Get Mystery Box with random crypto!

CISO as a Service

لوگوی کانال تلگرام cisoasaservice — CISO as a Service C
لوگوی کانال تلگرام cisoasaservice — CISO as a Service
آدرس کانال: @cisoasaservice
دسته بندی ها: دستهبندی نشده
زبان: فارسی
مشترکین: 3.60K
توضیحات از کانال

Trend CyberSecurity (Service/Product) Compliance with Highest Standards international Practices, Strategic approach of the CISO with an effective output
Prepare, Plan, Design, Implement, Operate, Hardening, Optimize, OJT With..challenge!
@alirezaghahrood

Ratings & Reviews

3.00

2 reviews

Reviews can be left only by registered users. All reviews are moderated by admins.

5 stars

0

4 stars

0

3 stars

2

2 stars

0

1 stars

0


آخرین پیام ها 3

2022-08-30 18:52:02
یعنی از صد سال پیش که میرزاده عشقی فریاد می زد:
ترقی اندر این کشور محال است/که در این مملکت قحط الرجال است

آب از آب تکان نخورده است و هنوز در این مملکت قحط الرجال است و هنوز در بر همان پاشنه می چرخد.
دریغ از یک قدم تکان خوردن...


-قحط الرجال-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.06.08
255 viewsAlireza Ghahrood, edited  15:52
باز کردن / نظر دهید
2022-08-30 14:56:19
این آمار تکان‌دهنده که به تازگی از سایت اداره مهاجرت کانادا منتشر شده است؛من را چنان می‌ترساند که
چو برمیکشم از سینه نفس،نفسم را برمیگرداند

یک سال ۵۲۵ هزار و ۶۰۰ دقیقه است
۳۶۵×۲۴×۶۰=۵۲۵,۶۰۰

پارسال ۱۱ هزار ایرانی رفتن کانادا

یعنی هر ۴۷ دقیقه یک ایرانی از ایران خارج شده و رفته کانادا!!


این آمار منهای آمار خروج به مقصد کشورهای دیگه است.


-تاراج-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.06.08
569 viewsAlireza Ghahrood, edited  11:56
باز کردن / نظر دهید
2022-08-30 11:02:03 To the extent that most of these new regulations are still malleable, your organization may want to actively influence what directions these regulations take and how they are implemented and enforced


-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.06.08
258 viewsAlireza Ghahrood, 08:02
باز کردن / نظر دهید
2022-08-30 11:02:03 A cyber “incident” is something that could have led to a cyber breach, but does not need to have become an actual cyber breach: By one official definition, it only requires an action that “imminently jeopardizes” a system or presents an “imminent threat” of violating a law.
This leaves companies navigating a lot of gray area, however. For example, if someone tries to log in to your system but is denied because the password is wrong. Is that an “imminent threat”? What about a phishing email? Or someone searching for a known, common vulnerability, such as the log4j vulnerability, in your system? What if an attacker actually got into your system, but was discovered and expelled before any harm had been done?
This ambiguity requires companies and regulators to strike a balance. All companies are safer when there’s more information about what attackers are trying to do, but that requires companies to report meaningful incidents in a timely manner. For example, based on data gathered from current incident reports, we learned that just 288 out of the nearly 200,000 known vulnerabilities in the National Vulnerability Database (NVD) are actively being exploited in ransomware attacks. Knowing this allows companies to prioritize addressing these vulnerabilities.
On the other hand, using an overly broad definition might mean that a typical large company might be required to report thousands of incidents per day, even if most were spam emails that were ignored or repelled. This would be an enormous burden both on the company to produce these reports as well as the agency that would need to process and make sense out of such a deluge of reports.
International companies will also need to navigate the different reporting standards in the European Union, Australia, and elsewhere, including how quickly a report must be filed — whether that’s six hours in India, 72 hours in the EU under GDPR, or four business days in the Unites States, and often many variations in each country since there is a flood of regulations coming out of diverse agencies.

