<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; Main Digg</title>
	<atom:link href="http://elamb.org/category/security/main-page/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>The Importance of Basic Accounting Concepts to IT Students Explained!</title>
		<link>http://elamb.org/the-importance-of-basic-accounting-concepts-to-it-students-explained/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-importance-of-basic-accounting-concepts-to-it-students-explained</link>
		<comments>http://elamb.org/the-importance-of-basic-accounting-concepts-to-it-students-explained/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 00:54:47 +0000</pubDate>
		<dc:creator>brenz</dc:creator>
				<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<category>accounting</category>
	<category>concepts</category>
	<category>competitive</category>
	<category>basic</category>
	<category>students</category>
	<category>knowledge</category>
	<category>applied</category>
	<category>programming</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3204</guid>
		<description><![CDATA[Accounting Concepts is really important in today’s business world. Not only the basic but even to the highest degree of accounting. If you don’t notice, I can say that every day in our life we used Mathematics and some sort &#8230; <a href="http://elamb.org/the-importance-of-basic-accounting-concepts-to-it-students-explained/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Accounting Concepts is really important in today’s business world. Not only the basic but even to the highest degree of accounting. If you don’t notice, I can say that every day in our life we used Mathematics and some sort of accounting. We usually count money, calculate the change and always check if how much money did we spent and how much still got. Almost every person on different profession needs to have at least basic knowledge of accounting because sometimes it will make you more competitive in your field when you have basic accounting knowledge. </p>
<p>On our previous seminar for IT/CS intern students like me, the speaker tends to share his knowledge about basic accounting concepts. The importance of basic accounting concepts on our course is that we will be more competitive and gain an additional knowledge which we can use in our future job. We are IT students who will become programmers and software developers someday or we might establish our own company in the near future. It is important that we know the basic debit/credit in accounting if we are going to create an accounting program or software but for me basic accounting concepts is not enough when you plan to be a accounting programs developer instead use it as a starting point for further studies about accounting concepts. Because the more knowledge on accounting plus the skills on programming, you will definitely develop an effective accounting program.</p>
<p>Once you applied accounting concepts and programming it will surely gives you a nice income. I still remember what my former professor told us about his experienced when he was still applying for a job, he applied in an organization/company as a programmer but when he was interviewed, the interviewee asked him if he had a background on accounting he answered none, obviously he did not passed the interview because of that simple question, so he advised us to take basic accounting course as early as now because maybe we might also encounter the same problem he encountered before.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/the-importance-of-basic-accounting-concepts-to-it-students-explained/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Date Online: fake profiles!</title>
		<link>http://elamb.org/how-to-date-online-fake-profiles/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-date-online-fake-profiles</link>
		<comments>http://elamb.org/how-to-date-online-fake-profiles/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 11:08:58 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[date scams]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[romance scam]]></category>

	<!-- AutoMeta Start -->
	<category>fake</category>
	<category>medan</category>
	<category>dari</category>
	<category>cewek</category>
	<category>cantik</category>
	<category>pictures</category>
	<category>dating</category>
	<category>sites</category>
	<category>fake</category>
	<category>medan</category>
	<category>dari</category>
	<category>cewek</category>
	<category>cantik</category>
	<category>pictures</category>
	<category>dating</category>
	<category>sites</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3616</guid>
		<description><![CDATA[How to Date Online Fake Profile Pictures Online dating is now a very popular way to meet a partner. Match.com &#038; eHarmony are very popular dating web sites and claim that 1 of every 5 marriage (in Western world?) are &#8230; <a href="http://elamb.org/how-to-date-online-fake-profiles/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>How to Date Online</h1>
<h2>Fake Profile Pictures</h2>
<p>Online dating is now a very popular way to meet a partner.  Match.com &#038; eHarmony are very popular dating web sites and claim that 1 of every 5 marriage (in Western world?) are from dating sites.  </p>
<p>But on thing that goes unsaid is the amount of scams that happen on these sites.  There are many &#8220;romance scammers&#8221; on these sites.  Below are examples of face profile pictures that these con artists use to lure you in.</p>
<p><a href="http://elamb.org/wp-content/uploads/2011/09/filipina1.jpg"><img src="http://elamb.org/wp-content/uploads/2011/09/filipina1-150x150.jpg" alt="" title="filipina heart fake profile" width="150" height="150" class="alignleft size-thumbnail wp-image-3618" /></a></p>
<p>http://ic-girl.blogspot.com/2009/03/cewek-cantik-dari-medan.html<a href="http://elamb.org/wp-content/uploads/2011/09/ella-date-scam1.png"><img src="http://elamb.org/wp-content/uploads/2011/09/ella-date-scam1-150x150.png" alt="" title="filipino cupid fake profile" width="150" height="150" class="alignleft size-thumbnail wp-image-3617" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/how-to-date-online-fake-profiles/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>filipino cupid filipino heart: scam ring</title>
		<link>http://elamb.org/filipino-cupid-filipino-heart-scam-ring/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=filipino-cupid-filipino-heart-scam-ring</link>
		<comments>http://elamb.org/filipino-cupid-filipino-heart-scam-ring/#comments</comments>
		<pubDate>Sun, 25 Sep 2011 03:01:08 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[date scams]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[scam]]></category>

	<!-- AutoMeta Start -->
	<category>filipino</category>
	<category>philippines</category>
	<category>matt</category>
	<category>ring</category>
	<category>heart</category>
	<category>yasay</category>
	<category>ludivina</category>
	<category>filipinoheart</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3590</guid>
		<description><![CDATA[Filipino Cupid &#038; filipino heart scam How and Why I became a romance scammer on filipinoheart.com *The following is a real event that has been re-written from the original for clarity with names changed to protect those who were willing &#8230; <a href="http://elamb.org/filipino-cupid-filipino-heart-scam-ring/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>Filipino Cupid &#038; filipino heart scam</h1>
<h2>How and Why I became a romance scammer on filipinoheart.com</h2>
<p>*<em>The following is a real event that has been re-written from the original for clarity with names changed to protect those who were willing to come forward&#8230; the real ludivina yasay is a lady that scammed me lol.  The original author of this story is not named but she really did do this.  I may post the original (and change the names) for now you get a simulation of a REAL event.. the emails in this post is real, the story is real.</em>*</p>
<p>My name is Ludivina Yasay.  I am from Cebu City, Philippines.  About a year ago, I scammed an American named Matt T.  I met him on a popular dating website called filipinocupid.com (filipinoheart.com in the Philippines).  Over the course of 8 months, I took about $3000 dollars from him.</p>
<p><strong>Why did I do it?</strong><br />
I needed money.  </p>
<p><strong>How did I do it? </strong><br />
I gained his trust, told him what he wanted to hear and he believed me.  He fell in love then gave me money.</p>
<p><strong>How it all began</strong><br />
After graduating college, I could not find a job.  Jobs are REALLY hard to get in certain parts of the Philippines.  Places like General Santos, Cebu City and many other places have many people and very little jobs available.  Many families can barely afford to pay rent, utilities or even eat.  Even with a college degree, I could not find a job for over a year.</p>
<p>I started searching for jobs online.  While in the Internet café, I over heard two people talking about how they would get money via Western Union from a person they were chatting with.  While I was trying to unsuccessfully get jobs each day, they were getting paid from some guys online.  </p>
<p><strong>Filipino Heart Scam Ring</strong><br />
I found out my friend was involved in the same people I had seen in the Internet cafe.  She explained to me what was going on.  She told me that they would find guys from the United States on dating sites.  They used a fake profile on Filipino cupid, flirt with these men, start a relationship, then get money.  This ring of Filipino heart scammers were mostly gay men.  </p>
<p>They told me that they do it so much that they are actually able to buy home, cars and live very well in the Philippines.</p>
<p>Since my family and I were struggling, I decided to do it.  I create a fake account with a picture of a model.  I had a set of pictures.  Very quickly I had a guy who was interested, Matt T.</p>
<p>We began to talk and I told him everything he wanted to hear.  I told him that I was looking for a guy who is serious, I told him I was attracted to him.  I told him anything to make him feel good.  I didn’t care about him he is just a stranger.  I just need money.  </p>
<p><strong>How I got the Money</strong><br />
Message to Matt:</p>
<blockquote><p>hope you have a very nice day today&#8230; its have a wonderful today when i found you.. i fill always happy when you respond to my email.. and i fill that your a guy i that god given me and i know in my heart your the right one for me&#8230;. hope we could chat soon. i miss to chat w you.. take care&#8230;.. love&#8221;</p></blockquote>
<p>from MATT:</p>
<blockquote><p>That is very sweet.  I look forward to taking the time to know you better.  I want to know the dreams and wishes of your heart.<br />
 <img src='http://elamb.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   </p></blockquote>
<p>After a short time, he started to trust me so we were starting to speak like friends.  When I mention to him that my family does not have enough to eat he is concerned for me.. his “friend”.  I did not ask for money directly.  When I mention I am in trouble, he offered to send me money.  I pretend to be reluctant, then took the money.  </p>
<p><strong>Falling in Love &#038; telling the truth</strong><br />
Everytime I mention my troubles, he offered money.  After a while we started getting closer and closer and he is giving me more and more money.  The funny thing is I never even really asked him.. I just gained his trust and he offered when I said I am in trouble.</p>
<p>He told me about how he is getting a divorce with his wife.  He told me He has two kids.  He told me how he is lonely lately and all about his life.  Over the months, he help me anytime I needed it.  He helped me move to another city, find a job and even explained how I can help him with a business he runs and pay me!  </p>
<p>We started to really get close and even fall in love.  Over time, I realized that I really love him and do not want to live a lie.  As a practicing Catholic, it was hard for me to accept this lie.</p>
<p>I went to church and did confession.  The priest told me I should tell him the truth.</p>
<p>The closer we got the more I realize I cannot do this anymore to him.  He thinks I am some other woman.  One night he told me he wants me to be his girl friend.  So I decided to tell him the truth.</p>
<p>I told him my real name, showed him my real picture.  He was upset that I had lied to him for so long.  I was not sure if he would ever talk to me again after I told him the truth.  But I wanted him to know the truth.</p>
<p>I wonder if I can gain his trust back.  I feel that I hurt the only man I will ever love. </p>
<p>I regret what I did to him.  More than anything else, I don’t want to lose him.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/filipino-cupid-filipino-heart-scam-ring/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>How to get a certification:  CAP Exam part 1</title>
		<link>http://elamb.org/how-to-get-a-certification-cap-exam-part-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-get-a-certification-cap-exam-part-1</link>
