the world of IT security including hacking/cracking, risk assessments, penetration testing, computer forensics, Network Access Control, Firewalls, intrusion detection, security incident management, encryption, honeypots, and other security technology?</span></div><div>&nbsp;</div><div><span>Then, this might be the perfect opportunity for you.&nbsp;Network Vigilance is a nationally known, 17 year-old information security firm based in San Diego, California.&nbsp;We excel in providing security consulting/guidance, IT risk assessments, Firewall/VPN implementations, IDS/IDP NAC, endpoint, remote access and wireless security solutions, forensic analysis, and managed security services.</span></div><div>&nbsp;</div><div><span>We are seeking an a Senior Network Engineer, who we can develop into a competent Security Engineer, one who has excellent troubleshooting skills, is motivated to learn the security trade, can give great customer service and can perform implementation of various security products, including Check Point Cisco, Juniper, Symantec, Secure Computing, Websense, SourceFire, and others.</span></div><div>&nbsp;</div><div><span>This individual would ideally assist with risk assessments, provide technical product support to existing clients, roll out new security deployments, baseline and tune security devices and systems, implement anti-spam and Web filtering technologies, provide end-user network technical support including occasional weekend and after hours support if necessary.</span></div><div>&nbsp;</div><div><span>Ideal certifications would include MCSE, CCNA, CCNP, A+, N+, MCP, Citrix, VMWare, GIAC, or other security certifications, however experience is more important than certs.&nbsp;</span></div><div>&nbsp;</div><div><span>An excellent background for this role would include high level network administration/network support on Microsoft Server based products, (Windows 2000/2003 Server, IIS, SQL Server, Exchange, ISA, etc.), high level system troubleshooting, Linux/Unix servers, routing and switching, deployment of enterprise firewalls, IDS/IPS, and past deployment or consulting experience with network/security products or services.</span></div><div>&nbsp;</div><div><span>If this seems like appears like the perfect opportunity for you and please send us your resume at <a href="mailto:hr@netvig.com?subject=Security%20Engineer%20position%20posted%20at%20SDISSA.org">hr@netvig.com</a>.&nbsp;Please note that there is no relocation assistance offered for this position.&nbsp;Also, an in-person interview if not multiple interviews in San Diego will also be required, including a technical assessment.</span></div> Security Engineer http://www.sdissa.org/article.php?story=20070920115011163 http://www.sdissa.org/article.php?story=20070920115011163 Thu, 20 Sep 2007 08:50:11 -0700 Careers <font size="2"><div><font size="2"><strong>Company:</strong> Cardinal Health</font></div><div><font size="2"><strong>Contact:</strong>&nbsp;Cardinal Health Staffing&nbsp;&nbsp;<a href="mailto:chris.price@cardinalhealth.com?subject=Security%20Engineer%20position%20posted%20at%20SDISSA.org">chris.price@cardinalhealth.com</a></font></div><div><font size="2"><strong>Status:</strong> </font><font size="2">Position OPEN</font></div></font> <div><div><strong><font size="2">I.</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></strong><strong><font size="2">Basic Function:&nbsp;</font></strong></div></div><div><strong>&nbsp;</strong></div><div><font size="2">This candidate will be a member of a cross functional security team that is responsible for the Certification and Accreditation (e.g., DITSCAP/DIACAP) of products deployed in a government setting as well as for implementing and monitoring of the Company&rsquo;s information security policies and procedures to ensure that electronic protected health information (ePHI) is handled in an appropriate manner and meets all legislative requirements, such as those required by HIPAA.</font></div><div>&nbsp;</div><table style="BORDER-COLLAPSE: collapse" cellspacing="0" cellpadding="0" border="0"> <tbody> <tr> <td valign="top"> <div><strong>&nbsp;</strong></div> <div><strong><font size="2">II. Specific Duties, Activities, and Responsibilities:</font></strong></div> </td> <td valign="top"> <div><strong>&nbsp;</strong></div> <div><strong><font size="2">% of time</font></strong></div> </td> <td> <div><font size="2">&nbsp;</font></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Develop and maintain company information security policies and procedures ensuring compliance with HIPAA security rules as well as government specific (e.g., DIACAP) rules and regulations</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Perform security scans and audits of various systems in order to ensure all compliance regulations are met</font></div> </td> <td valign="top"> <div><strong><font size="2">30%</font></strong></div> </td> <td> <div><font size="2">&nbsp;</font></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Reviews updates and provides compliant specifications for operating systems, databases, and third party software as required</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Ensures that all CTS products maintain status as DITSCAP/DIACAP accredited and adhere to HIPAA regulatory standards, rules, or regulations with respect to technical security of product and information within the product</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Tests systems and ensures that all certified product security related issues are identified, and issues corrective actions as necessary</font></div> </td> <td valign="top"> <div><strong><font size="2">25%</font></strong></div> </td> <td> <div><font size="2">&nbsp;</font></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Advises appropriate business units on current technical security regulation</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Conducts appropriate reviews, audits, and metrics of accredited products</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Coordinates