Friday, July 10, 2020

BUSINESS CARD WEB DESIGNER

The Web designer is the digital creator. From a brief, he is able to do a global artistic translation , and to lay out the content for screens (web, mobile, tablets) linked to the content of the site. So it is up to him to design the visual identity of a site . Thanks to his artistic skills and his strength of proposal, he is able to graphically transpose the will of his client, his employer.

computer graphics webdesigner However, the role of the Web designer is more extensive. Indeed, he also has a role of adviser since he is the most capable of directing his interlocutor towards the most relevant path. It is also he who distinguishes between the extravagant wishes of the client and what is plausible or not. To do this, he can, depending on the size of the structure in which he works, collaborate with a marketing or technical team comprising elements such as the UX Designer, the UI Designer , the Graphic Designer or even the Developers - depending on the technicality of its mission it security architect.

WHERE DOES THE WEB DESIGNER WORK?
In an agency, with the advertiser or as a freelancer, the Webdesigner directs its tasks according to the human, financial and material resources at its disposal. The larger and more complex the project, the more it needs an expert team on which to rely in order to deliver an optimum result.

Although his function seems similar to that of the graphic designer, it is nothing. The Web designer has broader skills and has a more global perspective on the project. Unlike the graphic designer, the Web designer is not only responsible for rendering a visual in line with demand. This can be requested from time to time, however his position is less operational and invites him to consider the web project as a whole in order to bring consistency to the final rendering.

The objective of the Web designer and to attract visitors to a site. You should know that according to some studies on the brain , the visual would captivate more than the editorial (the brain integrates the visuals 600 thousand times faster than it integrates text without counting that 90% of the information sent to the brain is visual) , reason why the mission of the Webdesigner is paramount in the company

Concretely, the Web designer analyzes the scope of the project, then he makes recommendations that he deems useful. Then he will go to the information gathering stage so as not to miss any element when designing the visuals. If he is not attentive to details (dimensions, format, effects ...) he may, after spending long hours on a visual, have to start all over again. This is why it is important that he keeps himself informed of the details and that at each modification of the current project, that he is informed of the modifications to reconsider.

MISSIONS OF THE WEBDESIGNER
Briefing,
Reflection on layout, graphic presentation, navigation / ergonomics,
Graphic proposal after analysis of customer constraints and ambitions for validation,
Transfer of elements to technical teams (internal: webmasters, or external service providers) to proceed with integration, posting.
PROFILE
School of applied arts (example: Gobelins), or any training with an artistic dimension. A good general knowledge, a great graphic and visual sensitivity are necessary to exercise this profession.

SKILLS
HTML / CSS,
Photoshop / InDesign / Illustrator,
Vector software,
Ability to work in a team in project mode,
Global vision on projects.
QUALITIES OF THE WEB DESIGNER
Creativity,
Force of proposal,
Curiosity (permanent technological and creative watch),
Artistic sensitivity.

Thursday, July 9, 2020

ARCHITECTURE AND SECURITY OF COMPUTER SYSTEMS AND NETWORKS

Training aims
Today, the data implemented by the information system as well as internal and external exchanges are exposed to malicious acts of various kinds.

The future graduate will be able to understand the basic mechanisms of computer machine architectures and the processes related to their operating systems, the concepts for implementing computer networks and the technical, organizational and legal aspects of computer security. information system.


Opportunities
The computer science graduate of the Architecture and Security of Computer Systems and Networks option, will be intended to be recruited in the following positions: Duties of an architect

Security Auditors
Designer of specific systems in the service sector
Information systems security manager
IT Security Manager
IT risk advisor
Training managers
For more information please contact:

Center I S GA Rabat: M. HARCHI Said
Center I S GA Casablanca: M. Nabil CHERKAOUI
Center I S GA Marrakech: M. Yassine SAFSOUF
Center I S GA Fès: M. Rachid NAOUAL
Center I S GA ElJadida: Mr. Sabri Yassine
Programs
1st YEAR2nd YEAR3rd YEAR4th YEAR5th YEAR
1st YEAR
Semester 1:
Culture and communication
English
Algebra
Analysis
Boole algebra
Combinatorial logic
Algorithmic
Matlab programming
Mini projects
Semester 2:
Culture and communication
English
Analysis
Algebra
Electrical circuits
Sequential logic
Algorithmic
Programming C
Mini projects
Optional internship

Wednesday, July 8, 2020

Cybersecurity Architect

WHO ARE WE ?

