Cover Page
Personal Summary
I have >** years IT consulting experience, concentrating in Security and/or Compliance Program and Policy development. My customers include many household name organizations (Cisco, Symantec, Sony, Starbucks, Bridgestone/Firestone, US Air Force, Navy, Army, Marine Corps, Center for Disease Control, Novo Nordisk, etc.)
I have a Master's Degree in Information Systems Security. I have earned ~20 industry certifications including CISSP, CISA, ITIL, Microsoft, Cisco, Citrix, Checkpoint, Linux, Forensics, and Cryptography. I was actually one of four Windows/Active Directory Subject Matter Experts (SMEs) hired by Microsoft to write the exam questions for the Windows Server 2008 MCITP exams.
I have published several books and two DVD series on Information Systems Security, Penetration Testing, Forensics, Policy Design, and IT Risk Management. I have spoken at many of the leading industry conferences and taught hundreds of courses on the subjects listed above as well.
I have been certified by the U.S. court system as an Expert Witness, and provided testimony as an Expert on Computer Security and Digital Forensics. I have worked on both Civil and Criminal cases.
Table of Contents
1
1
2
2
2
3
Books / Videos Published & Lectures 5
Books & Videos: 5
Lectures: 5
6
6
7
Michael J. Lester
Consultant / Instructor / Author
Email: *******@***********************.***
Profile
Innovative Information Security, privacy and compliance consultant with over 15 years experience in all aspects of Information Technology with a primary focus on developing Enterprise Wide Information Security, Data Privacy, and Compliance programs for household-name multi-national customers
Published author of several books, courseware, and two DVD series in the field of Information Systems Security, Digital Forensics, Penetration Testing, Security Policy, IT Risk Management. (see section on "Books/Videos Published" page 5)
Public speaker, lecturer, and Instructor on Information Systems Security
Summary of Qualifications
>15 years Information Systems, Project Management, and Security Consulting experience
Master's of Science degree in Information Systems Management with a Concentration in Security
Earner of ~20 industry certifications from ISC2, ISACA, ITIL, Microsoft, Cisco, Citrix, Checkpoint, ISFCE, PGP, and CompTIA (see section on "Certifications" page 7)
Recognized by Microsoft as a Subject Matter Expert (SME). One of four experts hired by Microsoft to write and tech edit the exam questions for the Windows Server 2008 MCITP exams
Certified by the US Court System as an Expert in Computer Security and Digital Forensics (Expert Witness in both Civil and Criminal Cases)
Areas of Expertise
Information Security, Regulatory Compliance, Privacy and Risk Management Professional Data Security Management and Protection.Data Classification, Data Loss Prevention (DLP), Access Control, Identity Management, Business Continuity & Disaster Recovery
Banking, HealthCare, Entertainment, Retail and Distribution, Defense, Pharmaceutical, Government Regulatory compliance (partial list) -- OCC, SOX, GLBA, HIPAA, SB1386, ISO17799 (2700x), and privacy programsStandards compliance (partial list) – PCI DSS, and NIST SP800
Experience
Information Systems and Security Program Consultant 2000-Present
Responsibilities:
Design and implementation of security and regulatory compliance programs for clients including Bridgestone/Firestone, Warner Bros., Sony, Northrop Grumman, Novo Nordisk, Department of Defense (DoD), Microsoft, Cisco, Pacific Health Services, Starbucks, etc.
Accomplishments – Representative Projects:Designed and erected two Data Classification, Data Protection, and Data Loss Prevention (DLP) programs (with accompanying Policies, Protection Standards, and Procedures documentation, diagrams, signed off by C-Level Management) for household-name, multi-national clients.Designed Payment Card Industry (PCI-DSS), HIPAA, OCC, and J-SOX compliance programs for retail customer (>2500 retail outlets) [from concept down to the encryption schemes, key-management procedures, and source-code]This project required educating the client every step of the way from lunch n’ learns on security practices to Cryptography 101 courses for developers (designed courseware and instructed)Creation of forensic analysis and Incident Response (IR) procedures for a household-name retail organization These procedures saved the organization from having to report a data compromise incident. It is estimated to have saved the client tens-of-millions of dollars in lost customers, reputation, and additional expenses like credit-reportingDesigned Certification and Accreditation Program for global military contractor for Service Oriented Architecture (SOA) to link branches of US military and intelligence organizationsCreated a leading information security program framework in less than 12 months to meet the FFIEC and OCC requirements for a bank to have a well defined information security program Successfully mapped and converted existing proprietary controls to the COBIT and ISO 27001 controls framework.Defined a full suite of preventative and detective controls for data confidentiality and integrityEstablished Quantitative/Qualitative and Metrics-based Risk Management ProgramsDevelopment of an Enterprise Wide Information Security and Compliance metrics / Dashboard ( Metrics are one of the most important factors in enabling decision makers )
Program Manager, Logical Security, LLC. Responsibilities:
Manager in charge of the CISSP, Ethical Hacking (EHC, Network Vulnerability Assessor), Security+, and the Computer Forensics training programs
Duties include curricula creation, class instruction, lab design, classroom design, management of instructors and the ongoing maintenance of the program
Design of certification exams both written and practical application of skills labs
Instruction of 5 and 7 day courses, on-site Instructor-Led Training (ILT), Video/Computer Based Training (CBT), Webinars, and On-Line Training (OLT)
Quality assurance and technical editing of materials
Clients include US Air force, US Navy, US Army, Center for Disease Control (CDC), Cisco, Symantec, Oracle, HP, Dell, Bridgestone/Firestone, RSA Security, EMC, Northrop/Grumman, Lockheed, Harris Corp, PricewaterhouseCoopers, Booz Allen Hamilton, NIST, FAA, etc.
