Agenda By Day


September 10, 2009
7:30 a.m.-8:30 a.m. Registration And Continental Breakfast
7:30 a.m.-8:20 a.m. Breakfast Preso W/The Center For Internet Security - Establishing Practical, Unambiguous & Logically Defensible Security Metrics
Elizabeth A. Nichols, Ph.D., The Center for Internet Security, Speaker
Steven Piliero, The Center for Internet Security, Speaker

This presentation will describe an initial set of information security metrics, developed via expert consensus. These metrics provide standard security definitions that are necessary for intra- and inter-enterprise benchmarking of security performance. An emphasis is placed on outcome metrics as true measures of information security success. Key takeaways include:

  • Overview and need for outcome-based, consensus security metrics
  • Practical security metric examples
  • Security metric definitions and resources
  • 8:30 a.m.-8:50 a.m. Welcome And Setting the Stage
    Robert Whiteley, Forrester, Speaker
    8:50 a.m.-9:35 a.m. Navigating The New Security & Risk Reality
    Khalid Kark, Forrester, Speaker

    Shift happens. And you need to deal with the consequences. We’ve been discussing “change” for years: dramatic changes to workplace dynamics, new sourcing models, and evolving application portfolios. But change is no longer hypothetical — it’s real. This session will move beyond discussions of the economy and help you understand how to navigate the new security reality. Session attendees will learn:

    • The major business trends you need to prepare for when the inevitable upturn in the global economy comes
    • How to master three major shifts: 1) a shift in business expectations; 2) a shift in ownership; and 3) a shift in security architecture
    • Why you need to move beyond asking questions of your CIO and business peers to providing guidance and evolving your SRM practice
    9:30 a.m.-5:00 p.m. One-On-One Meetings With Forrester Analysts

    Each attendee is able to schedule up to two 20-minute one-on-one sessions with the Forrester analysts of their choice, depending on availability. These meetings are consistently rated as one of the most popular features of Forrester Events.

    9:35 a.m.-10:20 a.m. Successful Approaches To Addressing Consumerization: A Panel Discussion
    Natalie Lambert, Forrester, Moderator
    Paul Martine, Citrix, Speaker
    Eric Sachs, Google, Speaker
    John N. Stewart, Cisco Systems, Speaker

    Like it or not, consumer-grade hardware and software has penetrated your company. Originally it started as executives demanding iPhones, but now we see Google Docs, Macs, Skype, and Twitter being extensively used by enterprise workers. This analyst-moderated session with three security executives will discuss the policies, controls, and practices to minimize the threat of consumerization. Attendees will learn:

    • What the threats versus benefits of supporting consumer technology are
    • How to evolve your security and risk practices to combat the risks of consumerization
    • What employee acceptable use policies today's security execs are implementing
    10:20 a.m.-11:05 a.m. Morning Networking Break In The Technology Showcase
    11:05 a.m.-11:45 a.m. The New Security Blanket: Four Key Strategies For Protecting Your Information-Driven Organization
    Art Gilliland, Symantec , Speaker

    Change is constant. As a Security & Risk professional, how do you protect your information-driven organization and still remain competitive in your business? In 2008 alone, 90% of breaches involved organized crime targeting corporate information. IP theft cost companies $600 million globally, and 285 million records were stolen. How do you cope with this new security reality? This session will outline four key strategies for protecting your company and provide practical use case studies.

    11:45 a.m.-12:30 p.m. A Dose Of Reality: Why You Should Take A Cautious Approach To A Shift In IT Architectures
    Marcus J. Ranum, Tenable Network Security, Speaker
    There's always some new technical solution on the horizon that promises a quick ROI and tremendous business value. These days, it's cloud computing. But with new platforms come new attack paradigms. Come hear Marcus Ranum discuss his view on the security landscape and how to think about the new challenges that cloud poses. This session will cover:

  • How we're still solving problems we caused 15 years ago
  • New cloud threats like "denial of economic sustainability"
  • What you need to do and how to push back to limit the risks of new IT models
  • 12:30 p.m.-2:00 p.m. Lunch And Dessert In The Technology Showcase
    2:00 p.m.-2:45 p.m. Track Session

