<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; Certification</title>
	<atom:link href="http://elamb.org/category/certification/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>How to get a certification:  CAP Exam part 1</title>
		<link>http://elamb.org/how-to-get-a-certification-cap-exam-part-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-get-a-certification-cap-exam-part-1</link>
		<comments>http://elamb.org/how-to-get-a-certification-cap-exam-part-1/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 17:22:46 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<category>cap</category>
	<category>exam</category>
	<category>isc2</category>
	<category>cap</category>
	<category>exam</category>
	<category>isc2</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3562</guid>
		<description><![CDATA[CAP Exam I had studied all night after freaking out about the test. I was sick and had to drive to another city to take that damn test. I was exhausted and tired.. lame excuse for being ugly lol. Its &#8230; <a href="http://elamb.org/how-to-get-a-certification-cap-exam-part-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>CAP Exam</h1>
<p><div id="attachment_3579" class="wp-caption alignleft" style="width: 160px"><a href="http://elamb.org/wp-content/uploads/2011/09/how-to-get-a-certification-cap-exam.jpg"><img src="http://elamb.org/wp-content/uploads/2011/09/how-to-get-a-certification-cap-exam-150x128.jpg" alt="passed the cap exam" title="how to get a certification cap exam" width="150" height="128" class="size-thumbnail wp-image-3579" /></a><p class="wp-caption-text">me with picture of CAP notificaiton</p></div><br />
I had studied all night after freaking out about the test.  I was sick and had to drive to another city to take that damn test.  I was exhausted and tired.. lame excuse for being ugly lol.  Its all good.. I still get laid.. but enough about ME.. lets talk about the test <img src='http://elamb.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<h2>How to get a certification</h2>
<p>- ISC2 Certified Authorization Professional (ISC2 CAP)<br />
- Risk Management Certification<br />
- Passing Score 700 out of 1000 points (125 questions on the test *25 test questions not counted toward the results)<br />
- Application Fee: $419<br />
- Verify 2 years experience in this field<br />
- Endorsement Form<br />
- Answer questions to criminal history and background<br />
- Other Info: its a CBT, 3 hours to test, based on NIST 800 series</p>
<h2>How Hard is the CAP Exam</h2>
<p>I just took the ISC2 Certified Authorization Professional test (CAP Exam).  I just want to give others who are about to take this test some idea of what they are up against.  I noticed there is not a lot of Security Professionals talking about it.  I keep hearing that there are only *1000 CAP certified people on Earth (circa 2011).  I don&#8217;t think its because of the difficulty level (lol.. i mean i would not call it an EASY test, but its no CISSP or CCIE.. btw <a href="http://en.wikipedia.org/wiki/CCIE_Certification">CCIE has about 25,000 certified as of about 2010</a> individuals on early despite being around for since 1993&#8230; according to Cisco, &#8220;fewer than 3% of Cisco certified individuals attain CCIE certification&#8221;).  I think there are so few CAP certified people because its not a well know certification and its in a specialized field.  Perhaps the numbers of CAP certified individuals will always be low.</p>
<p>My overall impression is that it is much harder than Security+ but much easier than CISSP.  If you have recent experience with DoD Information Assurance Certification &#038; Accreditation Process (DIACAP) you should have an easy time grasping the National Institute of Standards &#038; Technology (NIST) Special Publication 800 series concepts allowing you to pass the CAP exam.  I would say the same about all the C&#038;A frameworks, NIACAP, NISPOM, DCID 6/3, DITSCAP etc.  If you know the certification &#038; accreditation process well than you will pick up risk management framework fast.  If you have been doing the NIST C&#038;A and/or Risk Management Framework, the test should be a mere refresher course for you and a couple of weeks of reviewing NIST 800 regulations and OMBs you already know might be enough for you to pass the CAP Exam and get this certifications.  You should know, however, that quite a bit has changed since 2009 in the certification &#038; accreditation process of getting authorization.</p>
<p>The test is in the style of the CISSP in that you must choose what is MOST right in many cases.  All questions are 4-multiple choice type questions.</p>
<h1>Study Material for the Certified Authorization Professional</h1>
<p>One of my biggest issues about the CAP material is that is has almost NO decent study material.  There is &#8220;The CISSP and CAP prep guide&#8221; by Russell Dean &#038; Ronald L. Krutz, this is the ONLY book I have found aside from one or two lame ebooks (as of 2011).  </p>
<h2>What I used to get a CAP Certification</h2>
<p>The very first thing you should do is become a member of Isc2.org and download the <strong>ISC2 CAP Candidate Information Bulletin</strong>.  The CAP Exam CIB breaks down all the objectives that you need to be knowledgeable in.  </p>
<p>Read and/or be very familiar with the following NIST &#038; OMB documents:<br />
- NIST 800-37<br />
- NIST 800-53<br />
- NIST 800-53A<br />
- NIST 800-64<br />
- NIST 800-30<br />
- NIST 800-100<br />
- NIST 800-83<br />
- NIST 800-53<br />
OMB circular A-130<br />
Privacy Act of 1974<br />
FISMA Act of 2002<br />
**The full list of documents &#038; regs to be familiar with are located in CAP CIB </p>
<p>Another great resource is practice tests.  Ucertify.com has GREAT content for the CAP, some of the best you will find for the Certified Authorization Professional.  </p>
