K is the founder and Chief Inspiration Officer at Native Intelligence, Inc., a firm that has spent the last ten years supporting security awareness efforts of government organizations and private industry clients. K is a CISSP, holds a degree from Johns Hopkins University, and is the author of the chapter on Security Awareness Programs in the soon-to-be-published three-volume "Handbook of Information Security." She is a contributor to NIST Special Publication 800-16, "Information Technology Security Training Requirements: A Role- and Performance-Based Model." She has had several articles and interviews on Security Awareness Programs published. Currently, K is working with Mich Kabay of Norwich University on an illustrated book on cyber security for general audiences.
Several hundred thousand people worldwide have taken security awareness courses that K has developed. Some of these courses have been translated into several languages. K has developed awareness programs that include surveys, e-learning, newsletters, security mascot and themes, screen savers, posters, contests, videos, individual responses to security questions, and security awareness give-aways. K is a requested speaker at security conferences and events throughout the US. K is also an active member of the Executive Board of the Federal Information Systems Security Educators' Association (FISSEA).
A3 How I Hacked Your Wireless LAN (And How to Stop Me)
Speaker - Jon Green [ Presentation], Senior Product Manager, Aruba Networks, Inc.
Jon Green, CISSP, is a senior product manager for Aruba Networks with primary responsibility for wireless security solutions. Jon has published a number of papers and speaks often on topics including mobility, wireless, and network security. Prior to joining Aruba in 2003, his experience included a variety of technical consulting and engineering positions at companies including Bay Networks, Shasta/Nortel Networks, Atrica, and Foundry Networks. He holds a BS in Information Technology from Western Governor's University, is a licensed commercial pilot, and has produced a number of award-winning wines.
A4 The Rise of X-Morphic Exploitation
Speaker - Gunter Ollmann [ Presentation], Director of Security Strategy, IBM Internet Security Systems
Gunter Ollmann serves as director of security strategy at IBM Internet Security Systems. With more than two decades of service within the information technology (IT) field, Ollmann is responsible for IBM Internet Security Systems' overall strategy for handling next generation security threats. As the former director of X-Force, Ollmann was also responsible for IBM Internet Security Systems' security research and development efforts, including all security content for IBM ISS products and services, zero-day vulnerability analysis, observation and analysis of global security trends and vulnerability discovery. Ollmann was previously the head of X-Force security assessment services in EMEA. In this role, he managed a distributed team of highly skilled consultants in multiple locations throughout Europe. He also pioneered specialist methodologies and techniques for the successful assessment of custom software solutions and increased the growth and application of the IBM ISS global center of excellence in security assessment and penetration testing. Prior to joining IBM ISS, Ollmann was the professional services director of Next Generation Security Software (NGS Software), a leader in vulnerability research and attack-based consulting. He was responsible for the development of business relationships, including building NGS' international clientele and defining the direction of research activities and the development of the company's vulnerability-based knowledge services. Ollmann grew NGS' premier consulting service, dispensing cutting-edge security advice to product vendors to aid them in the development of commercial technology.
A5 XML and Web 2.0 Threats You Never Knew About
Speaker - Steve Orrin [ Presentation], Director of Security Solutions, Intel Corporation
Steve Orrin is Director of Security Solutions for SSG-SPI at Intel Corporation and is responsible for security strategy and product direction. Steve joined Intel as part of Intel's acquisition of Sarvega, Inc., where he was their CSO. Steve was formerly VP of Security Solutions for Watchfire, Inc. Steve was previously CTO of Sanctum, a pioneer in Web application security testing and firewall software, and came to Watchfire through their acquisition of Sanctum. Prior to joining Sanctum, Steve was CTO and co-founder of Lockstar, Inc. Lockstar provided enterprises with the means to secure XML/Web Services and enable legacy enterprise applications for e-business. Orrin joined Lockstar from SynData Technologies where he was CTO and chief architect of their desktop e-mail and file security product. He is a member of the the Computer Security Institute (CSI), Internation Association of Cryptographic Research (IACR) and is co-founder of Web Application Security Consortium (WASC) and the SafeSOA Taskforce. He participates in several OASIS, IETF and AFEI working groups..
A2 Transforming Information Security to Information Risk Management
Speaker - John Pironti [ Presentation], Chief Information Risk Strategist, Getronics
John P. Pironti is the Chief Information Risk Strategist at Getronics. He has designed and implemented enterprise wide electronic business solutions, information security programs, and threat and vulnerability management solutions for key customers in a range of industries, including financial services, government, hospitality, aerospace and information technology. Mr. Pironti has a number of industry certifications including Certified in the Governance of Enterprise Information Technology (CGEIT), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Information Systems Security Architecture Professional and (ISSAP) and a Information Systems Security Management Professional (ISSMP). He is also a published author and writer, and a frequent speaker on electronic business and security topics at domestic and international industry conferences.