What Companies Can Do Now
Make sure your procedures are up to the task.
Companies subject to SEC regulations, which includes most large companies in the United States, need to quickly define “materiality” and review their current policies and procedures for determining whether “materiality” applies, in light of these new regulations. They’ll likely need to revise them to streamline their operation — especially if such decisions must be done frequently and quickly.
Keep ransomware policies up to date.
Regulations are also being formulated in areas such as reporting ransomware attacks and even making it a crime to pay a ransom. Company policies regarding paying ransomware need to be reviewed, along with likely changes to cyberinsurance policies.
Prepare for required “Software Bill of Materials” in order to better vet your digital supply chain.
Many companies did not know that they had the log4j vulnerability in their systems because that software was often bundled with other software that was bundled with other software. There are regulations being proposed to require companies to maintain a detailed and up-to-date Software Bill of Materials (SBOM) so that they can quickly and accurately know all the different pieces of software embedded in their complex computer systems.
Although an SBOM is useful for other purposes too, it may require significant changes to the ways that software is developed and acquired in your company. The impact of these changes needs to be reviewed by management.

What More Should You Do?
Someone, or likely a group in your company, should be reviewing these new or proposed regulations and evaluate what impacts they will have on your organization. These are rarely just technical details left to your information technology or cybersecurity team — they have companywide implications and likely changes to many policies and procedures throughout your organization.
229 viewsAlireza Ghahrood, 08:02
باز کردن / نظر دهید
2022-08-30 11:02:03 “If you can’t measure it, you can’t manage it.”

New Cybersecurity Regulations Are Coming. Here’s How to Prepare.

A whole suite of new cybersecurity regulations and enforcement are in the offing, both at the state and federal level in the U.S. and around the...

Cybersecurity has reached a tipping point. After decades of private-sector organizations more or less being left to deal with cyber incidents on their own, the scale and impact of cyberattacks means that the fallout from these incidents can ripple across societies and borders.
Now, governments feel a need to “do something,” and many are considering new laws and regulations. Yet lawmakers often struggle to regulate technology — they respond to political urgency, and most don’t have a firm grasp on the technology they’re aiming to control. The consequences, impacts, and uncertainties on companies are often not realized until afterward.
In the United States, a whole suite of new regulations and enforcement are in the offing: the Federal Trade Commission, Food and Drug Administration, Department of Transportation, Department of Energy, and Cybersecurity and Infrastructure Security Agency are all working on new rules. In addition, in 2021 alone, 36 states enacted new cybersecurity legislation. Globally, there are many initiatives such as China and Russia’s data localization requirements, India’s CERT-In incident reporting requirements, and the EU’s GDPR and its incident reporting.
Companies don’t need to just sit by and wait for the rules to be written and then implemented, however. Rather, they need to be working now to understand the kinds of regulations that are presently being considered, ascertain the uncertainties and potential impacts, and prepare to act.

What We Don’t Know About Cyberattacks
To date, most countries’ cybersecurity-related regulations have been focused on privacy rather than cybersecurity, thus most cybersecurity attacks are not required to be reported. If private information is stolen, such as names and credit card numbers, that must be reported to the appropriate authority. But, for instance, when Colonial Pipeline suffered a ransomware attack that caused it to shut down the pipeline that provided fuel to nearly 50% of the U.S. east coast, it wasn’t required to report it because no personal information was stolen. (Of course, it is hard to keep things secret when thousands of gasoline stations can’t get fuel.)
As a result, it’s almost impossible to know how many cyberattacks there really are, and what form they take. Some have suggested that only 25% of cybersecurity incidents are reported, others say only about 18%, others say that 10% or less are reported.
The truth is that we don’t know what we don’t know. This is a terrible situation. As the management guru Peter Drucker famously said: “If you can’t measure it, you can’t manage it.”