<h2>Areas to Spend a LOT of time on:</h2>
<p>I would definitely know and fully understand the Risk Management Framework (800-37).  You need to know the tasks on each of the six steps of the Risk Management Framework (800-37).  System Development Lifecycle is also HUGE on this test(800-64).  I would know how Risk Management Framework lines up with SDLC and Risk Assessment process (800-37, 64, 30).  Risk Assessment process, Risk Management Framework and SDLC are all interconnected.  You should know how they work together.  Tasks that are done at each stage and step in all those process and what role does each task is a need to know.  Roles and Responsibilities should be fully understood and memorized.  Although everyone of the steps in the Risk Management framework are covered pretty good, I feel like the following two steps were beaten to death:  Continuous Monitoring &#038; assessments (security control assessor) </p>
<p>The test is computer based and randomized so you might get a completely different set of subject areas.  Your best bet is to study what is in the CAP-CIB and use a bunch of practice tests.</p>
<h2>What I DID NOT see on the Exam:</h2>
<p>I was surprised not to see anything on the NIACAP, DIACAP, FITSAP, DCID 6/3 and DITSCAP.  I was fully expecting it and prepared for it.  Many of the practice test go on and on about Project/Program Management subject areas.  But the only question I recall on that had to do with knowing the role of a Program Manager&#8230; thats about it.  </p>
<h2>Pro &#038; CON on the ISC2 CAP Cert</h2>
<p><strong>CONS:</strong>  I feel like the CAP is currently (2011) not in great demand.  If you do a search on any job database (monster, indeed, simplyhired) you see that there are not many employees listing it as a requirement.  For example, a 2011 search on isc2 CAP anywhere in the US gives 49 results &#8212; http://jobsearch.monster.com/search/?q=isc2-cap<br />
I also think that the certification is WAY over priced.  Its $419 which I think is even more than the ISC2 CISSP concentrations.<br />
There is almost no study material for it.</p>
<p><strong>PROS:</strong>  Covers very important risk management framework material.  Its computer based, so the results are instant.  Its good lead up and practice for the ISSEP.  The ISSEP covers a lot of what is in the CAP.  NIST will get increasingly more important as DoD, NSA and other national security system agencies take on the NIST.</p>
<p>*CAP Exam: CAP certified people in the world (circa 2011):<br />
Canada	6<br />
Germany	1<br />
Korea, Republic of	2<br />
Puerto Rico	2<br />
United States	997<br />
reference: https://www.isc2.org/member-counts.aspx#cap    </p>
<p>**Certification Authorization Professional Candidate Information Bulletin is on ISC2.org.  May have to be a member to get the document</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/how-to-get-a-certification-cap-exam-part-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Training &amp; Certification: CAP &#8211; Security Authorization of Federal Information Systems</title>
		<link>http://elamb.org/training-and-certification-cap-security-authorization-of-federal-information-systems/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=training-and-certification-cap-security-authorization-of-federal-information-systems</link>
		<comments>http://elamb.org/training-and-certification-cap-security-authorization-of-federal-information-systems/#comments</comments>
		<pubDate>Tue, 02 Aug 2011 21:29:45 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<category>authorization</category>
	<category>rmf</category>
	<category>risk</category>
	<category>understand</category>
	<category>explains</category>
	<category>unacceptable</category>
	<category>sdlc</category>
	<category>800</category>
	<category>authorization</category>
	<category>rmf</category>
	<category>risk</category>
	<category>understand</category>
	<category>explains</category>
	<category>unacceptable</category>
	<category>sdlc</category>
	<category>800</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3386</guid>
		<description><![CDATA[Understanding the Security Authorization of federal information systems The ISC2 CAP candidate needs to understand the multitier approach to evaluating strategic &#038; tactical risk across an organization/enterprise. This is discussed thoroughly in NIST SP 800-39, Managing Information Security Risk. 800-39 &#8230; <a href="http://elamb.org/training-and-certification-cap-security-authorization-of-federal-information-systems/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1><strong>Understanding the Security Authorization of federal information systems<br />
</strong></h1>
<p>The ISC2 CAP candidate needs to understand the multitier approach to evaluating strategic &#038; tactical risk across an organization/enterprise.  This is discussed thoroughly in NIST SP 800-39, Managing Information Security Risk.  800-39 explains risk management from the organization, mission, and system perspective.</p>
<p>800-39 explains how and organization does risk framing by making risk assumptions, knowing risk constraints, risk tolerance, priorities &#038; tradeoffs.  Implementation of an organization’s risk management strategy is also based it’s governance structure.   </p>
<p>Security Authorization is a risk management process that based on identification of threats, vulnerabilities and countermeasures.  800-39 and 800-37 explains what must be included in a risk assessments that will evaluated residual risks and determine if they are acceptable or unacceptable to the organization as whole.  Unacceptable risks can be reduced by implementing security controls.</p>
<p><strong>Understanding the Security Authorization of federal information systems covers the following key areas:<br />
</strong><br />
Understand the Risk Management Approach to Security Authorization<br />
