Welcome to RecertHero!
Submit bugs, feature requests, and feedbackISC2 · Free
Free continuing-education opportunities that count toward CISSP-ISSAP renewal — vendor webinars, community talks, and free courses. RecertHero estimates the CPE value of every opportunity, so you can plan toward the 60 CPEs CISSP-ISSAP requires every 3 years — without re-keying each entry into ISC2's portal.
50 results mapped to CISSP-ISSAP, soonest first.
It’s now or never to modernize security. Our networks can no longer stretch to the apps living in the cloud and teams working remotely, plus cyber threats routinely exploiting the excessive trust built into them. Network transformation projects are always daunting – especially when you can never know exactly what your business will need tomorrow. New risks to mitigate, standards to comply with, and use cases to scale will inevitably emerge. Join (ISC)² and Cloudflare April 20, 2022 at 2:00 p.m. Eastern, 11 a.m. Pacific to hear Cloudflare Field Technologist, Trey Guinn share perspectives on how to both fast-track and future-proof your security approach. He has seen organizations commit to network and security architectures that were complex and costly to keep changing to adapt to future needs. Trey will advise us on the most important principles to evaluate new technology platforms with confidence that it’ll enable your organization to evolve and innovate faster than ever before. In this webinar you’ll also hear about: • The most pressing business and IT drivers of digital transformation • The emergence of the Internet as the new corporate network • The key criteria to evaluate Zero Trust security and SASE networking investments
Recently, we saw the disastrous effects of numerous far-reaching supply chain breaches and third-party code vulnerabilities, including SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. Unfortunately, we can expect to see more of the same in 2022 and beyond. When we consider these latest cyber events, it’s important to prepare—with the right people, processes, and tools—for what’s unquestionably yet to come. This is why every organization must be sure to have a robust third-party security risk strategy in place. Join Panorays Co-Founder and CTO, Demi Ben-Ari as he shares tips on how to best reduce supply chain risk and contain attacks. Plus he’ll discuss: 1. Why supply chain security is critically important right now 2. What actually happened with SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. 3. How to take action when a supply chain attack happens, and how to minimize the blast radius.
No doubt, you’ve heard the buzz about zero trust. Zero trust isn’t a product but rather a journey. While the end goal is worthwhile, like most things in security, getting there won’t be fast or easy. In this live session, June 28, 2022 at 1:00 p.m Eastern/10:00 a.m. Pacific IANS Faculty and (ISC)² discuss: • Exactly what a strong zero trust architecture requires • Concrete steps to take and products to consider to that help keep you moving on the right path • Ways to measure progress, set realistic milestones and ensure goals are obtainable
Palo Alto Networks Unit 42 cloud threat researchers wanted to understand how supply chain attacks occur in the cloud native applications. To gain insight into this growing threat, they analyzed data from a variety of public data sources around the world. Additionally, they executed a red team exercise at the request of a large SaaS provider against their cloud-based software development environment. Unit 42’s findings indicate that many organizations are still have a long way to go in achieving supply chain security in the cloud. Join Palo Alto Network and (ISC)2 on November 16, 2021 at 1:00p.m. Eastern for the Unit 42 Cloud Threat Report and how supply chain attacks in the cloud can occur and provide actionable recommendations organizations can adopt to protect their cloud native supply chains.
In this first part, we’ll explore the important preliminary questions about whether Zero Trust should be a priority for your organization and provides guidance on defining trusted users and devices, and how to integrate identity and network. It will address how to build a business case for Zero Trust, addressing business drivers such as cloud environments and business continuity needs.
In the current environment, many legacy VPN and remote access solutions are being overwhelmed, and organizations are reacting with ‘band aid’ fixes. The goal is to enable business critical users with cloud-based private access as quickly as possible with the least amount of friction. Strategically, this will mean combining a cloud-based Next Gen Secure Web Gateway (providing cloud and web inline security) and a zero trust network access (ZTNA) solution (providing scalable and fast remote access) as part of your SASE architecture. Here are five areas to consider when updating your blueprint for remote access security: 1. Most legacy VPNs were deployed to handle around a third an organization’s workforce, but they are being pushed to handle two-thirds or more in the current crisis. The poor performance and user experience of overloaded VPNs can be easily replaced with cloud-enabled private access - for critical business use cases. 2. Shift your remote access strategy from VPNs providing network access, with the opportunity for lateral movement by malicious insiders and compromised accounts, to secure, cloud-enabled, zero trust application access. 3. ZTNA maintains the traditional remote access features of device posture checking and strong authentication, but improves the security of data centers and public cloud environments by not exposing any IPs, ports or services to the public internet. 4. The deployment of legacy VPNs to multiple data centers and multi-cloud environments can be complex for IT and users. Cloud-enabled ZTNA seamlessly and transparently provides access to hybrid IT environments with high performance, global scale, and much less complexity.