What Needs To Be Reported, by Whom, and When?
Governments have decided that this approach is untenable. In the United States, for instance, the White House, Congress, the Securities and Exchange Commission (SEC), and many other agencies and local governments are considering, pursuing, or starting to enforce new rules that would require companies to report cyber incidents — especially critical infrastructure industries, such as energy, health care, communications and financial services. Under these new rules, Colonial Pipeline would be required to report a ransomware attack.
To an extent, these requirements have been inspired by the reporting recommended for “near misses” or “close calls” for aircraft: When aircraft come close to crashing, they’re required to file a report, so that failures that cause such events can be identified and avoided in the future.
On its face, a similar requirement for cybersecurity seems very reasonable. The problem is, what should count as a cybersecurity “incident” is much less clear than the “near miss” of two aircraft being closer than allowed.
202 viewsAlireza Ghahrood, 08:02
باز کردن / نظر دهید
2022-08-30 11:01:05 “If you can’t measure it, you can’t manage it.”


-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.06.08
212 viewsAlireza Ghahrood, 08:01
باز کردن / نظر دهید
2022-08-30 04:37:28 صرفا با احترام

اين ويديو هاي رو كه خفت مي كنند و روز روشن و … حتما ديدين، فاجعه داستان، نظاره گر بودن مردم است!!!!!
همين و بسط بديم به مشكلات، اشتباهات و قوانين يك طرفه و رانتي… كه در جامعه مي بينيم
چقدر مردم پشت هم هستند!؟ زمان جنگ و قبلش با امروز، فرهنگ ما دستخوش چي شده است!؟
انتظار نيست مثلا در كيس خفت گيري آپلو هوا كنند نظارگًران سينما ٢٠٠٠!!

رسوندم منظورم و!؟
همه مي نالند از سيستم، دولت…
بد خودمون سوژه خنده ايم
مثلا
در يك كيسي، در يك جلسه من و دعوت نكردند، دور هم تصميم گرفتند با پيش فرض اين كه اين تصميم، اشتباه محض است، اما براي حفظ جايگاه و چنگ براي غنيمت ببشتر، همه يكصدا بله قربان گفتند خوب جامعه ما از فضا اومده!؟ همين عزيزان! در مشكلات جامعه چه مي كنند!؟ صرفا دنبال حفظ منافع حتي با دولاشدن، بر خلاف عقايد اشون كار و حرف و عملي انجام دادن، براي حفظ يك صندلي پوسيده، دريافتي دو زار بيشتر و و و
بزارين بيشتر بشكافم
از منظر عوام، كسي من و از دور قضاوت كند ميگويد فلاني مذهبي است
چون مثلا ته ريش داره، يقه ديپلمات(نه … ) مي پوشد و از حرف هاش هم بوي كلمات عربي مياد و …
اولا مذهب و عقايد هيچ انساني به كسي ارتباط ندارد،
دوما من مذهب رو مثل … افيون ملت هاي مي دونم، با اين حال … فريمورك سفارشي خودم و دارم كه توش يك بند از زرتشت است با بعلاوه؛
زندگي كنم، لذت ببرم، به كسي آسيب نزنم، حق كسي رو پايمال نكنم، براي حق مظلوم بجنگم حتي اگر من ذينفع نباشم! به هر جانداري انرژي مثبت انتقال بدم، كمك كنم بدون چشم داشت در جهت رشد، توسعه، صلح، عدالت….

ما نیامده ایم که بود و نبودمان هیچ تاثیری بر جامعه بر تاریخ، بر زندگی و بر آینده نداشته باشد. ما آمده ایم که با دشمنان وطن دشمنی کنیم و برنجانیم شان و همدوش مردان-زنان با ایمان تفنگ برداریم و سنگر بسازیم و همپای آدم های عاشق، به خاطر اصالت و صداقت عشق بجنگیم. ما آمده ایم که با حضورمان، جهان را دگرگون کنیم، نیامده ایم تا پس از مرگمان بگویند: از کرم خاکی هم بی آزارتر بود و از گاو مظلومتر، ما باید وجودمان و نفس کشیدن مان، و راه رفتن مان، و نگاه کردن مان و لبخند زدن مان هم مانند تیغ به چشم و گلوی بدکاران و ستمگران برود...
ما نیامده ایم فقط به خاطر آنکه همچون گوسفندی زندگی کرده باشیم که پس از مرگمان، گرگ و چوپان و سگ گله، هر سه ستایش مان کنند.