The Defense Mission Systems activity provides equipment, solutions and services related to electronic combat systems, surveillance and reconnaissance, naval combat, surface and underwater combat.

From development to integration in passing through repair and maintenance in operational condition, the Brest site covers the entire life cycle of maritime patrol and surveillance systems and equipment, naval, airborne and land electronic warfare as well as sonar systems for mine hunters and acoustic products for airborne submarine control (hardened sonars and buoy treatment systems).

WHO ARE YOU ?
- Do you have an Engineer training, do you have an internationally recognized CISSP type certification in Cybersecurity or do you have the prerequisites (experience greater than 5 years full time in the field)? - Do you know the Analyzes risks (EBIOS or equivalent) and know how to apply them taking into account the constraints of the business domain addressed? - Do you master the norms, standards and regulations of IT security and have significant experience in the certification process? - You have participated in offers / security maintenance projects (MCS), or have you been confronted with Cyber ​​crisis situations? - Do you have knowledge of the security of programmable logic controllers, or are you aware of the associated problem? - Do you have leadership natural,which demonstrates your ability to work and manage transversally? - Do you like working in a team and have an ability to argue and synthesize? - You have a good level of English, written or spoken, which will allow you to present solutions and architectures of security to French or foreign state customers, and to convince their experts system architect job description?
Occasional trips at national and international level are to be expected.

WHAT WE CAN DO TOGETHER TOGETHER:

The rise of cybercrime, fostered by the increasing complexity of systems and networks, means that we must implement increasingly effective cybersecurity measures in our systems.

The Technical and Software Department (DTIL)) is in charge of defining and implementing anti-submarine warfare and mine warfare systems, with a pole dedicated to piloting system aspects relating to cybersecurity. You will join this pole, as part of a job creation.

Your main missions will be to:
- Manage the Solution Security architecture and engineering activities, as well as the technical relationship with the client and the Administration (DGA, Mod UK ...). - Ensure a consistent definition of the technical functions, taking into account account of the life cycle of the equipment or system, deployment and operational use - Carry out security analyzes and expertise during the definition, implementation and throughout the entire life cycle of the system.- Participate in the analysis of vulnerabilities throughout the life cycle and in the implementation of MCS contracts.- Contribute to the establishment of supporting documents in order to defend technical solutions, then participate in the management of the implementation during development.- Set up and ensure the necessary training and communication actions - Establish a technical relationship of trust with the Client and the Administration (DGA, Mod UK, etc.) and respond to their comments - Develop technical specifications security solutions for software and hardware development teams - Perform security audits on architectures - Prepare files for certification - Integrate the network of Cyber ​​business experts.- Prepare files for homologation - Integrate the network of Cyber ​​business experts.- Prepare files for approval - Integrate the network of Cyber ​​business experts.
The prospect of joining an innovative Group motivates you? So join us by applying for this offer.

Tuesday, July 7, 2020

For the CFDT, the deficits linked to the covid must be separated from the pension scheme

On BFM Business, Frédéric Sève, national secretary of the union, believes that there is no urgency to resume pension reform.
Emmanuel Macron and the new Prime Minister Jean Castex have been very clear: the pension reform has not been abandoned, negotiations should even resume quickly. A prospect that hardly enchants the CFDT. On BFM Business, Frédéric Sève, national secretary of the union, believes that we should "not rush", "it is a long project in which it is not necessary to go quickly" and thus avoid making "counterproductive decisions".

However, according to the pension guidance council, the situation suddenly worsened with the coronavirus crisis, the plan deficit could reach 30 billion euros this year. "It is not in the summer that we will solve the financial problem," comments Frédéric Sève systems architect jobs.

Increase in contributions
The central union nevertheless makes a proposal to absorb this shock. "We believe that the covid deficits have come out of the rest" and therefore transferred to a dedicated sinking fund. "Such a debt, it is not soluble in the operation of pension plans".

There remains the question of resources: "it can be fiscal resources, contribution resources", the CFDT is therefore not against an increase in these levies "after, we must choose the right ones. It is a situation of national solidarity , we are not in a deficit linked to the functioning of the system, we are in something completely exogenous, "concludes the official.

Monday, July 6, 2020

Security of data and information

As far as interest is concerned, port IT security meets the following critical areas, as highlighted in the 2011 ENISA report, namely:

poor awareness / attention towards maritime IT security which translates into inadequate preparation to deal with IT risks;
complexity of ICT systems in the maritime context which also include very specific elements, with respect to which the rapid overall technological development has in some cases reduced the attention on the vulnerabilities related to the lack of updates. Furthermore, it has been noted that there is no standardization of good practices to ensure adequate protection of ICT systems. Security guidelines often refer only to basic measures and do not match the complexity of ICT tools or do not cover all the relevant technology;
fragmentation of maritime authorities : there are different levels of governance in the maritime sector with respect to IT security and related risks. The lack of coordination between these organizations and those existing at European and national level leads to disharmony in tackling maritime security;
low view of IT security in the maritime regulation : the current regulatory environment poses a lot of attention to safety ( safety ) and physical security ( physical security ) of the port areas, but leaves out almost all aspect of computer security and prevention of possible cyber attacks through illegal acts;
absence of a uniform approach to IT risks : maritime authorities are managing IT security considering only a part of the actual risks, neglecting all the relevant aspects of the protection of critical maritime infrastructure, for the identification of the necessary measures to prevent and manage , all types of IT incidents;
lack of economic incentives for the implementation of IT security; Information architects job description
need for initiatives aimed at collaboration, the exchange of information and the sharing of experiences between the actors involved. There are few and few collaborative sector initiatives.
These aspects represented the starting point, against which to consider a cross-border action plan to strengthen port security, through the use of ICT solutions and dedicated procedures, to be introduced through individual pilot actions, assigned to the ports involved.

Pilot actions of cyber security
The cyber security pilot actions concerned the ports of Koper and Trieste, respectively for the execution of:

penetration test [7] ;
single data management platform [8] ;
GDPR compliance actions [9] .
The pilot penetration test action implemented at the Port of Luka Koper was aimed at verifying and subsequently preventing cyber attacks on the port system and all systems connected to it, verifying their vulnerabilities and updating the database .

In particular, the following tests were performed:

security control according to the black box principle , which includes checks on the possibility of unauthorized access to data and their modification;
verification of the adequacy of data retention at local workstations, to avoid further abuse of the system;
assumption of the identity of existing users in the system;
changes in user privileges;
functionality evaluation;
OS security checks of servers with the MS Windows Server application ;
provision of a new test to verify the completion of the corrective actions identified following the initial test.
Penetration tests in port ICT systems
The penetration test implemented in the Port of Koper ( and in particular the provision of a subsequent verification test ) can reasonably be considered an exception, within the overall framework of the protection of the ICT port systems analyzed in the SECNET project [10] .

This critical aspect, which emerged thanks to the study indicated, could represent an opportunity, if included in the framework of the periodic exercises envisaged pursuant to Section A / 18.3. and Paragraph 18.4 [11] and ss . Part B of the ISPS Code ( respectively, Annexes II and III of Regulation (EC) No. 725/2004 ).

In this sense, Paragraph 18.5. Part B, on the subject of exercises ( so-called Drills), states that, " To ensure effective application of the provisions of the port facility security plan ( understood as security ), it is necessary to carry out exercises at least once every three months ... The exercise should serve to test the individual elements of the security plan, in particular those relating to the security threats listed in paragraph 15.11 ".

Subject of the quarterly exercises made mandatory by PFSO and the Port Security Authority [12] , are therefore the threat scenarios coded ( originally for the purpose of the security assessment of the port facility ) in Paragraph 15.11 and related to typical risk scenarios , referring to the safety ( security ) physical .

In particular, risk scenario 4 (Paragraph 15.11.4.) Assumes importance in its breadth, where it contemplates the hypothesis of " Access (in the port facility) or unauthorized use , including the presence of illegal immigrants ".