Recent research shows that more than 85% of web traffic is comprised of cloud services. The rapid adoption of cloud and mobile is fundamentally changing network traffic patterns and the movement of data, rendering existing network and security models obsolete. This shift is resulting in enterprise security teams supplementing next-gen firewalls (NGFWs), secure web gateways (SWGs), and VPNs with cloud access security brokers (CASBs). While CASBs address a key set of cloud-specific use cases tied to visibility, data security, compliance, and threat protection, your dissolving corporate perimeter is also forcing security teams to rethink their entire legacy security stack. After all, if most of your web traffic is comprised of cloud services, why does most of your security spend on security tools that are not effective in this new world? Join Netskope for Part 1 of this 3-part series to discover new blind spots that exist with legacy security tools, why simply moving legacy security tools to the cloud is not enough, top cloud security use cases driving the need for a new perimeter and the essential requirements for a new, more effective perimeter.
With the move to cloud and the multitude of approaches, your ability to effectively monitor and secure workloads gets even more difficult. IT complexity, the rate of change, lack of skills, and organizational silos have made confidently managing security and performance nearly impossible. Visibility is critical. Join Gigamon and (ISC)2 on February 25, 2021 at 1:00pm Eastern for a discussion of the security considerations for on-prem private, public and hybrid clouds. You’ll learn best practices and see how a little planning and design can go a long way. Achieve a secure and viable hybrid cloud implementation and get a high return on your investment. Join our session to learn how.
There is much talk in the Industry with regards to Zero Trust Networking (ZTN) - but what does it involve and what does this mean for Network Visibility? In this Webinar we will explore the reason for ZTN, some of the current ideas surrounding the implementations of ZTN and where Network Visibility plays a key role in securing such environments. With one of the key concepts of ZTN being the encryption and authentication of data in motion, we will also discuss the need for Metadata and why this can be an advantage over traditional methods of monitoring. Join Gigamon and (ISC)2 on August 13, 2020 at 1:00PM Eastern for an examination of: - Understanding the ZTN trust model at a high level - See which components are important within ZTN and why - Understand why the perimeter is changing and why the need for segementation goes beyond physical devices - How Metadata can play a key role in understanding the activity of applications on your network
Digital transformation is driving the need to review cloud and web use in our organizations. Secure web gateways (SWGs) are now the core of SASE architecture to provide content and context for granular policy controls for apps and web. Here are five areas to consider for your SASE blueprint. Over half of SWG sessions are now cloud apps and services. •Web filtering needs to advance to decoding cloud app traffic inline. •The allow/block model no longer works for cloud, you need to manage risk. •Appliance limitations are being replaced with cloud native platforms. •Performance matters to avoid security trade-offs.
Cryptography is omnipresent. Every business unit uses crypto in some shape or form. A marketing web page uses a TLS certificate to assert its identity. A CRM solution that stores customer data uses symmetric key cryptography to encrypt data at rest. An organization's digital security is only as strong as its business units' weakest crypto practices. This has forced organizations to rethink the way teams consume crypto services and driven the need for centralized orchestration and control. Join AppviewX and (ISC)2 on May 6, 2021, at 1:00 PM Eastern Time for a discussion on how a Crypto Service Mesh orchestrates all the diverse crypto services in an organization, abstracts the nitty-gritty details, and provides a standardized, user-friendly, policy-controlled way for different business units to consume these services. We’ll examine: · How various business units consume crypto today · An introduction to Crypto Service Mesh · How a Crypto Service Mesh weaves together people, process, and technology
Zero Trust has generated a great deal of “buzz” in the last few years. Many solution providers tout the benefits of Zero Trust, but the approach may not be a fit for you and your organization. Join iboss and (ISC)2 on May 4, 2021 at 1:00PM Eastern as we explore the evolution of network security design principles in order to gain a deeper understanding of how technology can be leveraged to meet evolving user needs and the behavioral and technological direction behind SASE and Zero Trust.
