
Mid-Atlantic Information Security Forum 2012
March
20-21
JW Marriott
Washington, DC
Information Security Forums bring together experienced IT and information security practitioners for confidential information sharing on the industry's most important issues, technologies, and trends. The two-day event includes keynote addresses, technical and strategic roundtable discussions led by IANS' Faculty, networking receptions, and the opportunity to learn about new technologies.
Why Attend
- Gain tangible, real world insights on best practices and lessons learned directly from your peers
- Stay current with emerging technologies and early-stage deployments
- Connect with the industry's leading minds
- Network and connect with other influential senior IT managers and business leaders
- Earn 16 Continuing Education Credits
IANS Charity Spotlight: Higher Achievement
Higher Achievement closes the opportunity gap during the pivotal middle school years. By leveraging the power of communities, Higher Achievement’s proven model provides a rigorous year-round learning environment, caring role models, and a culture of high expectations, resulting in college-bound scholars with the character, confidence, and skills to succeed.
Donate to Higher Achieve when you register for the Mid-Atlantic Information Security Forum.
About IANS Charity Spotlight: IANS is proud to partner with worthy causes that benefit our communities, our nation, and the world. Please give them your support!
To suggest a candidate for the IANS Charity Spotlight, email Adrienne Wilson at awilson@iansresearch.com.
The IANS 2012 Mid-Atlantic Information Security Forum Curriculum will be dictated by our Steering Committee, our Faculty of Industry Experts, and by the IANS 2012 Research Agenda.
This curriculum will represent the ongoing conversations among the Steering Committee and IANS Faculty of top areas of interest and concern for 2012 while still maintaining the highest relevancy for security professionals.
At IANS, we strive to serve the security professionals by identifying key topics and trends and provide insights and approaches to enhance attendees’ ability to anticipate and respond to these forces. Based on our peer-based research model we may make changes to our Forum curriculum in response to users’ interests to include breaking news and issues of the highest importance.
Aaron Turner will lead the Information Protection track. In an increasingly mobile world, information security teams are challenged with finding ways to secure pertinent data, while purging irrelevant information, and justifying to upper management how these tasks contribute to the overall success of the business.
Sessions include:
- InfoSec Failure - Why Organizations are Losing More Data Every Day
- Anatomy of a Persistent Attack & Response Roadmap
- Mobile Risks- How Mobile Technologies are Facilitating Data Loss & Data Theft
- The IANS Mobile App - Lessons Learned & Best Practices for Moving Forward
Marcus Ranum will lead the Incident Reponse & Planning track, covering a wide variety of subjects including logging, audit, segmentation, APT, and malware response.
Sessions include:
- Getting Mileage From Audit and Logging
- Audit Infrastructure
- Incident Response
- Metrics: Developing Good & Meaningful Metrics That Matter
IANS SVP of Research and CTO, Dave Shackleford will lead the Counter-Threat Operations track, which will cover such topics as building and coordinating a Security Operations Center, security tactics, social engineering, mitigation, and avoidance techniques.
Sessions include:
- So You Say You Need a SOC?
- Better Living Through Offensive Security
- The Top Security Mistakes and How to Avoid Them
- Socially Engineering Your Way to Better Security
Randy Sabett will lead the Risk and Compliance track. Security and legal teams should be closely aligned in order to advance the protection and controls of corporate data. This track will highlight the areas where security and legal intersect.
Sessions include:
- Data Security Exposure: A GRC & Case Law Update
- Tricks and Tips for Data Breach Response
- Avoiding Liability From Mobile, Social Networks, & Things Beyond Your Control
- Cloud Security Contract Primer
Diana Kelley will lead the Application Security track which will review the value of building security into the AppDev lifecycle as well as the possible pitfalls.
Sessions include:
- AppSec: Waste of Resources or Fundamental Requirement?
- Lessons from the AppSec Trenches: What Works and What Doesn’t?
- Measuring and Optimizing the Value of your AppSec Program
- Debunking the “Faster, Cheaper, More Secure – Pick Two” Myth
Keynote Address
This talk will explore the implication of cyber to critical infrastructures. Michael Assante will explain how the combination of advances in networked computing and user demands are blurring lines and threatening traditional planning assumptions. We will explore tough questions such as: How will discrete systems manage virtualization, cloud computing, proliferating network connections, mixed use personal technology, and an evolving threatscape? And discuss how organizations should engineer new systems to be resilient yet fragile in the face of mounting complexity.
