Layer 8 and Why People are the Most Important Security Tool

Presented at NolaCon 2017, May 20, 2017, 4 p.m. (Unknown duration).

People are the cause of many security problems, but people are also the most effective resource for combating them. Technology is critical, but without trained professionals, it is ineffective. In the context two case studies, the presenter will describe specific instances where human creativity and skill overcame technical deficiencies. The presenter believes this topic to be particularly relevant for “blue teamers” who often must defend their organization’s’ information assets under less-than-ideal circumstances.

Technical details will include the specific tools used, screenshots of captured data, and analysis of the malware and the malicious user’s activity. The goal of the presentation is show the importance of technical ability and critical thinking, and to demonstrate that skilled people are the most important tool in an information security program.

For context, the conclusion reads: Several technological challenges conspired against the team during these incidents. Using both commercial and freely obtainable tools the team was able to overcome these obstacles in a resourceful and cost-efficient manner. The analysts’ actions demonstrate that problems can be solved creatively using limited resources. While companies must regularly evaluate commercial products, properly trained personnel can be more valuable to an organization than any hardware or software device.


Presenters:

  • Damon J. Small
    Damon Small began his career studying music at Louisiana State University. Pursuing the changing job market, he took advantage of computer skills learned in the LSU recording studio to become a systems administrator in the mid 1990s. Over the past 17 years as a security professional he has supported infosec initiatives in the healthcare, defense, aerospace, and oil and gas industries. In addition to his Bachelor of Arts in Music, Small completed the Master of Science in Information Assurance degree from Norwich University in 2005. His role as Technical Director includes working closely with NCC Group consultants and clients in delivering complex security assessments that meet varied business requirements. Twitter: @damonsmall

Links:

Similar Presentations: