Archive for the 'Meeting' Category

Next Meeting: August 23rd – Roundtable – Verizon DBIR

Date: Monday, August 23rd, 2010
Time: 11:30am to 1:00pm
Topic: Verizon DBIR
Format: Roundtable
Speaker: N/A

Roundtable Discussion – The Verizon 2010 DBIR:

We will be discussing the 2010 Data Breach study conducted by the Verizon Business RISK team in conjunction with the US Secret Service.  This is the first year for the USSS data so there are some interesting changes from previous years.  You can download the report from the following link.

http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Next Meeting: June 28th – Roundtable: Iowa’s Breach Notification Law (SF 2308)

Date: Monday, June 28th, 2010
Time: 11:30am to 1:00pm
Topic: Iowa’s Breach Notification Law (SF 2308)
Format: Roundtable
Speaker: N/A

Iowa’s Breach Notification Law (SF 2308)

We will be reviewing the provisions of Iowa’s breach notification law (SF 2308) and the impact to our organizations. This will be a round table discussion.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Note: Location has changed for the June Meeting.

Integrity Technology Systems, Inc.
2525 N. Ankeny Boulevard, Suite 111, Ankeny, IA 50023
Cell: 515.333.2260  |  Phone: 515.965.3756  |  www.ensureintegrity.com | dave.nelson@ensureintegrity.com

Please RSVP by calling or emailing Dave Nelson.

Map powered by MapPress

Next Meeting: May 24th – Protecting Your Applications from Backdoors

Date: Monday, May 24th, 2010
Time: 11:30am to 1:00pm
Topic: Protecting Your Applications from Backdoors
Format: Speaker
Speaker: Clint Pollock

Protecting Your Applications from Backdoors:
How to Secure Your Business Critical Applications from Time Bombs, Backdoors & Data

With the increasing practice of outsourcing and using 3rd party libraries, it is nearly impossible for an enterprise to identify the pedigree and security of the software running its business critical applications. As a result backdoors and malicious code are increasingly becoming the prevalent attack vector used by hackers.

Whether you manage internal development activities, work with third party developers or are developing a COTS application for enterprise, your mandate is clear- safeguard your code and make applications security a priority for internal and external development teams.

In this session we will cover;

  • Prevalence of backdoors and malicious code in third party attacks
  • Definitions and classifications of backdoors and their impact on your applications
  • Methods to identify, track and remediate these vulnerabilities

Speaker Bio

Clint Pollock is a Senior Solutions Architect at Veracode. Since 1997, he has also created security solutions for large-scale enterprise environments on behalf of CREDANT Technologies and Netegrity. In his current role, Clint helps globally distributed organizations evaluate, track, and mitigate their application security risk.  Clint’s greatest strengths are his enthusiasm, experience and determination to help customers succeed in maintaining secure, compliant systems, and avoid the consequences and bad headlines that come with application security breaches.  Clint resides in Chicago, IL.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Next Meeting: March 22nd – Roundtable Discussion: Security Monitoring

Date: Monday, March 22nd, 2010
Time: 11:30am to 1:00pm
Topic: Roundtable Discussion: Security Monitoring
Format: Discussion
Speaker: N/A

This month’s meeting will be a round table discussion about security monitoring. Come join the conversation.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Next Meeting: February 22nd – Oracle Security Risks

Date: Monday, February 22nd, 2010
Time: 11:30am to 1:00pm
Topic: Oracle Security Risks
Format: Speaker
Speaker: Stephen Kost

Stephen Kost is the Chief Technology Officer for Integrigy Corporation.  He has been writing about and presenting on Oracle security and auditing for the past 11 years.  He has worked with Oracle products since 1994 in many roles including database administrator, technical architect, IT security auditor, and applications administrator.

Stephen says “For most IT security professionals, the Oracle Database is a security challenge due to the complexity of the database and lack of database experience, especially as these databases often contain an organizations most critical data.  This presentation will focus on a few of the highest risk and most difficult to solve security risks in an Oracle Database environment including security vulnerabilities, password weaknesses, and generic privileged access.  To highlight the unrealized risk of security vulnerabilities in the database, a number of actual patched and un-patched security issues will be demonstrated.  In order to mitigate these risks, resources and best practices for securing an organization’s database will be discussed.”

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Next Meeting: January 25th – Inspecting the OSI Layers

Date: Monday, January 25th, 2010
Time: 11:30am to 1:00pm
Topic: Inspecting the OSI Layers
Format: Speaker
Speaker: Jim A. Libersky

Jim will be walking us through all 7 of the OSI layers and how they work together. Understanding how the OSI stack works together is more important today than ever.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Next Meeting: November 23rd, 2009 – Privacy Breach or Not A Privacy Breach?

