Monday, June 3, 2024

Forgive and free yourself!

Forgiveness makes you free. Mere words don't let you forgive, it is important to show forgiveness through actions. You see, I used the term 'let you' instead of 'make you', ask me why? 

No one else can 'make you' forgive, it is you who has to 'let you' let go. Just let go... Be free of the burden, the extra baggage you're carrying... Just let go. 

How to just let go, forget and forgive? Through actions... Good actions. Do good when it matters. Be there when it matters. Take care when it matters.

Wednesday, August 2, 2017

Making DLP Management Successful

DLP implementation changes organization's culture and the way everyone perceives information and importance associated with it in terms of security.

The management of DLP solution should be aligned with the key requirement which led to DLP implementation in first place. If the pre-implementation was well thought-out and planned, the management part just needs to follow the execution. Starting small and building confidence before expanding is key to DLP program success.

In a very nutshell, organizations should do the following from pre-implementation to post-implementation for successful DLP program:

1) Identify the need, pain-points and build a business case
2) Create information classification matrix
3) Locate information to be protected
4) Initialize employee awareness to get the buy-in
5) Identify key data loss use-cases
6) Identify and get on-board key stakeholders from each department in-scope
7) Identify workflow based approvals (if required)
8) Shortlist the right DLP solution
9) Start small (focusing on endpoint agent with 'monitor')
10) Implement key use-cases build confidence
11) Move to warning
12) Move to block
13) Expand to other information leaking vectors similarly
14) Consistently improve
15) Show DLP worth to management based on Point 1

Wednesday, February 1, 2017

Infrastructure Security - Vulnerability Management

Vulnerability is a weakness in a system that can be exploited and leveraged upon by different threat agents. In computer security, vulnerabilities can exist in information systems ranging from operating systems to databases to web servers to web applications to switches to routers to even security solutions and devices. Vulnerabilities can occur and are exploited because of lack of security focus during application and system development, reliance on protocols that are vulnerable or because of dependency on third party packages and services.

Vulnerability management solutions help automate the process of proactively identifying vulnerabilities in systems and evaluate associated risks so that proper and prioritized vulnerability remediation and risk mitigation can be carried out before a threat agent exploits these vulnerabilities. Vulnerability management solutions are not mere vulnerability assessment tools but on top they provide features like organization specific risk, risk acceptance, risk tracking, ticketing system, and user roles and permissions to name a few.

Vulnerability management solutions apart from reducing the threat exposure due to prevalent vulnerabilities also help in meeting compliance requirements for PCI DSS, FISA, HIPAA and CIS standards for vulnerability and configuration management. The central vulnerability management console supports identification of vulnerabilities on multiple systems, devices and web applications deployed in organizations and remain future proof with regular updates. Role creation can help different departments to fulfill their responsibilities related to vulnerability identification, infrastructure auditing and web application testing with ease and effectiveness via intuitive dashboard and actionable reporting.

Vulnerability management solutions also provide the ability to test the effectiveness of existing controls on servers and desktops like anti-virus, OS hardening and patch management, browser hardening, password hardening etc. The ease of validating vulnerabilities via itself or third party exploitation tools makes vulnerability management solutions unique and help improve risk mitigation efforts.

Endpoint Security - Malware Protection

In computer security, the general definition of an endpoint is any device connecting to the network. When talking about endpoint security, the device can be a mobile device, a laptop, a workstation or even a server. Endpoint security is hence securing of these devices by mostly using technology based solutions. One of the important tasks involved in endpoint security is protecting endpoints from malware. Malware is any malicious program that can adversely affect, disrupt and damage the working of the endpoint and on top of that steal sensitive information. The most common types of malware are viruses, worms, Trojans, adware and spyware.

Endpoint security technology solutions provide different set of features that can help in detection and prevention of malware. Apart from detection and prevention, endpoint security also helps in remediating the compromised endpoints. The features provided by endpoint security solutions range from antivirus, personal firewall, exploit prevention, host intrusion prevention to proactive protection capabilities like vulnerability and patch management.

