PLAY PODCASTS
Software Engineering Institute (SEI) Podcast Series

Software Engineering Institute (SEI) Podcast Series

431 episodes — Page 8 of 9

Computer and Network Forensics: A Master's Level Curriculum

Students learn how to combine multiple facets of digital forensics and draw conclusions to support full-scale investigations. Related Training Advanced Incident Handling Advanced Information Security for Technical Staff Listen on Apple Podcasts.

Feb 2, 201024 min

Introducing the Smart Grid Maturity Model (SGMM)

The SGMM provides a roadmap to guide an organization's transformation to the smart grid. Listen on Apple Podcasts.

Jan 12, 201025 min

Leveraging Security Policies and Procedures for Electronic Evidence Discovery

Being able to effectively respond to e-discovery requests depends on well-defined, enacted policies, procedures, and processes. Listen on Apple Podcasts.

Jan 9, 201025 min

Integrating Privacy Practices into the Software Development Life Cycle

Addressing privacy during software development is just as important as addressing security. Listen on Apple Podcasts.

Dec 22, 200917 min

Using the Facts to Protect Enterprise Networks: CERT's NetSA Team

Network defenders and business leaders can use NetSA measures and evidence to better protect their networks. Listen on Apple Podcasts.

Dec 1, 200922 min

Ensuring Continuity of Operations When Business Is Disrupted

Providing critical services during times of stress depends on documented, tested business continuity plans. Related Course Introduction to CERT Resiliency Management Model Listen on Apple Podcasts.

Nov 10, 200921 min

Managing Relationships with Business Partners to Achieve Operational Resiliency

A defined, managed process for third party relationships is essential, particularly when business is disrupted. Related Course Introduction to CERT Resiliency Management Model Listen on Apple Podcasts.

Oct 20, 200927 min

The Smart Grid: Managing Electrical Power Distribution and Use

The smart grid is the use of digital technology to modernize the power grid, which comes with some new privacy and security challenges. Listen on Apple Podcasts.

Sep 29, 200920 min

Electronic Health Records: Challenges for Patient Privacy and Security

Electronic health records (EHRs) are possibly the most complicated area of IT today, more difficult than defense. Listen on Apple Podcasts.

Sep 8, 200926 min

Mitigating Insider Threat: New and Improved Practices

Two hundred and eighty-two cases of actual insider attacks suggest 16 best practices for preventing and detecting insider threat. Listen on Apple Podcasts.

Aug 18, 200936 min

Rethinking Risk Management

Business leaders need new approaches to address multi-enterprise, systems of systems risks across the life cycle and supply chain. Related Courses Assessing Information Security Risk Using the OCTAVE Practical Risk Management: Framework and Methods Listen on Apple Podcasts.

Jul 7, 200929 min

The Upside and Downside of Security in the Cloud

When considering cloud services, business leaders need to weigh the economic benefits against the security and privacy risks. Listen on Apple Podcasts.

Jun 16, 200927 min

More Targeted, Sophisticated Attacks: Where to Pay Attention

Business leaders need to take action to better mitigate sophisticated social engineering attacks. Listen on Apple Podcasts.

May 26, 200920 min

Is There Value in Identifying Software Security "Never Events?"

Now may be the time to examine our responsibilities when developing software with known, preventable errors - along with some possible consequences. Listen on Apple Podcasts.

May 5, 200920 min

Cyber Security, Safety, and Ethics for the Net Generation

Capitalizing on the cultural norms of the Net Generation is essential when developing security awareness programs. Listen on Apple Podcasts.

Apr 14, 200920 min

An Experience-Based Maturity Model for Software Security

Observed practice, represented as a maturity model, can serve as a basis for developing more secure software. Listen on Apple Podcasts.

Mar 31, 200921 min

Mainstreaming Secure Coding Practices

Requiring secure coding practices when building or buying software can dramatically reduce vulnerabilities. Related Course Secure Coding in C and C++ Listen on Apple Podcasts.