Michael Assante is currently the President & Chief Executive Officer of National Board of Information Security Examiners (NBISE) and Chair of NBISE’s National Board. Michael Assante is an internationally recognized expert and thought leader in information and cyber security and the recipient of many awards in the space. Mr. Assante most recently held the position of Vice President and Chief Security Officer at the North American Electric Reliability Corporation and oversaw the implementation of cyber security standards across the North American electric power industry. Prior to joining NERC, Assante held notable positions at Idaho National Labs, was Vice President and Chief Security Officer for American Electric Power, and pioneered the security intelligence landscape in his role as Chief Operating Officer of LogiKeep. A former U.S. Navy intelligence officer with experience in information warfare and information security management, Mr. Assante recognized the need to bring intelligence-type analysis to the networks of the corporate world by identifying risks and threats specific to the hardware, software and systems used by individual organizations.
The security vendor consolidation spree has major market implications. VCs are investing in fewer security start ups, leaving an "innovation void" that if not addressed could lead to a very concerning cycle of less innovation in security, giving the bad guys an even stronger upper hand. Peter Kuper shares his perspective on why finance and technology are inextricably linked, why you should care, and who could be the next best bet in the security landscape.
Peter Kuper is a Partner with In-Q-Tel, the strategic investing firm that identifies, adapts, and delivers innovative technologies to support the missions of the Intelligence Community. Peter actively seeks and works with private companies with a particular focus on security and enterprise software. Previously, Peter was the lead software analyst for Morgan Stanley where he published industry leading investment reports and led over 18 public transactions. Overall, Peter was a Wall Street analyst for 15 years offering him the opportunity to work with some of the most dynamic and talented public and private companies and the world's leading investment professionals. As a visible voice for the software industry Kuper has given numerous presentations to professional and government groups and has been interviewed on CNBC, Bloomberg Television, and quoted in most leading publications including The Wall Street Journal and The Financial Times. He has also published articles in IEEE Magazine. Peter currently serves as an adviser to the Pacific Northwest National Lab and is a Faculty member for IANS.
Speakers
Mr. Ranum has been consistently recognized as one of computer security’s innovators and creative thinkers. Since 1989 he has held every position that is possible within a high-tech business – from junior system administrator and software engineer to CEO, CTO, and marketing director. He is the principal author of several major Internet security products, including firewalls, VPNs, and intrusion detection systems.
Mr. Ranum is presently serving as the CSO of Tenable Network Security, Inc.
Expertise: Intrusion detection • Virtual private networks • Firewalls • Data leakage • Host IDS • Network architecture • Network IDS • Application security • Log management • Vulnerability management
Randy V. Sabett, J.D., CISSP, is Counsel at ZwillGen. He advises clients on information security, privacy, IT licensing, and intellectual property. Randy has over 20 years of infosec experience, including as an NSA crypto engineer and a CISSP. He works closely with companies in helping them develop strategies to protect and exploit their information and IP based on various evolving business models, including SaaS, mobile applications, cloud, and more traditional client/server architectures. He also drafts and negotiates a variety of technology transaction agreements. Randy served as a commissioner for the Commission on Cyber Security for the 44th Presidency and has been recognized as a leader in privacy and data security in the 2007 – 2011 editions of Chambers USA: America's Leading Lawyers for Business. He has been recognized as one of the Top 50 Under 45 by the American Lawyer’s “IP Law and Business” and is listed in the International Who’s Who of Business Lawyers.
Expertise: Compliance and regulations • Data classification • eDiscovery • PCI compliance • Risk management • IT licensing
Aaron Turner is currently the President of CEI, an information security consultancy focused on helping Fortune 100 companies manage the risks associated with technology dependencies in critical infrastructure systems. Prior to CEI, Aaron was the Co-Founder and CEO of RFinity, a mobile security technology startup formed as the result of research conducted at the US Department of Energy's Idaho National Laboratory (INL). While at INL, he collaborated with a team of information security experts to design the world's first large-scale testing effort to evaluate how critical infrastructure has become dependent on computing systems and the resulting vulnerabilities that those dependencies cause.
