Sep
10
Chicago, IL

Midwest Information Security Forum 2012

Midwest Information Security Forum 2012

September 10-11
Chicago Marriott Downtown
Chicago, IL

Information Security Forums bring together experienced IT and information security practitioners for confidential information sharing on the industry's most important issues, technologies, and trends. The two-day event includes keynote addresses, technical and strategic roundtable discussions led by IANS' Faculty, networking receptions, and the opportunity to learn about new technologies.

Why Attend

  • Gain tangible, real world insights on best practices and lessons learned directly from your peers
  • Stay current with emerging technologies and early-stage deployments
  • Connect with the industry's leading minds
  • Network and connect with other influential senior IT managers and business leaders
  • Earn 16 Continuing Education Credits

Midwest Information Security Forum 2012

The IANS 2012 Information Security Forum Curriculum will be dictated by our Steering Committee, our Faculty of Industry Experts, and by the IANS 2012 Research Agenda.

This curriculum will represent the ongoing conversations among the Steering Committee and IANS Faculty of top areas of interest and concern for 2012 while still maintaining the highest relevancy for security professionals.

At IANS, we strive to serve the security professionals by identifying key topics and trends and provide insights and approaches to enhance attendees’ ability to anticipate and respond to these forces. Based on our peer-based research model we may make changes to our Forum curriculum in response to users’ interests to include breaking news and issues of the highest importance.

Track 1: Tentative: Information Protection In A Borderless World

In an increasingly mobile world, information security teams are challenged with finding ways to:

  • Secure the data that is pertinent to their organizations
  • Purge what is irrelevant
  • Consider technologies that help protect corporate information
  • Justify to upper management how these tasks contribute to the overall success of the business

Sessions include:

  • “What Wikileaks and Shady RAT Mean for InfoSec Professionals”
  • “Data Control Effectiveness - What You Won't Find in Vendors' Marketing Materials”
  • “Data Gone Walkabout - What Mobile Technology Means to Data Security”
  • “Mobile Device Management, Haven't We Seen This Movie Before?”

Track 2: Tentative: Security 2.0: The Proactive Security Organization

Building and managing a proactive security organization that is able to navigate organizational changes, budget and personnel constraints, and heightened awareness around incidents is a growing problem for many organizations. Using a fictional company as a use case, this interactive discussion will include role-play that provoke participants to think about alternative strategies for running a truly proactive security organization.
Sessions include:

  • “Building a Proactive Security Process”
  • “Audit Infrastructure”
  • “Incident Response”
  • “Metrics: Developing Good & Meaningful Metrics That Matter”

Track 3: Tentative: Next Generation Security Operations

Security professionals must continually assess the myriad tools and technologies that assist in protecting organizational information assets. Added pressure from non-security professionals who are pushing the latest and greatest buzzwords like “cloud,” “SIEM,” and “risk management,” can muddy the waters.
Sessions include:

  • "Security Operations Today"
  • "Security Data Aggregation and Evolution"
  • "Security Architecture 2.0"
  • "Pen Tests Today and Tomorrow"

Track 4: Tentative: Strategy 2.0: Anticipating legislation, Mitigating Risk

Security and legal teams should be closely aligned in order to advance the protection and controls of corporate data. Too often, though, these two groups work independently, often creating snags in the process. Join this session to learn about:

  • New laws and regulations coming down from Capitol Hill
  • Regulatory impact on technology
  • A legal perspective on including new technologies like cloud and social media in your organization’s mix
  • How to balance security and privacy

Sessions include:

  • “K Street Meets Silicon Valley: A Risk-Centric Approach to 2011"
  • "Legal and Security Implications in the Cloud"
  • "Debunking the Myths of IT Security Governance"
  • "Who’s There? The Authentication Explosion and its Legal Ramifications"