<a href="http://elamb.org/training-certification-risk-management-framework-rmf-steps/" title="Training &#038; Certification - RMF steps" target="_blank">Understanding and distinguishing among the Risk Management Framework (RMF) steps</a><br />
Define and Understand Roles &#038; Responsibilities<br />
Understand the Relationship between the RMF and SDLC<br />
Understand Legal, Regulatory, and Other Requirements for Security Authorization<br />
Understand Common Controls and Security Control Inheritance<br />
Understand Ongoing Monitoring Strategies<br />
Understand How the Security Authorization Process Relates to:</p>
<blockquote><p>1. Organization-wide risk management<br />
2. System Development Life Cycle (SDLC)<br />
3. Information system boundaries<br />
4. Authorization decisions</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/training-and-certification-cap-security-authorization-of-federal-information-systems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Training and Certification: certified authorization professional (1)</title>
		<link>http://elamb.org/training-and-certification-certified-authorization-professional-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=training-and-certification-certified-authorization-professional-1</link>
		<comments>http://elamb.org/training-and-certification-certified-authorization-professional-1/#comments</comments>
		<pubDate>Sun, 31 Jul 2011 21:10:18 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Risk Management Framework]]></category>

	<!-- AutoMeta Start -->
	<category></category>
	<category></category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3383</guid>
		<description><![CDATA[The Certified Authorization Professional (CAP) is a certification that indicates a professional level of knowledge/skill on the subject of federal information system authorization (formerly certification &#038; accreditation). In the US federal government, “Authorization” to operate a federally owned information system &#8230; <a href="http://elamb.org/training-and-certification-certified-authorization-professional-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The Certified Authorization Professional (CAP) is a certification that indicates a professional level of knowledge/skill on the subject of federal information system authorization (formerly certification &#038; accreditation).  In the US federal government, “Authorization” to operate a federally owned information system is a formal acceptance of risk from an Authorization Officer (AO).  An AO is a high ranking official granted the authority to make major risk related decisions for an entire branch/or unit within a federal organization.  The AO accepts or rejects the risks that information systems poses to his or her organization based on the recommendations of a security control assessors audit and accompanied Security Authorization Package.</p>
<p>The CAP is based almost entirely on federal information security/protection laws, National Institute of Standards &#038; Technology (NIST), and Office of Management &#038; Budget regulations.  </p>
<p><strong>There are seven domains the CAP exam focuses on:</strong><br />
1. <a href="http://elamb.org/training-and-certification-cap-security-authorization-of-federal-information-systems/">Understanding the Security Authorization of Information Systems</a><br />
2. Categorize Information Systems<br />
3. Establish the Security Control Baseline<br />
4. Apply Security Controls<br />
5. Assess Security Controls<br />
6. Authorize Information System<br />
7. Monitor Security Controls</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/training-and-certification-certified-authorization-professional-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Cert Beginner Part-2: Setting up a Network Lab (Rack)</title>
		<link>http://elamb.org/cisco-cert-beginner-part-2-setting-up-a-network-lab-rack/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisco-cert-beginner-part-2-setting-up-a-network-lab-rack</link>
		<comments>http://elamb.org/cisco-cert-beginner-part-2-setting-up-a-network-lab-rack/#comments</comments>
		<pubDate>Wed, 02 Mar 2011 02:04:34 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[ccent]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[Other Stuff]]></category>
		<category><![CDATA[Super GEEK]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3180</guid>
		<description><![CDATA[One of the reasons I failed the CCENT was that I didn&#8217;t prepare for router/switch simulators that are on the test. I knew the theory and concepts behind Interconnecting Cisco network devices, but I hadn&#8217;t spent much time on the &#8230; <a href="http://elamb.org/cisco-cert-beginner-part-2-setting-up-a-network-lab-rack/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>One of the reasons I failed the CCENT was that I didn&#8217;t prepare for router/switch simulators that are on the test.  I knew the theory and concepts behind Interconnecting Cisco network devices, but I hadn&#8217;t spent much time on the command line of an actual router.  Since the test is timed you don&#8217;t have a lot of time to try to figure commands out on the fly.  You certainly can, because Cisco command line is pretty user friendly.</p>
<p>To prepare for the test you must be comfortable in the Internetwork Operating System (IOS).  That is why my CCNA, CCNP buddies encouraged me to set up my own Cisco network.   They told me how to buy them cheap, what components to buy and how I should actually network them to prep for the Cisco certs.</p>
<p><strong>Cheap Cisco Equipment:<br />
</strong>  Talking about what actual Cisco models to buy in this post will not be effective since anything I name will be completely obsolete by the time you read this.  But I will tell you that my CCNA/CCNP friends recommended buying old Cisco equipment from ebay and Craig&#8217;s list.  And even schooled me on what was a good deal.  In some cases I would just give them money and they would buy if for me.  I ended up buying a lot of stuff I don&#8217;t need but you are more than likely much smarter with your money.</p>
