Archive for the 'Uncategorized' Category

Next Meeting: July 26th – Measuring and Communicating Risk with FAIR

Date: Monday, July 26th, 2010
Time: 11:30am to 1:00pm
Topic: Measuring and Communicating Risk with FAIR
Format: Speaker
Speaker: Kevin Riggins

Measuring and Communicating Risk with FAIR:

Measuring and communicating risk is a challenging task. Having a repeatable, well understood method of measuring risk that is based on a common taxonomy is very important. Factor Analysis of Information Risk provides both a framework for defining and understanding risk and a basic method of analyzing and communicating that risk.

Speaker Bio

Kevin Riggins, CISSP has over 22 years of experience in information technology and has focused on Information Security since 1999. He has been a Certified Information Systems Security Professional since 2004 and currently works for a Fortune 500 financial service company where he leads a team of information security analysts responsible for internal consulting, risk assessments and vendor security reviews. He writes about various information security topics on his blog, Infosec Ramblings ( http://www.infosecramblings.com), has been published in (IN)Secure magazine, and is a frequent speaker at conference and industry association meetings. He has served as the technical editor for Syngress on several books; CISSP Study Guide, CompTIA Linux+ Certification Study Guide (2009 Exam), and Eleventh Hour Linux+.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Date: Monday, May 24th, 2010
Time: 11:30am to 1:00pm
Topic: Protecting Your Applications from Backdoors
Format: Speaker
Speaker: Clint Pollock

Protecting Your Applications from Backdoors:
How to Secure Your Business Critical Applications from Time Bombs, Backdoors & Data

With the increasing practice of outsourcing and using 3rd party libraries, it is nearly impossible for an enterprise to identify the pedigree and security of the software running its business critical applications. As a result backdoors and malicious code are increasingly becoming the prevalent attack vector used by hackers.

Whether you manage internal development activities, work with third party developers or are developing a COTS application for enterprise, your mandate is clear- safeguard your code and make applications security a priority for internal and external development teams.

In this session we will cover;

  • Prevalence of backdoors and malicious code in third party attacks
  • Definitions and classifications of backdoors and their impact on your applications
  • Methods to identify, track and remediate these vulnerabilities

Speaker Bio

Clint Pollock is a Senior Solutions Architect at Veracode. Since 1997, he has also created security solutions for large-scale enterprise environments on behalf of CREDANT Technologies and Netegrity. In his current role, Clint helps globally distributed organizations evaluate, track, and mitigate their application security risk.  Clint’s greatest strengths are his enthusiasm, experience and determination to help customers succeed in maintaining secure, compliant systems, and avoid the consequences and bad headlines that come with application security breaches.  Clint resides in Chicago, IL.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Location: Buccaneer Computer Systems

Map powered by MapPress

Next Meeting: Date Correction

Josh pointed out that the date for Septembers meeting was incorrect. It is actually the 28th.  I apologize for the confusion. The original post has been updated also.

-Kevin

Next Meeting – July 27th, 2009 – Threat Matrix

Date: Monday July 27th, 2009
Time: 11:30am to 1:00pm
Topic: Threat Matrix
Speaker: Guy Weaver

Guy Weaver is the Senior Systems Engineer for the Central Region at Purewire, Inc. Mr. Weaver has over twenty years experience in the IT industry with a broad range of skills. He holds many certifications including CISSP, CCSP, CEH and ITIL. Guy has worked for one of the largest health care systems in country, was a Networking Practice Manager for a global systems integrator, a Systems Engineer at Cisco Systems covering security and core infrastructure for a Fortune 10 account, and a Systems Engineer at Blue Coat Systems supporting WAN optimization and legacy web gateway customers.

Location: Regular meeting location at Buccaneer Computer Systems.

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.

Seeking Speakers

The Des Moines ISSA chapter is seeking individuals who are interested in speaking at our chapter meetings. The topics and dates we are needing to fill are:

08/24/2009
InfoSec Employment: Finding the Right Job and Hiring the Right Talent

09/29/2009
Security Incident and Event Management

10/26/2009
Regulatory Update: SOX, HIPAA, FISMA and Others

11/23/2009
Outsourced Security: Is it right for you?

If you are interested or know someone who might be, please use the contact form below to let our chapter President, Dave Nelson, know. Please include the date and topic in your note.

Thank you.

Contact Dave Nelson
  1. (required)
  2. (valid email required)
 

cforms contact form by delicious:days

Chapter Officer Elections

From the President, Dave Nelson:

As you know, the operations of an ISSA chapter require the dedication and support of its members. One way you can show your support is to volunteer to serve as a chapter officer.

Chapter officers are critical to developing the educational and networking opportunities as well and handling the business functions of the chapter.

Nominations are due by April 17th for the VP, Secretary and Treasurer positions. If you have any interest in serving in one of these capacities please let me know and provide a quick bio. I’ll send out the candidate lists on 4/20 and elections will be at our 4/27 meeting.

Nominations can be sent to the chapter president using the form below.

Contact Dave Nelson
  1. (required)
  2. (valid email required)
 

cforms contact form by delicious:days

Next Meeting

Date: Monday April 27th, 2009
Time: 11:30am to 1:00pm
Topic: Disaster Recovery and Business Continuity Case Study
Speaker: Sean McClanahan with Westec and Jeff Daniels with InfoBunker
Location: Our regular meeting location at Bucaneer Computer Systems

If you are not a member of ISSA and would like to visit to see what we are all about, please go here to register as a guest.