It is clear that the scenario indicated refers to the hypothesis of material or physical entry into the port facility, by subjects and means not having an authorization, or that they remain in it against the will of the managers of the facility, but this aspect, it could also detect cyber security .

Now, consider that each PFSP in its structure must contain at least the items referred to in Section A / 16.3, and in particular point 2, indicating " measures to prevent unauthorized access to the port facility ... and to restricted areas of the plant itself ".

In particular, the restricted access areas of the port facility, pursuant to Paragraph 16.25. et seq ., may include places where sensitive security information is stored, as well as places where there are radio and telecommunications systems [13] and other collective services.

Restricted access areas subject to security measures governing regulated access can therefore include, for example, the places where the servers that make up the network infrastructure are stored and in particular, the web server, any servers dedicated to providing specific services for professional and private operators, backup servers and any other peripheral element, serving the protected network infrastructure.

These elements therefore fit fully into the organization of the security device, so as to be correctly identified in the PFSP as infrastructure to be protected, with the indication of the related countermeasures. All this after evaluating the specific risk scenarios within the PFSA [14] .

Friday, July 3, 2020

Brutal force attacks targeting RDP grew during pandemic

The COVID-19 pandemic has radically changed the nature of daily work, forcing employees to do much of their work through remote access. Aware of the change of scenery, cyber criminals - especially ransomware operators - try to exploit new opportunities to increase their profits. Data provided by ESET telemetry confirms this trend with the increase in the number of unique clients reporting brute force attack attempts that were blocked by ESET network attack detection technology.

Before the period of confinement, many of the collaborators who are working remotely today used to do it from the office and used infrastructure monitored and controlled by their IT department. But the new coronavirus pandemic caused a major change in the daily dynamics of many sectors globally. Today, a large percentage of “office” work is done through home devices with collaborators who access confidential company systems through Windows Remote Desktop Protocol (RDP), a Solution created and patented by Microsoft to allow connection to the corporate network from remote computers.


What is the duty of an architect

Related reading: 42% of companies were not prepared to telework safely

Despite the growing importance of RDP (as well as other remote access services), organizations often neglect its proper configuration and protection. Contributors use easy-to-guess passwords and do not make use of additional layers of authentication or protection, making it easier for cybercriminals to compromise an organization's systems.

That is probably also the reason why RDP has become such a popular attack vector in recent years, especially among ransomware operators. These cybercriminals often: carry out brute force attacks targeting poorly secured networks, raise their permissions to the administrator level, and then disable or uninstall security solutions to finally run ransomware that encrypts data that is crucial to the victim.

The data provided by ESET telemetry (see Figure 1), demonstrate the notable increase in the number of unique clients who reported an attack attempt via RDP.


Figure 1. Trend of attack attempts via RDP against unique clients (per day), detected by ESET technologies

Protection against brute force attacks
To address the risk of increased RDP use, ESET researchers have devised a new detection layer that is hidden within the ESET Network Attack Protection engine and is designed to block incoming brute force attacks from external IP addresses, considering both RDP and SMB protocols.

Called ESET Brute-Force Attack Protection, this new security layer detects clusters of failed login attempts from external environments, suggesting an incoming brute-force attack, and then blocks more attempts. Subsequently, the IP addresses corresponding to the most important attack attempts are added to a blacklist that protects millions of other devices from future attacks.

New technology has proven effective against both random and targeted attacks. For it to work properly, the RDP Network Level Authentication (NLA) option must be enabled on the server.

According to the data provided by ESET telemetry, most of the IPs blocked between January and May 2020 were detected in the United States, China, Russia, Germany and France (see Figure 2).


Figure 2. Countries with the highest number of blocked IP addresses (between January 1 and May 31, 2020).

The countries with the largest percentage of targeted IP addresses were Russia, Germany, Japan, Brazil, and Hungary (see Figure 3).


Figure 3. Countries in which the majority of brute force attacks were recorded according to ESET telemetry data (between January 1 and May 31, 2020).

How to configure remote access correctly
However, even with protection measures like ESET Brute-Force Attack Protection, organizations must keep their remote access configured correctly. For this, we offer some recommendations below:

Disable RDP services exposed to the internet. If that is not possible, minimize the number of users who can connect directly to the organization's servers over the Internet.
Require strong and complex passwords for all accounts that can log in through RDP.
Use an additional layer of authentication ( MFA / 2FA ).
Install a virtual private network ( VPN ) gateway as an intermediary for all RDP connections from outside your local network.
In the perimeter firewall, disable external connections to local machines on port 3389 (TCP / UDP) or any other RDP port.
Protect your security software against possible alterations or uninstalls by setting a password to make changes to its configuration.
Isolate any unsafe or obsolete computers that must be accessed from the Internet using RDP and replace them as soon as possible.
See the article by renowned ESET researcher Aryeh Goretsky for a detailed description of how to correctly configure your RDP connection .
Most of these best practices apply to FTP, SMB, SSH, SQL, TeamViewer, VNC and other services as well.

Wednesday, July 1, 2020

HOW TO BECOME A SECURITY ARCHITECT

Desjardins Group is the largest cooperative financial group in Canada and one of the main employers in the country. It offers the full range of financial products and services and brings together expertise in wealth management, personal and damage insurance, service to businesses of all sizes, in securities, in asset management, in venture capital as well as secure, state-of-the-art virtual access modes.

Level of employment

NV-11

You develop security architectures within the framework of various complex and transversal projects. You design and implement technological solutions aimed at meeting the evolving needs and technological targets of the organization. You represent the unit with different decision-making bodies and assume functional supervision, coordination and coaching of professionals in its unit.

Your role consists in designing detailed architectures, software, and test and implementation strategies within the framework of very large-scale files and projects, of transversal and highly innovative character. You analyze, develop and recommend solutions and orientations at the functional, organic or technological level. The importance of mastering technology and anticipating innovations as well as your ability to optimize work processes then become essential skills. You exercise an advisory role with customers and various stakeholders in matters of integration and stowage, requiring to know how to communicate effectively and to demonstrate a fine understanding of the needs of the different interlocutors architect roles and responsibilities.

The files and projects under your responsibility are strategic in nature and involve very high operational and conceptual complexity. These require a comprehensive and in-depth analysis and understanding of the business field and the organization. There are many ties. You are called upon to interact with a very large number of stakeholders working in various fields of expertise.

You act as a consultant and exercise a leadership and influence role with senior management, authorities and your unit.

Additional responsibilities

Conceive the technological security solutions, necessary for the advancement of the projects under his responsibility and develop the architectures detailed in his area of ​​expertise, the configurations and the implementation plans of the solutions meeting the evolving needs and the technological targets of the organization.
Act as a security consultant in his field of specialty with various stakeholders and bodies.
Perform needs analysis, performance capacity, implementation costs and determine appropriate strategies.
Represent his unit with various committees and directorates in connection with the mandates entrusted to him.
Coordinate a team of professionals during construction projects and perform the required tie-ups.
Participate in the development of operating targets and their transition strategy.
Provide a watchdog role in order to understand and anticipate current trends and best practices in their area of ​​expertise.
Ensure the quality of project deliverables under his responsibility.

Special condition

Number of jobs available: 4

Profile sought

Bachelor's degree in an appropriate discipline
A minimum of eight years of relevant experience
Experience in agile and squad mode (an asset)

Please note that other combinations of relevant training and experience could be considered

For vacant positions available in Quebec, please note that knowledge of French is required

Specific

knowledge Knowledge of good practices in identity management, authentication and authorization to access IT assets
Knowledge of products and technologies enabling the effective application of authentication and authorization in a large company
Knowledge of card payment systems, applicable regulations and security features and of related compliance
Knowledge of application security and applicable methodologies
Knowledge of network security and applicable solutions, including, firewall, IPS, IDS, SIEM, NGFW, proxies, gateways, Wifi, segmentation, micro segmentation, etc.
Knowledge of cloud security and applicable solutions
Knowledge of systems security, including operating systems, database management systems, notions of hardening, deployment of global policies, BYOD, NGAV , EDR, update assessment, etc.

Run Your Applications Locally, Over Your Organization's Network, or Anywhere in the World

Applications are easy to use and with COMSOL Server™, they are easy to access, deploy, and share, too. You can install the COMSOL Server™ so...