Mar 17, 200920 min

Security: A Key Enabler of Business Innovation

Making security strategic to business innovation involves seven strategies and calculating risk-reward based on risk appetite. Related Courses Assessing Information Security Risk Using the OCTAVE Approach Introduction to the CERT Resiliency Engineering Framework Listen on Apple Podcasts.

Mar 3, 200923 min

Better Incident Response Through Scenario Based Training

Teams are better prepared to respond to incidents if realistic, hands-on training is part of their normal routine. Related Courses Advanced Incident Handling Advanced Information Security for Technical Staff Listen on Apple Podcasts.

Feb 17, 200922 min

An Alternative to Risk Management for Information and Software Security

Standard, compliance, and process are more effective than risk management for ensuring an adequate level of information and software security. Related Course Assessing Information Security Risk Using the OCTAVE Approach Listen on Apple Podcasts.

Feb 3, 200925 min

Tackling Tough Challenges: Insights from CERT's Director Rich Pethia

Rich Pethia reflects on CERT's 20-year history and discusses how he is positioning the program to tackle future IT and security challenges. Listen on Apple Podcasts.

Jan 20, 200917 min

Climate Change: Implications for Information Technology and Security

Climate change requires new strategies for dealing with traditional IT and information security risks. Listen on Apple Podcasts.

Dec 9, 200823 min

Using High Fidelity, Online Training to Stay Sharp

Virtual training environments can deliver high quality content to security professionals on-demand, anywhere, anytime. Related Courses Managing Enterprise Information Security Information Security for Technical Staff Listen on Apple Podcasts.

Nov 25, 200826 min

Integrating Security Incident Response and e-Discovery

Responding to an e-discovery request involves many of the same steps and roles as responding to a security incident. Related Course Managing Computer Security Incident Response Teams Listen on Apple Podcasts.

Nov 11, 200825 min

Concrete Steps for Implementing an Information Security Program

A sustainable security program is based on business-aligned strategy, policy, awareness, implementation, monitoring, and remediation. Related Course Managing Enterprise Information Security: A Practical Approach for Achieving Defense-in-Depth Listen on Apple Podcasts.

Oct 28, 200821 min

Virtual Communities: Risks and Opportunities

When considering whether to conduct business in online, virtual communities, business leaders need to evaluate risks and opportunities. Listen on Apple Podcasts.

Oct 14, 200818 min

Developing Secure Software: Universities as Supply Chain Partners

Integrating security into university curricula is one of the key solutions to developing more secure software. Related Course Secure Coding in C and C++ Listen on Apple Podcasts.

Sep 30, 200823 min

Security Risk Assessment Using OCTAVE Allegro

OCTAVE® Allegro provides a streamlined assessment method that focuses on risks to information used by critical business services. Related Course OCTAVE Listen on Apple Podcasts.

Sep 16, 200818 min

Getting to a Useful Set of Security Metrics

Well-defined metrics are essential to determine which security practices are worth the investment. Listen on Apple Podcasts.

Sep 2, 200818 min

How to Start a Secure Software Development Program

Software security is accomplished by thinking like an attacker and integrating security practices into your software development lifecycle. Listen on Apple Podcasts.

Aug 20, 200820 min

Managing Risk to Critical Infrastructures at the National Level

Protecting critical infrastructures and the information they use are essential for preserving our way of life. Listen on Apple Podcasts.

Aug 5, 200822 min

Analyzing Internet Traffic for Better Cyber Situational Awareness

Automation, innovation, reaction, and expansion are the foundation for obtaining meaningful network traffic intelligence in today's extended enterprise. Related Courses Information Security for Technical Staff Advanced Information Security for Technical Staff Listen on Apple Podcasts.

Jul 28, 200829 min

Managing Security Vulnerabilities Based on What Matters Most

Determining which security vulnerabilities to address should be based on the importance of the information asset. Related Course Information Security for Technical Staff Listen on Apple Podcasts.