Track 1
Tentative: Information Protection In A Borderless World
Session 1
What Wikileaks and Shady RAT Mean for InfoSec Professionals
This session will be a facilitated discussion focusing on how organizations can use recent awareness of Wikileaks and Shady RAT to drive data security program improvements through an approach that focuses on measurable outcomes.
Session 2
Data Control Effectiveness - What You Won't Find in Vendor's Marketing Materials
Come to discuss the relative effectiveness of currently-deployed data protection controls based upon the experience of facilitators and attendees and identify controls that could be leveraged from other InfoSec focus areas to support a holistic data security program.
Session 3
Data Gone Walkabout: What Mobile Technology Means to Data Security
This session will be a facilitated discussion focusing on how organizations can begin to manage how data is exposed to/through mobile technologies.
Session 4
Mobile Device Management, Haven't We Seen This Movie Before?
What happens to an IT infrastructure when a significant number of devices are in use that are not part of an enterprise configuration management process? Should it be any surprise? Is it possible to act now to prevent the tragic ending we've seen before?
Track 2
Tentative: Security 2.0: The Proactive Security Organization
Session 1
Building a Proactive Security Process
In this session we will discuss typical advanced security practices, what you can expect from them, how to try to cost-justify them, and what will likely be required as a matter of course in the future.
Session 2
Managing Bring Your Own Device To Work Programs: Audit & Response
In many organizations, management is now mandating blocking the growing data leakage hole. In this session we will discuss the changing demands on organizations' audit infrastructure and how to grow with them and cope with them.
Session 3
Incident Response
This role-playing, case based approach will allow participants to compare approaches for escalation of and response to a data breach inside the organization, taking into account the implications of lost data in a Wikileaks world.
Session 4
Developing Good & Meaningful Metrics That Matter
So often security professionals are asked to provide metrics to senior business leaders in order to justify budget, spending, effectiveness, or job security. However, the real question is, "how do you know which metrics really matter?"
Track 3
Tentative: Next Generation Security Operations
Session 1
Security Operations Today
This roundtable will address:
  • The new and changing roles in security today
  • Which roles overlap with operational roles
  • The shift in roles from information security to pure operational teams
  • How work gets done
  • The tools and techniques best suited to security, and which belong with more focused operations teams
Session 2
Security Data Aggregation and Evolution
Participants will gain insight around what information is useful, how it can be used, and what its impacts are for interpreting the security posture of an organization. A specific focus will be placed on gathering metrics from the data and how to prevent and detect data breaches.
Session 3
Security Architecture 2.0
Attendees will discuss new risks and considerations with virtualization technology, and how they’re being addressed. This roundtable will focus on how organizations are addressing risks posed by and the controls required when leveraging cloud technologies.
Session 4
Pen Tests Today and Tomorrow
Vulnerability management is a common element of many organizations' security programs. While internal security teams perform testing themselves, they still leverage external firms for specific tests. This session will cover tools, techniques for better testing, tips & tricks for getting better results, and best approaches to aligning pen tests with metrics business initiatives.
Track 4
Tentative: Strategy 2.0: Anticipating legislation, Mitigating Risk
Session 1
K Street Meets Silicon Valley: A Risk-Centric Approach to 2011
Participants will glean from this session an understanding of the linkage between legislation from capitol hill and its impact on the technology and policies in play to protect organizational systems and data.
Session 2
Legal and Security Implications in the Cloud
This session will focus on providing a toolkit of the right questions to consider when exploring the storage of data outside the company firewall.
Session 3
Debunking the Myths of IT Security Governance
This session will examine some of the tensions that come into play when considering how to handle security governance and offer possible approaches to help overcome them.
Session 4
The Authentication Explosion and Its Legal Ramifications
Recent events have affected the way security professionals safeguard the enterprise with authentication protocols. In this IFT we will address best practices for providing multi-tiered user authentication to your employees and partners.

Keynote Address

Soon to be Announced!

Stay tuned; we will be announcing our Keynote speaker shortly.

Speakers

Marcus Ranum
Industry Experience:

Mr. Ranum has been consistently recognized as one of computer security’s innovators and creative thinkers. Since 1989 he has held every position that is possible within a high-tech business – from junior system administrator and software engineer to CEO, CTO, and marketing director. He is the principal author of several major Internet security products, including firewalls, VPNs, and intrusion detection systems.

