I am a big fan of continuing education and have been fortunate to have worked for companies that have provided me with the chance to attend relevant courses and achieve some certifications to supplement my job experience.  Over the last 30+ years, I have taken a decent amount on courses. Over the next few blog entries, I will share some of these experiences. Course material aside, what makes a course go from "good" to excellent is, of course,  the instructor. I have been fortunate to have learned from some of the very best over the years. I only wish I could have been a better pupil.

My "career" in IT is all due to a former boss, Lloyd Wiebe, who changed the work schedule around so I could take a 1 year college entry level programming course back in the mid 1980's. After graduating from the course on a Friday, I started teaching it in another town the following Monday...no kidding. That is all it took back in the day. Thank you Lloyd for your kindness.

During the 1990's I studied for the usual Novell, Microsoft NT4 and 2000 certifications, which reflected my work tasks. In 1999, I was at my first SANS class (NT4 Security) in London, hosted by Allan Paller and Dr. Eugene Schultz. This had a massive impact on my world view about IT courses; all due to the extreme skill of the instructor Dr. Schultz and the passion of Allan Paller. Thank you both for starting my SANS journey.

Due to a job change, I headed into the Information Security area, with a minor in forensics and e-discovery. Starting with the ISC2's  Certified Information Security Professional (CISSP-2002), followed by ISACA's Certified Information Systems Auditor  (CISA-2003), in house ITIL Foundation training(2005) , Certified Information Security Manager (CISM-2007), Guidance Software's EnCASE Certified Examiner (EnCE-2008), and finally Certified in Risk and Information Systems Control (CRISC-2011).  EnCE was a written test followed by an actual forensics examination and report. All the others were rote memorization from PowerPoint Slides. Not my favourite way to do things.

During 2000, I encountered ILOVEYOU, which could be called my first Incident Response case. I spent many long days helping the company recover from this event. Part of my tasks including rebuilding computers with 3.5" floppies; manually, one at a time.

In 2004, I encountered my next IR and forensics case, when a computer was installed outside of the firewall and warez was installed. Fortunately for me, I had purchased Harlan Carvey's book (Windows Forensics Incident Recovery) a few months before. His instructions and scripts got me the answers I needed to explain what happened. Thank you so much Harlen for my start in forensics.

Due to new focus areas at work; I alternated between  vulnerability management, and IT Audit. In 2008, I was in the US performing an IT audit and was able to fit in the NSA IAM / IEM courses, which was the US National Security Agency INFOSEC Assessment and Evaluation Methodology.

During 2012, I was maturing the IT Audit parts of my job and  was working in Disaster Recovery and Business Continuity Planning. I was fortunate to be able to convince a fellow Canadian who was teaching in another part of Europe to come and share his expert skills on Auditing a Business Continuity Management Program, Business Impact Analysis Process and BCP exercises. Thank you Denis for sharing your expertise. https://www.linkedin.com/in/denisgoulet/

Thats all for now. Next entry covers Digital Forensics and ICS.


 

Comments

Popular posts from this blog

Alls well that ends well...