The second edition of CIBOK is established with the same five objectives as the first edition:
Target Audience for the Second Edition (unchanged from the first edition):
The second edition of CIBOK is written for individuals involved in or responsible for cybercrime investigations and incident response activities across public, private, and law enforcement sectors.
For investigators and prosecutors in law enforcement
Investigators new to cybercrime investigation
Those who organize cybercrime investigation department
Future senior officers who will lead investigation
Human resource development trainers
For IT/Security managers and staff in private organizations
Those who are in charge of incident response in SOC, CSIRT, and IT department
CIO and CISO who organize incident response system
Manager of CSIRT or risk management department
IT Security human resource development trainers
CIBOK objectives and application
Executive Editor
Authors
| Aaron Goldstein | Aaron Goldstein is a cyber incident response leader and researcher. He has experience in complex, large-scale cyber breaches where he has provided strategic solutions to secure environments of all sizes. |
| Alberto Casares | Alberto Casares is a threat intelligence researcher and analyst, and CTO of Constella Intelligence where he focuses on identity threat detection and response. He has led several research & development projects supported by the Spanish Ministry of Industry and is a Cybersecurity professor for the University of Granada Master's in Cybersecurity degree program. |
| Antonia Nisiota (PhD) | Antonia Nisiota (PhD) is a Cyber Security Operations Center leader, researcher and analyst with specialties in security posture management, threat hunting, and computer and memory forensics. |
| Billy Gouveia | Billy Gouveia is the CEO and Founder of SureFire, Inc. He has more than 20 years' experience spanning cyber incident response, intelligence collection and analysis, and technology. |
| Bradley Potteiger (PhD) | Bradley Potteiger (PhD) is Co-Founder and Chief Technology Officer of ArmsCyber. He has intelligence collection, cyber defense, analysis, and technology development experience from government and industry organizations, including the US Department of Defense. He has developed specialized experience in active defense methods utiilzing zero trust, automated moving target defense, deception technologies, and recovery principles of cyber security. He has taught and performed academic research at the University of Maryland and The Johns Hopkins University Applied Physics Laboratory on topics of cyber security, autonomous vehicle security and privacy, election integrity, space systems, and national security. |
| Chris Coulter | Chris Coulter is a forensic examiner and incident responder who has led engagements in government, industry, and individual computer crimes investigations. He is a patent holder (Digital forensic acquisition kit and methods of use thereof - United States US 13/019,796) for technology that he developed and delivered to the market to simplify the complex methods of evidence acquisition in forensic computer investigations. His experience includes corporate leadership in cyber security services and products, audit and investigations experience with PwC, Stroz Friedberg LLC, MIT Labs, and the IRS. |
| Dan Gunter | Dan Gunter is the founder and CEO of Insane Cyber, a cyber threat hunting and forensics firm focused on IT and OT networks. He has extensive OT and industrial control systems cyber security research and incident response experience gained from working with clients in Oil and Gas, and global Energy companies. He also served as a USAF Cyber Warfare Officer in the AFCERT and CYBERCOM teams. |
| David Emerson | David Emerson has extensive leadership experience from Chief Information Security and Technology roles with several product and services companies. He is CTO of SolCyber, a Managed Security Services Provider who help to ensure secure program and operational posture for their clients. |
| Erin Joe | Erin Joe is a Senior Executive at Mandiant in Google's Office of the CISO. After a 25 year career culminating as a Senior Executive in the FBI, she joined Mandiant and Google to apply her experience in cyber crime investigation and crisis response. |
| Hideki Ninomiya | Hideki Ninomiya is CEO and Founder of Orient Co., Ltd. He has an extensive career of both IT leadership and cyber security and cyber crime analysis and risk advisory services spanning Pharmaceuticals and other industries in Japan. He also advises boards of companies about cyber risks and security organization and posture development. |
| Hiroshi Nishino | Hiroshi Nishino is a Chairperson of the CIBOK Editorial Committee, CEO of HI Initiative Co., Ltd. In 1991, he founded Proseed Co., Ltd. and introduced numerous global standard knowledge systems such as PMBOK, ITIL, and COPC into Japan. He contributed to the establishment of promotion organizations for PM, ITSM, and CIKF. Additionally, since 2001, he has been involved in government IT procurement reform, participating in various government committees to propose and implement comprehensive bidding systems, CIO advisor systems, and human resource development initiatives. Concurrent Roles:Vice Chairman of the Board, CeFIL (Specific Nonprofit Corporation); Co-founder of the Digital Business Innovation Center; Member of the Global Cybercrime Experts Committee, International Criminal Police Organization (Interpol); Co-founder and Board Member of the Cybercrime Investigation and Research Forum, a general incorporated association; Part-time Lecturer at the Graduate School of Information and Life Sciences, University of Tsukuba; Part-time Lecturer, Liberal Arts Education, University of Toyama. |
| Ian(Iftach)Amit | Ian (Iftach) Amit is a seasoned manager in the security and software industry with vast experience in a myriad areas of information security- from enterprise security, through retail, to end user software and large back-end systems. He is an Information Security expert with experience ranging from low level technical expertise and up to corporate security policy, regulatory compliance and strategy. Ian is a frequent BlackHat and DefCon speaker, and founding member of the PTES (Penetration Testing Execution Standard), IL-CERT, and the Tel-Aviv DEFCON group (DC9723). |
| Karim Hijazi | Karim Hijazi is an investor and cyber security intelligence leader with over 30 years of practical experience in cyber security and intelligence. He founded several cyber intelligence services companies to address global botnets and their impact on government organizations and private companies. |
| Kathryn Shih | Kathryn Shih is a cyber security analyst, investor, and practitioner with cloud and artificial intelligence program development and management specialties gained in organizations including Akamai Technologies, Amazon Web Services, and Google. |
| Kelly Robertson | Kelly Robertson has more than 30 years of professional cyber security experience spanning 30 countries. He has held key technical and market positions with leading ICT and cyber security companies including SAIC, Nokia, Juniper Networks, White Hat Security, Atos, and Horizon3.ai. His contributions from hands-on technical program development, training, and market defining activities has been helpful in the perspectives provided in this edition. He is a long time friend and colleague of Dr. Shook, with whom he has collaborated for more than 20 years on advancing themes of recognizing and addressing cyber risks through effective programs and processes. |
| Maria Vello | Maria Vello is a cybercrime veteran with decades of experience bridging the gap between public and private sectors to advance threat intelligence and cybercrime investigations. Maria is the former President and CEO of National Cyber Forensics Training Alliance (NCFTA) in the USA and the former CEO of Cyber Defense Alliance (CDA) in the UK. |
| Mark Mullison | Mark Mullison is the Chief Technology Officer of Allied Universal, and has more than 30 years of technology and cyber security leadership experience spanning telecommunications, education, and physical security industries. |
| Neil Binnie (PhD) | Neil Binnie (PhD) is a senior cyber security Executive with experience spanning Global Construction and Real Estate, and Aerospace. |
| Noriaki Hayashi | Noriaki Hayashi is a Senior Researcher with Trend Micro Incorporated in Japan. He is a highly-skilled and certified administrator and systems engineer in several computing platforms and technologies. He has more than 17 years of systems management and security experience, including program and project management, security research, and threat response. |
| Omalola Fagbule (PhD) | Omalola Fagbule (PhD) is a Cyber security Awareness Specialist and researcher focused on understanding human motivation and perceptions. She develops training programs and materials addressing the motivations and actions of cyber criminals to educate staff and raise organizational awareness. |
| Patrick A. Westerhaus | Patrick A. Westerhaus joined Wells Fargo in 2016 and is heading up a team in Enterprise Information Security (EIS), Cyber Threat Fusion Center (CTFC), working to consolidate and analyze data in an effort to develop an enterprise program to reduce cyber, fraud, and money laundering risk for the institution. Prior to joining Wells Fargo, Patrick was with KPMG in their fraud and forensic practice and he spent the last 12 years in the FBI reaching the level of Supervisory Special Agent in the Headquarters Cyber Division. During his tenure in the FBI Patrick led investigations into corporate government fraud, public corruption, counterterrorism, counterintelligence, cyber fraud/theft and his last position was at the NCIJTF’s Virtual Currency Team. Patrick has a Bachelor of Business Administration in accounting from Gonzaga University, a Masters in Forensic Science in Security Management from The George Washington University, and a graduate certificate in International Security from Stanford. Patrick also is a CPA and he maintains CFE & CAMS certifications. |
| Satoshi Shimizu | Satoshi Shimizu is a founder of the Cybercrime Investigations Knowledge Forum and editor of the first edition of the Cybercrime Investigation Body of Knowledge. He has an extensive career leading technology and cyber security products and programs development for Trend Micro as a Regional CISO for the Japan BU, and as a Director of the Japan Cybercrime Control Center, and of an INTERPOL alliance project with Trend Micro - he has helped to define international intelligence and response efforts to global combat cybercrime. |
| Scott McCready | Scott McCready is CEO of SolCyber and has led cyber security products and services delivery around the world for some of the best-known security companies including FireEye, Symantec, NTT, and EDS. |
| Simon Mullis | Simon Mullis is an experienced cyber security products and services executive who has led teams at FireEye, Palo Alto Networks, Tanium, and cofounded Venari Security as Chief Technology Officer. He also has represented industry and public sector needs of cyber security as a public speaker at technology and security conferences across Europe and North America. |
| Tammy Archer | Tammy Archer has extensive cybersecurity leadership experience as the CISO of Inchcape PLC, a global automotive distribution services company, and former CISO of HSBC. She previously served the UK Government as CISO of the Foreign and Commonwealth Office, and in the UK Ministry of Defence, and the Royal Navy. |
| Wajih Yassine | Wajih Yassine is a senior cyber security and forensics engineer with experience gained supporting Google and Cylance customers. He has contributed to the development of cloud and enterprise forensics tools. |
| Judith H. Germano | The founding member of Germano Law LLC, a law firm specializing in cybersecurity governance and data privacy issues. |
| Craig W. Sorum | A 25-year veteran of the FBI who conducted and supervised hundreds of domestic and international cybercrime investigations. |
| David Cowen | A Certified SANS Instructor, CISSP, and GIAC Certified Forensic Examiner working in digital forensics and incident response. |
| Eric Zimmerman | A senior director in Kroll’s Cyber Security and Investigations practice and former FBI Special Agent with a tremendous depth and expertise in cyber investigations. |
| Luke Dembosky | A partner in Debevoise & Plimpton’s Cybersecurity & Data Privacy group who has been a regular advisor to the leadership of the DOJ and theFBI. |
| John Jolly | President of Syncurity and the former Vice President of the Cyber Security Division at General Dynamics. |
| Philip Fodchuk | Formerly of the Canadian RCMP and Big4 Audit firms, now at Suncor, maturing and enhancing the information security and cyber investigations capabilities of the organization. |
Download CIBOK 2nd edition. The copyright is reserved for Japan Cybersecurity Innovation Committee (JCIC) so that delivery to the others nor secondary use of CIBOK is prohibited. If you wish to use for the 3rd party, please inform us via Inquiry form below.
CIBOK 2nd Edition
Download (PDF)