Mr. Ranum is presently serving as the CSO of Tenable Network Security, Inc.

Expertise: Intrusion detection • Virtual private networks • Firewalls • Data leakage • Host IDS • Network architecture • Network IDS • Application security • Log management • Vulnerability management

Randy Sabett
Industry Experience:

Randy V. Sabett, J.D., CISSP, is Counsel at ZwillGen. He advises clients on information security, privacy, IT licensing, and intellectual property. Randy has over 20 years of infosec experience, including as an NSA crypto engineer and a CISSP. He works closely with companies in helping them develop strategies to protect and exploit their information and IP based on various evolving business models, including SaaS, mobile applications, cloud, and more traditional client/server architectures. He also drafts and negotiates a variety of technology transaction agreements. Randy served as a commissioner for the Commission on Cyber Security for the 44th Presidency and has been recognized as a leader in privacy and data security in the 2007 – 2011 editions of Chambers USA: America's Leading Lawyers for Business. He has been recognized as one of the Top 50 Under 45 by the American Lawyer’s “IP Law and Business” and is listed in the International Who’s Who of Business Lawyers.

Expertise: Compliance and regulations • Data classification • eDiscovery • PCI compliance • Risk management • IT licensing

Aaron Turner
Industry Experience:

Aaron Turner is currently the President of CEI, an information security consultancy focused on helping Fortune 100 companies manage the risks associated with technology dependencies in critical infrastructure systems. Prior to CEI, Aaron was the Co-Founder and CEO of RFinity, a mobile security technology startup formed as the result of research conducted at the US Department of Energy's Idaho National Laboratory (INL). While at INL, he collaborated with a team of information security experts to design the world's first large-scale testing effort to evaluate how critical infrastructure has become dependent on computing systems and the resulting vulnerabilities that those dependencies cause.

Dave Shackleford
Industry Experience:

Dave Shackleford is the Senior Vice President of Research and the Chief Technology Officer at IANS. Dave is a SANS analyst, instructor and course author, as well as a GIAC technical director. Dave previously was the founder and principal consultant with Voodoo Security, and has consulted with hundreds of organizations in the areas of security, regulatory compliance and network architecture and engineering. Dave is a former QSA with several years' experience performing PCI assessments. He is a VMware vExpert, and has extensive experience designing and configuring secure virtualized infrastructures. Dave has previously worked as CSO for Configuresoft, CTO for the Center for Internet Security, and has also worked as a security architect, analyst, and manager for several Fortune 500 companies.

Expertise: Network Intrusion Detection and Prevention • Network Firewalls and Access Controls • Security Architecture • Penetration Testing • Regulatory Compliance • Patch and Configuration Management • Virtualization Security • Incident Response

Phil Gardner
Industry Experience:

Having built IANS’ end user research offering, Phil now oversees all strategic, sales and operational decisions at IANS. Phil began his career in security with seven years with the U.S. Navy as a Strike Fighter Pilot & Ordnance Requirements Officer. After receiving a Masters in Business Administration from Harvard Business School, he joined Goldman, Sachs & Co. in Mergers & Acquisitions and later became an associate with McKinsey & Company in Boston, MA. In 1996, Phil became one of the founders of Provant, Inc., a publicly traded training company serving the Fortune 1000 and Federal Government. He left Provant in 2000 to launch the Institute for Applied Network Security. Phil is a graduate of Harvard Business School and Harvard College; and, he graduated at the top of his class in US Navy Flight School.

The Steering Committee

The Steering Committee is a consortium of the region’s top senior information security executives from Fortune 1000 companies, large government agencies, and academic institutions. These executives guide and shape the Forum Curriculum and Agenda, ensuring the event is relevant and exciting for participants.

The 2012 Midwest Steering Committee will be announced shortly.

If you would like to nominate someone for the 2012 Midwest Steering Committee, please contact Mike Gillett at mgillett@iansresearch.com

Steering Committee Chairman

Stay tuned:
IANS will be announcing our Keynote speaker shortly.

Steering Committee

Stay tuned:
IANS will be announcing the Midwest Information Security Forum Steering Committee shortly.