		<comments>http://elamb.org/how-to-get-a-certification-cap-exam-part-1/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 17:22:46 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Assurance/SSAA]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[Certification/CISSP]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[security]]></category>

	<!-- AutoMeta Start -->
	<category>cap</category>
	<category>exam</category>
	<category>isc2</category>
	<category>cap</category>
	<category>exam</category>
	<category>isc2</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3562</guid>
		<description><![CDATA[CAP Exam I had studied all night after freaking out about the test. I was sick and had to drive to another city to take that damn test. I was exhausted and tired.. lame excuse for being ugly lol. Its &#8230; <a href="http://elamb.org/how-to-get-a-certification-cap-exam-part-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>CAP Exam</h1>
<p><div id="attachment_3579" class="wp-caption alignleft" style="width: 160px"><a href="http://elamb.org/wp-content/uploads/2011/09/how-to-get-a-certification-cap-exam.jpg"><img src="http://elamb.org/wp-content/uploads/2011/09/how-to-get-a-certification-cap-exam-150x128.jpg" alt="passed the cap exam" title="how to get a certification cap exam" width="150" height="128" class="size-thumbnail wp-image-3579" /></a><p class="wp-caption-text">me with picture of CAP notificaiton</p></div><br />
I had studied all night after freaking out about the test.  I was sick and had to drive to another city to take that damn test.  I was exhausted and tired.. lame excuse for being ugly lol.  Its all good.. I still get laid.. but enough about ME.. lets talk about the test <img src='http://elamb.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<h2>How to get a certification</h2>
<p>- ISC2 Certified Authorization Professional (ISC2 CAP)<br />
- Risk Management Certification<br />
- Passing Score 700 out of 1000 points (125 questions on the test *25 test questions not counted toward the results)<br />
- Application Fee: $419<br />
- Verify 2 years experience in this field<br />
- Endorsement Form<br />
- Answer questions to criminal history and background<br />
- Other Info: its a CBT, 3 hours to test, based on NIST 800 series</p>
<h2>How Hard is the CAP Exam</h2>
<p>I just took the ISC2 Certified Authorization Professional test (CAP Exam).  I just want to give others who are about to take this test some idea of what they are up against.  I noticed there is not a lot of Security Professionals talking about it.  I keep hearing that there are only *1000 CAP certified people on Earth (circa 2011).  I don&#8217;t think its because of the difficulty level (lol.. i mean i would not call it an EASY test, but its no CISSP or CCIE.. btw <a href="http://en.wikipedia.org/wiki/CCIE_Certification">CCIE has about 25,000 certified as of about 2010</a> individuals on early despite being around for since 1993&#8230; according to Cisco, &#8220;fewer than 3% of Cisco certified individuals attain CCIE certification&#8221;).  I think there are so few CAP certified people because its not a well know certification and its in a specialized field.  Perhaps the numbers of CAP certified individuals will always be low.</p>
<p>My overall impression is that it is much harder than Security+ but much easier than CISSP.  If you have recent experience with DoD Information Assurance Certification &#038; Accreditation Process (DIACAP) you should have an easy time grasping the National Institute of Standards &#038; Technology (NIST) Special Publication 800 series concepts allowing you to pass the CAP exam.  I would say the same about all the C&#038;A frameworks, NIACAP, NISPOM, DCID 6/3, DITSCAP etc.  If you know the certification &#038; accreditation process well than you will pick up risk management framework fast.  If you have been doing the NIST C&#038;A and/or Risk Management Framework, the test should be a mere refresher course for you and a couple of weeks of reviewing NIST 800 regulations and OMBs you already know might be enough for you to pass the CAP Exam and get this certifications.  You should know, however, that quite a bit has changed since 2009 in the certification &#038; accreditation process of getting authorization.</p>
<p>The test is in the style of the CISSP in that you must choose what is MOST right in many cases.  All questions are 4-multiple choice type questions.</p>
<h1>Study Material for the Certified Authorization Professional</h1>
<p>One of my biggest issues about the CAP material is that is has almost NO decent study material.  There is &#8220;The CISSP and CAP prep guide&#8221; by Russell Dean &#038; Ronald L. Krutz, this is the ONLY book I have found aside from one or two lame ebooks (as of 2011).  </p>
<h2>What I used to get a CAP Certification</h2>
<p>The very first thing you should do is become a member of Isc2.org and download the <strong>ISC2 CAP Candidate Information Bulletin</strong>.  The CAP Exam CIB breaks down all the objectives that you need to be knowledgeable in.  </p>
<p>Read and/or be very familiar with the following NIST &#038; OMB documents:<br />
- NIST 800-37<br />
- NIST 800-53<br />
- NIST 800-53A<br />
- NIST 800-64<br />
- NIST 800-30<br />
- NIST 800-100<br />
- NIST 800-83<br />
- NIST 800-53<br />
OMB circular A-130<br />
Privacy Act of 1974<br />
FISMA Act of 2002<br />
**The full list of documents &#038; regs to be familiar with are located in CAP CIB </p>
<p>Another great resource is practice tests.  Ucertify.com has GREAT content for the CAP, some of the best you will find for the Certified Authorization Professional.  </p>
<h2>Areas to Spend a LOT of time on:</h2>
<p>I would definitely know and fully understand the Risk Management Framework (800-37).  You need to know the tasks on each of the six steps of the Risk Management Framework (800-37).  System Development Lifecycle is also HUGE on this test(800-64).  I would know how Risk Management Framework lines up with SDLC and Risk Assessment process (800-37, 64, 30).  Risk Assessment process, Risk Management Framework and SDLC are all interconnected.  You should know how they work together.  Tasks that are done at each stage and step in all those process and what role does each task is a need to know.  Roles and Responsibilities should be fully understood and memorized.  Although everyone of the steps in the Risk Management framework are covered pretty good, I feel like the following two steps were beaten to death:  Continuous Monitoring &#038; assessments (security control assessor) </p>