<p><strong>What to Buy:<br />
</strong>They told me that it was important to buy two switches and two routers to practice with routing protocols and spanning tree.  They explained that it is important to understand the behavior of the technologies in order to know how to troubleshoot.  Theory is important too, but to prepare for the CCENT you must get comfortable with the command line interface so you don&#8217;t waste time figuring out basic stuff on the fly.<br />
<a href="http://elamb.org/wp-content/uploads/2011/03/Lab-2950-2950-24-640.jpg"><img src="http://elamb.org/wp-content/uploads/2011/03/Lab-2950-2950-24-640-150x150.jpg" alt="" title="Lab-2950-2950-24-640" width="150" height="150" class="alignnone size-thumbnail wp-image-3188" /></a><br />
<a href="http://elamb.org/wp-content/uploads/2011/03/cisco-land-net.jpg"><img src="http://elamb.org/wp-content/uploads/2011/03/cisco-land-net-300x282.jpg" alt="" title="cisco-land-net" width="300" height="282" class="alignnone size-medium wp-image-3192" /></a></p>
<p><em><a href="http://www.ciscoland.net">courtesy of Cisco land</a></em></p>
<p><strong>DIAGRAM:</strong><br />
Build a diagram first!  This is difficult for me because I like to just jump in and try things.  But creating a network diagram and understanding what it is you want to set up is very important.<br />
<a href="http://elamb.org/wp-content/uploads/2011/03/basic-network-diagram.jpg"><img src="http://elamb.org/wp-content/uploads/2011/03/basic-network-diagram-150x150.jpg" alt="" title="basic-network-diagram" width="150" height="150" class="alignnone size-thumbnail wp-image-3187" /></a><br />
<em><a href="http://www.ratemynetworkdiagram.com">from rate my network diagram</a><br />
</em></p>
<p><strong>Virtual Cisco LAB:<br />
</strong>Another very useful tool for those who really can not afford to drop $100 dollars on old Cisco equipment is the use GNS3.  Its like a VM Ware for Cisco IOS.  It allows you to create a virtual network and mess around with actual Cisco IOS.  Its really pretty cool&#8230; and (best of all) it free!!  Aside from air, I am not sure there is anything more useful.  Its is a great tool if you are serious about studying for the CCENT/CCNA/CCNP.<br />
<a href="http://elamb.org/wp-content/uploads/2011/03/gns3_windows_mini.png"><img src="http://elamb.org/wp-content/uploads/2011/03/gns3_windows_mini-300x211.png" alt="" title="gns3_windows_mini" width="300" height="211" class="alignnone size-medium wp-image-3189" /></a><br />
courtesy of <a href="http://gns3.net">gns3.net</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cisco-cert-beginner-part-2-setting-up-a-network-lab-rack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Cert Beginner Part-1: where to start</title>
		<link>http://elamb.org/cisco-cert-beginner-part-1-where-to-start/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisco-cert-beginner-part-1-where-to-start</link>
		<comments>http://elamb.org/cisco-cert-beginner-part-1-where-to-start/#comments</comments>
		<pubDate>Sun, 27 Feb 2011 06:02:21 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[ccent]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[Other Stuff]]></category>
		<category><![CDATA[Super GEEK]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3175</guid>
		<description><![CDATA[Since I failed the Cisco Certified Entry Networking Technician (CCENT) (lol), I have decided to get smart on Cisco again. I have been out of it a long time doing mostly DoD Certification &#038; Accreditation work. I used to be &#8230; <a href="http://elamb.org/cisco-cert-beginner-part-1-where-to-start/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Since I failed the Cisco Certified Entry Networking Technician (CCENT) (lol), I have decided to get smart on Cisco again.  I have been out of it a long time doing mostly DoD Certification &#038; Accreditation work.  I used to be a network engineer with a CCNA, until I found a career that pays better with less competition.  So now, I am just doing Cisco stuff for fun.  </p>
<p>After failing the CCENT, I talk to my resident networking GURU&#8217;s (a CCNA Security, a CCNP and a CCIE).  I wanted to know what was the best approach on attacking the CCNA again.  They told me what they did.. set up a Cisco lab in the house was he most common answer.</p>
<p>The book they recommended to start with was CCNA-CCNENT ICND1.  Its really not the most fun book in the world to read, but if your starting out or starting over with this stuff it should be like your networking bible.  Among technical Cisco books, its a solid first start.. which is much more than I can say about any of the first start Cisco&#8217;s 5500 ASA books&#8211; there is just now such thing.  You will be expected to have a solid understanding of networking, the OSI model and TCP/IP.  If you have a Comptia Network+, the CCENT might be the logical next step.  If you do networking pretty regularly, have been doing it for about a year and are familiar to Cisco equipment, you might be better off going straight to the Cisco Certified Network Associate (CCNA).  If you&#8217;re going for the fully blown CCNA, the book to get is the CCNA ICND2.  I have been warned that you need to very, very good at subneting!!  The CCNA is much harder than it was when I took it in 2001.  I would even say that the CCENT is harder than the CCNA used to be.</p>
<p>In addition to getting the right books to read, the Cisco Gurus told me to set up a lab.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cisco-cert-beginner-part-1-where-to-start/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When does a DoD Information System require a re-accreditation</title>
