<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Community Site Security? in Member Support</title>
    <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25609#M5106</link>
    <description>&lt;P&gt;Need to take as a grain of salt of these types of scans, they typically don't mean a whole lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go scan dhs.gov, whitehouse.gov, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bottom line, I don't think we need to spend time and money on meeting these scans. Of course the overall security measures need to be in place, but no necessarily spending effort chasing some academic security standards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;JMHO,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2019 16:28:00 GMT</pubDate>
    <dc:creator>Chuxing</dc:creator>
    <dc:date>2019-07-19T16:28:00Z</dc:date>
    <item>
      <title>Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25605#M5104</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1247402195"&gt;@david-shearer&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1566072329"&gt;@amandavanceISC2&lt;/a&gt;&amp;nbsp;this Community site needs some love and attention to when it comes to security. In particular, it is missing several "security headers". The site gets a failing grade of "D" [&lt;A href="https://securityheaders.com/?q=https%3A%2F%2Fcommunity.isc2.org%2F&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;report here&lt;/A&gt;]. In comparison the isc2.org site gets a grade of A [report &lt;A href="https://securityheaders.com/?q=isc2.org%2F&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;here&lt;/A&gt;].&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 17:32:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25605#M5104</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-07-19T17:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25608#M5105</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for bringing this to our attention. We will have our security team review this information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 16:17:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25608#M5105</guid>
      <dc:creator>SamanthaO_isc2</dc:creator>
      <dc:date>2019-07-19T16:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25609#M5106</link>
      <description>&lt;P&gt;Need to take as a grain of salt of these types of scans, they typically don't mean a whole lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go scan dhs.gov, whitehouse.gov, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bottom line, I don't think we need to spend time and money on meeting these scans. Of course the overall security measures need to be in place, but no necessarily spending effort chasing some academic security standards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;JMHO,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 16:28:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25609#M5106</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2019-07-19T16:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25610#M5107</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that site provides a reliable assessment this is certainly an embarrassment for (ISC)2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming the community site is still being 'developed' --- like I said in &lt;A href="https://community.isc2.org/t5/Member-Support/ISC2-membership-web-site-remodeling-competition/m-p/24729#M4795" target="_blank" rel="noopener"&gt;another post&lt;/A&gt;, it's like they employed the waterfall model, but re-ordered the phases --- perhaps we'll see this attended to shortly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I seem to be feeling over-optimistic today --- could have been something I ate...&amp;nbsp;&lt;img id="manlol" class="emoticon emoticon-manlol" src="https://community.isc2.org/i/smilies/16x16_man-lol.png" alt="Man LOL" title="Man LOL" /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 16:33:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25610#M5107</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-07-19T16:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25616#M5110</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/323397747"&gt;@Chuxing&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;these types of scans, they typically don't mean a whole lot.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Unfortunately, we hear (la, la, la, la, la, not listening to you) a lot until something happens. Then it is on record that management knew about it and maybe they didn't do anything about it because someone told them not to. I wouldn't want to be in that position. I take AppSec very seriously. That is why I showed the comparison between sites and the differences in grades. Why should social media sites be a &amp;lt;blank&amp;gt;. The organization has a responsibility to protect your data and mine.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 17:46:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25616#M5110</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-07-19T17:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25626#M5113</link>
      <description>&lt;P&gt;There’s security risk, and there’s risk management. For any realistic risk management, one has to evaluate the probability and the impact, then decide what is the most optimum risk treatment. One of the risk treatments is acceptance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is my humble opinion that in this case, acceptance should be the treatment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If ISC2 has unlimited resources, sure, go ahead to make the residual risk next to zero.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FWIW,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 23:56:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25626#M5113</guid>
      <dc:creator>Chuxing</dc:creator>
      <dc:date>2019-07-19T23:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25627#M5114</link>