<p>The test is computer based and randomized so you might get a completely different set of subject areas.  Your best bet is to study what is in the CAP-CIB and use a bunch of practice tests.</p>
<h2>What I DID NOT see on the Exam:</h2>
<p>I was surprised not to see anything on the NIACAP, DIACAP, FITSAP, DCID 6/3 and DITSCAP.  I was fully expecting it and prepared for it.  Many of the practice test go on and on about Project/Program Management subject areas.  But the only question I recall on that had to do with knowing the role of a Program Manager&#8230; thats about it.  </p>
<h2>Pro &#038; CON on the ISC2 CAP Cert</h2>
<p><strong>CONS:</strong>  I feel like the CAP is currently (2011) not in great demand.  If you do a search on any job database (monster, indeed, simplyhired) you see that there are not many employees listing it as a requirement.  For example, a 2011 search on isc2 CAP anywhere in the US gives 49 results &#8212; http://jobsearch.monster.com/search/?q=isc2-cap<br />
I also think that the certification is WAY over priced.  Its $419 which I think is even more than the ISC2 CISSP concentrations.<br />
There is almost no study material for it.</p>
<p><strong>PROS:</strong>  Covers very important risk management framework material.  Its computer based, so the results are instant.  Its good lead up and practice for the ISSEP.  The ISSEP covers a lot of what is in the CAP.  NIST will get increasingly more important as DoD, NSA and other national security system agencies take on the NIST.</p>
<p>*CAP Exam: CAP certified people in the world (circa 2011):<br />
Canada	6<br />
Germany	1<br />
Korea, Republic of	2<br />
Puerto Rico	2<br />
United States	997<br />
reference: https://www.isc2.org/member-counts.aspx#cap    </p>
<p>**Certification Authorization Professional Candidate Information Bulletin is on ISC2.org.  May have to be a member to get the document</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/how-to-get-a-certification-cap-exam-part-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ho Chen Tung Scam</title>
		<link>http://elamb.org/suspected-a-scam/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=suspected-a-scam</link>
		<comments>http://elamb.org/suspected-a-scam/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 00:02:13 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[email scam]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[scam]]></category>

	<!-- AutoMeta Start -->
	<category>abdulaziz</category>
	<category>abiri</category>
	<category>fayez</category>
	<category>tung</category>
	<category>chen</category>
	<category>intimating</category>
	<category>kin</category>
	<category>calendar</category>
	<category>abdulaziz</category>
	<category>abiri</category>
	<category>fayez</category>
	<category>tung</category>
	<category>chen</category>
	<category>intimating</category>
	<category>kin</category>
	<category>calendar</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2147</guid>
		<description><![CDATA[Ho Chen Tung scam Dear Friend, Thank you so much for your response to my email. It is only natural that you be a bit apprehensive haven received such a mail from somebody that you barely know. Therefore I would &#8230; <a href="http://elamb.org/suspected-a-scam/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>Ho Chen Tung scam</h1>
<blockquote><p>Dear Friend,</p>
<p>Thank you so much for your response to my email. It is only natural that you be a bit apprehensive haven received such a mail from somebody that you barely know. Therefore I would want to start by properly intimating you of who I really am. My name is Ho Chen Tung Foreign operations Hang Seng Bank Ltd. (Hong Kong). Moreover, I believe that you will be anxious to know the kind of business proposition that I have in stock for you. Well, I am soliciting your assistance to be able to transfer a huge amount of money US$21,300,000.00 from my bank that is lying idle with no one ever coming to lay claim to it. Before I go ahead let me tell you how the funds came into existence in the first place.</p>
<p>We had a client sometime ago by the name of Mr. Fayez Abdulaziz Abiri from Iraq and he was a member of the Iraqi forces and also a business man. He made a fixed numbered deposit with a value of US$18,796,000.00 only for 24 calendar months in my branch and this was before the USA and Iraq war.</p>
<p>When the 24 calendar months elapsed, we sent a notification to him so he will advice if still want to extend his term of deposit or not but we did not hear from him. After sometime we tried contacting him again and still there was no reply from him. As his banking officer, I decided to carry out my own investigation as to the where about of Mr. Fayez Abdulaziz Abiri only to find out Fayez Abdulaziz Abiri had died of Kidney infection at Mukaradeeb where his personal oil well was.</p>
<p>It is obvious that you would now want to ask if Mr. Abdulaziz Abiri did not have a next of kin. Interestingly, he did not leave a next of kin on his official document. In fact I asked him some time ago if he was sure that he will not want to include a next of kin in our record and he told me that none of his relative is aware of the account and he wish that it remain so. And to date this money has accumulated interest. Therefore, nineteen million five Hundred Thousand United State Dollars is still lying in my bank and no one will ever come forward to claim it. However, according to the laws of my country at the expiration of six {6} years the funds will revert to the ownership of the Hong Kong Government if nobody applies to claim the funds. Against this backdrop, my suggestion to you is that I will like you as a foreigner to stand as the next of kin to Fayez Abdulaziz Abiri so that you will be able to receive his funds.</p>
<p>If you are interested in doing this business with me, please go ahead and contact me again with you full names, contact address and telephone numbers. I want you to know that I have carefully planned out the modalities of this business and I will be intimating you of it upon confirmation that you are willing to move ahead with me. You will be made the next of kin thereby putting you the position to inherit this huge amount.</p>
<p>Finally, I need you to know that I have evaluated the risk involved in this deal and I guarantee that if you follow my instructions religiously, it will be hazard free. As far as I am concerned it is worth undertaking and I implore you to come along with me because the reward will be great for both of us.</p>
<p>I anticipate hearing from you again soon and I hope it will be positive because I really want us to work together as partners in harnessing this once in a life time opportunity.</p>