		<link>http://elamb.org/when-does-a-dod-information-system-require-a-re-accreditation/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=when-does-a-dod-information-system-require-a-re-accreditation</link>
		<comments>http://elamb.org/when-does-a-dod-information-system-require-a-re-accreditation/#comments</comments>
		<pubDate>Fri, 25 Feb 2011 01:08:03 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3164</guid>
		<description><![CDATA[How do you determine when a DoD Information System should have a full re-accreditation? We are not talking about the obvious: -3 year expiration -completely new version and/or overhaul of a system We are talking about a single client on &#8230; <a href="http://elamb.org/when-does-a-dod-information-system-require-a-re-accreditation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>How do you determine when a DoD Information System should have a full re-accreditation?</p>
<p>We are not talking about the obvious:<br />
-3 year expiration<br />
-completely new version and/or overhaul of a system</p>
<p>We are talking about a single client on within an Information System getting an upgraded operating systems, or a firewall being upgraded or the addition of 4 Cisco internetworking devices and a VLAN change. </p>
<p>How do we know what is a basic sustaiment change, a configuration management changed (approved by the Configuration Board members) or a full blown 100,000 dollar re-accreditation.</p>
<p>You would think there was some kind of matrix that could match up modifications to a DoD IS with what actions must be performed.  If there is one, I have not seen it.  </p>
<p>All we have is high level regs that tell us IA Workforce peons (who must deal with details, schedules and limited funds) almost nothing we don&#8217;t already know.</p>
<p><strong>Assessing the IA Impact &#038; Maintaining Situational Awareness:</strong><br />
DoD 8500.2, Information Assurance gives us IA Controls such as<br />
DCII-1, dealing with IA  Impact Assessment.  Its states, &#8220;Changes to the DoD information system are assessed for IA and accreditation impact prior to implementation.&#8221;  The DoD instruction also tells us the we are supposed conduct comprehensive annual reviews of our systems process, procedures and IA Control status.</p>
<p><strong>How are we supposed to monitor &#8220;Changes to the DoD information system?</strong></p>
<p>We know that we are supposed monitor all DoD IS&#8217;s to keep track of the baseline.  And according to the regs, we are supposed to do this by a configuration management process (DCPR-1, CM Process).  That configuration management process is supposed to have a &#8220;configuration control board that implements procedures to ensure a security review and approval of all proposed DoD information system changes, to include interconnections to other DoD information systems.&#8221; </p>
<p><strong>So Configuration Management gives us oversight on changes to DoD IS but who within the CM process determines whether changes to a system should have a re-accreditation?</strong><br />
IA Control DCCB-2, Control Board tells us that&#8221; all information systems are under the control of a chartered Configuration Control Board that meets regularly according to DCPR-1.&#8221; Is also tells us that the Information Assurance Manager (IAM) is a member of the CCB.  </p>
<p>From my interpretation of these high level statements, the IAM is the subject matter expert who has a lot of say so on the IA impact of modifications to a given DoD IS.</p>
<p>But the question remains.. HOW DO WE KNOW WHAT NECESSITATES A RE-ACCREDITATION?</p>
<p>I did not find anything for that in 8500.2 so I moved on to CJCSI 6510.01, but it only says the same things that 8500.2 says (Configuration Management, CCB, having a baseline).  But it did say this: </p>
<blockquote><p>&#8220;Ensure a configuration management (CM) process is implemented and establish appropriate levels of configuration management to <strong>maintain the accredited security posture</strong>.  The <em><strong>security impact of each change or modification to an information system or site configuration will be assessed against the security requirements and the accreditation conditions issued by the DAA</strong></em>..&#8221;</p></blockquote>
<p>Still pretty high level, but we are getting closer since the instruction is telling us: &#8220;..<em><strong>security impact of each change or modification to an information system or site configuration will be assessed against the security requirements and the accreditation conditions issued by the DAA</strong></em>&#8220;.  </p>
<p>I thought that the only way to get more insight is to look at the lower level regulations within specific branches.  Air Force&#8217;s Certification &#038; Accreditation Program, 33-210, for example talks specifically about reaccreditation.  It states, Information system owner (ISO) &#8220;Alerts AFNetOps of any changes to the topology or software affecting the security posture of the enclave boundaries so that the gateway package can be reaccredited if necessary. (3.8.6.6.4.)&#8221;  And in table 3.2. it states &#8220;PM/SM/ISO will enter information in EITDR, host an initial stakeholder meeting, and initial security review to determine if a new version is to be created.&#8221;  It mentions different reaccreditation actions for Networked and Standalone systems.  Its goes on say that &#8220;if changes will not affect the security posture of the IS, the PM/SM/ISO will annotate the outcome of the meeting and make necessary edits to the C&#038;A package.&#8221; </p>
<p>The Army&#8217;s AR 25-2, Information Assurance regulation, has an entire section on Accrediation &#038; Reaccreditation (5-5), but offers still no specifics.  The Army does have <a href="http://www.google.com/search?source=ig&#038;hl=en&#038;rlz=&#038;=&#038;q=AR+380-19&#038;aq=f&#038;aqi=g2&#038;aql=&#038;oq=">AR 380-19</a>, AIS Information System Security and it is pretty specific (see excerpt below).. but it is now OBSOLETE and replaced by AR 25-5.</p>
<p>All regulation and instructions are inline as far as the need to reaccredit if there is an IA IMPACT, but no specifics on what constitues an &#8220;IA Impact&#8221;.  8510, DIACAP mentions that the IA posture of an IS must remain acceptable, in order to retain its Authorization to Operate (ATO). If I were the IAM for a day.. I would hang my hat of this important statement.</p>
<p><strong>We have to work with what we have!!</strong><br />
Based on what we have:<br />
Changes in a DoD IS&#8217;s IA Controls determine whether or not a system will need a reaccrediation.  There is no specifics on what can force a reaccrediation.  So we must conclude that there is no &#8220;magic bullet&#8221; that will instantly create the need for a reaccreditation.  In other words, no modifications to a certain hardware or software or certain subsystems or even the changes to network architecture will be the reason for reaccreditation every single time.  </p>
<p>Significant changes to IA Controls are the only thing we can really put our finger on.  </p>
<p>So lets say that IA Control, DCCS-2,  Configuration Specification was changed on an Information System.  This IA Control deals with making sure the all IA Enabled and IA Products have the DISA Security Technical Implementation Guides (or equivalent) applied.  Maybe an example will help us understand the process of determining reaccreditation:  A DoD Information System Owner requests the addition of four new storage devices to the system enclave.  Lets say, that these storage devices will have an adverse affect on the security posture of the overall system because they are not in compliance with DCAS-2, Acquisition Standards&#8230; so the storage devices have not gone through NSA/Common Criteria.  Additionally the storage devices will not be compliant with DCCS which means they will not have security in accordance with DISA/NSA checklists and guidance.</p>
<p>Prior to being implemented or even tested the request for this change should go through the configuration management process where the IAM will tell the Program Manager and System Owner (or is representative) the security impact to the over all system.  He or she would have to explain to them that the change may affect the current ATO, because they will now be non-compliant on two (possibly more controls) that were previously compliant.  The IAM would also be wise to get in contact with other subject matter experts such as the system administrator and/or IAO would be in charge of implementing and testing the system.  The IAM might also contact the Certifying Authority (or representative) to determine if such a change would create the need for a reaccreditation.</p>
<p>One thing the IAM does NOT want to do is simply sign the Program Managers and System Owners up for some changes to the system that would jeapordise the Authorization to Operate.  The IAM should do their homework and present the real risk of the modifications to the system owner.  CYA is paramount. </p>
<p><strong>Once the IAM determine the impact, and the modification are made:</strong><br />
According to DoD 8500.2, 5.8.5.  &#8220;ensure that IA-related events or configuration changes that may impact accreditation are reported to affected parties, such as Information Owners and DAAs of interconnected DoD information systems.&#8221;</p>
<p>Some older regulations are more specific.  AR 380-19, AIS System Security for example:<br />
3-6. Reaccreditation</p>
<p>      a. All AIS, except those designated as nonsensitive, will be formally reaccredited within 3 months after any of the following occurs:</p>
<p>            (1) Addition or replacement of a mainframe or significant part of a major system.</p>
<p>            (2) A change in sensitivity designation (para 2-2a).</p>
<p>            (3) A change in security mode of operation (para 2-2b).</p>
<p>            (4) A significant change to the operating system or executive software.</p>
<p>            (5) A breach of security, violation of system integrity, or unusual situation that appears to invalidate the accreditation.</p>
<p>            (6) A significant change to the physical structure housing the AIS that affects the physical security described in the accreditation.</p>
<p>            (7) Three years has elapsed since the effective date of the existing accreditation. </p>
<p>      b. Reaccreditation will include the same steps accomplished for the original accreditation; however, those portions of the documentation that are still valid need not be redone.</p>
<p>AR 380-19 has been replaced with AR 25-5 which is pretty high level.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/when-does-a-dod-information-system-require-a-re-accreditation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About to take the CCENT Certification Test (Part II): Failed Certification</title>
		<link>http://elamb.org/about-to-take-the-ccent-certification-test-part-ii-failed-certification/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=about-to-take-the-ccent-certification-test-part-ii-failed-certification</link>
		<comments>http://elamb.org/about-to-take-the-ccent-certification-test-part-ii-failed-certification/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 03:30:58 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2697</guid>
		<description><![CDATA[In July I wrote a short post about taking the CCENT to get my networking marketability back up. Well, I took it about one month ago and failed it. It is the first certification I failed. The bad the thing &#8230; <a href="http://elamb.org/about-to-take-the-ccent-certification-test-part-ii-failed-certification/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In July I wrote a short post about <a href="http://elamb.org/about-to-take-the-ccent-certification-test/">taking the CCENT</a> to get my networking marketability back up.  Well, I took it about one month ago and failed it.  It is the first certification I failed.  The bad the thing about this, is that it is the lowest level Cisco certification you can take!  So, as you can imagine, I took the failure hard.  But since I feel that failure is not an option, I have decided to take it again.  </p>
<p><strong>How is the CCENT?</strong>  I would say it is easy.  That may sound like a contradiction coming from a guy who just failed it, but allow me to explain.  It covers all the basics of TCP/IP &#038; Cisco switching and routing.  If you have a year of experience doing routing and switching on Cisco equipment in small to medium environment, you will probably laugh at this test.  If you are like me and have mostly an academic understanding of Cisco technology, you may struggle.</p>
<p><strong>Where did I go wrong?</strong>  I think I just didn&#8217;t put enough time into getting on the switches and routers I have at home.  In fact, I am ashamed to admit, I put almost no time into it.  I have been very busy for the last 7 months working on a very large project.. so I just don&#8217;t have a lot of spare time.</p>
<p>Anyway, I will be taking the test again soon.. Wish me luck.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/about-to-take-the-ccent-certification-test-part-ii-failed-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>About to take the CCENT Certification Test</title>
		<link>http://elamb.org/about-to-take-the-ccent-certification-test/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=about-to-take-the-ccent-certification-test</link>
		<comments>http://elamb.org/about-to-take-the-ccent-certification-test/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 04:09:03 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Other Stuff]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2476</guid>
		<description><![CDATA[About 7 years ago I got a CCNA certification. That is a Cisco Certified Network Associate. I got to use the full scope of my Cisco networking skills one time for four months and then didn&#8217;t touch another router or &#8230; <a href="http://elamb.org/about-to-take-the-ccent-certification-test/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>About 7 years ago I got a CCNA certification.  That is a Cisco Certified Network Associate.  I got to use the full scope of my Cisco networking skills one time for four months and then didn&#8217;t touch another router or switch for 7 years.  So I lost all but the very basic switching &#038; routing skills.  </p>
<p>I decided to start slow and start from nothing.  I think it was a good choice because I have noticed that the CCENT, Cisco Certified Entry Network Technician is about as exhaustive as the old CCNA.  From what my CCNA, CCNP, CCIE co-workers/friends and instructors have told me, all the Cisco tests are exponentially harder than they used to be.  </p>
<p>My goal is the get my CCNA back.  After that, I am not sure what direction I will go in.  The CCNP is in very high demand but like I said, I heard the tests for CCNP are HELLA hard. </p>
<p>For now, its a simple enty level Cisco networking technician.  In the end I am certain it will increase my marketability.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/about-to-take-the-ccent-certification-test/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Find an IT Security Jobs</title>
		<link>http://elamb.org/find-an-it-security-jobs/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=find-an-it-security-jobs</link>
		<comments>http://elamb.org/find-an-it-security-jobs/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 14:48:32 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[security experts]]></category>
		<category><![CDATA[System security engineering]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2436</guid>
		<description><![CDATA[So do you have any suggestions for someone starting out in IT Security? What certifications, knowledge, training, forums, do you suggest? They will pay for the A+ cert, Network + and Security + certification. Do you have any suggestions for &#8230; <a href="http://elamb.org/find-an-it-security-jobs/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>So do you have any suggestions for someone starting out in IT Security?   What certifications, knowledge, training, forums, do you suggest?   They will pay for the A+ cert,  Network + and Security + certification.  Do you have any suggestions for someone just starting out in security?  After CompTia what should I focus on.  Although Iâ€™m not sure yet of my final career goals, Iâ€™d like to first get a job very quickly in IT security, hopefully with the government, state, or any local government;  when I say quick I mean within the next few weeks Thanks Rob for whatever info you can suggest</strong></p>
<p>Hello,</p>
<p>If you want a job fast I would suggest checking out simplyhired.com.  I would also put my resume out on Monster.com, if you have not already done so.  If you want a security job the security+ is the way to go, but also consider doing a search on monster and simplyhired to look at the skills and certifications that employers are looking for.  Pay particular attension to keywords and phrases that they are using.  You will know the keywords/phrase because they are repeated in nearly every resume for your chosen career path and/or job title.</p>
<p><strong>How I get Jobs Fast</strong><br />
For example, in my career &#8220;system security engineer&#8221; and &#8220;information security officer&#8221; I see the following keywords/phrases over and over: security clearance, cissp, 8500, diacap.  If noticed that when I have these keywords on my resume, I get calls almost DAILY from all over the US.  Here is how you can do the same:<br />