Organizations around the world have transitioned to working from home in past months, and this transition has challenged advanced security models and user behaviors in a COVID-19 world. A significant number of users discovered that poor technology and/or infrastructure was the biggest barrier to effective remote working. As we speed towards the new normal of hybrid workplaces, organizations are reviewing their business continuity plans and restoring productivity to pre-covid times. Cybercriminals are getting smarter; work from home has expanded the enterprise perimeter; and the digital ecosystem is growing rapidly including new cloud applications. A significant part of IT Security effort is to ensure appropriate infrastructure and tools for their employees as well as top of the line cyber hygiene controls. Therefore, companies need a cyber security strategy that is consistent and crosses their on-premises perimeter. “Never trust, always verify”, is the bedrock of Zero Trust. With a Zero Trust model, every request to access information/data must be authenticated, authorized, and encrypted before permission is granted. It is not a product but an enterprise cybersecurity plan to protect its resources. In this session the participants will learn about: o Enterprise challenges in Zero Trust implementation o How Zero Trust responds to different risk factors o Ways to secure enterprise Hybrid environment o How Entrust's high assurance IAM solution helps in achieving Zero Trust
As organizations build out their infrastructure across public, private and hybrid platforms, security architects need to extend their enterprise security policies and protocols to all workloads, no matter where they reside. Still, security operations teams are challenged with proactively detecting threats, deviations from organizational policies and violations of industry and organizational compliance for mission-critical applications in the cloud. Why is that? Join Gigamon and (ISC)2 on September 6, 2018 at 1:00PM Eastern where we’ll explore ways to assure compliance and decrease time to detect threats in mission-critical applications, reduce risk by leveraging a common platform across your entire IT environment and ensuring SLAs are met by tightly integrating the public cloud provider’s APIs and critical cloud provider services to automatically detect changes in virtual private clouds and virtual networks.
Industry thought leaders have stated that if you can only tackle one project to improve the security of your organisation it should be Privileged Access Management (PAM). Our own research backs this up with the 2018 Privileged Access Threat Report revealing organizations using automated PAM technology experience far fewer serious breaches than those that did not. Karl Lankford, Lead Solutions Engineer EMEA at Bomgar will discuss what ‘privilege’ means to your business and how implementing a PAM solution can drive significant improvements across the organisation. You will learn: •Why organisations should make PAM their top 2019 investment •Why quickly controlling and automating key PAM capabilities is critical to your organisation’s success •Help you to prepare the business case for your PAM project and to get Executive Leadership buy in
The U.S. White House “Executive Order on Improving the Nation’s Cybersecurity” (EO), released May 12, has far-ranging and fast-moving implications for all industries — not just government agencies — and in particular prioritizes the application of Zero Trust. In this CrowdCast tailored especially for cybersecurity leaders, Zero Trust experts examine and explain the EO, including its Zero Trust mandate and what it means for both government and non-government organizations. After viewing this webcast security leaders will understand: • How the EO impacts all industries (including those based outside the U.S.) • The critical deadlines the EO imposes • What technologies are required to meet the Zero Trust mandate • How to approach the Zero Trust mandate in a manageable, phased manner • How non-government organizations benefit from this guidance Speakers: • Mr. James Yeager, VP of Public Sector & Healthcare (CrowdStrike) • Mr. Ajit Sancheti, VP of Identity Protection • Mr. Richard Wong, SVP, Global Head of Security Market Advisory, Frost & Sullivan • Moderated by: Mr. Kapil Raina, VP Zero Trust & Identity Marketing
It’s not a question of IF your network will be breached, but WHEN. News broadcasts for the last several years have shown that most enterprise networks will be hacked at some point. In addition, the time it takes for most IT departments to notice the intrusion usually takes months—over six months according to the Ponemon Institute. This gives hackers plenty of time to find what they want and exfiltrate whatever information they want. There are some clear things that you can do to minimize your corporate risk and the potential costs of a breach. One new approach is to create a resilient security architecture model. The intent of this model is to create a solution that gets the network back up and running after a breach has occurred, as fast as possible. While prevention should always be a key security architecture goal, a resilient architecture goal focusses on recognizing the breach, investigating the breach, and then remediating the damage as quickly as possible. Join Keysight and (ISC)2 for an examination of what network security resilience is, the benefits of such and examples of the visibility and security solutions that can be implemented to reduce the time to remediation.
72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us for this live replay session as Zscaler and (ISC)² discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster
“How can we implement a zero trust strategy?” is a question asked by nearly every security team that wants to avoid increasing their attack surface and being the victim of a high-profile breach. A zero trust strategy is rooted in the principle of “never trust, always verify” — which minimizes risk by securing sensitive data, systems, and services. However, all too often security teams discover that they don't have the visibility they need to do this. The first step to implementing a zero trust strategy and achieving exceptional security hygiene? Building and maintaining an inventory of your critical assets. Please join Axonius and (ISC)² on August 23 at 1:00pm Eastern/10:00 a.m. Pacific as we share how teams can approach zero trust principles and how keeping an asset inventory can help answer the toughest zero trust questions: What device is trying to access corporate assets? What vulnerabilities exist on my applications and services? Which users have access to critical resources? Is my zero trust application managed or unmanaged?