Accomplishments – Representative Projects Taught hundreds of successful classes (CISSP, Hacking, Forensics, Security+, & customized courses), some of which were open to the public, some for household-name clients Class sizes were as large as ~90 students at a time
Writer & Consultant, Logical Security, inc. Responsibilities:
Writing of information system security curricula, presentations and lectures for clients including,, (Bio available on this site), et al
Security program consultation
Senior Consultant & Instructor, MicroLink Corporation
Responsibilities:
Consulting with clients on network design, implementation, administration and training
Management of subordinate consultants, developers, contractors
Management of training facilities, trainers and site staff
Curriculum creation and quality assurance
Instructor training and evaluation (Train-the-Trainer courses & videos)
Project Management, Training-site coordination
Security Auditing & Security Policy Design
Firewall Design/Auditing & penetration testing
Active Directory design, implementation, migration, troubleshooting, security
Windows Server NT4.0, 2000, 2003, 2008 administration/configuration
Linux Server administration/configuration
Network Infrastructure (DNS, WINS, DHCP) design, implementation, troubleshooting, security
TCP/IP Routing & Switching, VPN Design (IPSec Tunneling, L2TP, PPTP, SSL-VPN, L2F, GRE & SSH Tunneling)
X.509 Certificate services, PKI (Public Key Infrastructure), SSL (Secure Sockets Layer), TLS (Transport Layer Security)
DRP (Disaster Recovery Planning), SANs (Storage Area Networks), Backup Policy and Data Archival/Destruction Policy assessment and creation (Including Legal & Regulatory considerations)
Terminal Services & Thin Client Infrastructure Design/Implementation/Support
High Availability/Load Balancing & Clustering
Messaging and Team Collaboration system Design/Implementation (Exchange, Lotus Notes)
Sales presentations and sales team coaching & Marketing Advisor
Instructor, IBM Learning Services / University of Miami NGJ Institute
Responsibilities:
Instruction of Microsoft and IBM curricula
Network Administrator, School Board of Broward County
Responsibilities:
Administered mixed network environment, comprising desktop and portable Windows NT, Windows 95, Windows 98, Apple, and IBM AS/400 systems
Administered Exchange servers, Web servers, SQL Servers and Domain controllers
Managed Network Infrastructure (name resolution, routing & switching, access-controls)
Managed WAN connectivity between campuses
End user training, Project presentations
Books / Videos Published & Lectures
Books & Videos:
Cover Page
Personal Summary
I have >15 years IT consulting experience, concentrating in Security and/or Compliance Program and Policy development. My customers include many household name organizations (Cisco, Symantec, Sony, Starbucks, Bridgestone/Firestone, US Air Force, Navy, Army, Marine Corps, Center for Disease Control, Novo Nordisk, etc.)
I have a Master's Degree in Information Systems Security. I have earned ~20 industry certifications including CISSP, CISA, ITIL, Microsoft, Cisco, Citrix, Checkpoint, Linux, Forensics, and Cryptography. I was actually one of four Windows/Active Directory Subject Matter Experts (SMEs) hired by Microsoft to write the exam questions for the Windows Server 2008 MCITP exams.
I have published several books and two DVD series on Information Systems Security, Penetration Testing, Forensics, Policy Design, and IT Risk Management. I have spoken at many of the leading industry conferences and taught hundreds of courses on the subjects listed above as well.
