|
Montana Information Security Expert achieves NSA’s IAM and IEM credentials
Colorado Springs, CO (PRWEB) November 27, 2005 -- Information Assurance professional Jeremy Martin has recently earned the National Security Agency (NSA)’s credentials of Infosec Assessment Methodology (IAM) and InfoSec Evaluation Methodology (IEM) at a Colorado Springs based company, Security Horizons. These certifications give Mr. Martin a clear advantage in the Information Security world and fits nicely with his experience.
“I would suggest anyone in the Information Security field go through IAM training. The coverage of IAM course at Security Horizons will improve the services I provide and will give great value to my customers. The IEM framework allows me to give a complete security evaluation from the inside out and provide a clear path for legal compliance”, Jeremy said. The IAM provides Jeremy the knowledge and framework to assess the security of an organization or agency in a way that both the NSA and private industry leaders worked together to standardize. The IEM provides the framework to evaluate the security through a hand on approach.
Jeremy Martin has worked in computer industry since 1996 and has achieved some of the industry’s top honors of CISSP-ISSAP, ISSMP, NSA-IAM, NSA-IEM, and CEH. During this time, he has authored articles for industry publications ranging from highly detailed how-to documents to generalized informational pieces. Jeremy has built EDI integrations with many well know manufacturing companies in the transportation industry. He also provides services to some of the Fortune 500 and teaches information security courses including professional hacking, digital forensics investigation, and ISC2’s CISSP for IT professionals across the US.
The IAM and the IEM allows Mr. Martin to merge his senior level experience in telecommunications security, application development, and ethical hacking into a streamlined process for certification and accreditation of information systems. This process will be used to insure that companies with fiduciary responsibility for regulatory compliance such as DITSCAP, GLBA, HIPPA, FIRPA, FISMA, NERC, NIST, PCI, or Sarbanes Oxley (SOX) stay within the bounds of their legal requirements.
What is IAM?
The IATRP describes the IAM as “The IAM consists of a standard set of activities required to perform an INFOSEC assessment. In other words, the methodology explains the depth and breadth of the assessment activities that must be performed to be acceptable within the IATRP. The IAM "sets the bar" for what needs to be done for an activity to be considered a complete INFOSEC Assessment. Providers who advertise an INFOSEC assessment capability and consumers seeking assistance in performing INFOSEC Assessments should use the IAM as the baseline for their discussions. Because the IAM is a baseline, providers can expand upon it to further meet the needs of the customers. However, any "expansion" must not reduce or interfere with the original intent of any IAM activity.”
What is the IEM?
Security Horizons describes the IEM as “The IEM covers the steps involved in a comprehensive evaluation of a customer's technical components, beginning with customer coordination and the definition of applicable scope for each project. Students will learn how the information defined during the IAM process will be used to create customized roadmaps for increased security posture. Hands-on experience with recognized security tools is included as part of the training in order to increase each student's familiarity with commonly used evaluation software. The course ends with instruction in the techniques utilized to create the System Criticality Vulnerability Matrices and even provides important information on the creation of a reusable metric to measure customer security posture increase or decrease via trending mechanisms.”
From the NSA website: “The National Security Agency developed the INFOSEC Assurance Training and Rating Program (IATRP) to meet the needs of all potential customers who need INFOSEC Assurances Services. The IATRP is a partnership between NSA and INFOSEC providers (U.S. Government and private sector). The IATRP sets the standard for INFOSEC Assurance Methodology through NSA-sponsored classes.”
For more information about the IAM, IEM, or the NSA involvement please visit www.iatrp.com or www.nsa.gov.
###
|