Applying zero trust architectures in an iterative way – one project at a time – has proven a sustainable method to deepen zero trust capabilities across a program. On September 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, IANS and (ISC)² discuss specific zero trust use cases to help accelerate your organization’s zero trust maturation, including: • Walking through zero trust use cases within various domains: people, devices, applications • Discussing the available tooling options and considerations necessary to implement the use case • Words of caution and recommendations to help your organization advance in its zero trust journey
Never Trust, Always Verify. Cloud workloads are constantly evolving and changing. Third-party providers operate outside of company networks. With data in various places, companies can't keep up with who and what have access, and they don't know how critical data might be being exploited. Now you can take an evolutionary step in security with a Zero Trust framework that eliminates implied trust with continuous validation at every stage of a digital interaction, enables developer teams to modernize applications with cloud native development, allows security teams to strengthen defenses across the application lifecycle. On September 28, 2022 at 1:00 p.m. Eastern / 10:00 a.m. Pacific, join Palo Alto Networks and (ISC)² to learn how you can apply an enterprise-wide Zero Trust strategy with integrated capabilities for complete cloud native application protection in your organization. You’ll also find out why organizations that tightly integrate DevSecOps principles into their development lifecycles are: - Over 7X more likely to have strong or very strong security postures - 9X more likely to have low levels of security friction
Technology and identities are inseparable today. Together they drive digital transformation and fuel business innovation. However, they also represent a tremendous attack surface. Statistically most data breaches have an identity angle. The rates of successful attack are causing organizations to rethink their security strategy by putting identity security at the core of their cyber initiatives. The challenge organizations face is how to protect the connection between technology and identities without compromising the power that this pairing provides. This can be a daunting task for any organization. The good news is that years of research and development have taught us there are best practices to consider. Whether you are seeking information on how to get started, how to lower cyber insurance costs, how to move towards zero trust, or how to enhance your already seasoned identity programs, this session will offer insights and information to assist you on your journey. Join SailPoint and (ISC)² October 25, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as they talk about Identity Security with focus on: -Understanding risks posed by the marriage of technology and identity -Discussing how your identity security program impacts your end users – and why it’s a good thing! -Discovering how to develop a clear roadmap for your Identity Security program
User identities, endpoints, applications, and networks have all turned into attack vectors, expanding the attack surface and elevating business risk. Point security solutions target an area but often fail to integrate well with others. This leads to a false sense of security, leaving security gaps and exposing organizations to cyber risks and costly remediation efforts. Beyond the Perimeter brings together leaders from Zscaler, CrowdStrike and Okta to discuss the pivotal role AI plays in cybersecurity and why best-of-breed integrations provide critical defense for a resilient end-to-end Zero Trust architecture. Join us to: - Discover key considerations when building an AI-powered Zero Trust security architecture - Learn how best-in-class integrated solutions provide superior security and improve operational efficiencies - Hear from our customers on how to future-proof your security investments as threats evolve in the face of AI - Watch integration demos showcasing real-life scenarios that empower security teams on how to build a robust end-to-end protection Speakers: Syam Nair, CTO and EVP of R&D, Zscaler Elia Zaitsev, CTO, CrowdStrike Sagnik Nandy, President & Chief Development Officer, Okta Eddie Parra, Sr. Director Partner Solutions, Zscaler Chris Kachigan, Vice President, Global Solution Architecture, CrowdStrike
You can’t protect what you can’t see. This is true — especially for cybersecurity teams attempting to manage and shrink the attack surface of their organization. According to the Cloud Security Alliance, misconfigurations are responsible for up to 63% of security incidents. To combat this misgiving, organizations should perform an attack surface assessment to identify critical assets and risks associated with them. An attack surface assessment is an effort that's focused on increasing visibility by examining the entry points to all of your assets and data. This assessment is unique to each organization, leading to the detection of assets, vulnerabilities, and misconfigurations. In this session, January 17, 2023 at 1:00 p.m., Eastern/ 10:00 a.m. Pacific Axonius and (ISC)2 will share insights on how an attack surface assessment can help you with: • Discovering asset identification and inventory • Identifying previously unknown misconfigurations and vulnerabilities • Prioritizing security risks
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.