Jul 22, 200823 min

Identifying Software Security Requirements Early, Not After the Fact

During requirements engineering, software engineers need to think deeply about (and document) how software should behave when under attack. Related Course Secure Coding in C and C++ Listen on Apple Podcasts.

Jul 8, 200822 min

Making Information Security Policy Happen

Targeted, innovative communications and a robust life cycle are keys for security policy success. Related Course Managing Enterprise Information Security Listen on Apple Podcasts.

Jun 24, 200824 min

Becoming a Smart Buyer of Software

Managing software that is developed by an outside organization can be more challenging than building it yourself. Related Course Software Acquisiton Survival Skills Course Listen on Apple Podcasts.

Jun 10, 200821 min

Building More Secure Software

Software security is about building better, more defect-free software to reduce vulnerabilities that are targeted by attackers. Related Course Secure Coding in C and C++ Listen on Apple Podcasts.

May 27, 200816 min

Connecting the Dots Between IT Operations and Security

High performing organizations effectively integrate information security controls into mainstream IT operational processes. Related Course Managing Enterprise Information Security: A Practical Approach for Achieving Defense-in-Depth Listen on Apple Podcasts.

May 13, 200824 min

Getting in Front of Social Engineering

Helping your staff learn how to identify social engineering attempts is the first step in thwarting them. Listen on Apple Podcasts.

Apr 29, 200823 min

Using Benchmarks to Make Better Security Decisions

Benchmark results can be used to compare with peers, drive performance, and help determine how much security is enough. Listen on Apple Podcasts.

Apr 15, 200820 min

Protecting Information Privacy - How To and Lessons Learned

Aligning with business objectives, integrating with enterprise risks, and collaborating with stakeholders are key to ensuring information privacy. Listen on Apple Podcasts.

Apr 1, 200822 min

Initiating a Security Metrics Program: Key Points to Consider

A sound security metrics program is grounded in selecting data that is relevant to consumers and collecting it from repeatable processes. Listen on Apple Podcasts.

Mar 18, 200812 min

Insider Threat and the Software Development Life Cycle

Significant insider threat vulnerabilities can be introduced (and mitigated) during all phases of the software development life cycle. Listen on Apple Podcasts.

Mar 4, 200823 min

Tackling the Growing Botnet Threat

Business leaders need to understand the risks to their organizations caused by the proliferation of botnets. Listen on Apple Podcasts.

Feb 19, 200820 min

Building a Security Metrics Program

Selecting and reporting meaningful security metrics depend on picking topics of great interest, defining the business context, and having access to sound data. Listen on Apple Podcasts.

Feb 5, 200822 min

Inadvertent Data Disclosure on Peer-to-Peer Networks

Peer-to-peer networks are being used today to unintentionally disclose government, commercial, and personal information. Listen on Apple Podcasts.

Jan 22, 200820 min

Information Compliance: A Growing Challenge for Business Leaders

Directors and senior executives are personally accountable for protecting information entrusted to their care. Related Course Managing Enterprise Information Security: A Practical Approach for Achieving Defense-in-Depth Listen on Apple Podcasts.

Jan 8, 200821 min

Internal Audit's Role in Information Security: An Introduction

Internal Audit can serve a key role in putting an effective information security program in place, and keeping it there. Listen on Apple Podcasts.

Dec 10, 200714 min

What Business Leaders Can Expect from Security Degree Programs

Information security degree programs are proliferating, but what do they really offer business leaders who are seeking knowledgeable employees? Listen on Apple Podcasts.

Nov 27, 200718 min

The Path from Information Security Risk Assessment to Compliance

Information security risk assessment, performed in concert with operational risk management, can contribute to compliance as an outcome. Related Course Assessing Information Security Risk Using the OCTAVE Approach Listen on Apple Podcasts.

Nov 13, 200726 min