1) Find a good job title that fits what you do or what you want to do<br />
2) Do a search for that job title [use google, simplyhired.com, monster.com, dice.com or any other search engine/job database]<br />
    &#8211; Read through the job results and try to find keywords/phrases that seem to be in most or all of the jobs listed<br />
3) Try to get as many of the applicable keywords/phrases in your resume<br />
    &#8211; Either have the skills required for the chosen job title or begin working toward them<br />
    &#8211; I am not suggesting that you put lies on your resume, you&#8217;ll have to look for job titles that you have experience &#038; skills in<br />
    &#8211; Don&#8217;t mess with stuff that completely out of your league or level of expertise, be honest on your resume<br />
    &#8211; Sometimes employers will take you if you are willing to learn the skills or earn the require certification/degree in a certain time  frame.  Put that on your resume.<br />
4) Put your resume [with keywords/phrases in place] online, as many places as you can</p>
<p><strong>Research Employer Demand in certain locations </strong><br />
I am from California and I have been trying for years to find a decent job (for what I do) there.  They&#8217;ve got them in southern California but almost none in Northern.  California seems to be lacking jobs and then they don&#8217;t want to pay comparable to the cost of living there.  I noticed that Cali has a LOT of networking jobs.  If you type in <a href="http://en.wikipedia.org/wiki/Cisco_Career_Certifications">CCNP</a> in simplyhired.com for Cali, you&#8217;ll find a lot of good paying jobs.  The problem is that CCNP is a very difficult certification to get (or so I&#8217;ve heard).</p>
<p>I would recommend checking out what sort of IT skills employers are looking for in the area you want to work.   For example, even though I have lots of certifications, most of the ones that I have [that are still active lol] won&#8217;t help me for moving back to Northern California.  I researched it and found that they are mostly looking for Network Engineers [as of 2006-2010] and my Cisco routing and switching skills are still developing.  </p>
<p><strong>Play Capitalisms Game: Start a Business</strong><br />
Another option is to start your own business.  This may sound daunting, but believe it or not my website elamb.org qualifies as a business.  It took me about 1 year to get it making money, but now it makes between $400 &#8211; 800/month without me even looking at it.  It has made as much as 2k and I know <a href="www.problogger.net">people</a> who make more in a month then many people make in a year with their blogs.  It is becoming harder and harder to be an employee.  Companies do the bare minimum to take care of employees, the economy goes in a recession (or worse) and hard working people can not find a job and the value of the dollar flutuates on a downward spiral.  It seems the only way to be comfortable in this new &#8220;capitalism&#8221; is to have multiple streams of income.</p>
<p>If you are interested, start at your states business page and <a href="http://www.google.com/search?hl=en&#038;q=start+a+business+irs&#038;aq=f&#038;aqi=g1&#038;aql=&#038;oq=&#038;gs_rfai=">here</a> </p>
<p> Thanks,<br />
 Rob E.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/find-an-it-security-jobs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIACAP Essentials + IA Control Validation Training (part 1)</title>
		<link>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=diacap-essentials-ia-control-validation-training-part-1</link>
		<comments>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 04:49:25 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[ditpr]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[information assurance]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Security Awareness]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=1727</guid>
		<description><![CDATA[I&#8217;ve been scheduled to go to DIACAP Essentials + IA Control Validation training. It is the same training that is given to validators at AFCA, so I guess it is pretty serious stuff. I was very reluctant to go until &#8230; <a href="http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been scheduled to go to DIACAP Essentials + IA Control Validation training.  It is the same training that is given to validators at AFCA, so I guess it is pretty serious stuff.  I was very reluctant to go until I realized that I actually really need the CPE&#8217;s to maintain my CISSP.</p>
<p>Since I&#8217;ve been doing the DIACAP stuff for about 2 years now, I&#8217;m not certain there is any new information for me to learn.</p>
<blockquote><p><strong>DIACAP Essentials </strong><br />
The Department of Defense Information Assurance Certification and<br />
Accreditation Process (DIACAP) Essentials course blends lecture and hands-on<br />
exercises to introduce students to DIACAP policy (to include FISMA<br />
requirements of a comprehensive, repeatable, and auditable Information<br />
Security process). </p></blockquote>
<blockquote><p><strong>IA Control Validation In-Depth </strong>- 3 Days<br />
The IA Control Validation In-Depth course takes the students DIACAP<br />
education and turns the view from an implementor to a Validator perspective<br />
and involves the students in the validation process for the IA Controls<br />
(DoDI 8500.2).</p></blockquote>
<p>What I am hoping to get from the course is a better handle on the FISMA process.<br />
I don&#8217;t feel like I really have a handle on what is supposed to happen with it.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/diacap-essentials-ia-control-validation-training-part-1/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

