cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
AppDefects
Community Champion

Community Site Security?

@david-shearer  @amandavanceISC2 this Community site needs some love and attention to when it comes to security. In particular, it is missing several "security headers". The site gets a failing grade of "D" [report here]. In comparison the isc2.org site gets a grade of A [report here].

12 Replies
SamanthaO_isc2
ISC2 Former Staff

Hello @AppDefects , 

 

Thank you for bringing this to our attention. We will have our security team review this information. 

 

 

 

Samantha O'Connor
(ISC)² Online Community Manager
Chuxing
Community Champion

Need to take as a grain of salt of these types of scans, they typically don't mean a whole lot.

 

Go scan dhs.gov, whitehouse.gov, etc.

 

Bottom line, I don't think we need to spend time and money on meeting these scans. Of course the overall security measures need to be in place, but no necessarily spending effort chasing some academic security standards.

 

JMHO,

 


____________________________________
Chuxing Chen, Ph.D., CISSP, PMP
Shannon
Community Champion

 

 

If that site provides a reliable assessment this is certainly an embarrassment for (ISC)2.

 

Assuming the community site is still being 'developed' --- like I said in another post, it's like they employed the waterfall model, but re-ordered the phases --- perhaps we'll see this attended to shortly.

 

(I seem to be feeling over-optimistic today --- could have been something I ate... Man LOL)

 

 

Shannon D'Cruz,
CISM, CISSP

www.linkedin.com/in/shannondcruz
AppDefects
Community Champion


@Chuxing wrote:

these types of scans, they typically don't mean a whole lot.


Unfortunately, we hear (la, la, la, la, la, not listening to you) a lot until something happens. Then it is on record that management knew about it and maybe they didn't do anything about it because someone told them not to. I wouldn't want to be in that position. I take AppSec very seriously. That is why I showed the comparison between sites and the differences in grades. Why should social media sites be a <blank>. The organization has a responsibility to protect your data and mine.

Chuxing
Community Champion

There’s security risk, and there’s risk management. For any realistic risk management, one has to evaluate the probability and the impact, then decide what is the most optimum risk treatment. One of the risk treatments is acceptance.

 

It is my humble opinion that in this case, acceptance should be the treatment.

 

If ISC2 has unlimited resources, sure, go ahead to make the residual risk next to zero.

 

FWIW,


____________________________________
Chuxing Chen, Ph.D., CISSP, PMP
david-shearer
ISC2 Former Staff

Message received.

Regards,

David Shearer
CEO

(ISC)2, Inc.
311 Park Place Blvd., Suite 400
Clearwater, FL 33759

www.isc2.org | www.iamcybersafe.org | dshearer@isc2.org
Thanks,

David Shearer
| CEO | dshearer@isc2.org | www.isc2.org | iamcybersafe.org |
denbesten
Community Champion

Lithium communities at other companies (Checkpoint, CiscoSpotifySprint, Dell) get similar grades.  It seems like the "AppSec" vulnerability and its response belong to Lithium, not (ISC)².  

 

(ISC)²'s risk is most likely reputational damage from a supplier breach.  Their mitigation is to minimize non-public information shared with suppliers and to include a "supplier breach" scenario in their Incident Response playbook so that they are prepared to quickly respond.  

 

My guess/hope is that (ISC)² is only sharing first/last name, email and a list of certificates held (to be turned into badges). If true, @Chuxing is on the right track regarding the severity and appropriate response.

 

I do suggest that if one believes there to exploit potential, the community is not the best place to start the conversation.  Instead, one ought to follow responsible disclosure practices.  That is, privately report the issue and a reasonable deadline to the company before you go public.

rslade
Influencer II

> denbesten (Community Champion) posted a new reply in Member Support on

>   I do suggest that if one believes there to exploit potential, the
> community is not the best place to start the conversation.

You could, of course, sign on to the CISSPforum, and, privately and safely, discuss
it there ...

https://community.isc2.org/t5/Welcome/Privacy/m-p/10722

https://community.isc2.org/t5/Welcome/CISSPforum-replacement/m-p/11006

====================== (quote inserted randomly by Pegasus Mailer)
rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org
True patriotism hates injustice in its own land more than
anywhere else. - Clarence Darrow
victoria.tc.ca/techrev/rms.htm http://twitter.com/rslade
http://blogs.securiteam.com/index.php/archives/author/p1/
https://is.gd/RotlWB

............

Other posts: https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413

This message may or may not be governed by the terms of
http://www.noticebored.com/html/cisspforumfaq.html#Friday or
https://blogs.securiteam.com/index.php/archives/1468
cdc
Newcomer III

When was the last ISC2 security risk assessment performed and what were the results?