Results 1 to 2 of 2

Thread: CISSP organizers had a security breach

  1. #1
    Join Date
    Jun 2003
    Posts
    3,621
    Rep Power
    24

    Default CISSP organizers had a security breach

    Security cert body gives lesson in insecurity

    By John Leyden, The Register Jun 3 2004 7:54AM

    Security certification and training body (ISC)2 has apologised for a serious security breach which saw the personal details of thousands of respondents to a survey posted onto an insecure server.

    Phone numbers, email and contact addresses for many of the estimated 20,000 respondents to (ISC)2 Constituent Survey were easily available on the site because of lax security for a short time towards the end of last week. The data was unencrypted and left open to harvesting through simple URL manipulation despite a promise from (ISC)2 to survey participants that "your answers and feedback will be kept strictly confidential and will not be associated with you, your organization, or your employer". It was also possible to modify the information filled in, according to a Register reader, who sent us a sample of data (home and work addresses and phone numbers) to back up his concerns.
    http://www.securityfocus.com/news/8822

  2. #2
    Join Date
    Feb 2003
    Posts
    4,163
    Rep Power
    0

    Default Re:CISSP organizers had a security breach

    If I am not mistaken CISSP is one of the harder Security certification to attain. They require some 4 years of professional experience on IT security, Right?

    Well it happens to the best of us I guess.


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •