Ultimate Computer Security Resources

I’ve gathered all the bookmarks of my most frequently visited computer security websites and decided to archive them in one place. I’ll continue to update this list as I come across quality organizations and blogs dedicated to the preservation of information security.

Premier Organizations Related to Information Security and Cyber Crime

US-CERT - The United States Computer Emergency Readiness Team provides valuable information for technical and home users. The site includes Security Alerts, Bulletins, Tips, Vulnerabilities, Announcements, and other resources of interest, as well as a number of incident reporting avenues.

NSA – The U.S. National Security Agency publishes comprehensive Security Configuration Guides for Applications, Databases, IPv6, Operating Systems, Routers, Switches, VoIP, IP, Web Servers, Internet Browsers, Wireless Networks, and other technologies.

FIRST – The Forum for Incident Response and Security Teams is an international collaboration of incident response teams from the government, industrial, and academic sectors.

NVD – NVD is a U.S. Department of Homeland Security National Vulnerability Database.

CERIAS – The Center for Education and Research in Information Assurance and Security is a multi University driven project for education and research on technical, legal, and ethical issues of computer security.

CIAC – The United States Department of Energy’s Office of the Chief Information Officer created an informative collection of virus data, bulletins, incidents, tools, and links to related government sites.

IC3 – An FBI and National White Collar Crime partnership to receive cyber crime complaints.

My Top 10 Favorite Information Security Blogs

In no particular order

Security Bloggers Network – A collaborative network of over 100 invitation only computer security blog feeds.

Network Security Blog – Senior Security consultant Martin Mckeay’s personal infosec blog. He writes for ComputerWorld and frequently co-hosts a podcast.

Schneier on Security – Bruce Schneier, a best selling author and security guru, covers security technology on his blog.

Anton Chuvakin Blog - Dr Anton Chuvakin’s infosec blog. He holds a Ph D. in Physics and the certifications GCIA, GCIH, GCFA. He is a successful author and currently working as a Chief Logging Evangelist.

Roger’s Information Security Blog – I don’t know much about Roger, but his blog is updated frequently and I’ve enjoyed his perspective on things.

A Day in the Life of an Information Security Investigator – This is one of the few blogs that talk about computer crime investigations and forensic examinations.

Dancho Danchev’s Blog – An independent security consultant assesses a variety of computer security issues.

TaoSecurity – Blog operated by Richard Bejtlich the Director of Incident Response for General Electric.

Darknet – A very popular ethical hacking blog focused around learning to hack as a defensive tool.

An Information Security Place – Michael Farnum’s computer security blog. He is a Security engineer and holds the CISSP, GSEC Silver, and Security + certifications.