Oct
17
San Francisco, CA

Pacific Information Security Forum 2012

Pacific Information Security Forum 2012

October 17-18
The Parc 55 Hotel
San Francisco, CA

Information Security Forums bring together experienced IT and information security practitioners for confidential information sharing on the industry's most important issues, technologies, and trends. The two-day event includes keynote addresses, technical and strategic roundtable discussions led by IANS' Faculty, networking receptions, and the opportunity to learn about new technologies.

Why Attend

  • Gain tangible, real world insights on best practices and lessons learned directly from your peers
  • Stay current with emerging technologies and early-stage deployments
  • Connect with the industry's leading minds
  • Network and connect with other influential senior IT managers and business leaders
  • Earn 16 Continuing Education Credits

Pacific Information Security Forum 2012

The IANS 2012 Information Security Forum Curriculum will be dictated by our Steering Committee, our Faculty of Industry Experts, and by the IANS 2012 Research Agenda.

This curriculum will represent the ongoing conversations among the Steering Committee and IANS Faculty of top areas of interest and concern for 2012 while still maintaining the highest relevancy for security professionals.

At IANS, we strive to serve the security professionals by identifying key topics and trends and provide insights and approaches to enhance attendees’ ability to anticipate and respond to these forces. Based on our peer-based research model we may make changes to our Forum curriculum in response to users’ interests to include breaking news and issues of the highest importance.

Track 1: Information Protection

Aaron Turner leads the Information Protection track. In an increasingly mobile world, information security teams are challenged with finding ways to secure pertinent data, while purging irrelevant information, and justifying to upper management how these tasks contribute to the overall success of the business. Sessions include:

  • InfoSec Failure - Why Organizations Are Losing More Data Every Day
  • Anatomy of a Persistent Attack and Response Road Map
  • Mobile Risks- How Mobile Technologies Are Facilitating Data Loss and Data Theft
  • The IANS Mobile App - Lessons Learned and Best Practices for Moving Forward
Track 2: Incident Response and Planning

Marcus Ranum will lead the Incident Response and Planning track, covering a wide variety of subjects including logging, audit, segmentation, APT, and malware response. Sessions include:

  • Getting Mileage from Audit and Logging
  • What About Metrics?
  • Malware Response
  • Segmentation and Domain Analysis

Track 3: Counter-Threat Operations

IANS Senior VP of Research and CTO, Dave Shackleford, leads the Counter-Threat Operations track, which will cover such topics as building and coordinating a security operations center (SOC), security tactics, social engineering, mitigation, and avoidance techniques. Sessions include:

  • So You Say You Need a SOC?
  • Better Living Through Offensive Security
  • Top Security Mistakes and How To Avoid Them
  • Socially Engineering Your Way To Better Security

Track 4: Risk and Compliance

Randy Sabett leads the Risk and Compliance track. Security and legal teams should be closely aligned in order to advance the protection and controls of corporate data. This track will highlight the areas where security and legal intersect. Sessions include:

  • Data Security Exposure: A GRC and Case Law Update
  • Tricks and Tips for Data Breach Response
  • Avoiding Liability from Mobile, Social Networks, and Things Beyond Your Control
  • Cloud Security Contract Primer
Track 1
Information Protection
Session 1
InfoSec Failure - Why Organizations Are Losing More Data Every Day
This opening session will provide a global overview of the current state of the threats that organizations face. From ideological-based attacks (such as Anonymous, etc.) to targeted persistent adversaries to global crimeware rings, understanding the spectrum will provide a foundation for the remainder of the track.
Session 2
Anatomy of a Persistent Attack and Response Road Map
In this session, participants will discuss a specific use case on a Global 2000 firm that nearly lost everything during an attack and then responded in a way that redefined their IT infrastructure for the next five years. We will follow the actual response timeline of how this organization discovered and responded to a sophisticated persistent attack.
Session 3
Mobile Risks - How Mobile Technologies Are Facilitating Data Loss and Data Theft
The reality of 4G hotspots, tethered smartphones, and lost or stolen tablets are all affecting the way different organizations are managing mobile technology risk. This session will provide an overview of how risk can be measured and whether or not there is any hope of getting ahead of the curve instead of responding reactively as we've done over and over and over again in the past.
Session 4
The IANS Mobile App - Lessons Learned and Best Practices for Moving Forward
The first version of the IANS mobile app left even a very security-focused firm vulnerable because the implementation strayed from industry best practices. Come hear how IANS leveraged leading security providers to improve the security of the app and learn some of the lessons that can be applied to mobile security in your own organization.
Track 2
Incident Response and Planning
Session 1
Getting Mileage from Audit and Logging
Your system and audit logs are about as exciting as watching paint dry--unless you need them. When you do need them, they can be the dividing line between unemployment and being a hero.
Session 2
What About Metrics?
Ninety-nine point four percent of security metrics are useless because they aren't tied to anything that makes sense for your organization or business. To date, most metrics are just a "gee, wow" number.
Session 3
Malware Response
If you haven't had to do a malware response - yet - you're probably simply unaware of what's going on with your systems.
Session 4
Segmentation and Domain Analysis
Break your network up into little pieces and you can manage it in little pieces, understand how those pieces talk to each other (and why!), and increase your chance of detecting APT-style attacks. Given that most people can't physically segment their networks anymore, what are some alternatives? How can you virtually segment your network to get a better picture of what's going on?
Track 3
Counter-Threat Operations
Session 1
So You Say You Need a SOC?
More and more organizations are looking at building or expanding a centralized security monitoring capability. There are lots of ways to do this, some good, some bad.
Session 2
Better Living Through Offensive Security
There's no better way to demonstrate that security is lacking than emulating what an attack would really look like. Penetration testing your systems and applications can help you better understand where your weaknesses really are.
Session 3
Top Security Mistakes and How To Avoid Them
As consultants, we've seen the full gamut of crazy behaviors in organizations, ranging from configuration errors to a complete lack of security common sense. In this session we'll discuss some of the top security pitfalls and how to avoid them.
Session 4
Socially Engineering Your Way To Better Security
Social engineering is one of the top avenues of exploitation attackers use to compromise your environment. Many organziations don't do much social engineering or leave it to outside consultants. While this is a viable approach in many cases, learning more about social engineering techniques can help you improve your security posture significantly.
Track 4
Risk and Compliance
Session 1
Data Security Exposure: A GRC and Case Law Update
For years, we’ve been hearing that we need to worry about data security liability. From the changing legislative and regulatory environment to contract and tort liability for insecure systems, legal issues just seem to be multiplying. Where are we today? Will new legislation pass this year? Do we need to worry about the next GLBA, Sarbox, TJX, or Heartland?
Session 2
Tricks and Tips for Data Breach Response
Teams involved with data breach response know the wearying process of performing triage on a compromised system. Whether imaging machines, participating in endless conference calls with card associations, or performing incident response on the network, the technical aspects of data breach response can be daunting. There is a whole other side, however – management's response.
Session 3
Avoiding Liability from Mobile, Social Networks, and Things Beyond Your Control
We all know the parade of horribles associated with the bring-your-own-device (BYOD) approach to mobile devices, the dangers of social networking, and other-things-beyond-your-control (OTBYC). While the technological aspects can be confounding, the liability aspects can--in some cases--be worse.
Session 4
Cloud Security Contract Primer
It goes without saying that security in the cloud keeps many a security manager up at night. Despite the seemingly endless promises from cloud vendors, contracts get signed without proper controls--and the security organization pays. During this session, we will tear apart the important aspects of a cloud services agreement and examine ways to deal with security and liability in a way that makes sense for your organization.

Keynote Address

Soon to be Announced!

Stay tuned; we will be announcing our Keynote speaker shortly.

Speakers

Marcus Ranum
Industry Experience:

Mr. Ranum has been consistently recognized as one of computer security’s innovators and creative thinkers. Since 1989 he has held every position that is possible within a high-tech business – from junior system administrator and software engineer to CEO, CTO, and marketing director. He is the principal author of several major Internet security products, including firewalls, VPNs, and intrusion detection systems.

Mr. Ranum is presently serving as the CSO of Tenable Network Security, Inc.

Expertise: Intrusion detection • Virtual private networks • Firewalls • Data leakage • Host IDS • Network architecture • Network IDS • Application security • Log management • Vulnerability management

Randy Sabett
Industry Experience:

Randy V. Sabett, J.D., CISSP, is Counsel at ZwillGen. He advises clients on information security, privacy, IT licensing, and intellectual property. Randy has over 20 years of infosec experience, including as an NSA crypto engineer and a CISSP. He works closely with companies in helping them develop strategies to protect and exploit their information and IP based on various evolving business models, including SaaS, mobile applications, cloud, and more traditional client/server architectures. He also drafts and negotiates a variety of technology transaction agreements. Randy served as a commissioner for the Commission on Cyber Security for the 44th Presidency and has been recognized as a leader in privacy and data security in the 2007 – 2011 editions of Chambers USA: America's Leading Lawyers for Business. He has been recognized as one of the Top 50 Under 45 by the American Lawyer’s “IP Law and Business” and is listed in the International Who’s Who of Business Lawyers.

Expertise: Compliance and regulations • Data classification • eDiscovery • PCI compliance • Risk management • IT licensing

Aaron Turner
Industry Experience:

Aaron Turner is currently the President of CEI, an information security consultancy focused on helping Fortune 100 companies manage the risks associated with technology dependencies in critical infrastructure systems. Prior to CEI, Aaron was the Co-Founder and CEO of RFinity, a mobile security technology startup formed as the result of research conducted at the US Department of Energy's Idaho National Laboratory (INL). While at INL, he collaborated with a team of information security experts to design the world's first large-scale testing effort to evaluate how critical infrastructure has become dependent on computing systems and the resulting vulnerabilities that those dependencies cause.

Dave Shackleford
Industry Experience:

Dave Shackleford is the Senior Vice President of Research and the Chief Technology Officer at IANS. Dave is a SANS analyst, instructor and course author, as well as a GIAC technical director. Dave previously was the founder and principal consultant with Voodoo Security, and has consulted with hundreds of organizations in the areas of security, regulatory compliance and network architecture and engineering. Dave is a former QSA with several years' experience performing PCI assessments. He is a VMware vExpert, and has extensive experience designing and configuring secure virtualized infrastructures. Dave has previously worked as CSO for Configuresoft, CTO for the Center for Internet Security, and has also worked as a security architect, analyst, and manager for several Fortune 500 companies.

Expertise: Network Intrusion Detection and Prevention • Network Firewalls and Access Controls • Security Architecture • Penetration Testing • Regulatory Compliance • Patch and Configuration Management • Virtualization Security • Incident Response

Alex Hutton
Industry Experience:

Alex Hutton is a big fan of trying to understand security and risk through metrics and models. Currently, Alex is the Director of Risk Management for a top 25 bank. A former principal for Research & Intelligence with the Verizon Business RISK Team, Alex also helped produce the Verizon Data Breach Investigation, the Verizon's PCI Compliance report, was responsible for the VERIS data collection and analysis efforts, and developed information risk models for their Cybertrust services. Alex is the veteran of several security start-ups.

Alex likes risk and security so much, he spends his spare time working on projects and writing about the subject. Some of that work includes contributions to the Cloud Security Alliance documents, the ISM3 security management standard, and work with the Open Group Security Forum.