    Track A: Shift In Expectations: Modernizing Your SRM Program
    Elevating Security With Risk Management Techniques
    Chris McClean, Senior Analyst, Forrester

    Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
    Protecting Information When You Don’t Own The Assets
    Andrew Jaquith, Analyst, Forrester

    Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
    PCI Unleashed: Embracing PCI As A Next-Generation Security Architecture
    John Kindervag, Principal Analyst, Forrester
    2:45 p.m.-3:00 p.m. Intermission
    3:00 p.m.-3:30 p.m. Guest Executive Forum With Trusted Computing Group - Enterprise Metadata Services For NAC And Beyond
    Steve Venema, Ph.D., The Boeing Company, Speaker

    Metadata, or data that describes other data, is an important aspect of network access control (NAC) and, more generally, information security. TCG’s Trusted Network Connect (TNC) workgroup has developed and standardized an “Interface for Metadata Access Points” (IF-MAP) that allows a heterogeneous set of NAC components from multiple vendors to coordinate their respective sensing, decisions, and actions by sharing standardized metadata through the publish/subscribe/search capabilities of IF-MAP. Attendees will learn:

    • How Boeing is deploying an IF-MAP-compliant metadata service
    • How IF-MAP can enable for other metadata services such as network location services
    • More about the deployment of IF-MAP use cases in larger enterprises
    3:00 p.m.-3:30 p.m. Guest Executive Forum With VeriSign - Deconstructing The July 4th DDoS Attacks
    Ken Silva, VeriSign, Speaker

    Recently, several US and South Korean government and commercial Web sites were the target of large-scale DDoS attacks. The attacks caused disruption of a number of Web sites and generated a great deal of interest within the information security community. In this presentation, Ken Silva, CTO of VeriSign, will provide an analysis of these attacks, explain their significance for the IT and business communities, and explain how they could have been easily prevented. From this presentation, you'll understand:

    • How traffic to these Web sites was disrupted.
    • What is known about the motives behind these attacks.
    • The future direction of cyberattacks.
    3:30 p.m.-4:15 p.m. Afternoon Networking Break In The Technology Showcase
    4:15 p.m.-5:00 p.m. Track Session

    Track A: Shift In Expectations: Modernizing Your SRM Program
    How Your CIO’s Plans Will Change Security
    Marc Cecere, Vice President, Principal Analyst, Forrester

    Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
    Executive Exchange: Managing Identity For Noncorporate Users And Devices
    Andras Cser, Principal Analyst, Forrester

    Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
    Building An Identity Strategy To Harness Consumerization And Cloud Computing
    Bill Nagel, Senior Editor, Forrester
    5:00 p.m.-6:30 p.m. Networking Reception In The Technology Showcase

    September 11, 2009
    7:30 a.m.-8:30 a.m. Registration And Continental Breakfast
    7:30 a.m.-8:20 a.m. Breakfast Presentation With Blue Coat Systems - How Do Legitimate Web Sites Pose A Security Risk?
    Bob Hansmann, Blue Coat Systems, Speaker

    Everyone knows that surfing the Web is dangerous and that even legitimate sites can be compromised. Security teams need to understand the facts behind this fear statement.

    • How many ways can someone become infected visiting legitimate Web sites? Security professionals need to know how this goes beyond SQL injection and malicious iFrames.
    • Where do today's security solutions fit in a best practices defense? Learn how to coordinate what you have for a stronger defense and to identify any remaining holes.
    • What new strategies and technologies are coming to strengthen protection against these fast-moving, Web-based attacks?
    8:30 a.m.-8:45 a.m. Day Two Opening Remarks
    Robert Whiteley, Forrester, Speaker
    8:45 a.m.-9:30 a.m. How Economics, Cloud Services, And Outsourcing Challenge Your Risk Exposure
    Paul Roehrig, Ph.D., Forrester, Speaker

    External pressures such as a melting economy are now combined with internal pressures such as the requirement for clear ROI and new technologies like cloud or utility services to create a virtual tornado of new pressures on IT security. As security professionals, we're usually guilty of claiming something big is happening, but this time, it's for real. This session will discuss:

    • How the core enterprise requirements for IT security are changing — and not just a little
    • How cloud computing services are accelerating the process of "natural selection" in the security space
    • The growing reliance on external service providers to deliver security services
    • How security professionals have to extend beyond the “traffic cop” role, improve how they leverage external service providers, and help drive safe implementation of more utility services into the enterprise
    9:30 a.m.-10:15 a.m. Architecting Secure Collaboration Across The Internet
    Steve Whitlock, The Boeing Company, Speaker

    Many organizations look to the Internet to collaborate with employees, partners, and customers. But as an industry, we need an architecture that reduces the attack surface and provides secure communications, information protection, and a secure environment in which to open information. Come hear Steve Whitlock share his thoughts and advice on how to build out this next-generation architecture. In this session, attendees will:

    • Understand when and why you should use application-specific versus general purpose tunnels to communicate across the Internet>/li>
    • Discuss the merger of fine-grained access control with encryption and how it can be applied directly to information flows
    • Learn why you should break up the traditional OS into small, provably correct modules built on VMs that coordinate to act like an OS
    9:30 a.m.-3:30 p.m. One-On-One Meetings With Forrester Analysts

    Each attendee is able to schedule up to two 20-minute one-on-one sessions with the Forrester analysts of their choice, depending on availability. These meetings are consistently rated as one of the most popular features of Forrester Events.

    10:15 a.m.-10:45 a.m. Morning Networking Break In The Technology Showcase
    10:45 a.m.-11:30 a.m. Bridging The Skills Gap: Preparing For The Next Generation Of Security Talent
    W. Hord Tipton, (ISC)2, Speaker

    Many companies are adept at understanding shifts in security technology and processes. But what about people? CISOs constantly claim that new security skills are needed, but few feel equipped to tackle the problem. This session will overview shifts in the security talent landscape and prepare you for hiring the right talent when you need it. Attendees will:

    • Understand how security and risk management talent is evolving
    • Reexamine the current skills and certifications that are needed for your business
    • Discuss how to prepare for hiring, training, and ramping new security talent
    11:30 a.m.-12:30 p.m. Practical Advice On Navigating The New Security Reality
    Daniel E. Geer, Sc.D., Verdasys, Speaker
    Andrew Jaquith, Forrester, Speaker
    Herbert H. Thompson, People Security, Speaker

    Shifts in stakeholder expectations, ownership of assets, and security architecture will radically change CISO priorities. In this session, a lively panel of practitioners will debate what it all means for CISOs: the new rules of the road, the ultimate destination, and practical directions on how to get there. Attendees will:

  • Understand the grand challenges in information security and their potential solutions
  • Learn about the mistakes CISOs are making today and what to do about them
  • Discuss key competencies the CISO organization must master before the upturn
  • 12:30 p.m.-1:45 p.m. Lunch And Dessert In The Technology Showcase
    1:45 p.m.-2:30 p.m. Track Session

    Track A: Shift In Expectations: Modernizing Your SRM Program
    How To Create A Lean Security Organization
    Khalid Kark, Vice President, Research Director, Forrester

    Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
    Reexamining The Impact Of Collaboration And Web 2.0
    Rob Koplowitz, Vice President, Principal Analyst, Forrester

    Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
    The New Identity And Access Management Architecture
    Andras Cser, Principal Analyst, Forrester
    2:30 p.m.-2:40 p.m. Intermission
    2:40 p.m.-3:25 p.m. Track Session

    Track A: Shift In Expectations: Modernizing Your SRM Program
    Getting The Most From Your Security Vendors
    Jonathan Penn, Analyst, Forrester

    Track B: Shift In Ownership: Protecting Data Outside Your Four Walls
    The Security Of B2B: Enabling An Unbounded Enterprise
    Robert Whiteley, VP, BT Portfolio & Strategy, Forrester

    Track C: Shift In Security Architecture: Building A Flexible, Compliant Foundation
    Making A Bring-Your-Own-PC Program A Reality
    Natalie Lambert, Analyst, Forrester