      <description>Message received.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;David Shearer&lt;BR /&gt;CEO&lt;BR /&gt;&lt;BR /&gt;(ISC)2, Inc.&lt;BR /&gt;311 Park Place Blvd., Suite 400&lt;BR /&gt;Clearwater, FL 33759&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.isc2.org" target="_blank"&gt;www.isc2.org&lt;/A&gt; | &lt;A href="http://www.iamcybersafe.org" target="_blank"&gt;www.iamcybersafe.org&lt;/A&gt; | dshearer@isc2.org</description>
      <pubDate>Sat, 20 Jul 2019 00:43:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25627#M5114</guid>
      <dc:creator>david-shearer</dc:creator>
      <dc:date>2019-07-20T00:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25659#M5126</link>
      <description>&lt;P&gt;Lithium communities at other companies (&lt;A href="https://securityheaders.com/?q=https%3A%2F%2Fcommunity.checkpoint.com%2F&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;Checkpoint&lt;/A&gt;, &lt;A href="https://securityheaders.com/?q=https%3A%2F%2Fcommunity.cisco.com%2Ft5%2Ftechnology-and-support%2Fct-p%2Ftechnology-support&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;Cisco&lt;/A&gt;,&amp;nbsp;&lt;A href="https://securityheaders.com/?q=https%3A%2F%2Fcommunity.spotify.com%2F&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;Spotify&lt;/A&gt;,&amp;nbsp;&lt;A href="https://securityheaders.com/?q=https%3A%2F%2Fcommunity.sprint.com%2Ft5%2FCommunity-Guidelines%2Fct-p%2Fgeneral&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;Sprint&lt;/A&gt;, &lt;A href="https://securityheaders.com/?q=https%3A%2F%2Fwww.dell.com%2Fcommunity%2FDell-Community%2Fct-p%2FEnglish&amp;amp;followRedirects=on" target="_blank" rel="noopener"&gt;Dell&lt;/A&gt;) get similar grades.&amp;nbsp; It seems like the "AppSec" vulnerability and its response belong to Lithium, not (ISC)².&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(ISC)²'s risk is most likely reputational damage from a supplier breach.&amp;nbsp; Their mitigation is to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;minimize non-public information shared with suppliers and to include a "supplier breach" scenario in their Incident Response playbook so that they are prepared to quickly respond.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My guess/hope is that (ISC)² is only sharing first/last name, email and a list of certificates held (to be turned into badges). If true,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/323397747"&gt;@Chuxing&lt;/a&gt;&amp;nbsp;is on the right track regarding the severity and appropriate response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do suggest that if one believes there to exploit potential, the community is not the best place to start the conversation.&amp;nbsp; Instead, one ought to follow responsible disclosure practices.&amp;nbsp; That is, &lt;STRONG&gt;privately&lt;/STRONG&gt; report the issue and a reasonable deadline to the company before you go public.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2019 04:24:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25659#M5126</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2019-07-21T04:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25701#M5143</link>
      <description>&amp;gt; denbesten (Community Champion) posted a new reply in Member Support on&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; I do suggest that if one believes there to exploit potential, the&lt;BR /&gt;&amp;gt; community is not the best place to start the conversation.&lt;BR /&gt;&lt;BR /&gt;You could, of course, sign on to the CISSPforum, and, privately and safely, discuss&lt;BR /&gt;it there ...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/Welcome/Privacy/m-p/10722" target="_blank"&gt;https://community.isc2.org/t5/Welcome/Privacy/m-p/10722&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/Welcome/CISSPforum-replacement/m-p/11006" target="_blank"&gt;https://community.isc2.org/t5/Welcome/CISSPforum-replacement/m-p/11006&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;True patriotism hates injustice in its own land more than&lt;BR /&gt;anywhere else. - Clarence Darrow&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Mon, 22 Jul 2019 17:25:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/25701#M5143</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-07-22T17:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26848#M5473</link>
      <description>&lt;P&gt;When was the last ISC2 security risk assessment performed and what were the results?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 04:23:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26848#M5473</guid>
      <dc:creator>cdc</dc:creator>
      <dc:date>2019-08-14T04:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26849#M5474</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1353718417"&gt;@cdc&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;When was the last ISC2 security risk assessment performed and what were the results?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I have a feeling they concluded that performing a risk assessment was too much of a risk...&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 05:14:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26849#M5474</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-08-14T05:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26869#M5482</link>
      <description>&lt;P&gt;Would you share a list of what&amp;nbsp; you consider "academic" and therefore not worth time to implement?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:38:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26869#M5482</guid>
      <dc:creator>cdc</dc:creator>
      <dc:date>2019-08-14T16:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Community Site Security?</title>
      <link>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26870#M5483</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;, great catch!&amp;nbsp; The lack of content security policy is the main reason for the C grade.&amp;nbsp; Troy Hunt, Microsoft Regional Director and MVP, has several articles on his website about its purpose and how to configure.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 16:42:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Community-Site-Security/m-p/26870#M5483</guid>
      <dc:creator>cdc</dc:creator>
      <dc:date>2019-08-14T16:42:11Z</dc:date>
    </item>
  </channel>
</rss>