<p>Regards.<br />
Ho Chen Tung.</p>
<p>Thanks</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/suspected-a-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jim Ovia &#8211; Zenith Bank Real bank fake scam</title>
		<link>http://elamb.org/scam-6/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scam-6</link>
		<comments>http://elamb.org/scam-6/#comments</comments>
		<pubDate>Thu, 08 Sep 2011 12:50:37 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[nigerian email scam]]></category>
		<category><![CDATA[nigerian scams]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[western union]]></category>

	<!-- AutoMeta Start -->
	<category>ovia</category>
	<category>ovia</category>
	<category>jim</category>
	<category>caption</category>
	<category>150</category>
	<category>attachment_3557</category>
	<category>beeing</category>
	<category>learing</category>
	<category>ovia</category>
	<category>ovia</category>
	<category>jim</category>
	<category>caption</category>
	<category>150</category>
	<category>attachment_3557</category>
	<category>beeing</category>
	<category>learing</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=2390</guid>
		<description><![CDATA[JIM OVIA &#038; Zenith Bank Jim Ovia is a real person and Zenith Bank is a real Nigerian bank. There is a scam flooding the Internet using Zenith to profit. Many scammers (definitely not all) on the Internet are from &#8230; <a href="http://elamb.org/scam-6/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>JIM OVIA &#038; Zenith Bank</h1>
<p>Jim Ovia is a real person and Zenith Bank is a real Nigerian bank.  There is a scam flooding the Internet using Zenith to profit.<br />
<div id="attachment_3557" class="wp-caption alignleft" style="width: 160px"><a href="http://elamb.org/wp-content/uploads/2011/09/JIM-OVIA.jpg"><img src="http://elamb.org/wp-content/uploads/2011/09/JIM-OVIA-150x150.jpg" alt="" title="JIM OVIA" width="150" height="150" class="size-thumbnail wp-image-3557" /></a><p class="wp-caption-text"> Picture of Jim Ovia</p></div></p>
<p>Many scammers (<strong>definitely not all</strong>) on the Internet are from third world countries.  The case listed below is a scam coming from West Africa.  We can assume that the use of actual banks and people from Nigeria that this scam is based in Nigeria.  The following scam alludes to a  real bank in Nigeria called <a href="http://en.wikipedia.org/wiki/Zenith_Bank" title="Nigerian Bank Zenith" target="_blank">Zenith</a>.  It also mentions Jim Ovia, a real person, who is a former CEO of Zenith bank.  </p>
<p><strong>From Reader:</strong></p>
<blockquote><p>I have been sending money by Western Union a very large sum of money to a Jim Ovia of Zenth Bank for help in geting 2.5 millinon dollars. Now if I have not been dealing with this man someone else has beeing using his name and title.</p>
<p>I have read a Biography of Jim Ovia on the internet and after learing what<br />
a wire transfer is I feel like I have been scamed bad cause I have been sending the money through Western Union.</p>
<p>nmw</p></blockquote>
<p><strong>Always research and double check unsolicited (and solicited) claims of wealth on the Internet and in your inbox. </strong> Most things are not what they appear to be on the Internet.  Your trust should be hard earned especially on the &#8216;Net.  Some signs of the foul play will include (but will not be limited to):</p>
<p><strong>Use of free email such as .gmail and .hotmail:</strong>  Remember scammers do not typically have the resources to devote to setting up an email box and website that looks legit so they will use everything free that they can.</p>
<p><strong>BAD ENGLISH: </strong> If they have very poor grammar, it is an indication that they probably don&#8217;t have the education to be put in a place where they would be responsible for other people&#8217;s money particularly an English client.  </p>
<p><strong>Check the links of the email: </strong> Some emails look like the come from the real &#8220;paypal&#8221; or the real &#8220;Zenith Bank&#8221; but it is actually what is called &#8220;phishing&#8221;.  The email has all the official logos and letterhead but the links lead to fake sites.  If you look &#8220;under the hood&#8221; of the email, you will find the real URLs and IP address.  You may also see the use of free email.  If you go into the email and &#8220;Show Original&#8221;  or &#8220;Show source&#8221; you will see where email actually came from, where it is being forwarded to and where the links go to.</p>
<p>If it looks to good to be true, it probably is.  This is an axiom that is an unfortunate truth due to human greed and selfishness.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/scam-6/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Roles &amp; Responsibilities</title>
		<link>http://elamb.org/roles-and-responsibilities/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=roles-and-responsibilities</link>
		<comments>http://elamb.org/roles-and-responsibilities/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 22:45:43 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[C&A]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[DoD Risk Management Framework]]></category>
		<category><![CDATA[DoD RMF]]></category>
		<category><![CDATA[ISSEP]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Risk Management Framework]]></category>

	<!-- AutoMeta Start -->
	<category>owner</category>
	<category>owner</category>
	<category>isse</category>
	<category>assessor</category>
	<category>role</category>
	<category>caption</category>
	<category>officer</category>
	<category>mchugh</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3487</guid>
		<description><![CDATA[NIST roles and responsibilities are addressed throughout the special publication 800 series. The definition of the roles &#038; responsibilities are as follows: Head of Agency The Head of Agency is also known as the Chief Executive Officer. This role is &#8230; <a href="http://elamb.org/roles-and-responsibilities/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>NIST roles and responsibilities are addressed throughout the special publication 800 series.  The definition of the roles &#038; responsibilities are as follows:</p>
<p><strong>Head of Agency </strong><br />
The Head of Agency is also known as the Chief Executive Officer. This role is the highest level executive senior officer within an organization.  They have ultimate responsible for the providing information security protection.  The level of protection must be at the same level as the importance of the information.  The Department of Defense equivanent is a DoD Head of component (i.e. Secretary of the Army).<br />