Date: Monday,November 23rd, 2009
Time: 11:30am to 1:00pm
Topic: Information Security Incident: Privacy Breach or Not A Privacy Breach?
Format: Speaker
Speaker: Rebecca Herold

There are many types of information security incidents that occur in organizations on a daily basis.  However, information security incidents are not always a privacy breach.  There are currently 48 US state and territory breach notice laws, and they have been joined by the HITECH Act breach response requirements.  Not to mention the FISMA breach response requirements for federal agencies. So, what is a “breach” under these laws?  The general question of “what is a privacy breach” is one that too few organizations have really answered, documented and prepared response plans to cover.  Rebecca will provide different types of incidents and talk with session attendees about whether or not they would be a privacy breach under the HITECH Act in particular, and the other breach response laws in general.  She will also discuss whether notice would be necessary.  The types of incidents discussed will be some that are often not considered when creating incident and breach response plans, but need to be because they occur fairly often.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Next Meeting: October 26th, 2009 – Hands-on Hacking

Date: Monday, October 26th, 2009
Time: 9:00 am to 1:00pm
Topic: Hands-On Hacking at ISU ISEAGE Lab
Format: Hands on Lab

Location: ISU ISEAGE Lab

Join the Des Moines chapter for a day of learning and experimentation with hacking tools at the ISU Internet Scale Event and Attack Generation Environment (ISEAGE) Lab. The ISEAGE lab will be configured with a simulated environment which models the real internet. Attendees will be given a computer with attack tools for their   experimentation and may work in teams or individually.

REGISTRATION DUE BY 10/19/2009

Cost to members is free, non-members pay $25.00, but $20 can be put towards an ISSA membership.

Location information and a few more details can be seen in this flyer: Des Moines ISSA Hacking Event

If you have questions, please use the form below.

Contact Dave Nelson
  1. (required)
  2. (valid email required)
 

cforms contact form by delicious:days

Next Meeting – September 28th, 2009 – Digital Forensics

Date: Monday, September 28th, 2009
Time: 11:30am to 1:00pm
Topic: Memory Analysis for Incident Responders and Forensic Analysts
Format: Webcast
Speaker: Rob Lee

Rob Lee is a Director for MANDIANT (http://www.mandiant.com/), a leading provider of information security consulting services and software to Fortune 500 organizations and the U.S. Government. Rob is also the Curriculum Lead for Digital Forensic Training at the SANS Institute (http://forensics.sans.org/). Rob has more than 13 years experience in computer forensics, vulnerability and exploit discovery, intrusion detection/prevention, and incident response. Rob graduated from the U.S. Air Force Academy and served in the U.S. Air Force as a founding member of the 609th Information Warfare Squadron, the first U.S. military operational unit focused on Information Operations. Later, he was a member of the Air Force Office of Special Investigations where he conducted computer crime investigations, incident response, and computer forensics. Prior to joining MANDIANT, he directly worked with a variety of government agencies in the law enforcement, Dept. of Defense, and intelligence communities where he was the technical lead for a vulnerability discovery and exploit development team, lead for a cyber forensics branch, and led a computer forensic and security software development team. Rob also coauthored the bestselling book, Know Your Enemy, 2nd Edition. Rob earned his MBA from Georgetown University in Washington D.C. Finally, Rob was awarded the “Digital Forensic Examiner of the Year” from the Forensic 4Cast 2009 Awards.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Next Meeting – August 24th, 2009 – How to Succeed or Fail in Cryptography

New location. See Below

Date: Monday August 24th, 2009
Time: 11:30am to 1:00pm
Topic: How to Succeed or Fail in Cryptography

Cryptography is hard to do, with many failed examples. Learn from the failures and succeed against the odds. This talk will explain, with examples, common cryptographic pitfalls, solutions, and mitigation strategies. Best practices in policies, procedures, and technology will be discussed. Questions and feedback from the audience are encouraged. If time permits, audience participation will be solicited for experiences in both good and bad cryptography.
Key points:
* Good cryptography is now easy, but bad cryptography is easier.
* Good cryptography is in the details.
* Bad cryptography is often indistinguishable from good.

Format: Webcast
Speaker: Anthony Stieber

Anthony J. Stieber’s first information technology job was in 1991. Since then, he has worked in academia, banks, retail, and insurance; installed military and commercial firewalls; engineered medical diagnostic systems; reverse-engineered Internet stores; encrypted terabyte data warehouses; provided expertise for court cases; spoken at international cryptography conferences; and become an apprentice locksmith and a published writer. He now knows things he can’t talk about, but he is willing to talk about the rest.

Location:
Wells Fargo Home Mortgage – Cambridge Building
7600 Office Plaza Drive S.
West Des Moines, IA

Map powered by MapPress

Guests must go through the visitors entrance and show a picture ID, you may also ask for Marti Maxon or Maria Paredes when you arrive

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.