درسته در بيشتر كيس ها توانم حقي رو نتوانسته باز پس بگيره، … و موضوعاتي كه براي خيلي ها پر رنگ است و براي من سطحي است و از دست دادم!

حالا تو اين بند از هر شخص، … كه حرفي زده با روحيات، تفكرات ام همراستا است چه براي ١٠٠٠٠٠ سال پيش چه براي ديروز بعد از ظهر
فارغ از اون گوينده، به حرفش جامعه عمل مي پوشم

حالا
من براي شهادت حضرت امام حسين (ع) پسر حضرت امير(ع) سياه مي پوشم
هر كي مارو ديد تيكه انداخت و سخره گرفت
ا قهرود كسي فوت شده، ا ..
اين و فريز كنيم، با تاخير هفته پيش يك ويديو به دستم رسيد همون هاي كه قضاوت سطحي كردند، اعتقادي نداشتند داشتن دولا وار سينه مي زدند!
براي چي!؟ اعتقاد نه
اين مرگ اي بيش نيست

پدر جامعه و كشور ما را اين سيستمي كه به ادميان دوپا، نفاق و رقص بالماسكه رو ياد داده در آورده، اين رفتار اپيدمي شده و اگر تو در اين حلقه علاقه نداشته باشي وارد شي، بايد ترك كني، گوشه نشين بشي

بله حال ام خوب است وقتي ارتباطات ام با اين نوع نگرش قالب بر كشورم فاصله دار مي شود!


-كاش وطن، و تن بود-

‏Up2date 4 Defence Today,
‏Secure Tomorrow
‏@CisoasaService
1401.06.08
223 viewsAlireza Ghahrood, edited  01:37
باز کردن / نظر دهید
2022-08-01 19:59:39
جبر یا اختیار؟
۱) هرکسی تاحدی مجبور و تاحدی مختار است (0 و 1 نیست)
۲) هرچه شخص: شناختش و تجربه‌اش از فرایندهای احساسی-هیجانی خود عمیق، نزدیک و عینی؛ افکارش سنجیده و تلاشش در زیست اصیل (خودسنجیده، آگاهانه و مسئولانه) جدی‌تر باشد، سهم اراده شخصی در شخصیت و رفتارش افزایش خواهدیافت.


- -

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.05.10
119 viewsAlireza Ghahrood, edited  16:59
باز کردن / نظر دهید
2022-08-01 19:50:23
پیش‌بینی هوش مصنوعی از سلفی‌های آخرالزمانی!

از هوش مصنوعی خواسته شده است که "آخرین سلفی‌هایی" که روی زمین گرفته خواهد شد را به تصویر بکشد که به تولید تصاویر کابوس‌واری منجر شده است.

انسان‌هایی که با پوست در حال ذوب شدن، چهره‌های آغشته به خون و بدن‌های جهش‌یافته از خود عکس می‌گیرند، در حالی که در مقابل جهانی در حال سوختن ایستاده‌اند، چیزی است که هوش مصنوعی "دال-ای"(DALL-E) معتقد است آخرین سلفی‌های اینفلوئنسرها در آخرالزمان خواهد بود.


- -

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.05.10
127 viewsAlireza Ghahrood, edited  16:50
باز کردن / نظر دهید
2022-08-01 13:55:51 نت بلاکس: اینترنت ایران دچاراختلال شدید شده است
۲۱ درصد از اینترنت ایران دچار اختلال شده است و اختلال همچنان ادامه دارد.


-آگاهي رساني امنيت سايبري-

Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1401.05.10
261 viewsAlireza Ghahrood, 10:55
باز کردن / نظر دهید