completion/updates for product certification and accreditation</font></div> </td> <td valign="top" colspan="2"> <div><strong><font size="2">25%</font></strong></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Establishes/maintains appropriate QMS policies and guidelines for product teams</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Maintains on-going lifecycle accreditation for certified products</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Conducts assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI)</font></div> </td> <td valign="top" colspan="2"> <div><strong><font size="2">15%</font></strong></div> </td> </tr> <tr> <td valign="top"> <div><a name="OLE_LINK1"><span><span><font size="2">&sect;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Performs special projects, assists in problem solving and quality initiatives as required</font></span></a></div> </td> <td valign="top" colspan="2"> <div><strong><font size="2">5%</font></strong></div> </td> </tr> </tbody></table><div><strong>&nbsp;</strong></div><div><strong><font size="2">III. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Position Requirements:</font></strong></div><div><font size="2"><strong>Reports to:&nbsp;</strong><strong><span>Sr. Security Engineer</span></strong>&nbsp;&nbsp;&nbsp;&nbsp; </font></div><div><font size="2"><strong>Supervises: &nbsp;</strong>Self</font></div><div><font size="2"><strong>Education or Equivalent:&nbsp;</strong>BA/BS in related field</font><span> or equivalent combination of education and experience.</span></div><div>&nbsp;</div><div><strong><font size="2">Experience/Knowledge/Skills Requirements:</font></strong></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Bachelors degree in Information Systems or equivalent experience</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">6 years experience in information systems with at least 2 years focus on network security</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Experience with network/system security scanning tools</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Healthcare experience and CISSP is highly desirable</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">At least two years experience administering or directing security risk management and network compliance programs</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Knowledge and expertise in Federal government regulations (DITSCAP/DIACAP, NICAP, OMB 130, DoD 5800.2 NIST 800-37, FIPS 140-1, &amp;2, FIPS 199, HIPAA, etc).</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Being a highly motivated self-starter with the ability to handle multiple tasks</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Possess excellent conflict resolution and negotiation skills</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Demonstrate strong decision-making and problem-solving skills</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Excellent verbal and written communication skills</font></span></div><div>&nbsp;</div><div><font size="2">These are only minimum qualifications for this position at this grade level.&nbsp;Other factors taken into consideration when deciding what position and grade level to place an employee such as performance level, capable contribution and company need.</font></div><div>&nbsp;</div><div><font size="2"><strong>Work Environment:&nbsp;</strong>Works out of and performs primary duties in the San Diego Corporate Office.</font></div><div><font size="2"><strong>Compensation:&nbsp;</strong>Competitive compensation based upon experience with an excellent benefits package.</font></div><div><strong>&nbsp;</strong></div> Seeking Subject Matter Experts http://www.sdissa.org/article.php?story=20070514174621628 http://www.sdissa.org/article.php?story=20070514174621628 Mon, 14 May 2007 14:46:00 -0700 Announcements <p>Are you a Subject Matter Expert (SME)?&nbsp; Would you like to assist the chapter answering questions on your subject of expertise?&nbsp; From time-to-time SD ISSA receives calls from local media, schools, and businesses for our opinion, judgment, discernment on various information security topics.&nbsp; If you would like to be included on our SME Listing <a href="http://www.sdissa.org/fckeditor/editor/president@sdissa.org?subject=SME%20Listing&amp;body=Contact%20Peter%20Bybee%20for%20consideration%20to%20be%20included%20on%20the%20SD%20ISSA%20SME%20Listing.">please contact Peter Bybee</a>.&nbsp; <span><span style="font-family: Arial; font-size: small;">Peter will follow up with you on your SME nomination.</span></span>&nbsp; We need you're expertise to service our community.</p> Meeting Location http://www.sdissa.org/article.php?story=20070327131536576 http://www.sdissa.org/article.php?story=20070327131536576 Tue, 27 Mar 2007 11:15:36 -0700 General News <p>SDISSA meets on the 2nd Wednesday of each month at the Admiral Baker Clubhouse.</p> <p><span style="font-family: Arial; font-size: small;"><strong>TIME:</strong> 11:30am to 1:00pm LUNCH TIME MEETING<br /><strong><br /></strong><strong>COST: </strong>&#36;10.00 for ISSA Members (RSVP), &#36;15.00 ISSA Members (at door), &#36;20.00 Non-Members<br /><br /><strong>LOCATION:</strong> <br />&nbsp;<br /></span><strong>The Admiral Baker Clubhouse</strong><br />At 2400 Admiral Baker Rd,&nbsp; San Diego, CA 92120<br />(619) 487-0090<br /><br />Take Friars road east until Santo Road, take a left and very soon veer right onto the Admiral Baker Clubhouse.&nbsp; Then stay left and follow the road around to the clubhouse.&nbsp; No base sticker or government badge is needed.<br /><br />You&rsquo;re going to love the setting, ambiance, and history of the place!<br /><br /><strong>Driving Directions from Highway 15:</strong><br /><br />1) Take Friars Road exit East. Pass through the first stoplight (Rancho Mission).<br />2) Turn left at the second light (Santo Road).<br />3) Make an immediate right turn onto Admiral Baker Road.<br />4) Follow the road to its end at the golf course clubhouse.</p>