Dave Shackleford is the Senior Vice President of Research and the Chief Technology Officer at IANS. Dave is a SANS analyst, instructor and course author, as well as a GIAC technical director. Dave previously was the founder and principal consultant with Voodoo Security, and has consulted with hundreds of organizations in the areas of security, regulatory compliance and network architecture and engineering. Dave is a former QSA with several years' experience performing PCI assessments. He is a VMware vExpert, and has extensive experience designing and configuring secure virtualized infrastructures. Dave has previously worked as CSO for Configuresoft, CTO for the Center for Internet Security, and has also worked as a security architect, analyst, and manager for several Fortune 500 companies.
Expertise: Network Intrusion Detection and Prevention • Network Firewalls and Access Controls • Security Architecture • Penetration Testing • Regulatory Compliance • Patch and Configuration Management • Virtualization Security • Incident Response
David Etue brings experience including security program leadership, management consulting, product management, and technical implementation. David is the vice president of corporate development strategy at SafeNet, where he is responsible for SafeNet's strategic decisions regarding product and solution partnerships, as well as mergers and acquisitions. He was previously the cyber security practice lead at management consultancy PRTM, VP of Products & Markets at Fidelis Security Systems, led General Electric's global computer security program, and held various positions in technology strategy, operations and product management. He is a Certified Information Privacy Professional, a graduate of GE’s Information Management Leadership Program, and a certified Six Sigma Green Belt.
Kevin Johnson is a security consultant with Secure Ideas. Kevin came to security from a development and system administration background. He has many years of experience performing security services for Fortune 100 companies, and in his spare time he contributes to a large number of open source security projects. Kevin's involvement in open-source projects is spread across a number of projects and efforts. He is the founder of many different projects and has worked on others. He founded BASE, which is a Web front-end for Snort analysis. He also founded and continues to lead the SamuraiWTF live DVD. This is a live environment focused on Web penetration testing. He also founded Yokoso and Laudanum, which are focused on exploit delivery. Kevin is a senior instructor for SANS and the author of Security 542: Web Application Penetration Testing and Ethical Hacking. He also presents at industry events, including DEFCON and ShmooCon, and for various organizations, like Infragard, ISACA, ISSA, and the University of Florida.
Alex Hutton is a big fan of trying to understand security and risk through metrics and models. Currently, Alex is the Director of Risk Management for a top 25 bank. A former principal for Research & Intelligence with the Verizon Business RISK Team, Alex also helped produce the Verizon Data Breach Investigation, the Verizon's PCI Compliance report, was responsible for the VERIS data collection and analysis efforts, and developed information risk models for their Cybertrust services. Alex is the veteran of several security start-ups.
Alex likes risk and security so much, he spends his spare time working on projects and writing about the subject. Some of that work includes contributions to the Cloud Security Alliance documents, the ISM3 security management standard, and work with the Open Group Security Forum. Alex is a founding member of the Society of Information Risk Analysts, and blogs for their website and records a podcast for the membership. He also blogs at the New School of Information Security Blog. Some of his earlier thoughts on risk can be found at the Riskanalys.is blog.
Diana Kelley is an internationally recognized security expert with 20 years of IT security experience. She founded SecurityCurve in April of 2003 to provide risk-focused advisory services to enterprises and deliver strategic, competitive knowledge to security software vendors.
Prior to returning to SecurityCurve in January 2008, she was Vice President and Service Director for the Security and Risk Management Strategies (SRMS) service at Burton Group. Diana was the Executive Security Advisor for CA’s eTrust Business Unit where she was responsible for advising customers on strategic security solutions and helped guide CA’s security business. Prior to that, she served as the Vice President of Security Technology for Safe3W, Inc (acquired by iPass) and was the General Manager of a development group at Symantec Corp and the media spokesperson for the company on the 2000 “Proactive Security Tour”. She was the Vice President of Corporate Development for LockStar and helped the company succeed in being named to the Red Herring “Top 50 Companies in the Digital Universe”.