Alex is a founding member of the Society of Information Risk Analysts, and blogs for their website and records a podcast for the membership. He also blogs at the New School of Information Security Blog. Some of his earlier thoughts on risk can be found at the Riskanalys.is blog.

Expertise: Governance, Risk, and Compliance • Security Management • Enterprise Risk Management • Security Data Warehousing

Diana Kelley
Industry Experience:

Diana Kelley is an internationally recognized security expert with 20 years of IT security experience. She founded SecurityCurve in April of 2003 to provide risk-focused advisory services to enterprises and deliver strategic, competitive knowledge to security software vendors.

Diana speaks frequently at major conferences: RSA, BlackHat, InfoSec World,NetWorld/InterOp, The Internet Security Conference, and ComDex.

She has authored numerous articles, columns, white papers and research documents and co-authored Cryptographic Libraries for Developers.

Expertise: Risk Management • Penetration Testing • Security Audit • Compliance • Systems and Network Architecture

Ed Moyle
Industry Experience:

Ed Moyle is a 15+ year veteran of information security as well as an industry-recognized thought leader, advisor, writer, and manager. Ed is currently Senior Security Strategist with Savvis, providing strategy, consulting, and solutions to clients worldwide and a founding partner of SecurityCurve.

Ed is co-author of "Cryptographic Libraries for Developers," and a frequent contributor to the Information Security industry as author, public speaker, and analyst.

Expertise: Cryptography • Secure Data Transfer • Secure Key Management • Authentication • Data Integrity

Mike Rothman
Industry Experience:

Mike Rothman is President and an Analyst of Information Security & Research Analysis firm Securosis. He started his career as a programmer and a networking consultant, joining META Group in 1993 and spearheading their initial foray into information security research. He left in 1998 to found SHYM Technology, focusing on the PKI software market, and then held senior roles at CipherTrust and TruSecure. He started Security Incite in 2006 to provide the "voice of reason" in what he considered an "over-hyped yet underwhelming" security industry. He took a brief detour as SVP, Strategy and Chief Marketing Officer at eIQNetworks in 1998 joining Securosis at the beginning of 2010 year with a "rejuvenated cynicism" about the state of security and what it takes to survive as a security professional.

In 2007, Rothman published "The Pragmatic CSO" to introduce technically-oriented security professionals to the nuances of what is required to be a senior security professional. He also has a "very expensive" degree "that he uses literally zero percent" (much to his parents joy) in Operations Research and Industrial Engineering from Cornell University.

Expertise: Network Security • SIEM • Log Management • Management of Security and Security Services

Phil Gardner
Industry Experience:

Having built IANS’ end user research offering, Phil now oversees all strategic, sales and operational decisions at IANS. Phil began his career in security with seven years with the U.S. Navy as a Strike Fighter Pilot & Ordnance Requirements Officer. After receiving a Masters in Business Administration from Harvard Business School, he joined Goldman, Sachs & Co. in Mergers & Acquisitions and later became an associate with McKinsey & Company in Boston, MA. In 1996, Phil became one of the founders of Provant, Inc., a publicly traded training company serving the Fortune 1000 and Federal Government. He left Provant in 2000 to launch the Institute for Applied Network Security. Phil is a graduate of Harvard Business School and Harvard College; and, he graduated at the top of his class in US Navy Flight School.

The Steering Committee

The Steering Committee is a consortium of the region’s top senior information security executives from Fortune 1000 companies, large government agencies, and academic institutions. These executives guide and shape the Forum Curriculum and Agenda, ensuring the event is relevant and exciting for participants.

The 2012 Pacific Steering Committee will be announced shortly.

If you would like to nominate someone for the 2012 Pacific Steering Committee, please contact Jarret Shaeffer at jshaeffer@iansresearch.com.

Steering Committee Chairman

Stay tuned:
IANS will be announcing our Steering Committee Chairmen shortly.

Steering Committee

Stay tuned:
IANS will be announcing the Pacific Information Security Forum Steering Committee shortly.