1:30 pm–2:30 pm
CSI Conference Session
B1 Information Protection and Privacy: Cooperative Education and Awareness
Speaker - Naomi Fine [ Presentation], President and Founder, Pro-Tec Data
Naomi Fine, Esq. is a nationally recognized authority on information and intellectual property protection. Her depth of knowledge comes from working with hundreds of world-class companies to assess needs, develop tailored strategies, identify sensitive information, establish policies and procedures, and provide training and tools which secure competitive advantage. Ms. Fine has been cited by Fortune, Business Week, Time Magazine, USA Today, The New York Times Cybertimes the LA Times and the Industry Standard as a leading expert in her field. Ms. Fine's work for MCI, Apple Computer and Tandem Computers has been described as exemplary in industry trade journals, including The Personnel Journal, The Sales & Marketing Management Magazine, and Security Management Magazine. Ms. Fine is an authoritative and enthusiastic speaker for many industry associations, as well as being a published author of numerous articles related to information and intellectual property protection. Prior to founding Pro-Tec Data, Ms. Fine was a business attorney counseling high technology companies on protection, licensing and other transactions related to intellectual property.
B5 Real-World Security for SCADA and Process Control Systems
Speaker - Ed Goff, CISSP [ Presentation], System Architect - IT&T Security, Progress Energy
Ed Goff, CISSP, started his IT career in the U.S. Air Force in 1995 where he was responsible for managing vital Command and Control systems including UNCLASSIFIED-to-SECRET interfaces. Ed is currently a IT Security System Architect at Progress Energy based in Raleigh, NC. Ed has been working with Supervisory Control and Data Acquisition (SCADA) and Process Control Systems (PCS) for over 5 years. In that time, Ed has collaborated with experts in the SCADA and PCS field from the electric power (including nuclear), water management, chemical and manufacturing industries, plus several U.S. national laboratories. Ed is currently serving as the Vice-Chair of the Cyber Security Compliance Advisory Group of the South Eastern Electric Reliability Corporation (SERC). Ed was requested to participate in panel discussions in a recent SERC Compliance Seminar. He is the IT Security Functional Lead for Progress Energy's North American Electric Reliability Corporation (NERC) Compliance initiative. As part of the NERC Compliance initiative, he is leading project teams of engineers, operations and IT to develop and implement solutions that address numerous complex problems for SCADA and PCS (e.g. access control, monitoring, network security, and systems management).
B4 The SDLC and Security Awareness for Application Developers
Nishchal Bhalla, the Founder of Security Compass, is a specialist in product testing, code reviews, web application testing, host and network reviews. Prior to joining Security Compass, Nish was a Principal Consultant at Foundstone, where he performed numerous security reviews (Web Application / Code ) for major software companies, online banking and trading & e-commerce sites. He also helped develop and teach the
B3 Testing and Validation of Network Security Devices
Speaker - Dustin D. Trammell [ Presentation], Security Researcher, BreakingPoint Systems, Inc.
Founder of the Computer Academic Underground, co-founder of the Austin Hackers Association (AHA!), and currently employed in Security Research by BreakingPoint Systems, Inc., Dustin has over a decade of experience in various areas of information security including vulnerability assessment, penetration testing, secure network architecture, vulnerability research and development, and security research in specific areas related to network protocols, network applications, steganography, and VoIP. Over the years Dustin has been involved with many security community projects such as design and development of Sender Policy Framework (SPF) for e-mail (RFC 4408) and contributing to the Metasploit Framework project. Dustin has also released numerous security tools such as the infamous PageIt! mass-paging application, the hcraft HTTP exploit-crafting framework, and the SteganRTP VoIP steganography tool. He regularly releases vulnerability and exploit advisories, speaks at security related events and conferences, and is involved with many aspects of the Voice over IP Security Alliance (VoIPSA).
2:45 pm–3:45 pm
CSI Conference Session
C4 Virtualization and Security
Speaker - Dennis Moreau [ Presentation], CTO, Configuresoft
As a Founder and the Chief Technology Officer for Configuresoft, Dennis Moreau is specialist in the application of leading edge technologies to the solution of complex problems in the systems management domain. His primary focus is in developing tools and methodologies to improve IT efficiency and effectiveness in systems management, security compliance and configuration optimization. He works actively with the National Institute of Standards and Technology (NIST) and Mitre on the development of security checklists standards and vulnerability assessment technology. Prior to joining Configuresoft, Dennis was the Chief Technology Officer for Baylor College of Medicine (BCM). He holds a doctorate in Computer Science and speaks regularly at IT management and security conferences.