Ed is a 15+ year veteran of information security as well as an industry-recognized thought leader, advisor, writer, and manager. Ed is currently Senior Security Strategist with Savvis, providing strategy, consulting, and solutions to clients worldwide and a founding partner of SecurityCurve.
Prior to this, Ed was a Senior Manager within CTG’s global information security solutions practice, where he provided C-level guidance across a wide segment of industry, including healthcare, telecommunications, energy, and financial services.
Ed was Vice President and Information Security Officer for Merrill Lynch Investment Managers(MLIM,) where he was responsible for coordinating all aspects of information security within the business unit. MLIM (now BlackRock Asset Management) consisted of approximately 2500 employees with over US $500 billion in assets under management. During his tenure at Merrill, Ed also developed firm-wide cryptographic solutions for secure data transfer, secure key management, authentication, and data integrity.
Having built IANS’ end user research offering, Phil now oversees all strategic, sales and operational decisions at IANS. Phil began his career in security with seven years with the U.S. Navy as a Strike Fighter Pilot & Ordnance Requirements Officer. After receiving a Masters in Business Administration from Harvard Business School, he joined Goldman, Sachs & Co. in Mergers & Acquisitions and later became an associate with McKinsey & Company in Boston, MA. In 1996, Phil became one of the founders of Provant, Inc., a publicly traded training company serving the Fortune 1000 and Federal Government. He left Provant in 2000 to launch the Institute for Applied Network Security. Phil is a graduate of Harvard Business School and Harvard College; and, he graduated at the top of his class in US Navy Flight School.
The Steering Committee
The Steering Committee is a consortium of the region’s top senior information security executives from Fortune 1000 companies, large government agencies, and academic institutions. These executives guide and shape the Forum Curriculum and Agenda, ensuring the event is relevant and exciting for participants.
If you would like to nominate someone for the 2012 Mid-Atlantic Steering Committee, please contact Tim Bernard at tbernard@iansresearch.com.
Steering Committee Chairman
Markel Corporation
Jake Kouns is the Director of Cyber Security and Technology Risks Underwriting for Markel Corporation. In this unique role, Mr. Kouns is responsible for strategy and oversight of the Enterprise Information Security Program for the company as well as the management of Cyber Liability insurance products. In his role as product line leader, he has broad responsible for all aspects of the products including the development of underwriting guidelines, pricing, risk analysis, claims oversight, training & marketing initiatives as well as risk management services for policy holders. Prior to joining Markel, he was Senior Network Security Manager for Capital One Financial where he was responsible for the day-to-day global security management of a large complex firewall environment, intrusion detection and risk assessment.
Mr. Kouns is an outspoken advocate for improved security practices and his opinion is often sought by publications such as Information Week, eWeek, Processor.com and SC Magazine. He is also the co-author of two books, Security in an IPv6 Environment and Information Technology Risk Management in Enterprise Environments. He is also a frequent public speaker on the topic of information security and has presented at many well-known security conferences including the RSA Conference, CISO Executive Summit, EntNet IEEE GlobeCom, CanSecWest and SyScan.
VF Corporation
Melissa is Chief Information Security and Technology Risk Officer for VF Corporation,
NYSE: vfc. VF ranks as number 310 in the Fortune 500, and is an $8 billion global apparel powerhouse, with offices around the world. VF is the parent company of dozens of top name brands in the industry, including The North Face, Wrangler, Lee, Nautica, and 7 for all Mankind.
Prior to joining VF in 2008 as its top security and risk officer, Melissa served as Director, Global Information Security and Risk Management, the Gillette Company; and as Senior Manager, Information Risk Management Practice for KPMG, LLC.
Melissa began her career as Manager, Assurance Practice, where she managed and delivered audit engagements for higher education, financial services, government, and manufacturing clients.
Melissa is an expert speaker on topics including managing a global security organization; PCI compliance; SOX compliance; Privacy compliance; reaping the benefits of a risk assessment; and establishing a global policy database. She has also served as a panel member at numerous technology and risk forums.
She earned a Masters in Business Administration from Boston University, after graduating from Bryant College, with a B.S. in Business Administration.
Melissa is a Certified Public Accountant, a Certified Information Security Specialist Professional , and a Certified Information Systems Auditor.