Standard Conference Price
IANS Information Security Forum - US $1350

Download a letter of approval template
This template will help you provide to your direct manager the pertinent information regarding the conference for their approval.

To download a copy of the Approval Letter, click here.

All attendees earn 16 CPE credits through our partnership with (ISC)²

Payment Methods

Credit Card
IANS, through RegOnline, accepts all major credit cards.

Purchase Orders (PO)
IANS accepts payment through purchase orders. To use this payment method, please contact CJ Oliveri at coliveri@iansresearch.com or (617) 399-8100.

Cancellations
By completing registration, you are reserving your place at the Forum. Registered attendees will select specific Forum discussion sessions onsite. Please note that space is limited and assigned on a first come, first serve basis.

All registrations must be approved by IANS. Forum delegate positions are restricted to security practitioners. Cancellations must be submitted in writing and received by two weeks prior to a forum to qualify for a refund. Refunds will only be given for one-half of the original registration fee. Any cancellations submitted within fourteen days of the Forum will not be subject to refunds.

Terms and Conditions

This conference is produced by IANS, which reserves the right, in its sole discretion, to limit or deny access to the conference to any entity or individual. IANS’ receipt of a registration application and payment does not constitute acceptance until some form of acknowledgment or acceptance is sent; applications and payments that are not accepted will be returned within 30 days of receipt.

IANS is not affiliated with Apple Corporation, Microsoft Corporation, or Amazon.com Inc. All trademarks are the property of the respective trademark owners. IANS retains the right to substitute a prize or gift card of equal or greater retail value. Additional restrictions may apply.

IANS does not permit combination of discounts or promotional codes.

Forum Discounts and Promotions

IANS Enterprise Research Clients:

If your company is an IANS Enterprise Research client, you may have pre-paid Forum Seats available.
Do you have pre-paid Forum Seat waiting for you?
Contact CJ Oliveri at coliveri@iansresearch.com to find out if your company is an IANS Enterprise Research Client.

Bring a Team:

When you register three colleagues from the same company at the same time with payment, the fourth colleague may attend for free.

Present at IANS:

IANS Presenters receive a 50% discount for giving a 10 minute case-study style briefing outlining the approach and solution that they or their information security team developed when addressing a relevant issue or theme.

Association Discounts:

Discounts are also available for nonprofit, government, and educational institutions. All ISC² members receive a $350 discount to attend our Information Security Forum. Please contact CJ Oliveri at coliveri@iansresearch.com for more information.

IANS Discounts and Promotions Policy

Discounts, specials, and promotions cannot be combined.

Unless otherwise indicated, all promotional items are distributed on the second day of the Information Security Forum.

Location Information

Pacific Information Security Forum 2012
October 17-18, 2012
Forum Schedule

The Parc 55 Hotel
55 Cyril Magnin Street San Francisco, CA 94102
Phone: (415) 392-8000
http://www.parc55hotel.com

We asked a few delegates from our New England Information Security Forum what they thought about our events:

What is an IANS forum?
Did your company benefit from IANS?
Why do you keep coming back?
Do you recommend attending?
What makes IANS so unique?

Past IANS forums have included teams from

AT&T
Beth Israel Deaconess Medical Center
Bose Corporation
Dunkin' Brands
Genzyme
Iron Mountain
Massachusetts Institute of Technology
Nokia
Raytheon
State Street
United Parcel Service
Bain Capital
Big Y Foods, Inc.
Boston Scientific
Fidelity Investments
Harvard
Kraft Group
McGraw-Hill
Northwestern Mutual
RBS Citizens
The TJX Companies, Inc
WGBH
Bank of America
Blue Cross Blue Shield of MA
Commonwealth of Massachusetts
GE Capital
HSBC Bank
Legal Sea Foods
Monster Worldwide
Nuance Communications
Social Security Administration
Thermo Fisher Scientific
WilmerHale