September 10, 2009 |
| 7:30 a.m.-8:30 a.m. |
Registration And Continental Breakfast
|
| 7:30 a.m.-8:20 a.m. |
Breakfast Preso W/The Center For Internet Security - Establishing Practical, Unambiguous & Logically Defensible Security Metrics
Elizabeth A. Nichols, Ph.D., The Center for Internet Security, Speaker
Steven Piliero, The Center for Internet Security, Speaker
This presentation will describe an initial set of information security metrics, developed via expert consensus. These metrics provide standard security definitions that are necessary for intra- and inter-enterprise benchmarking of security performance. An emphasis is placed on outcome metrics as true measures of information security success. Key takeaways include:
Overview and need for outcome-based, consensus security metrics
Practical security metric examples
Security metric definitions and resources
|
| 8:30 a.m.-8:50 a.m. |
Welcome And Setting the Stage
Robert Whiteley, Forrester, Speaker
|
| 8:50 a.m.-9:35 a.m. |
Navigating The New Security & Risk Reality
Khalid Kark, Forrester, Speaker
Shift happens. And you need to deal with the consequences. We’ve been discussing “change” for years: dramatic changes to workplace dynamics, new sourcing models, and evolving application portfolios. But change is no longer hypothetical — it’s real. This session will move beyond discussions of the economy and help you understand how to navigate the new security reality. Session attendees will learn:
- The major business trends you need to prepare for when the inevitable upturn in the global economy comes
- How to master three major shifts: 1) a shift in business expectations; 2) a shift in ownership; and 3) a shift in security architecture
- Why you need to move beyond asking questions of your CIO and business peers to providing guidance and evolving your SRM practice
|
| 9:30 a.m.-5:00 p.m. |
One-On-One Meetings With Forrester Analysts
Each attendee is able to schedule up to two 20-minute one-on-one sessions with the Forrester analysts of their choice, depending on availability. These meetings are consistently rated as one of the most popular features of Forrester Events.
|
| 9:35 a.m.-10:20 a.m. |
Successful Approaches To Addressing Consumerization: A Panel Discussion
Natalie Lambert, Forrester, Moderator
Paul Martine, Citrix, Speaker
Eric Sachs, Google, Speaker
John N. Stewart, Cisco Systems, Speaker
Like it or not, consumer-grade hardware and software has penetrated your company. Originally it started as executives demanding iPhones, but now we see Google Docs, Macs, Skype, and Twitter being extensively used by enterprise workers. This analyst-moderated session with three security executives will discuss the policies, controls, and practices to minimize the threat of consumerization. Attendees will learn:
- What the threats versus benefits of supporting consumer technology are
- How to evolve your security and risk practices to combat the risks of consumerization
- What employee acceptable use policies today's security execs are implementing
|
| 10:20 a.m.-11:05 a.m. |
Morning Networking Break In The Technology Showcase
|
| 11:05 a.m.-11:45 a.m. |
The New Security Blanket: Four Key Strategies For Protecting Your Information-Driven Organization
Art Gilliland, Symantec , Speaker
Change is constant. As a Security & Risk professional, how do you protect your information-driven organization and still remain competitive in your business? In 2008 alone, 90% of breaches involved organized crime targeting corporate information. IP theft cost companies $600 million globally, and 285 million records were stolen. How do you cope with this new security reality? This session will outline four key strategies for protecting your company and provide practical use case studies.