I have been certified by the U.S. court system as an Expert Witness, and provided testimony as an Expert on Computer Security and Digital Forensics. I have worked on both Civil and Criminal cases.
Table of ContentsCover Page 1Personal Summary 1Profile 2Summary of Qualifications 2Areas of Expertise 2Experience 3Books / Videos Published & Lectures 5Books & Videos: 5Lectures: 5Education 6Biography from Publisher 6Certifications 7
Michael J. Lester
Consultant / Instructor / Author
Email: *******@***********************.***
Profile
Innovative Information Security, privacy and compliance consultant with over 15 years experience in all aspects of Information Technology with a primary focus on developing Enterprise Wide Information Security, Data Privacy, and Compliance programs for household-name multi-national customers
Published author of several books, courseware, and two DVD series in the field of Information Systems Security, Digital Forensics, Penetration Testing, Security Policy, IT Risk Management. (see section on "Books/Videos Published" page 5)
Public speaker, lecturer, and Instructor on Information Systems Security
Summary of Qualifications
>15 years Information Systems, Project Management, and Security Consulting experience
Master's of Science degree in Information Systems Management with a Concentration in Security
Earner of ~20 industry certifications from ISC2, ISACA, ITIL, Microsoft, Cisco, Citrix, Checkpoint, ISFCE, PGP, and CompTIA (see section on "Certifications" page 7)
Recognized by Microsoft as a Subject Matter Expert (SME). One of four experts hired by Microsoft to write and tech edit the exam questions for the Windows Server 2008 MCITP exams
Certified by the US Court System as an Expert in Computer Security and Digital Forensics (Expert Witness in both Civil and Criminal Cases)
Areas of Expertise
•1 Information Security, Regulatory Compliance, Privacy and Risk Management Professional
•2 Data Security Management and Protection.
•3 Data Classification, Data Loss Prevention (DLP),
•4 Access Control, Identity Management,
•5 Compliance Monitoring,
•6 Incident Response, Forensics
•7 Business Continuity & Disaster Recovery
•8 Cryptography
•9 Banking, HealthCare, Entertainment, Retail and Distribution, Defense, Pharmaceutical, Government
•10 Regulatory compliance (partial list) -- OCC, SOX, GLBA, HIPAA, SB1386, ISO17799 (2700x), and privacy programs
•11 Standards compliance (partial list) – PCI DSS, and NIST SP800
Experience
Information Systems and Security Program Consultant 2000-Present
Responsibilities:
Design and implementation of security and regulatory compliance programs for clients including Bridgestone/Firestone, Warner Bros., Sony, Northrop Grumman, Novo Nordisk, Department of Defense (DoD), Microsoft, Cisco, Pacific Health Services, Starbucks, etc.
Accomplishments – Representative Projects:Designed and erected two Data Classification, Data Protection, and Data Loss Prevention (DLP) programs (with accompanying Policies, Protection Standards, and Procedures documentation, diagrams, signed off by C-Level Management) for household-name, multi-national clients.Designed Payment Card Industry (PCI-DSS), HIPAA, OCC, and J-SOX compliance programs for retail customer (>2500 retail outlets) [from concept down to the encryption schemes, key-management procedures, and source-code]
o This project required educating the client every step of the way from lunch n’ learns on security practices to Cryptography 101 courses for developers (designed courseware and instructed)Creation of forensic analysis and Incident Response (IR) procedures for a household-name retail organization
o These procedures saved the organization from having to report a data compromise incident. It is estimated to have saved the client tens-of-millions of dollars in lost customers, reputation, and additional expenses like credit-reportingDesigned Certification and Accreditation Program for global military contractor for Service Oriented Architecture (SOA) to link branches of US military and intelligence organizationsCreated a leading information security program framework in less than 12 months to meet the FFIEC and OCC requirements for a bank to have a well defined information security program Successfully mapped and converted existing proprietary controls to the COBIT and ISO 27001 controls framework.Defined a full suite of preventative and detective controls for data confidentiality and integrityEstablished Quantitative/Qualitative and Metrics-based Risk Management ProgramsDevelopment of an Enterprise Wide Information Security and Compliance metrics / Dashboard (“Metrics are one of the most important factors in enabling decision makers”)
Program Manager, Logical Security, LLC. (www.logicalsecurity.com)
Responsibilities:
Manager in charge of the CISSP, Ethical Hacking (EHC, Network Vulnerability Assessor), Security+, and the Computer Forensics training programs
Duties include curricula creation, class instruction, lab design, classroom design, management of instructors and the ongoing maintenance of the program
Design of certification exams both written and practical application of skills labs
Instruction of 5 and 7 day courses, on-site Instructor-Led Training (ILT), Video/Computer Based Training (CBT), Webinars, and On-Line Training (OLT)
Quality assurance and technical editing of materials
Clients include US Air force, US Navy, US Army, Center for Disease Control (CDC), Cisco, Symantec, Oracle, HP, Dell, Bridgestone/Firestone, RSA Security, EMC, Northrop/Grumman, Lockheed, Harris Corp, PricewaterhouseCoopers, Booz Allen Hamilton, NIST, FAA, etc.
Accomplishments – Representative Projects Taught hundreds of successful classes (CISSP, Hacking, Forensics, Security+, & customized courses), some of which were open to the public, some for household-name clients Class sizes were as large as ~90 students at a time
Writer & Consultant, Logical Security, inc. (www.logicalsecurity.com)
Responsibilities:
Writing of information system security curricula, presentations and lectures for clients including Microsoft, RSA Security, SQLSoft (Bio available on this site), et al
Security program consultation
Senior Consultant & Instructor, MicroLink Corporation
Responsibilities:
Consulting with clients on network design, implementation, administration and training
Management of subordinate consultants, developers, contractors
Management of training facilities, trainers and site staff
Curriculum creation and quality assurance
Instructor training and evaluation (Train-the-Trainer courses & videos)
Project Management, Training-site coordination
Security Auditing & Security Policy Design
Firewall Design/Auditing & penetration testing
Active Directory design, implementation, migration, troubleshooting, security
Windows Server NT4.0, 2000, 2003, 2008 administration/configuration
Linux Server administration/configuration
Network Infrastructure (DNS, WINS, DHCP) design, implementation, troubleshooting, security
TCP/IP Routing & Switching, VPN Design (IPSec Tunneling, L2TP, PPTP, SSL-VPN, L2F, GRE & SSH Tunneling)
X.509 Certificate services, PKI (Public Key Infrastructure), SSL (Secure Sockets Layer), TLS (Transport Layer Security)
DRP (Disaster Recovery Planning), SANs (Storage Area Networks), Backup Policy and Data Archival/Destruction Policy assessment and creation (Including Legal & Regulatory considerations)
Terminal Services & Thin Client Infrastructure Design/Implementation/Support
High Availability/Load Balancing & Clustering
Messaging and Team Collaboration system Design/Implementation (Exchange, Lotus Notes)
Sales presentations and sales team coaching & Marketing Advisor
Instructor, IBM Learning Services / University of Miami NGJ Institute
Responsibilities:
Instruction of Microsoft and IBM curricula
Network Administrator, School Board of Broward County
Responsibilities:
Administered mixed network environment, comprising desktop and portable Windows NT, Windows 95, Windows 98, Apple, and IBM AS/400 systems
Administered Exchange servers, Web servers, SQL Servers and Domain controllers
Managed Network Infrastructure (name resolution, routing & switching, access-controls)
Managed WAN connectivity between campuses
End user training, Project presentations
Books / Videos Published & Lectures
Books & Videos:
“Gray Hat Hacking : The Ethical Hacker's Handbook” 1st Edition by McGraw Hill/Osborne Publishing (ISBN # 007*******)
Coauthor is Shon Harris (Author CISSP All in One Guide, McGraw Hill & Hackers Challenge/Hacking Exposed, McGraw Hill) President of Logical Security, inc. She is renowned for her work with the DoD (Dept. of Defense), DoE (Dept. of Energy), NSA (National Security Agency) etc.
Visit the IT security section of your local bookstore or search for "Gray Hat Hacking" on Amazon, Barnes & Noble, or anywhere books are sold, to purchase
“Gray Hat Hacking: Chinese" 1st Edition by McGraw Hill Publishing (ISBN 978-7-302-14615-5)
"Hacking ẻtico" by Anaya Publishing (ISBN-10 # 844*******)
"CISSP All-In-One Guide" by McGraw Hill Publishing
(ISBN 007*******)
Ghost Writer, Contributing Editor & Technical Editor
“Manual Hackera" by Grada Publishing
(ISBN 978-80-247-1346-5)
CISSP Video Mentor by Pearson Publishing (DVD, ISBN 078*******)
Author & Presenter
CompTIA Security+ SY0-201 Video Mentor by Pearson Publishing (DVD, ISBN 978**********)
Author & Presenter
Lectures:
Michael Lester will be lecturing at the Black Hat USA Conference (Las Vegas) in July of 2010 (Shon Harris will be co-lecturing) http://www.blackhat.com/html/bh-us-10/training/bh-us-10-training_sh-cissp-bc.html
Education
Boston University September 2006
(an NSA National Center of Academic Excellence in Information Assurance Education)
Master of Science Degree with Major in Information Systems and Concentration in Security
Barry University June 2003
Bachelor of Science Degree with Major in Information Technology
Cum Laude
Biography from Publisher
From: McGraw Hill / Osborne Publishing Inc.
Michael J. Lester
Consultant / Instructor / Author
Michael J. Lester holds a Master’s Degree in Information Systems Security from Boston University (a National Security Agency [NSA] “Center of Excellence”) as well as around 20 industry certifications including CISSP, CISA, CCE #876, Security+, MCSE:Security, CCSE+, and ITIL. He was an author for “Gray Hat Hacking: The Ethical Hacker’s Handbook 1st Edition”, McGraw Hill Publishing (ISBN # 007*******), a book on advanced penetration testing techniques, and many other articles and presentations.
He has written courseware and lectured on Microsoft security, penetration testing, Linux/UNIX security, and infrastructure security. He is the chief instructor for Shon Harris’s Logical Security LLC. (author “CISSP All in One Guide”, McGraw Hill Publishing), and he teaches and develops courses on CISSP, hacking/pen-testing, digital forensics/eDiscovery, CISA, and others.
Microsoft employed Michael twice as a Subject Matter Expert (SME) to author and tech edit the exams for Windows Server 2008 (Longhorn) and other Microsoft Certified IT Professional (MCITP) certifications (formerly known as the MCSE certification series).
In his consulting practice he has worked for household name organizations including, Bridgestone/Firestone, Warner Bros., Department of Defense, Northrop Grumman, Novo Nordisk, and the U.S. House of Representatives. For these clients he has stood up entire security programs, regulatory compliance programs (OCC, SOX, HIPAA, GLBA), Payment Card Industry Data Security Standards (PCI DSS) compliance programs, and performed similar audits. He has performed vulnerability assessments and penetration tests, and is sought after for his document writing work (policies, standards, procedures, and guidelines). He also has experience implementing the ITIL, CoBIT, and ISO 17799 (2700x) frameworks.
He is currently authoring a book on Digital Forensics, teaching, and consulting. His resum can be found at www.ParadigmShiftConsulting.com.
Certifications
(ISC)
International Information Systems Security Certification Consortium
CISSP Certified Information Systems Security Professional
ISFCE:
International Society of Forensic Computer Examiners
CCE #876 Certified Computer Examiners (Digital Forensics)
ISACA:
Information Systems Audit and Control Association
CISA Certified Information Systems Auditor
ITIL:
Information Technology Infrastructure Library
ITIL Foundation Certified
Microsoft:
Microsoft Subject Matter Expert (SME), Author & Technical Editor for Certification Exams (Windows Server 2008 “Longhorn” & 2008 EBS)
MCM: Directory Services Microsoft Certified Master: Directory Services (BETA rotation; 2 written exams passed)
MCSE: Messaging 2000 Microsoft Certified Systems Engineer + Messaging Windows 2000
MCSE: Security 2000 Microsoft Certified Systems Engineer + Security Windows 2000
MCSE+I Microsoft Certified Systems Engineer + Internet NT4.0
MCSA: Security 2003 Microsoft Certified Systems Administrator + Security Windows 2003
MCSE 2003 Microsoft Certified Systems Engineer Windows 2003
Exchange 2000 Administration (Certified)
Exchange 2000 Design (Certified)
Exchange 5.5 (Certified)
ISA Server (Firewall) (Certified)
Windows XP Professional (Certified)
Designing Win2000 Active Directory (Certified)
Designing Win2000 Network (Certified)
Designing Win2000 Migration (Certified)
Cisco:
CCNP Cisco Certified Network Professional (Expired)
CCDP Cisco Certified Design Professional (Expired)
Check Point:
CCSE+ Check Point Certified Security Expert Plus (Expired)
Citrix:
CCI Citrix Certified Instructor (Expired)
CCEA Citrix Certified Enterprise Administrator (Expired)
PGP Corporation:
PGP Universal Server & Desktop Certified Email and Stored Data Encryption
CompTIA & Chauncey Group:
CTT / CTT+ Certified Technical Trainer
Security+ (Certified)
Network+ (Certified)
Linux + (Certified)
I-Net+ (Certified)
A+ (Certified)
Additional Curricula:
Information Systems Security: Theory, Policy design, Infrastructure & Ethical Hacking
Information Systems Project Management
Database Theory, Design & Security
Object Oriented Programming
Communications Systems & Networks
Voice, Data & Broadband Technologies