C1 How to Win Management Support for Awareness
Speaker - Thomas Peltier [ Presentation], President, Thomas R. Peltier Associates, LLC
Tom Peltier has been an information security professional for over thirty years. During this time he has shared his experiences with follow professionals and because of his work has been given the 1993 Computer Security Institute's (CSI) Lifetime Achievement Award. In 1999 the Information Systems Security Association (ISSA) bestowed its Individual Contribution to the Profession Award and in 2001 he was inducted into the ISSA Hall of Fame. Tom was also awarded the CSI Lifetime Emeritus Membership Award. Over the past decade, Tom has averaged 4 articles published a year on various computer and information security issues, including developing policies and procedures, disaster recovery planning, copyright compliance, virus management and security controls. He has had six books published on policy development and risk assessment. He co-authored four other information security books. He continues to speak and teach information security courses throughout the world.
C5 Bot and Botnet Taxonomy
Speaker - Dr. Jose Nazario [ Presentation], Senior Security Engineer, Arbor Networks
Dr. Jose Nazario is a Senior Security Engineer within Arbor Networks' Arbor Security Engineering & Response Team (ASERT). In this capacity, he is responsible for analyzing burgeoning Internet security threats, reverse engineering malicious code, software development, developing security mechanisms that are then distributed to Arbor's Peakflow platforms via the Active Threat Feed (ATF) threat detection service.
Dr. Nazario's research interests include large-scale Internet trends such as reachability and topology measurement, Internet-scale events such as DDoS attacks, botnets and worms, source code analysis tools, and data mining. He is the author of the books "Defense and Detection Strategies against Internet Worms" and "Secure Architectures with OpenBSD." He earned a Ph.D. in biochemistry from Case Western Reserve University in 2002. Prior to joining Arbor Networks, he was an independent security consultant. Dr. Nazario regularly speaks at conferences worldwide, with past presentations at CanSecWest, PacSec, Blackhat, and NANOG. He also maintains WormBlog.com, a site devoted to studying worm detection and defense research.
C2 Securing Data and Databases, Inside and Outside Your Network
Speaker - Josh Shaul [ Presentation], Director of Technology Strategy, Application Security, Inc.
As the Director of Technology Strategy with Application Security, Inc., Josh Shaul helps customers in the development of strategic database asset protection, with the implementation and integration of DbProtect™, the company's industry-leading database security suite. Josh is the foremost security policy and standards guru at the firm, with added expertise in trusted computing and application-level security issues. He's recently authored Practical Oracle Security: Your Unauthorized Guide to Relational Database Security to resoundingly positive critical reviews. Wetting his feet in the IT security industry, Josh started with SafeNet, Inc. working on the industry's first complete IPsec accelerator chip. In over five years with SafeNet, he was responsible for the design, development and overall enhancement of SafeNet's embedded security solutions, covering a wide range of applications. For the last four years his focus has been primarily in field engineering, where he's leveraged his technical and consulting skills to help customers deploy security software and hardware into various SoCs, platforms and devices. Mr. Shaul holds a BS in Computer Systems Engineering from the University of Massachusetts. Josh has shared his expertise, by presenting at various industry conferences and events, including: ? Federal Information Assurance Technology Forum ? Federal Web Seminar on "Securing Your Data from Insider Threat ? GFirst ? IOUG COLLABORATE ? Midwest Oracle Users Group (MOUG) ? OWASP, Boston Chapter ? Toronto Oracle Users Group (TOUG) ? Twin City Security Conference
C3 Architecting Security Measurement and Management for Compliance
Speaker - Robert Martin [ Presentation], Principal Engineer, MITRE Corporation
Robert A. Martin is a Principal Engineer at MITRE, a company that works in partnership with the government to address issues of critical national importance. For the past 17 years, Robert's efforts have been focused on the interplay of risk management, cyber security, quality assessment and the use of software-based technologies. The majority of this time has been spent working on the CVE, OVAL, CAPEC, and CWE family of security standards initiatives in addition to basic quality measurement and management for software-based systems. Robert is a frequent speaker on the various security and quality issues surrounding information technology systems and has published numerous papers on these topics. Robert joined MITRE in 1981 with a bachelor's and master's in Electrical Engineering from Rensselaer Polytechnic Institute, later he earned an MBA from Babson College. He is a member of the ACM, AFCEA, IEEE, and the IEEE Computer Society.
4:00 pm–5:00 pm
CSI Conference Session
D3 Hacking the Invisible—WiFi, RFID and Bluetooth
Speaker - Richard Rushing [ Presentation], Chief Security Officer, AirDefense
Richard is a recognized IT security expert with almost 20 years experience working with computers and networks as a system analyst, network administrator, engineer, consultant and architect. Richard has participated in several corporate security councils setting standards and policies for entire organizations. Richard was most recently Chief Technical Officer of VeriSign's Network Security Services division where he identified and developed products and services to maintain VeriSign's focus on leading-edge security solutions. He was VeriSign's key player in the delivery of complex security consulting and architecture solutions to numerous Fortune 500 companies. In 1997 Richard teamed up with Jay Chaudhry and Jay Johnson to form SecureIT, a leading provider of security services to the IT industry that was acquired by VeriSign in 1998. Prior to SecureIT, Richard worked as a security consultant for the Technology Management Services group at GE Capital.
Rebecca is an information privacy, security and regulatory compliance consultant, author and instructor with her own business, Rebecca Herold, LLC, and over 17 years of experience. Rebecca is authoring her 11th book, and is the editor and primary author for the "Protecting Information" quarterly subscription security and privacy awareness multi-media publication. Rebecca has authored chapters for dozens of books and over one hundred published articles. In 2007 Rebecca was named a "Best Privacy Adviser" by Computerworld magazine and one of the "Top 59 Influencers in IT Security" by IT Security magazine. Rebecca is an Adjunct Professor for the Norwich University Master of Science in Information Assurance (MSIA) program. Rebecca is a frequent speaker and has been quoted in dozens of publications. Rebecca can be reached at http://www.privacyguidance.com, her blog at http://www.realtime-itcompliance.com, and rebeccaherold@rebeccaherold.com.
D5 Virtualization Impacts on Data Security & PCI DSS Strategies
Speaker - Chris Farrow [ Presentation], Director, Fortisphere
With more than 18 years of experience in systems engineering and security, Chris has assisted many Fortune 1000 companies in securing their infrastructures. His background spans several industries, including the military/defense, healthcare, manufacturing, investment banking and software development. Prior to joining Fortisphere, Chris worked with Configuresoft where he was the founder and director of Configuresoft's Center for Policy & Compliance, a research & advisory group created to address the issues of managing security within strict metrics. Prior to Configuresoft, Chris held positions as product manager and systems engineer for several well known technology vendors such as NetIQ, Intrusion.com and BindView Corporation. An active industry resource on the topics of compliance, security management and remediation strategies, Chris co-founded the PCI Security Vendor Alliance and was the driving force behind the CIS benchmark on virtual machine security. Chris has publicly spoken at numerous conferences including Blackhat, SANS, Gartner IT-Expo, InfoSec, ISSA and ISACA. He is a SANS local mentor and SANS Stay Sharp instructor in Colorado Springs, CO, and holds certifications from (ISC)2, ISACA, SANS, Microsoft and Novell.
Ron Woerner has over 17 years of experience in the security industry. He has been quoted in CSO, SC, and Information Security magazines and has been a noted speaker at security conferences throughout the U.S. including the RSA, CSI, and NebraskaCERT Security Conferences. He has been employed as an Air Force Intelligence Officer, the Information Security Officer for the Nebraska Department of Roads, a UNIX administrator for the Mutual of Omaha Companies, and the Lead Security Engineer for CSG Systems and ConAgra Foods. He is now the Security Compliance Manager for TD Ameritrade. Ron earned a Bachelors degree from Michigan State University and a Masters degree from Syracuse University in Information Systems. He was awarded the CISSP security certification in August of 2001, the NSA IAM certification in August of 2003, the Certified Ethical Hacker (CEH) designation in December 2005 and is a Certified Forensics Investigator.
E-F1 The Post-Forensics Interview
Speaker - Brad Smith [ Presentation], Director, Computer Institute of the Rockies
Brad Smith (RN, ASCIE, BS-Psy MCNPS, CISSP, NSA-IAM) started his computer training in 1971 and is still going strong. Living in the North West, Brad is currently working as a private practice informatics nurse helping rural and frontier medical facilities comply HIPAA. His company, the Computer Institute of the Rockies was selected as the 2005 Microsoft Small Business Solution Partner of the Year for its innovative and cost effective business solutions. He is a frequent speaker at the national medical and security conferences, where he makes complex ideas simple to grasp. Brad is known for his high-energy style of presenting and the real-world experiences he shares during these sessions. He values an active session where everyone is encouraged to share their ideas.
E-F4 Developing a Security Policy That Will Survive
Speaker - Michael Metzler [ Presentation], Master Security Architect, SAVVIS Federal Systems
Michael Metzler has 25 years of experience in Computer Science, Computer Networking and Security. He has delivered consulting service internationally that includes expertise and experience in security policy, security planning, network design and troubleshooting. Mr. Metzler has designed global networks for Fortune 500 customers and provided network security services for many major corporations, as well as for the United States and foreign government agencies. As a consultant, he has specialized in security policy, global network designs, enterprise networking strategies, and network security for customers that include major airlines, automobile manufacturers, aerospace and aircraft manufacturers, power utilities, pharmaceutical companies, petroleum companies, regional and global telecommunications providers, computer hardware, software manufacturers and government customers including network design and security work on Capitol Hill and at the White House, as well as with the Department of Defense. He has been a Certified Information Systems Security Professional (CISSP) since 1998, is a Certified Information Security Manager (CISM), and a member of FBI InfraGard. As a speaker, he has presented computer networking and security seminars worldwide at customer locations and public conferences including Computer Security Institute (CSI), NetWorld+InterOP, Internet World and Electronic Commerce Expo, International Computer Security Association (ICSA), and previous Digital Equipment Computer User Society (DECUS) events. His current projects include Information Assurance of aircraft data networks; providing system engineering, specifications, and security architecture for Internet and broadband networking aboard commercial airlines and U.S. Government aircraft; as well as counseling commercial enterprises in developing security programs to reduce risk related to Personally Identifiable Information and to meet Payment Card Industry Data Security Standards (PCI/DSS).
E-F2 Building Strong Web Services Authentication Using SAML
Jahan Moreh is the chief security architect at Sigaba. In this role, Jahan works with Sigaba's internal development staff and external customers to implement practical security strategies in Sigaba's product line. Moreh is co-holder of US patents 6158007, 6584564, and 69593636, all related to information security. He has testified before the Social Security Administration commission on the issues regarding privacy protection of citizens in face of information availability on the Internet. Moreh is a frequent speaker at major conferences and has published numerous papers and articles. In addition, Jahan Moreh is a senior member of teaching staff at the Department of Engineering and Information Science at UCLA, where he teaches classes in Distributed Systems Security.
1:30 pm–2:30 pm
CSI Conference Session
G4 Legal Developments in Security and Privacy
Speaker - M. Peter Adler [ Presentation], Partner, Pepper Hamilton LLP
M. Peter Adler is an attorney and the President of InfoCounsel, LLC. Two years ago Peter served as the Interim Chief Information Security Officer at the University of Colorado in Boulder. Last year he fulfilled similar duties for Montgomery College in Rockville, MD. In his security and privacy practice, he assists organizations with governance and legal issues pertaining to information security and privacy compliance. This practice follows a unified approach in providing simultaneous security and privacy compliance with multiple regulatory regimes. The laws, regulations and private standards he works with include the Gramm-Leach-Bliley Act (GLBA), the Health Insurance Portability and Accountability Act (HIPAA), the EU Data Protection Directive (including the US "Safe Harbor" and other derogations), FDA security regulations (21 C.F.R. Part 11), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the Federal Education Records Protection Act (FERPA), the Federal Information Systems Management Act (FISMA) and the numerous state laws regarding notice of security breaches the Payment Card Industry (PCI) Data Security Standard, and ISO, NIST and FIPS security standards. He also provides legal support during e-discovery and forensics in preparation for litigation.
Kimber recently joined Embarcadero Technologies, bringing more than 10 years experience in the Information Security industry. She started her career at Ernst & Young specializing in IT compliance; helping Fortune 500 organizations meet both regulatory and internal information security requirements. This included developing risk assessment, compliance, policy management, and product evaluation programs. She then spent 5 years at NetIQ, responsible for driving the strategy and marketing around the company's policy-based security products and sharing her regulatory compliance expertise with customers in all types of industries. She also regularly works with industry analysts from such firms as Gartner, META (now Gartner), and Forrester on these topics. Kimber has a bachelor's degree in Accounting from Baylor University, an MBA from Michigan State, and has received the Certified Public Accounting, the Certified Information Systems Auditor, and the Certified Information Systems Security Professional designations.
G1 Beware of Mobile Devices!
Speaker - Nicholas Miller [ Presentation], CEO, AirPatrol Corporation
Nicholas Miller is an innovative career entrepreneur who has founded a number of successful private and publicly traded companies in the software, wireless, and Internet sectors. His wide ranging experience as a high technology executive includes over 25 years of direct P & L responsibility, along with extensive experience in sales, marketing and technology start-ups. Miller was one of the first to identify the security threats posed by wireless technology and coined the phrase
G3 Securing Web Services
Speaker - Tara Kissoon [ Presentation], Director, Information Security Services, Global Information Security Office, Visa Inc.
Tara Kissoon is a Director within Visa's Information Security Services where her focus is on security assessments, security management and providing security expertise. She represents Visa on several International Working Groups. Tara has over 15 years experience in various aspects of Information Technology. Tara's diverse experience includes security reviews of complex network architectures, facilitating multi disciplined risk assessments, conducting various workshops and forums, and leading Information system audits specializing in system development, web architectures, application and database reviews and SOX compliance. Tara taught at Seneca College, where she was responsible for the development, delivery, and evaluation of information technology curriculum. She was appointed to represent her college on several advisory committees and developed the first security course at Seneca College. Tara is a Certified Information System Security Professional (CISSP) and a Certified Information Systems Auditor (CISA) and has achieved various industry certifications.
G2 Toward an Identity Metasystem
Speaker - Robert Richardson [ Presentation], Director, Computer Security Institute
2:45 pm–3:45 pm
CSI Conference Session
H1 Secure Your Mobile Devices!
Speaker - Emmitt Wells [ Presentation], Practice Director - NA Consulting, Getronics USA Inc.
Mr. Wells is a senior consultant with 19 years (15 years with Getronics) of professional experience in the IT industry and is currently responsible for a team of Infrastructure Engineers engaging in both pre-sales and post-sales opportunities including Network Architecture, Mobile Infrastructures, Unified Communications, and Video Conferencing. Most recently he was responsible for the US Security and Communications Portfolio Practice for North America and has managed large projects for both government and enterprise customers. He was also a key contributor to building the current global solution set for Getronics Network, Server, and Application Management Services. Throughout his career, he has focused on delivering IT services in a consistent, cost effective, and secure manner. This emphasis on security, wireless technologies, and IPT services brought him into the Getronics consulting organization to help distribute industry leading solutions amongst all Getronics services. Mr. Wells has both technical and business knowledge of the operations, delivery, and financial aspects necessary to run an effective ICT organization. He has managed up to 77 people in the ICTC organization, with a $5.1 million budget. Having been involved in the business line delivery most of his career; he brings a unique perspective on what is expected from a supporting organization. This part of the business does not drive the business through technology, but analyzes the business requirements and is a business enabler through technology. His experience in delivering outsourced services to external customers was very integral in beginning Getronics' EWWS/SWWE business initiative. Ultimately with the goal of reducing centralized expense allocations to the individual business lines to help facilitate lower pricing and increased revenue.
H5 Complying Across Continents
Speaker - Milton Luoma [ Presentation], Assistant Professor, Metropolitan State University
Milton H. Luoma, Jr. holds the degrees of Juris Doctor, M.S. in Computer Science, M.B.A., and M.S. in Engineering. He has also completed advanced work in the Ph.D. program in business at the University of Cincinnati. He has practiced law and worked as a business consultant in Minnesota for over 20 years. He has designed and developed the Computer Forensics and Computer Security programs at Fond du Lac Tribal & Community College in Minnesota. He is currently an Assistant Professor teaching Computer Science and Computer Foreniscs at Metropolitan State University in St. Paul, Minnesota. , Previous Speaking Engagements: Midwest Association for Legal Studies in Business Conferences; American Academy for Legal Studies in Business; Keynote Speaker at Northeast Service Cooperative Conference; Fairview Hospital Public Lecture Series; Brenau University Online College Conference; Minnesota State University IT & Wireless Technology Conference Licensed Attorney at Law, State of Minnesota; Graduate Certificate in Computer Forensics, Oregon State University; NTI Computer Forensics Certification
Speaker - Vicki Luoma [ Presentation], Assistant Professor, Minnesota State University
Vicki Luoma holds a Juris Doctor degree and is a candidate for a Ph.D. in Business. She has practiced law and worked as a business consultant in Minnesota for over 25 years. Further, she is a former Vice President of a small business university. She is currently an Assistant Professor in the College of Business at Minnesota State University.
H4 To Disclose the Breach or Not To?
Speaker - Pat Logan [ Presentation], Associate Professor, Marshall University
Dr. Logan is an associate professor in the College of Information Technology and Engineering at Marshall University. She has taught information security, computer forensics, multimedia, and cybercrime. She has been an invited speaker at both national and international conferences on security topics. In addition to her academic experience, Dr. Logan has over sixteen years of corporate experience including Assistant Vice President of Information Services at Sanwa Bank, Monterey Park, California. Her research interests include information security, computer forensics, Fourth Amendment issues that apply to the search and seizure of computer media, and the application of computer technology to courtroom presentations.
H2 Fuzzing the Security Perimeters: An Army of Wooden Horses at Your Gate
Speaker - Ari Takanen [ Presentation], CTO, Codenomicon
Ari Takanen, founder and CTO of Codenomicon, has since 1998 been focusing his work on information security issues in next-generation networks and security critical environments. The work of Codenomicon and the University of Oulu aims at ensuring that new technologies are accepted by the general public by providing means of measuring and ensuring quality in networked software. Ari Takanen is one of the people behind the PROTOS research that studied information security and reliability errors in e.g. WAP, SNMP, LDAP, VoIP implementations. His company, Codenomicon Ltd. provides automated tools with a systematic approach to test a multitude of interfaces on mission critical software, including but not limited to VoIP platforms, Internet routing infrastructure and 3G devices. Ari has been speaking at numerous security and testing conferences, and also at leading universities and international corporations. Especially the presentations at commercial companies have shown that that what we do at Codenomicon really matters and makes a change to the information society in general. He has co-authored a book on Voice over IP security (published by Addison-Wesley).
H3 Brand Your Security Program as Fun
Speaker - Todd Fitzgerald [ Presentation], Systems Security Officer, National Government Services
Todd Fitzgerald, CISSP, CISA, CISM serves as a Medicare Systems Security Officer for National Government Services, LLC (NGS), Milwaukee, WI which is the nation's largest processor of Medicare claims, and subsidiary of WellPoint, Inc. (NYSE:WLP) the nation's largest health insurer. Todd was named as a finalist for the 2005 Midwest Information Security Executive (ISE) of the Year Award, nominee for the national award, Judge for the 2006/08 central region awards, and has moderated several Executive Alliance Information Security Executive Roundtables. Todd is the co-author of the ISC2 book entitled CISO Leadership: Essential Principles for Success (January, 2008) and has authored articles on Information Security for The 2007 Official ISC2 Guide to the CISSP Exam, The Information Security Handbook Series, The HIPAA Program Reference Book, Managing an Information Security and Privacy Awareness and Training Program, and several other security-related publications. Todd is also a member of the Editorial Board for ISC2 Journal/Information Systems Security Magazine and is frequently called upon to present at national and local conferences. Todd serves on the Board of Directors for the HIPAA Collaborative of Wisconsin, and is an active leader, participant and presenter in multiple industry associations such as Information Systems Security Association (ISSA), Blue Cross Blue Shield Information Security Advisory Group, CMS/Gartner Security Best Practices Group, Workgroup for Electronic Data Interchange (WEDI), Information Systems Audit and Control Association (ISACA), and others. Todd has 28 years of Information Technology experience, including 20 years of management. Prior to joining NGS, Todd held various broad-based senior Information Technology management positions for Fortune 500 organizations such as American Airlines, IMS Health, Zeneca (subsidiary of AstraZeneca Pharmaceuticals), Syngenta, as well as prior positions with Blue Cross Blue Shield of Wisconsin.
4:00 pm–5:00 pm
CSI Conference Session
I1 Why NAC and Why Not NAC?
Speaker - Lisa Lorenzin [ Presentation], Principal Solutions Architect - Security Solutions, Juniper Networks
Lisa Lorenzin is a Principal Solutions Architect with Juniper Networks, specializing in security solutions, and a contributing member of Trusted Network Connect (TNC), a work group of the Trusted Computing Group (TCG) that defines an open architecture and standards for endpoint integrity and network access control. She has worked in a variety of Internet-related roles for the past 13 years, with more than a decade of that focused on network and information security. Lorenzin's experience in data center, government and enterprise environments, as well as her active participation and service in local user groups, has brought her a thorough understanding of the challenges network administrators and users face in today's world of expanding regulations and increasing security threats.
I4 Working with Law Enforcement Before and After an Incident
Speaker - Tom Prunier [ Presentation], Computer System Security Analyst Senior, Lockheed Martin
Tom Prunier is a Computer System Security Analyst for Lockheed Martin. Tom is currently contracted to the Federal Bureau of Investigations as a Cyber Crimes Investigation Instructor and a certified Intrusion incident handler. Tom previously was a Detective and a member of the Internet Crimes Against Children's Task Force for the State of Kansas and has investigated a wide variety of computer related crimes at the Local, State, and Federal Level. Tom has responded to numerous incidents in an investigative and computer forensic capacity. Tom has a Master of Arts in Computer Information Management and is an Associate Professor at Southwestern College in the fields of Criminal Justice, Computer Science, and Security Management.
I5 Visualization: Transforming How We View Security
Speaker - Anita D'Amico [ Presentation], Director, Secure Decisions div of AVI
Dr. Anita D'Amico is the Director of Secure Decisions, a division of Applied Visions, Inc. in Northport, NY. She is both a human factors psychologist and an information security specialist. Her research, publications, and teaching have been in the areas of: situational awareness, particularly improving decision-making through visualization; information security and information warfare; cognitive analysis; operational fatigue; and research methods. All Dr. D'Amico's research projects stress the development of visualizations that can be rapidly transitioned into real operational environments for real-world evaluation and early adoption.
I2 PCI in 2008
Speaker - Branden R. Williams [ Presentation], Director, PCI Practice, VeriSign
Branden R. Williams could easily be described as one of the industry's leading experts but that title does not encompass his robust talents. With four active professional certifications, a list of publications, more than a decade of experience, and an enviable knowledge of technology he has earned the respect of global, top named clients and industry insiders. Yet, Williams is much more than an IT expert, his astute understanding of business has enabled him to create innovative solutions that align with key organizational objectives. This rare combination of technology and business expertise has resulted in Williams becoming a sought after Information Technology and Strategy Leader by the world's foremost corporate executives. Equally impressive is Williams high energy, results oriented business style. Williams is firmly committed to partnering with organizations to maximize profitability and opportunity. Williams has a steadfast belief that IT and IT security should support and contribute to an organization. Utilizing his keen business insights and ability to communicate with technical and non-technical audiences, he has been able to collaborate with corporations to analyze, develop and implement enterprise wide solutions that support key business drivers. Williams has worked with clients in the financial, retail, healthcare, manufacturing, utilities, transportation, service provision and industrial sectors. He currently manages a multi-million dollar consulting practice while leading a global team of 80 certified Qualified Security Assessors (QSAs). Williams holds an MBA in Supply Chain Management and Logistics from the University of Dallas where he is also a graduate level Adjunct Professor consistently ranked in the top 10% of professors. He is a Lifetime Member of Pi Sigma Epsilon, and Founding Member of The Michelangelo Group Security Alliance. Williams is also a sought after speaker and author.
J2 FORUM: Using Risk Analysis to Keep Your Boss Out of Jail
Speaker - Thomas Peltier [ Presentation], President, Thomas R. Peltier Associates, LLC
Tom Peltier has been an information security professional for over thirty years. During this time he has shared his experiences with follow professionals and because of his work has been given the 1993 Computer Security Institute's (CSI) Lifetime Achievement Award. In 1999 the Information Systems Security Association (ISSA) bestowed its Individual Contribution to the Profession Award and in 2001 he was inducted into the ISSA Hall of Fame. Tom was also awarded the CSI Lifetime Emeritus Membership Award. Over the past decade, Tom has averaged 4 articles published a year on various computer and information security issues, including developing policies and procedures, disaster recovery planning, copyright compliance, virus management and security controls. He has had six books published on policy development and risk assessment. He co-authored four other information security books. He continues to speak and teach information security courses throughout the world.
J3 Private Data Mining and Citizens' Rights
Speaker - Andrew Lindell [ Presentation], Chief Cryptographer, Aladdin Knowledge Systems
Andrew Lindell is the Chief Cryptographer at Aladdin Knowledge Systems and an Assistant Professor at Bar-Ilan University in Israel. Andrew attained a Ph.D. at the Weizmann Institute of Science in 2002 and spent two years at the IBM T.J.Watson research lab as a Postdoctoral fellow in the cryptography research group. Andrew has carried out extensive research in cryptography, and has published more than 40 conference and journal publications, as well as a textbook on cryptography and another book detailing secure protocols. Andrew has presented at numerous international conferences, workshops and university seminars, and has served on program committees for top international conferences in cryptography. In addition to Andrew's notable academic experience, he joined Aladdin Knowledge Systems in 2004. In his position as Chief Cryptographer, he has worked on the cryptographic and security issues that arise in the design and construction of authentication schemes, smartcard applications, software protection schemes and more. Offering a unique combination of academic and industry experience, Andrew brings a fresh and insightful perspective on many of the crucial security issues that arise today.
"Enjoyed the mix of the highly technical hacking versus Policy & Awareness. Smaller size (compared to RSA) made it easier to speak with other people and make connections." Laura Nelson, Data Architect
UPS
"The sessions were very good, however, I most enjoyed the engaging conversation of my peers." Robert E. Lee, Jr., CEO
RK Goodworks, LLC
"It's the first conference I've seen with a track just for Security Training & Awareness." Tami Kilbourne, Sr. Technical Analyst
Philip Morris USA