<div id="attachment_3549" class="wp-caption alignleft" style="width: 160px"><a href="http://elamb.org/wp-content/uploads/2011/09/secretary_army_john_mchugh.jpg"><img src="http://elamb.org/wp-content/uploads/2011/09/secretary_army_john_mchugh-150x150.jpg" alt="" title="Head of Agency: secretary army john mchugh" width="150" height="150" class="size-thumbnail wp-image-3549" /></a><p class="wp-caption-text">image of secretary army john mchugh</p></div></p>
<p><strong>Risk Executive Function</strong><br />
The Risk Executive Function&#8217;s main focus is the overall risk to the entire organization.  They create a risk strategy for the organization that guides mission/business process and system-level risk assessments.  The Risk Executive Function is and important role for Tier 1 activities of managing risk of information systems IAW NIST SP 800-39.</p>
<p><strong>CIO</strong><br />
Chief Information Officer is an organizational official responsible for (1) designating a senior information security officer;  (2) developing and maintaining information security policies; (3) ensure that those with responsibilities in system security have proper training. </p>
<p><strong>Information Owner/Steward</strong><br />
&#8220;The information owner/steward is an organizational official with statutory, management, or operational authority for specified information and the responsibility for establishing the policies and procedures governing its generation, collection, processing, dissemination, and disposal.&#8221; NIST SP 800-37  The Information Owner must coodinate with the Information System Owner (DoD PM equivalent) for decisions involving the overall system.</p>
<p><strong>Senior Information Security Officer</strong><br />
The SISO is directly responsible to the CIO.  They&#8217;re focus is the information security of the organization&#8217;s data.  They act as a liaison between CIO and the Authorizing Official.  The DoD equivalent (circa 2010) is known as the Senior Information Assurance Officer (SIAO).</p>
<p><strong>Authorizing Official</strong><br />
AO formally accepts the risk of a system in the Implementation/Assessment phase of the System Development Lifecycle and Step 5, Authorization step of the Risk Management Framework.</p>
<p><strong>Common Control Provider<br />
</strong><br />
&#8220;The common control provider is an individual, group, or organization responsible for the development, implementation, assessment, and monitoring of common controls.&#8221;  NIST SP 800-37.  A common control is a security controls that covers multiple information systems within and organization.  Examples of common controls: Incident Response, Network boundary protection (firewalls, IDS/IPS). </p>
<p><strong>Information System Owner</strong><br />
&#8220;The information system owner is an organizational official responsible for the procurement, development, integration, modification, operation, maintenance, and disposal of an information system.&#8221; NIST SP 800-37</p>
<p><strong>Information System Security Engineer</strong><br />
&#8220;The information system security engineer is an individual, group, or organization responsible for conducting information system security engineering activities.&#8221; NIST SP 800-37  The ISSE implements security into the design of systems. The ISSE is often a consultant or Subject Matter Expert who focus is applying information assurance frameworks and regulations in an information system.   </p>
<p><strong>Information System Security Officer</strong><br />
This role is initiated at the Initial phase of the System Development Lifecycle (SDLC).  &#8220;The information system security officer<br />
 is an individual responsible for ensuring that the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the information system owner&#8221; NIST SP 800-37.  This role has been called and Information Assurance Officer (IAO) within the Department of Defense.  Within the DoD this role is appointed by the Information Assurance Manager (IAM).  Also known as the Information System Security Manager (ISSM).  The ISSM is often responsible to over site and being a supervisor of ISSO positions.  </p>
<p><strong>Security Control Assessor </strong><br />
&#8220;The security control assessor is an individual, group, or organization responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an information system to determine the overall effectiveness of the controls&#8221; NIST SP 800-37.  </p>
<p>The NIST &#038; DoD have very similar roles with different names:</p>
<table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0 width=625</p>
<tr style='height:60.0pt'>
<td width=384 style='width:4.0in;border:solid #EAEAEA 1.0pt;border-bottom:<br />
  solid #EAEAEA 3.0pt;background:#EEB00B;padding:.75pt 5.4pt 0in 5.4pt;<br />
  height:60.0pt'>
<p class=MsoNormal><b>DoDI 8510.01 DIACAP</b></p>
</td>
<td width=241 style='width:180.9pt;border-top:solid #EAEAEA 1.0pt;border-left:<br />
  none;border-bottom:solid #EAEAEA 3.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#EEB00B;padding:.75pt 5.4pt 0in 5.4pt;height:60.0pt'>
<p class=MsoNormal><b>NIST SP 800-37 Security Authorization</b></p>
</td>
</tr>
<tr style='height:41.15pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Heads of the DoD Components</b> </p>
</td>
<td width=241 valign=top style='width:180.9pt;border-top:none;border-left:<br />
  none;border-bottom:solid #EAEAEA 1.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Head of Agency (CEO)</b> </p>
</td>
</tr>
<tr style='height:41.15pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#FCF2E7;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Designated Accrediting Authority (DAA)/ </b></p>
</td>
<td width=241 style='width:180.9pt;border-top:none;border-left:none;<br />
  border-bottom:solid #EAEAEA 1.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#FCF2E7;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Authorizing Official </b></p>
</td>
</tr>
<tr style='height:41.15pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Program Manager (PM)/ Systems Manager (SM)</b> </p>
</td>
<td width=241 valign=top style='width:180.9pt;border-top:none;border-left:<br />
  none;border-bottom:solid #EAEAEA 1.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Information System Owner </b></p>
</td>
</tr>
<tr style='height:41.15pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#FCF2E7;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Information Assurance Manager (IAM)</b> </p>
</td>
