RE: IDS Training Plan & Job Descriptions

From: Bill Royds (email@royds.net)
Date: 01/22/02


From: "Bill Royds" <email@royds.net>
To: <thlewis@jetaconsulting.com>
Date: Tue, 22 Jan 2002 17:17:00 -0500

Of course, Stephen Northcutt and Judy Novak are the creators and teachers of the SANS GIAC GCIA course so the books fit nicely into that training.
  Also look into training associated with whatever IDS that you buy. Most makers of IDS have good training and Marty Roesch's Sourcefire has training for Snort, the most widely used open source IDS.

-----Original Message-----
From: Diehl Sgt Kristin F [mailto:DiehlKF@NOC.USMC.MIL]
Sent: Tue January 22 2002 16:40
To: 'SecLists'; Bill Royds
Cc: thlewis@jetaconsulting.com; focus-ids@lists.securityfocus.com
Subject: RE: IDS Training Plan & Job Descriptions

Network Intrusion Detection
****Stephan Northcutt and Judy Novak
Intrusion Signatures Analysis
*******Stephen Northcutt, Mark Cooper, Matt Fearnow, Karen Fredrick
Don't forget Incident Response also by New Riders
E. Eugene Schultz and Russell Shumway
Kristin

-----Original Message-----
From: SecLists [mailto:lists@secure.stargate.net]
Sent: Tuesday, January 22, 2002 3:53 PM
To: Bill Royds
Cc: thlewis@jetaconsulting.com; focus-ids@lists.securityfocus.com
Subject: RE: IDS Training Plan & Job Descriptions

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Two great books:
Network Intrusion Detection
****Stephan Northcutt and Judy Novak
Intrusion Signatures Analysis
*******Stephen Northcutt, Mark Cooper, Matt Fearnow, Karen Fredrick
both published by New Riders, can't remember the author names, don't have
the books in front of me...
Thanks,
shawn
> -----Original Message-----
> From: Thomas Lewis [mailto:thlewis@jetaconsulting.com]
> Sent: Mon January 21 2002 12:02
> To: focus-ids@lists.securityfocus.com
> Subject: IDS Training Plan & Job Descriptions
>
>
> I was helping a client put together a training program for a new IDS
> position they have created and was wondering if this group had any
> recommendations on good training courses, books, mailing lists (other than
> this one of course), etc. that would be helpful for this person. We
> anticipate this person would have a newbie's level of knowledge regarding
> IDS/Incident Response.
>
> Also, we are writing a job description for this position and if anyone has
> any examples that they would be willing to share it would be much
> appreciated,
>
> Thanks
>
> Thomas Lewis
>
>
>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (OpenBSD)
Comment: For info see http://www.gnupg.org
iD8DBQE8TdE33Qw8DHute6kRArczAKCPVOBTb7EsZXhdYQmI0r88WkMB2wCfd2J3
lF90BFZ7sg7+KpHrkyGBxNQ=
=qOvb
-----END PGP SIGNATURE-----