|
| 11:45 a.m.-12:30 p.m. |
A Dose Of Reality: Why You Should Take A Cautious Approach To A Shift In IT Architectures
Marcus J. Ranum, Tenable Network Security, Speaker
There's always some new technical solution on the horizon that promises a quick ROI and tremendous business value. These days, it's cloud computing. But with new platforms come new attack paradigms. Come hear Marcus Ranum discuss his view on the security landscape and how to think about the new challenges that cloud poses. This session will cover:
How we're still solving problems we caused 15 years ago
New cloud threats like "denial of economic sustainability"
What you need to do and how to push back to limit the risks of new IT models
|
| 12:30 p.m.-2:00 p.m. |
Lunch And Dessert In The Technology Showcase
|
| 2:00 p.m.-2:45 p.m. |
Track Session
Track A: Shift In Expectations: Modernizing Your SRM Program
Elevating Security With Risk Management Techniques
Chris McClean, Senior Analyst, Forrester
Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
Protecting Information When You Don’t Own The Assets
Andrew Jaquith, Analyst, Forrester
Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
PCI Unleashed: Embracing PCI As A Next-Generation Security Architecture
John Kindervag, Principal Analyst, Forrester
|
| 2:45 p.m.-3:00 p.m. |
Intermission
|
| 3:00 p.m.-3:30 p.m. |
Guest Executive Forum With Trusted Computing Group - Enterprise Metadata Services For NAC And Beyond
Steve Venema, Ph.D., The Boeing Company, Speaker
Metadata, or data that describes other data, is an important aspect of network access control (NAC) and, more generally, information security. TCG’s Trusted Network Connect (TNC) workgroup has developed and standardized an “Interface for Metadata Access Points” (IF-MAP) that allows a heterogeneous set of NAC components from multiple vendors to coordinate their respective sensing, decisions, and actions by sharing standardized metadata through the publish/subscribe/search capabilities of IF-MAP. Attendees will learn:
- How Boeing is deploying an IF-MAP-compliant metadata service
- How IF-MAP can enable for other metadata services such as network location services
- More about the deployment of IF-MAP use cases in larger enterprises
|
| 3:00 p.m.-3:30 p.m. |
Guest Executive Forum With VeriSign - Deconstructing The July 4th DDoS Attacks
Ken Silva, VeriSign, Speaker
Recently, several US and South Korean government and commercial Web sites were the target of large-scale DDoS attacks. The attacks caused disruption of a number of Web sites and generated a great deal of interest within the information security community. In this presentation, Ken Silva, CTO of VeriSign, will provide an analysis of these attacks, explain their significance for the IT and business communities, and explain how they could have been easily prevented. From this presentation, you'll understand:
- How traffic to these Web sites was disrupted.
- What is known about the motives behind these attacks.
- The future direction of cyberattacks.
|
| 3:30 p.m.-4:15 p.m. |
Afternoon Networking Break In The Technology Showcase
|
| 4:15 p.m.-5:00 p.m. |
Track Session
Track A: Shift In Expectations: Modernizing Your SRM Program
How Your CIO’s Plans Will Change Security
Marc Cecere, Vice President, Principal Analyst, Forrester
Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
Executive Exchange: Managing Identity For Noncorporate Users And Devices
Andras Cser, Principal Analyst, Forrester
Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
Building An Identity Strategy To Harness Consumerization And Cloud Computing
Bill Nagel, Senior Editor, Forrester
|
| 5:00 p.m.-6:30 p.m. |
Networking Reception In The Technology Showcase
|
September 11, 2009 |
| 7:30 a.m.-8:30 a.m. |
Registration And Continental Breakfast
|
| 7:30 a.m.-8:20 a.m. |
Breakfast Presentation With Blue Coat Systems - How Do Legitimate Web Sites Pose A Security Risk?
Bob Hansmann, Blue Coat Systems, Speaker
Everyone knows that surfing the Web is dangerous and that even legitimate sites can be compromised. Security teams need to understand the facts behind this fear statement.
- How many ways can someone become infected visiting legitimate Web sites? Security professionals need to know how this goes beyond SQL injection and malicious iFrames.
- Where do today's security solutions fit in a best practices defense? Learn how to coordinate what you have for a stronger defense and to identify any remaining holes.