<td width=241 valign=top style='width:180.9pt;border-top:none;border-left:<br />
  none;border-bottom:solid #EAEAEA 1.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#FCF2E7;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Information System Security Officer</b> </p>
</td>
</tr>
<tr style='height:58.35pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:58.35pt'>
<p class=MsoNormal><b>Information Assurance Officer (IAO)   </b></p>
</td>
<td width=241 style='width:180.9pt;border-top:none;border-left:none;<br />
  border-bottom:solid #EAEAEA 1.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:58.35pt'>
<p class=MsoNormal><b>Information System Security Officer/ Information System<br />
  Security Engineer</b> </p>
</td>
</tr>
<tr style='height:41.15pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#FCF2E7;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Certifying Authority (CA)</b> </p>
</td>
<td width=241 rowspan=2 valign=top style='width:180.9pt;border-top:none;<br />
  border-left:none;border-bottom:solid #EAEAEA 1.0pt;border-right:solid #EAEAEA 1.0pt;<br />
  background:#FCF2E7;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Security Control Assessor </b></p>
</td>
</tr>
<tr style='height:41.15pt'>
<td width=384 valign=top style='width:4.0in;border:solid #EAEAEA 1.0pt;<br />
  border-top:none;background:#F8E4CC;padding:.75pt 5.4pt 0in 5.4pt;height:41.15pt'>
<p class=MsoNormal><b>Validator</b> </p>
</td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/roles-and-responsibilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Background of the Study for Student Record System</title>
		<link>http://elamb.org/background-of-the-study-for-student-record-system/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=background-of-the-study-for-student-record-system</link>
		<comments>http://elamb.org/background-of-the-study-for-student-record-system/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 18:47:29 +0000</pubDate>
		<dc:creator>brenz</dc:creator>
				<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Other Stuff]]></category>

	<!-- AutoMeta Start -->
	<category>srs</category>
	<category>student</category>
	<category>institutions</category>
	<category>storage</category>
	<category>decisions</category>
	<category>educational</category>
	<category>helps</category>
	<category>assist</category>
	<category>srs</category>
	<category>student</category>
	<category>institutions</category>
	<category>storage</category>
	<category>decisions</category>
	<category>educational</category>
	<category>helps</category>
	<category>assist</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3226</guid>
		<description><![CDATA[The ever changing trend in technology brought the necessity for the automation of everything from paper-and-pen based to absolute computer domination. The overwhelming emergence of computers paved way to easier access of information that leads to increased production, efficiency and &#8230; <a href="http://elamb.org/background-of-the-study-for-student-record-system/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The ever changing trend in technology brought the necessity for the automation of everything from paper-and-pen based to absolute computer domination. The overwhelming emergence of computers paved way to easier access of information that leads to increased production, efficiency and reliability.</p>
<p>The increasing urbanity of modern information system allows the information and communication technologies to be utilized in different actions. In fact, the educational institutions are one of the leading users of computer applications in order to manage student data.</p>
<p>Student Record System (SRS) is a computer application that deals with the generation, collection, organization, storage, retrieval and dissemination of recorded knowledge. SRS provide capabilities for entering student information, building a student record and managing other student – related data needs in the school.</p>
<p>In the light of recent high profile cases there is increased emphasis being placed on all institutions to be able to demonstrate good record management. The effective management of records ensures sound decisions based on full, accurate and up-to-date information and by ensuring that the underlying principles behind those decisions can be traced, scrutinized and justified as necessary.</p>
<p>This breakthrough gave way to the development of databases which became useful for storing data for important information.<br />
In the development of database management system, the organization of storage of data was prioritized. A DBMS controls the creation, maintenance and use of the database storage structures of educational institutions of their users. It allows institutions to place control of institution wide database development in the hands of Database Administrators (DBAs) and other specialists.</p>
<p>An SRS provide the following benefits:<br />
1.	It helps facilitate decisions about courses students should take and assist with problems that may arise<br />
2.	It assist with monitoring accountability and future planning<br />
3.	It helps teachers make instructional decisions and to obtain specific information that  may assist in working with a student<br />
4.	It helps evaluate the success of various programs in  a certain curriculum</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/background-of-the-study-for-student-record-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Philippine Cupid</title>
		<link>http://elamb.org/philippine-cupid/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=philippine-cupid</link>
		<comments>http://elamb.org/philippine-cupid/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 01:57:51 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[date scams]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[online dating]]></category>

	<!-- AutoMeta Start -->
	<category>cupid</category>
	<category>cupid</category>
	<category>philippine</category>
	<category>filipino</category>
	<category>romance</category>
	<category>dating</category>
	<category>dating</category>
	<category>men</category>
	<category>cupid</category>
	<category>cupid</category>
	<category>philippine</category>
	<category>filipino</category>
	<category>romance</category>
	<category>dating</category>
	<category>dating</category>
	<category>men</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3502</guid>