Endpoint security solutions target both known (for which signatures have been created) and unknown (for which signatures are not available yet) malware. The effectiveness of endpoint security solutions against malware detection, prevention and spreading depends on solution configuration apart from the technology and intelligence incorporated into the solution. The endpoint security technology solutions provide easy centralized management. The centralized management helps in getting visibility into the level of security and system health of all endpoints. The centralized management also supports in easy security policy implementation, updating, reporting of critical system events and troubleshooting.

Monday, July 18, 2016

Effective Cyber Defense System

The five critical tenets of an effective cyber defense system as reflected in the CIS Critical Security Controls are:

Offense informs defense

Use knowledge of actual attacks that have compromised systems to provide the foundation to continually learn from these events to build effective, practical defenses. Include only those controls that can be shown to stop known real-world attacks.

Prioritization

Invest first in Controls that will provide the greatest risk reduction and protection against the most dangerous threat actors and that can be feasibly implemented in your computing environment.

Metrics

Establish common metrics to provide a shared language for executives, IT specialists, auditors, and security officials to measure the effectiveness of security measures within an organization so that required adjustmens can be identified and implemented quickly.

Continuous diagnostics and mitigation

Carry out continuous measurement to test and validate the effectiveness of current security measures and to help drive the priority of next steps.

Automation

Automate defenses so that organizations can achieve reliable, scalable, and continuous measurements of their adherence to the Controls and related metrics.

Monday, April 6, 2015

Effective Information Security Selling Guide

What are the qualities of a good sales person? Whenever someone asks me this question -- my mind wanders to 7 Habits (or qualities) of Highly Effective People, which are:

1) Pro-activeness and self-awareness
2) Start with the end in mind
3) Prioritize
4) Focus on win-win
5) Listen, understand then speak and get understood
6) Develop truest form of trust
7) Keep learning
 
These are the major qualities any person should seek and develop to be a good human being generally and very good sales-person particularly. 

Information security selling is not different than any other selling. The only difference between IT selling and security selling is that the latter focuses on niche market. Getting security opportunities, driving customers and closing deals can be scarce and time consuming but delightfully rewarding. In the words of Steve Jobs, you really put a dent in the universe but more in the security sense the feeling of protecting customers is both fascinating and cherishing. 

For information security selling to be effective, I propose the following list of steps from my experience: 

1) Identify pain-points -- what difficulties are being faced by the customer
2) Propose a solution -- that acts as ointment for the pain-point identified
3) Develop a business case -- focus on benefits in terms of time, resources and money!
4) Identify and set budget limitations -- develop win-win situation!  
5) Clarify, clarify, clarify! -- do demo, PoC, pilot to set the customer expectations right
6) Close the deal quickly -- keeping the purchase life-cycle in mind, focus on closing with full force
7) Give more -- develop dependency, be more than just useful! 

A good security selling encompasses strong passion, relentless vigor and constant follow-ups. Hope this post helps in making your customer choose the best solutions and services. Happy selling! 

Sunday, April 5, 2015

Setting-up NAT in VMware Workstation

In this tutorial, we are going to setup NAT configuration in VMware Workstation. The Workstation version being used is:


On VMware Workstation, click Edit and then Virtual Network Editor…















On the Virtual Network Editor window, click Add Network:






























On the pop-up window, select VMnet2 and click Ok:






























The new Virtual Network would initialize with random settings:






























The random settings adopted are as follows:






























Now, change the Subnet IP and Subnet mask as follows and click NAT Settings:


Configure the NAT Settings as follows and click OK:



























Afterwards, click DHCP Settings:































Set the DHCP Settings as follows:


















DHCP Service would initialize, once done click Apply:































We are all done to use our NAT configuration in VMs now.

Right click one of the VM where you want to configure NAT and click Settings:
























Configure the Network Adapter settings as follows and click OK:


Since, I like giving static IP addresses (the DHCP service would work just fine) to my VM machines:


The given settings would connect to Internet via the NAT configuration:


While, VMnet2 is set, we would see this network adapter in Network Connections as follows:

For any queries, please feel free to reach out to me on wajahatrajab[@]gmail[.]com.

How VA Tools Work?

Vulnerability Assessment tools assist us in finding weaknesses in a system before they can be exploited. A Vulnerability Assessment tool takes the following steps in determining vulnerabilities:

  • Discovering – Sends ICMP requests and probes ports to see if the system is up and running, additionally checks if the system is behind a firewall or a filtering device
  • Port Mapping – Probes UDP and TCP ports to see which ports are open and accepting connections
  • OS fingerprinting – Detects what OS is running on the target system
  • Service Mapping – Sends different probes to see which services are running on open ports
  • Vulnerability Mapping – Based on the identified services, it tries to find out the vulnerabilities associated with them
There are many Vulnerability Assessment tools available — NeXpose, Nessus and QualysGuard being the few which scan the whole infrastructure including web applications. While, there are some dedicated tools for only web application scanning (dynamic analysis) like AppScan Standard, WebInspect, Burp Suite and Acunetix. Similarly, there are dedicated tools for automated source code review (static analysis) like AppScan Source, Fortify and Veracode.

Alongside finding weaknesses, Vulnerability Assessment tools also provide remediation techniques for eradicating or patching the weakness.

Starting Information Security Career?

A lot of people ask me every now and then on how to start a career in information security? These people range from young graduates to mid-level professionals and to even manger level professionals. So, I thought of writing a blog post that would help hundreds of these knowledge pursuers and career changers to effectively enter the rich and broad field of information security. The post has been made from the perspective of service providers (joining one is the best way to learn ins and outs of information security!).

To keep it very simple, there are two major domains in information security field:

1) Technical
2) Managerial

In technical domain of information security, as the name suggests, almost all the work is technical. You (can) work on technical solutions and services either in R&D, pre-sales, post-sales, training and or support. Each of these are explained as follows:
  • R&D: You find out how different technologies work and gain expertise on them in your test environment (to start with). Or, you develop a technology solution or service or training of your own that helps protect organizations in their security goals and endeavors. 
  • Pre-Sales: You face customers! You pitch them your solutions and services. The pitching can range from presentations to demos to PoCs to running pilots to drafting RFP to complying with them (the requirements) via RFP response to designing BoQ. The majority of selling happens here! 
  • Post-Sales: Once the pre-sales ends successfully -- the post-sales phase kicks-in. In this phase, you implement and deploy solutions for the customer or provide services as per the defined scope and acknowledged project plan. The major component of this phase is helping customers in designing, configuring and implementing the solution or service in a way that benefits them the most.   
  • Training: The trainings can be product based or product independent and focusing on developing a particular skill. Usually, once the solution or service has been successfully implemented -- the customers desire to have a hands-on training to enable their resources to ensure they are able to handle daily routine operations associated with the solution or service. That is one aspect of training. Training can also be provided independently as well to enable customer resources to perform a particular area of their job (for example, incident response, malware analysis etc.) effectively. There are a lot of training bodies as well (EC-Council, (ISC)2, ISACA, etc.) -- delivering their trainings can be quite product financially and a lot of solution / service providers do this and have dedicated training teams and departments. 
  • Support: Support is an essential part of solution and service selling. Support ensures that business flow is continuous and customer retention is effectively 100%. In support phase, customers are able to get their issues fixed (via support engineers) swiftly in the solution they have deployed or the service that is being used.        
In order to be able to perform any of the above activities (or the activities associated to the phase of your interest) -- you need to have good technical research, knowledge acquiring and knowledge transferring skills. Often, technical people think -- they do not need to work on their soft-skills -- assumptions like that are very wrong. Good soft skills are a must for any information security professional and are very essential for growth!  

Now, coming to the second major domain of information security; the managerial part of information security encompasses security management practices varying from policy development, risk management, compliance assurance to process optimization, standards' implementation, suggesting controls, ensuring they are implemented and reviewing their effectiveness.

The managerial domain is more focused on people and processes and is interlinked with technical domain via use of technology. Managerial domain aligns information security with business goals of the organization and frequently takes into account ROI while reducing the risk at the same time. Different ISMS standards like ISO 2700x and BCM standards like ISO 22301 / 22313 come directly under managerial domain of information security.  

My recommendation for entering in information security has always been to start from technical domain, get a feeling of working in information security and then choose where you want to go. If you want to stay on technical side, following are some of the fields:
  • Work with security related solutions like endpoint security, vulnerability assessment, security information and event management, identity and access management, data leakage prevention, two-factor authentication, database security, web application firewalls, next generation infrastructure firewalls, IPS, IDS, advanced threat detection solutions and so on. 
  • Work with security related services like vulnerability / threat assessment, penetration testing, network design review, source code review, digital forensics, incident response, malware analysis / reverse engineering and so on.
  • Work with security related trainings to enhance skill of knowledge-seekers. Apart from trainings or courses offered by governing bodes -- trainings can range from integrating secure software development lifecycle to performing black-box / white-box penetration tests to performing incident response or doing malware analysis and so on.   
My other recommendation particularly for young graduates is to work with IT technologies first; get a good understanding of how stuff works, go in-depth and gain expertise of implementing them. Once, that is done -- you are in very good position to be able to either circumvent or protect these technologies and information systems. Changing role from implementing a technology to protecting becomes easy, this way. For a technical information security professional, high paced research and gaining quick knowledge of technologies is key to success alongside good soft-skills. 

Working in a technical domain for starting career in information security helps a lot in understanding intrinsic technologies and how can they be vulnerable (to attacks) and putting the right controls to keep them protected effectively and efficiently. This path also helps in entering managerial domains without much effort -- all you need to do is study ISMS or BCM standards and develop an understanding of performing thorough risk management or business impact assessment. Once you have developed a good understanding of how different standards work and can be implemented -- you are ready to work as Consultant for firms that want to implement or have their ISMS reviewed. 

The key skills generally needed to become an information security professional are as follows: 
  • Focused research 
  • Persistence and hard work
  • Communication (both oral and written)
  • People skills
The top certifications to transform your career in information security are as follows: 
  • CEH or CPTE (technical)
  • CHFI or CDFE (technical)
  • OSCP (technical)
  • CISSP (managerial)
  • ISO 270001 Lead Implementer / Auditor (managerial) 
  • BCI certifications (mostly managerial) 
I hope the information presented in this post would assist immensely in choosing information security as your career path. In case, you want to discuss this further -- please feel free to reach out to me on wajahatrajab[@]gmail[.]com.

Saturday, March 14, 2015

Growth Mindset vs. Fixed Mindset

Do you like going out of your comforts every now and then?
Do you like developing new skills and improving existing ones?
Do you like changing yourself for the better?

If yes, you have a growth mindset. If not, you have a fixed mindset. People with fixed mindset are prone to staying average -- whereas, people with growth mindset keep on pushing their average skills to grow further and further.

Following are some of the facts about people with growth mindset and people with fixed mindset:

  • For a growth mindset, success is the "process" of pushing themselves to achieve goals. Whereas, for a fixed mindset, success is "proving" themselves to others. 
  • People with growth mindset have the ability to stay innovative by taking constant inputs, analysis and criticism to further improve what they do. While, people with fixed mindset want to stick with what they know the best and what they are good at without giving much emphasis to good input, analysis and criticism. 
  • People with growth mindset do mistakes, learn from them and improve -- while, people with fixed mindset do mistakes and quit. 
  • People with growth mindset are explorers of new ventures -- whereas, people with fixed mindset are stuck in their comfort zones. 

To conclude, everything is in a constant flow -- that is how life works. Getting stuck in your brick-wall and not climbing it or pushing yourself to cross it, takes the life out of you. 

Sunday, July 6, 2014

How to make SIEM PoC effective?

Here is how you can make the SIEM PoC effective: 

1) List down the existing issues that need to be resolved 
2) List down the potential issues that could happen 
3) Ask for use case implementation for #1 and #2 
4) Observe the effectiveness of the solution as per your environment 
5) Observe usability, scalability and feature-set being offered 
6) Observe the skill level of the service provider / vendor 
7) Grade based on #3, #4, #5, #6 

Additionally, you may ask the following questions to your vendor to warm them up a little: 

1) Time it would take to go from installation to actual threat or security insights? 
2) Dedicated members or consultants needed to keep the solution up and inter-operable? 
3) Does the proposed solution provide alerts and provide step-by-step remediation? 
4) What if we don't have technologies in place that are needed to feed the SIEM?

Wednesday, June 11, 2014

Best Data Recovery Tools

I recently faced an interesting challenge of recovering data from my 1TB portable external storage device. The device's MBR somehow malfunctioned and I was left with almost 700GB of raw data. As per Windows, the only option to access the storage device was to format it but before doing that I wanted to recover the data first!

I majorly used the following tools for recovery:
  • Easeus Data Recovery
  • Recuva
  • TestDisk
As per my experience:
  • Easeus was the fastest tool to recover data
  • Recuva was the fastest tool in detecting data on the malfunctioned device
  • TestDisk was the best tool in recovering data that both Easeus and Recuva tools were unable to find

Saturday, March 29, 2014

Inguinal Hernia Surgery

To have surgery or not is same as to marry or not...

I am going to jot down my experience related to the recent surgery experience I had for right inguinal hernia. Interestingly, my hernia was congenital (or that is what the doctor said) and appeared quite late in life (though I am still sweet 16! *winks*).

To ensure readiness for the surgery - I had all the needed routine blood tests and even had an Ultra Sound for abdomen and lower abdomen to ensure if it really was hernia. Blood tests came back positive and Ultra Sound revealed hernia and nothing else. Yes, the medical technology helps.

So, I was okay and ready for surgery (the first-times really are memorable! No?). :)

March 22, 2014

The open surgery was scheduled for March 22, 2014 at 7 PM. I was pretty upbeat for the challenge and had only green tea and boiled egg around 10 AM and nothing else. Felt pretty hungry through-out the day but you have to follow the doctor's advice no matter what!

I reached the hospital around 3 PM and was escorted to a quiet room for (ever so needed) rest before the surgery. Blood pressure was checked -- which was below normal level (because of the lack of food in my system), but not of much concern.

Around 6 PM, a cannula was inserted into my right hand for series of injections and drips that were going to be passed onto the body. A drip was given, soon afterwards, albeit which flowed slowly but seemed to provide good deal of energy.

As soon the clock struck 7 PM, I was taken into the Operation Theater (OT sounds much better!). A spinal anesthesia was given which made my lower body senseless. The surgery began and was pretty much painless throughout, however, I did feel some pain in the left kidney while the Surgeon was doing his business. I complained a little but he assured that was normal and it would be fine in a little while (and, yes he was right -- the pain went away in couple of minutes). The drip flow was increased as soon as the surgery started and the bottle was empty within 30 minutes (I felt like superman! But without the sensation in lower body, ha!).

Because of the nature of congenital hernia (or the surgeon's expertise) - I was out of the Operation Theater in about roughly 40-45 minutes. My lower body was pretty numb and remained so for the next couple of hours.

Around 10 PM, when the anesthesia wore off, I started to feel excruciating pain and it increasingly became unbearable with each passing minute. I was given three to four injections from the cannula to calm down the pain for the night. The injections made the pain bearable and soon afterwards, I was given another drip for the night to keep the body energized. The doctor advised not to eat anything until 6 AM in the morning.

I tried to get some sleep and was quickly driven to the land of dreams.

March 23, 2014

After couple hour sleep -- I was awake again (this time to get the taste of after-shocks of surgery!). A little lower body movement resulted in increased pain even laughing (yes, when you have cousins with you, this can happen!) intensified the pain. So, I soon realized -- less talking the better (the life mantra of sages!). The pain was manageable till 1 AM and started to increase slowly but surely.

When the clock struck 3 AM, the pain became unbearable and I asked the nurse for pain relieving injections. She was only authorized to give one injection and injected it directly into the drip which had a slow flow, again. The pain did not recede and needed a doctor's intervention to calm it down.

Around 6 AM, I called for a doctor, who after assessing the situation, gave me four injections (three went in through the cannula) and one directly into the shoulder. The flow of drip was increased as well and the bottle emptied in 15 minutes. The pain decreased considerably and I was ready to have my first walk after the surgery. The getting up part from the bed, with assistance, was intense. After painful couple of minutes, I was on my legs and started to take little steps. I took this opportunity and went to the toilet as well -- all went well there.

After taking a little more slow steps, I went to bed and slept till 9 AM. When I woke up, I was feeling a lot better. The pain was there but it was manageable. The doctor came around 10 AM and advised to start taking liquid -- which I obliged by taking juice instantly. Afterwards, I slept till 1 PM. When, I woke up, I got up from the bed, this time myself, and took little steps and went to the toilet as well. I walked a little more and with little assistance sat down on a chair, took more juice and went to bed - when the pain started to hurt a little more.

At 2 PM, I was given the regular dose of injections to control the pain. Soon afterwards, I went to sleep and woke up at 4 PM. I took some green tea, which felt refreshing and stayed on the bed to keep the pain minimal. Around 9 PM, I got up from the bed, with some assistance, went to wash-room. I had first bowel movement and thankfully it was without any pain. At 10 PM, I had simple liquid soup as dinner. A routine dose of four injections were given and I slept around 11 PM.

March 24, 2014

I woke up at 3 AM, the pain was manageable, and went to toilet without any assistance, thankfully, all went fine there. Afterwards, I sat on a chair for couple of minutes and then went to bed again. The sleep was peaceful and woke up feeling more healthy around 7 AM. I took juice as breakfast and did a little walk around my room as well. Routine dose of injections was given at 10 AM and doctor was ready to have me discharged. The cannula was removed and I was advised to remain on liquid food till next routine doctor check-up scheduled for March 27, 2014 for bandage change.

I reached home around 1 PM - the day went a bit uncomfortable because of change of environment. I was given pain killers and infection related tablets to keep everything in check.

March 25, 2014

I was almost back to my normal self but with restricted movement.

March 26, 2014

I started increasing my movements -- still took anti-biotics and pain-killers to stay safe.

March 27, 2014

Doctor advised to start taking normal food. That was a new well-taken!

After taking real food -- I was almost back to normalcy. In a week time -- the bandage was removed and I re-joined office again!

To conclude, the surgery was not that bad for an experience. :) 

Friday, June 14, 2013

Plugged In, Not Charging - Solution

I have seen this error message a lot in laptops of all brands and sizes.

More than often the problem is with the battery related drivers than the hardware itself.

Here is the solution that works absolutely 100% of the times:

  1. Right click on 'My Computer'
  2. Go to 'Properties'
  3. Click 'Device Manager'
  4. Click the '+' sign on the 'Batteries'
  5. Delete all instances of 'Microsoft ACPI-Compliant Control Method Battery'
  6. Restart the laptop
  7. Log-in
  8. The status of battery now would be 'plugged in, charging'!  

Sunday, January 13, 2013

Learning - The Learning Ability

The learned is not the one who has learned a lot but actually the one who has learnt the ability to learn, unlearn and learn back again. How do you gain such an ability? Is it god-gifted or can you actually learn it starting fresh and ultimately become an expert?

I know more than few people who are prodigiously good at what they can do and that too without any formal education. These few people are either brilliant researchers or have such an amazing mind that they are able to grasp the complex of concepts within a blink of an eye.

We all think -- but most never analyse our thinking process. Why do we assume, perceive, take, mind, view and even idealise things as we do? Yes culture, peers, society, knowledge and education plays its part but in the end all this adds into our own thinking and we come to a certain liking, disliking, opinion and conclusion.

Let's take an example of one of my friends. She would shop or eat from a place where everyone is shopping or eating. The sole reason being, masses cannot be wrong. When this friend buys an eatable from some not so famous place -- she would start complaining about the taste, quality, quantity etc.

We are learning constantly amazingly even when we are taking a nap. It is nearly impossible not to learn even if you are trying not to learn. Learning is easy -- but unlearning what we have already learnt and learning a totally new concept over it is pretty hard.

If we can unlearn our notions and develop new notions over them then we can be classified as learned in real sense. How can you achieve such learning ability? It is not simple but you can try by being open-minded, ready to challenge your norms, accept being wrong, ready to being corrected, ask others for help and lastly but more importantly never becoming an expert. 

Friday, January 11, 2013

Or Something Similar

There comes a time in your daily routine life -- when whatever you do ends up being a mistake or something similar. You become frustrated and want to scream and cry out loud or something similar. What should you do when everything you touch becomes dust and evaporates in thin air or something similar, you get the idea. Right?

Life's full of curvy ups and downs. The thrills, twists, turns and climaxes depend mostly on your instant reactions and counter actions or something similar. The spoken word and the sped arrow or something similar like spent time cannot return but the after-thought feeling actually does to haunt and taunt. In matters of mere seconds you lose it if you do not control it -- your temper, temptations, anger or similar wave of emotions.

Yes, controlling your self is the hardest task to perform and executing it perfectly is near to impossible or something similar. Day-in and day-out you have to sweat like a champion sports-person to control your own self. The self that can instantly destruct like a nuclear bomb ready to shred everything into pieces that comes in its way. There are commonly two results of your actions. Either you win or you lose. Let me tell you the hidden third result which would make you a master of your self. An action that results in a win-win situation. Yes, neither you nor anyone else loses -- try it or something similar and see for your self.  

Words Will Not Rhyme

Up this time and thinking about
Time lost with a furious clout

A human can err, so what?
Angels cannot, so bait!

Nothing is over and out till
You believe in miracles still

You live in matter of seconds
The moment that fast descends

Let's face it with vigour
Destinies that keep rigour

Waiting for that exact time
When words will not rhyme

See you soon in cloud nine
Always you were, are mine!

Saturday, November 10, 2012

The Pakistan Saga!

What follows is just my individual thinking, analysis, observation, view, opinion and by no means I am promoting and marketing some or any doctrine what so ever! 

Pakistan recently banned quite a few sites for the blasphemous content that were displayed on Internet. Some one who is in my social circle asked a question which went like this, "Should we use Facebook now as the government has lifted the ban?" A heart throbbing question indeed.

Okay! Lets be a little logical here. Internet was the mean used to spread such hatred. Does that mean we should ban Internet in Pakistan? It is not just about Facebook. Why do the Pakistanis think they are the owner of Islam? Why did not the Muslims in other countries come out of their homes in protest? Why do we think we have to save Islam in our own righteous ways? So now what can be the solution to such issues? Well in my humblest opinion we should simply ignore. The less we care about such heinous displays of mediocre mindset the better would be the end result! We should focus on constructive solutions rather than hiding from the problem on hand. The blanket ban is not ignoring it is like what the Ostrich does to protect itself from the sandstorm. I think ignoring is the best solution. You can come up with better one.


I would also like to shed some light on the plight of Ahmadies in Pakistan. How many of us have read the religious books of Ahmadies? For that very matter how many of us have read our own religious books? Going into further granularity how many of us have really read Quran with translation? So who do we think we are to label someone as Kaafir?

Lets now just for the sake of our own well being start treating each other as mere humans and do not go into sects and divide ourselves and become prey to others! If I am Abbasi, you are Syed, she is Chaudhary and he is a Khan... What does it have to do with me being superior than others? In the very same manner, if I am Brelvi, you are Deobandi, she is Wahabi and he is Ahmadi... Please let them live and they will let you live. These are all different paths to the same destination. Let them have their path. Let us go on our path. In the end we will meet at the same place. Lets do it without pointing fingers at each other.

“Darkness can not drive out darkness; only light can do that. Hate cannot drive out hate; only love can do that.” 

- Martin Luther King


Let's all live in peace and harmony! :)

Life is important?

Why is money a priority in our lives? Why are the things bought from money important to us than our relations? Surely you can give me hundreds of reasons for these two questions but that would simply show your materialistic approach towards life. Do you think what you buy from money is important in any way than your life? 

On one particular day I witnessed a car accident. Definitely a horrible thing to happen to anyone. But what happened after the accident was more horrible than the accident itself. You may ask why? Well instead of thanking the stars that we are safe the accidentees started abusing each other for the loss that each incurred the other. Whoa! I wonder if they would have done the same after losing two three limbs and going unconscious or to the extreme if had reached the package expiration date. Why we start giving importance to unimportant things and do not see the obvious?

Tuesday, April 10, 2012

CISSP - Domain 10 - Operations Security

Operations Security relates security aspect in day to day activities of a business enterprise. The domain discusses all the questions regarding: How to keep the data at rest secure? How to securely destroy the data? What privileges need to be assigned and to whom and when? How to protect the hardware (maintenance) and software (piracy)? And how to carry out patch management, problem management, incident management etc.? The important access control concepts  like least privilege and need to know are also discussed along with mechanisms to facilitate and perform audit and monitoring. It can be said that Operations Security is basically the concise combination of all of the other domains of CISSP.