- What new strategies and technologies are coming to strengthen protection against these fast-moving, Web-based attacks?
|
| 8:30 a.m.-8:45 a.m. |
Day Two Opening Remarks
Robert Whiteley, Forrester, Speaker
|
| 8:45 a.m.-9:30 a.m. |
How Economics, Cloud Services, And Outsourcing Challenge Your Risk Exposure
Paul Roehrig, Ph.D., Forrester, Speaker
External pressures such as a melting economy are now combined with internal pressures such as the requirement for clear ROI and new technologies like cloud or utility services to create a virtual tornado of new pressures on IT security. As security professionals, we're usually guilty of claiming something big is happening, but this time, it's for real. This session will discuss:
- How the core enterprise requirements for IT security are changing — and not just a little
- How cloud computing services are accelerating the process of "natural selection" in the security space
- The growing reliance on external service providers to deliver security services
- How security professionals have to extend beyond the “traffic cop” role, improve how they leverage external service providers, and help drive safe implementation of more utility services into the enterprise
|
| 9:30 a.m.-10:15 a.m. |
Architecting Secure Collaboration Across The Internet
Steve Whitlock, The Boeing Company, Speaker
Many organizations look to the Internet to collaborate with employees, partners, and customers. But as an industry, we need an architecture that reduces the attack surface and provides secure communications, information protection, and a secure environment in which to open information. Come hear Steve Whitlock share his thoughts and advice on how to build out this next-generation architecture. In this session, attendees will:
- Understand when and why you should use application-specific versus general purpose tunnels to communicate across the Internet>/li>
- Discuss the merger of fine-grained access control with encryption and how it can be applied directly to information flows
- Learn why you should break up the traditional OS into small, provably correct modules built on VMs that coordinate to act like an OS
|
| 9:30 a.m.-3:30 p.m. |
One-On-One Meetings With Forrester Analysts
Each attendee is able to schedule up to two 20-minute one-on-one sessions with the Forrester analysts of their choice, depending on availability. These meetings are consistently rated as one of the most popular features of Forrester Events.
|
| 10:15 a.m.-10:45 a.m. |
Morning Networking Break In The Technology Showcase
|
| 10:45 a.m.-11:30 a.m. |
Bridging The Skills Gap: Preparing For The Next Generation Of Security Talent
W. Hord Tipton, (ISC)2, Speaker
Many companies are adept at understanding shifts in security technology and processes. But what about people? CISOs constantly claim that new security skills are needed, but few feel equipped to tackle the problem. This session will overview shifts in the security talent landscape and prepare you for hiring the right talent when you need it. Attendees will:
- Understand how security and risk management talent is evolving
- Reexamine the current skills and certifications that are needed for your business
- Discuss how to prepare for hiring, training, and ramping new security talent
|
| 11:30 a.m.-12:30 p.m. |
Practical Advice On Navigating The New Security Reality
Daniel E. Geer, Sc.D., Verdasys, Speaker
Andrew Jaquith, Forrester, Speaker
Herbert H. Thompson, People Security, Speaker
Shifts in stakeholder expectations, ownership of assets, and security architecture will radically change CISO priorities. In this session, a lively panel of practitioners will debate what it all means for CISOs: the new rules of the road, the ultimate destination, and practical directions on how to get there. Attendees will:
Understand the grand challenges in information security and their potential solutions
Learn about the mistakes CISOs are making today and what to do about them
Discuss key competencies the CISO organization must master before the upturn
|
| 12:30 p.m.-1:45 p.m. |
Lunch And Dessert In The Technology Showcase
|
| 1:45 p.m.-2:30 p.m. |
Track Session
Track A: Shift In Expectations: Modernizing Your SRM Program
How To Create A Lean Security Organization
Khalid Kark, Vice President, Research Director, Forrester
Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
Reexamining The Impact Of Collaboration And Web 2.0
Rob Koplowitz, Vice President, Principal Analyst, Forrester
Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
The New Identity And Access Management Architecture
Andras Cser, Principal Analyst, Forrester
|
| 2:30 p.m.-2:40 p.m. |
Intermission
|
| 2:40 p.m.-3:25 p.m. |
Track Session
Track A: Shift In Expectations: Modernizing Your SRM Program
Getting The Most From Your Security Vendors
Jonathan Penn, Analyst, Forrester
Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
The Security Of B2B: Enabling An Unbounded Enterprise
Robert Whiteley, VP, BT Portfolio & Strategy, Forrester
Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
Making A Bring-Your-Own-PC Program A Reality
Natalie Lambert, Analyst, Forrester
|
|