She resides in Greensboro, North Carolina with her husband, Matthew, and two children.
The George Washington University
Mr. Devlin has nearly four decades of IT and security leadership experience in both Fortune 500 companies and major universities. He has initiated and led enterprise-class programs in security, privacy, identity management, electronic messaging and emergency notification. Dennis is also a frequent lecturer, speaker and panelist on information security management topics at institutes and conferences.
Steering Committee
The American University
Lockheed Martin Corporation
The College Board
Bechtel
Magellan Health Services
The Washington Post Company
IBM
United States Postal Service
Nuclear Regulatory Commission
Standard Conference Price
IANS Information Security Forum - US $1350
Download a letter of approval template
This template will help you provide to your direct manager the pertinent information regarding the conference for their approval.
To download a copy of the Letter of Approval, click here.
All attendees earn 16 CPE credits through our partnership with (ISC)²
Payment Methods
Credit Card
IANS, through RegOnline, accepts all major credit cards.
Purchase Orders (PO)
IANS accepts payment through purchase orders. To use this payment method, please contact CJ Oliveri at coliveri@iansresearch.com or (617) 399-8100.
Cancellations
By completing registration, you are reserving your place at the Forum. Registered attendees will select specific Forum discussion sessions onsite. Please note that space is limited and assigned on a first come, first serve basis.
All registrations must be approved by IANS. Forum delegate positions are restricted to security practitioners. Cancellations must be submitted in writing and received by two weeks prior to a forum to qualify for a refund. Refunds will only be given for one-half of the original registration fee. Any cancellations submitted within fourteen days of the Forum will not be subject to refunds.
Terms and Conditions
This conference is produced by IANS, which reserves the right, in its sole discretion, to limit or deny access to the conference to any entity or individual. IANS’ receipt of a registration application and payment does not constitute acceptance until some form of acknowledgment or acceptance is sent; applications and payments that are not accepted will be returned within 30 days of receipt.
IANS is not affiliated with Apple Corporation, Microsoft Corporation, or Amazon.com Inc. All trademarks are the property of the respective trademark owners. IANS retains the right to substitute a prize or gift card of equal or greater retail value. Additional restrictions may apply.
IANS does not permit combination of discounts or promotional codes.
Forum Discounts and Promotions
| IANS Enterprise Research Clients: |
If your company is an IANS Enterprise Research client, you may have pre-paid Forum Seats available. |
| Bring a Team: |
When you register three colleagues from the same company at the same time with payment, the fourth colleague may attend for free. |
| Present at IANS: |
IANS Presenters receive a 50% discount for giving a 10 minute case-study style briefing outlining the approach and solution that they or their information security team developed when addressing a relevant issue or theme. |
| Association Discounts: |
Discounts are also available for nonprofit, government, and educational institutions. All ISC² members receive a $350 discount to attend our Information Security Forum. Please contact CJ Oliveri at coliveri@iansresearch.com for more information. |
| IANS Discounts and Promotions Policy |
Discounts, specials, and promotions cannot be combined. Unless otherwise indicated, all promotional items are distributed on the second day of the Information Security Forum. |
Location Information
Mid-Atlantic Information Security Forum 2012
March
20-21, 2012
Forum Schedule
JW Marriott
1331 Pennsylvania Avenue Northwest Washington, DC 20004
Phone: (202) 393-2000
http://www.jwmarriottdc.com
We asked a few delegates from our New England Information Security Forum what they thought about our events:
Past IANS forums have included teams from
Beth Israel Deaconess Medical Center
Bose Corporation
Dunkin' Brands
Genzyme
Iron Mountain
Massachusetts Institute of Technology
Nokia
Raytheon
State Street
United Parcel Service
Bain Capital
Big Y Foods, Inc.
Boston Scientific
Fidelity Investments
Harvard
Kraft Group
Northwestern Mutual
RBS Citizens
The TJX Companies, Inc
WGBH
Bank of America
Blue Cross Blue Shield of MA
Commonwealth of Massachusetts
GE Capital
HSBC Bank
Legal Sea Foods
Monster Worldwide
Nuance Communications
Social Security Administration
Thermo Fisher Scientific
WilmerHale













