<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Engineering - Be All That You Can Be in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Security-Engineering-Be-All-That-You-Can-Be/m-p/36167#M2617</link>
    <description>&lt;P&gt;&lt;EM&gt;"Security engineering isn't about adding a bunch of controls to something.&amp;nbsp;It's about coming up with security properties you'd like a system to follow, choosing mechanisms that enforce these properties, and assuring yourself that your security properties hold"&lt;/EM&gt; says Veeral Patel after giving up on reading Ross Anderson's quintessential &lt;A href="https://www.cl.cam.ac.uk/~rja14/book.html" target="_blank" rel="noopener"&gt;book&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So what he did was invent his own curriculum&amp;nbsp;to study the discipline. Does what he have in his&amp;nbsp;&lt;A href="https://github.com/veeral-patel/learn-security-engineering" target="_blank" rel="noopener"&gt;GitHub repo&lt;/A&gt;&amp;nbsp;hit the mark? Sadly, NO. Why people continue to "publish" documentation in GitHub baffles me. It's for code people!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Engineering is about process. You'll learn more by studying NIST SP 800-161&lt;A href="https://doi.org/10.6028/NIST.SP.800-160v1" target="_blank" rel="noopener"&gt; volume 1&lt;/A&gt; and &lt;A href="https://doi.org/10.6028/NIST.SP.800-160v2" target="_blank" rel="noopener"&gt;volume 2&lt;/A&gt;. Become a Systems Security Engineer. Solve hard systems security engineering problems. Certify&amp;nbsp;as an &lt;A href="https://www.isc2.org/Certifications/CISSP-Concentrations" target="_blank" rel="noopener"&gt;CISSP-ISSEP&lt;/A&gt;. Be All That You Can Be!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ps. we'll have to give him credit for digging up a link to the &lt;A href="https://csrc.nist.gov/csrc/media/publications/conference-paper/1998/10/08/proceedings-of-the-21st-nissc-1998/documents/early-cs-papers/dod85.pdf" target="_blank" rel="noopener"&gt;Orange book&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;IMG id="smileywink" class="emoticon emoticon-smileywink" src="https://community.isc2.org/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:32:41 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:32:41Z</dc:date>
    <item>
      <title>Security Engineering - Be All That You Can Be</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Security-Engineering-Be-All-That-You-Can-Be/m-p/36167#M2617</link>
      <description>&lt;P&gt;&lt;EM&gt;"Security engineering isn't about adding a bunch of controls to something.&amp;nbsp;It's about coming up with security properties you'd like a system to follow, choosing mechanisms that enforce these properties, and assuring yourself that your security properties hold"&lt;/EM&gt; says Veeral Patel after giving up on reading Ross Anderson's quintessential &lt;A href="https://www.cl.cam.ac.uk/~rja14/book.html" target="_blank" rel="noopener"&gt;book&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So what he did was invent his own curriculum&amp;nbsp;to study the discipline. Does what he have in his&amp;nbsp;&lt;A href="https://github.com/veeral-patel/learn-security-engineering" target="_blank" rel="noopener"&gt;GitHub repo&lt;/A&gt;&amp;nbsp;hit the mark? Sadly, NO. Why people continue to "publish" documentation in GitHub baffles me. It's for code people!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Engineering is about process. You'll learn more by studying NIST SP 800-161&lt;A href="https://doi.org/10.6028/NIST.SP.800-160v1" target="_blank" rel="noopener"&gt; volume 1&lt;/A&gt; and &lt;A href="https://doi.org/10.6028/NIST.SP.800-160v2" target="_blank" rel="noopener"&gt;volume 2&lt;/A&gt;. Become a Systems Security Engineer. Solve hard systems security engineering problems. Certify&amp;nbsp;as an &lt;A href="https://www.isc2.org/Certifications/CISSP-Concentrations" target="_blank" rel="noopener"&gt;CISSP-ISSEP&lt;/A&gt;. Be All That You Can Be!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ps. we'll have to give him credit for digging up a link to the &lt;A href="https://csrc.nist.gov/csrc/media/publications/conference-paper/1998/10/08/proceedings-of-the-21st-nissc-1998/documents/early-cs-papers/dod85.pdf" target="_blank" rel="noopener"&gt;Orange book&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;IMG id="smileywink" class="emoticon emoticon-smileywink" src="https://community.isc2.org/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:32:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Security-Engineering-Be-All-That-You-Can-Be/m-p/36167#M2617</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:32:41Z</dc:date>
    </item>
  </channel>
</rss>