		<description><![CDATA[Philippine Cupid Filipinocupid.com (also known as &#8220;philippine heart&#8221;, &#8220;filipino heart&#8221;, &#8220;filipina cupid&#8221;, or fc, fh for short) is a dating site. Although, philippine cupid is focused on Filipino men and women, there is huge presence of westerners there (mostly European &#8230; <a href="http://elamb.org/philippine-cupid/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>Philippine Cupid</h1>
<p>Filipinocupid.com (also known as &#8220;philippine heart&#8221;, &#8220;filipino heart&#8221;, &#8220;filipina cupid&#8221;, or fc, fh for short) is a dating site.  Although, philippine cupid is focused on Filipino men and women, there is huge presence of westerners there (mostly European &#038; American males).  The on line dating interface of the site is similar to the every grown genre of race specific dating sites (i.e. thai cupid, japan cupid, korean cupid, dominican cupid, columbian cupid, latina cupid, caribbean cupid and all the other cupid dating sites).</p>
<p>Philippine culture can be found among the profiles of the members, however the language on the site is almost exclusively English (with some spanish, french, italian and almost no tagalog).  Western men will quickly see that they are the primary target of many (if not most) of the filipinas on filipino cupid.  The same cannot be said of some of the other &#8220;cupid dating&#8221; sites.</p>
<p>Although the site is completely legitimate, popular and well done, members should be careful of the MANY <a href="http://elamb.org/filipino-date-scammers/" title="date scam" target="_blank">date scams</a>, <a href="http://elamb.org/romance-scam/" title="romance scam" target="_blank">romance scams</a> and fake date profiles on the site.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/philippine-cupid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ia awareness training</title>
		<link>http://elamb.org/ia-awareness-training/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ia-awareness-training</link>
		<comments>http://elamb.org/ia-awareness-training/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 15:12:20 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
				<category><![CDATA[Assurance]]></category>
		<category><![CDATA[Assurance/DIACAP]]></category>
		<category><![CDATA[Assurance/DITSCAP]]></category>
		<category><![CDATA[Certification/Security+]]></category>
		<category><![CDATA[Certification/Security+/Infrastructure Security/Network]]></category>
		<category><![CDATA[Certification/Security+/Operational & Organizational]]></category>
		<category><![CDATA[Computer Security]]></category>
		<category><![CDATA[DIARMF]]></category>
		<category><![CDATA[Main Digg]]></category>
		<category><![CDATA[Risk Management Framework]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Awareness/ISSA]]></category>

	<!-- AutoMeta Start -->
	<category>awareness</category>
	<category>training</category>
	<category>competencies</category>
	<category>cio</category>
	<category>strives</category>
	<category>continuum</category>
	<category>“continuum”</category>
	<category>800</category>
	<category>awareness</category>
	<category>training</category>
	<category>competencies</category>
	<category>cio</category>
	<category>strives</category>
	<category>continuum</category>
	<category>“continuum”</category>
	<category>800</category>
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=3485</guid>
		<description><![CDATA[Information Assurance Awareness Training NIST Special Publication 800-50, is a regulation dedicated to IA Awareness Training NIST SP 800-5, Building an Information Technology Security Awareness &#038; Training Program The 800-50 includes guidance on development and sustainment of an awareness &#038; &#8230; <a href="http://elamb.org/ia-awareness-training/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1>Information Assurance Awareness Training</h1>
<p></br></p>
<h2>NIST Special Publication 800-50, is a regulation dedicated to <strong>IA Awareness Training</strong></h2>
<p></br><br />
NIST SP 800-5, Building an Information Technology Security Awareness &#038; Training Program<br />
</br><br />
The 800-50 includes guidance on development and sustainment of an awareness &#038; training IT Security (aka information assurance training) program for all users, employees and supervisors within an organization.  Having a training program is mandated by the Federal Information Security Act of 2002.<br />
</br></p>
<h2>IA Awareness Training &#8211; Roles &#038; Responsibilities</h2>
<p><strong>Agency heads</strong> &#8211; must ensure that high priority is given to effective security awareness and training for employees.  Appoint a CIO<br />
<strong>CIO</strong> – Establish overall strategy, funding, tracking and report is in place for the IT security awareness and training program<br />
<strong>IT Security Program Manager </strong>– tactical deployment, development and maintenance of the IT security &#038; awareness program.<br />
<strong>Managers</strong> – responsible for complying with IT security awareness program.  Work with CIO and IT Security Program Managers to share responsibility.  Ensure all users are trained to fulfill their security roles before access is giving.  Promote professional development  and certification of the IT staff.<br />
<strong>Users</strong> – largest audience in any organization and are the single most important group of people who can help to reduce unintentional errors.<br />
</br><br />
800-50 calls learning a “continuum”.   The continuum of learning starts awareness and builds into education.<br />
Awareness – awareness is not training.  Awareness focuses on security concerns to ensure users are mindful of basic rules and issues in a given environment.<br />
</br><br />
<block>Awareness is not training. The purpose of awareness presentations is simply to focus attention on security. Awareness presentations are intended to allow individuals to recognize IT security concerns and respond accordingly.</block> &#8211;  800-50<br />
</br></p>
<blockquote><p>Training – is a formal focused method to develop a skill for job performance.<br />
Training strives to produce relevant and needed security skills and competencies – 800-50</p></blockquote>
<p></br></p>
<blockquote><p>Education – combines multidisciplinary areas into a common body of knowledge.
</p></blockquote>
<p></br><br />
<block>Education integrates all of the security skills and competencies of the various functional specialties into a common body of knowledge . . . and strives to produce IT security specialists and professionals capable of vision and pro-active response.</block> &#8211;800-50</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/ia-awareness-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