Standard Conference Price
IANS Information Security Forum - US $1350

Download a letter of approval template
This template will help you provide to your direct manager the pertinent information regarding the conference for their approval.

To download a copy of the Letter of Approval, click here.

All attendees earn 16 CPE credits through our partnership with (ISC)²

Payment Methods

Credit Card
IANS, through RegOnline, accepts all major credit cards.

Purchase Orders (PO)
IANS accepts payment through purchase orders. To use this payment method, please contact CJ Oliveri at coliveri@iansresearch.com or (617) 399-8100.

Cancellations
By completing registration, you are reserving your place at the Forum. Registered attendees will select specific Forum discussion sessions onsite. Please note that space is limited and assigned on a first come, first serve basis.

All registrations must be approved by IANS. Forum delegate positions are restricted to security practitioners. Cancellations must be submitted in writing and received by two weeks prior to a forum to qualify for a refund. Refunds will only be given for one-half of the original registration fee. Any cancellations submitted within fourteen days of the Forum will not be subject to refunds.

Terms and Conditions

This conference is produced by IANS, which reserves the right, in its sole discretion, to limit or deny access to the conference to any entity or individual. IANS’ receipt of a registration application and payment does not constitute acceptance until some form of acknowledgment or acceptance is sent; applications and payments that are not accepted will be returned within 30 days of receipt.

IANS is not affiliated with Apple Corporation, Microsoft Corporation, or Amazon.com Inc. All trademarks are the property of the respective trademark owners. IANS retains the right to substitute a prize or gift card of equal or greater retail value. Additional restrictions may apply.

IANS does not permit combination of discounts or promotional codes.

Forum Discounts and Promotions

IANS Enterprise Research Clients:

If your company is an IANS Enterprise Research client, you may have pre-paid Forum Seats available.
Do you have pre-paid Forum Seat waiting for you?
Contact CJ Oliveri at coliveri@iansresearch.com to find out if your company is an IANS Enterprise Research Client.

Bring a Team:

When you register three colleagues from the same company at the same time with payment, the fourth colleague may attend for free.

Present at IANS:

IANS Presenters receive a 50% discount for giving a 10 minute case-study style briefing outlining the approach and solution that they or their information security team developed when addressing a relevant issue or theme.

Association Discounts:

Discounts are also available for nonprofit, government, and educational institutions. All ISC² members receive a $350 discount to attend our Information Security Forum. Please contact CJ Oliveri at coliveri@iansresearch.com for more information.

IANS Discounts and Promotions Policy

Discounts, specials, and promotions cannot be combined.

Unless otherwise indicated, all promotional items are distributed on the second day of the Information Security Forum.

Location Information

Midwest Information Security Forum 2012
September 10-11, 2012
Forum Schedule

Chicago Marriott Downtown
540 North Michigan Avenue Chicago, IL 60611
Phone: (312) 836-0100
http://www.marriott.com/hotels/travel/chidt-chicago-marriott-downtown-magnificent-mile/

We asked a few delegates from our New England Information Security Forum what they thought about our events:

What is an IANS forum?
Did your company benefit from IANS?
Why do you keep coming back?
Do you recommend attending?
What makes IANS so unique?

Past IANS forums have included teams from

AT&T
Beth Israel Deaconess Medical Center
Bose Corporation
Dunkin' Brands
Genzyme
Iron Mountain
Massachusetts Institute of Technology
Nokia
Raytheon
State Street
United Parcel Service
Bain Capital
Big Y Foods, Inc.
Boston Scientific
Fidelity Investments
Harvard
Kraft Group
McGraw-Hill
Northwestern Mutual
RBS Citizens
The TJX Companies, Inc
WGBH
Bank of America
Blue Cross Blue Shield of MA
Commonwealth of Massachusetts
GE Capital
HSBC Bank
Legal Sea Foods
Monster Worldwide
Nuance Communications
Social Security Administration
Thermo Fisher Scientific
WilmerHale

Some of our Enterprise Clients include:

PREVIOUS
NEXT