//
YOOtheme

Training

Save the Date!

Silicon Valley ISSA has scheduled CISSP review sessions starting at 6pm Tuesday evenings in March and April

Click here for additional details.

Past Meetings


May 2013 - Panel: Going Forward - Creating a diverse information security workforce PDF Print E-mail
Tuesday, 21 May 2013 11:30
Date:5/21/2012
Time:11:30 - 1:30
RSVP:http://survey.constantcontact.com/survey/a07e7j1ww63hgxy5m0z/start
Speaker: Panel ModeratorJean Pawluk
 

Topic:

Panel: Going Forward - Creating a diverse information security workforce

We currently face a shortage of qualified and security savvy staff in every aspect of information and related security fields.

In 2010 the USA Labor Department's Bureau of Labor Statistics noted that with very low unemployment among IT security pros, the scarcity of women, African Americans, and Latinos was and is still highly evident. How can we build a strong base of the best and the brightest people to face the ever expanding challenges within security if we don't encourage over half the population to participate ?

Our panel will discuss some of lesson learned , present issues and what steps we can take to improve our ability to build a even stronger and more diverse community of women and men working in security. Our highly-accomplished panelists will also offer insight into how they achieved their professional goals and how those interested in these initiatives can get involved.

Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Monday, 27 May 2013 20:26
 
2013-April: RSA Implementing Lessons Learned From Being Breached PDF Print E-mail
Tuesday, 16 April 2013 11:00
Date:4/16/2012
Time:11:30 - 1:30
RSVP:http://survey.constantcontact.com/survey/a07e7b7aqrghfa8d1wy/start
Speaker:
    RSA
      Peter Andrious – Manager, Systems Engineering
      Chad Loeven – Technical Specialist
      Jack Estep – Field Operations Manager
 

Topic:

Implementing Lessons Learned From Being Breached

RSA will present Advanced Incident Response. The presentation will focus on the process, how that ties the many Security Technologies (Controls) together and how that allows us to drastically cut down on the investigative time, critical in an incident. RSA will review their organization pre-breach and post-breach to show how they applied their lessons learned. They will wrap up with a technical demo on host forensics inspection and memory analysis.

Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Wednesday, 15 May 2013 00:58
 
2013-March: Evolution of the BlackHole Exploit Kit and Platform Agnostic Mobile Threats PDF Print E-mail
Tuesday, 19 March 2013 18:06
Date:3/19/2012
Time:11:30 - 1:30
RSVP:http://survey.constantcontact.com/survey/a07e758elm5hdwdzsy8/start
Speaker:Chris Astacio – Manager for Security Research, Websense Security Labs

Bio:

Chris Astacio is a Manager for Security Research at Websense Security Labs, the team within Websense that ensures that our 65 million customers are protected against all type of web and email based threats. Chris is a specialist in javascript obfuscation and has done extensive research into web exploit kits, the most prevalent threat on the web used to compromise computers around the world.

 

Topic:

Evolution of the BlackHole Exploit Kit and Platform Agnostic Mobile Threats

Chris Astacio will cover two topics:

  • The BlackHole exploit kit is hugely successful — arguably the most successful exploit kit in history. Chris will discuss how BlackHole has evolved since it was first identified, and explore why its developers have been so successful. He will also outline the innovations and enhancements that have contributed to the kit’s success over the years.
  • Threats to mobile devices are less widespread than those targeting desktops and laptops. But as platform-agnostic exploits start to appear more frequently, will mobile threats increase? Chris will examine the possibility of mass mobile attacks, using tools like BlackHole, and discuss what vectors could be used to evolve these attacks.

Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Wednesday, 03 April 2013 03:40
 
2013-February - What is Endpoint User "Browser" Isolation? PDF Print E-mail
Tuesday, 19 February 2013 11:30
Date:2/19/2012
Time:11:30 - 1:30
RSVP:http://survey.constantcontact.com/survey/a07e70n2fuehctt4l7y/start
Speaker:Anup Ghosh – Founder and CEO, Invincea

Bio:

Until recently Anup Ghosh was also Research Professor and Chief Scientist in the Center for Secure Information Systems (CSIS) at George Mason University. He was previously Senior Scientist and Program Manager in the Advanced Technology Office of the Defense Advanced Research Projects Agency (DARPA) where he managed an extensive portfolio in information assurance and information operations programs. He previously held a role as Vice President of Research at Cigital, Inc. In his career he has served as principal investigator on contracts from DARPA, NSA, and NIST’s Advanced Technology Program and has written more than 40 peer-reviewed conference and journal articles. He was awarded the NSA’s Frank Rowlett Trophy for Individual Contributions in 2005 and the Secretary of Defense Medal for Exceptional Public Service for his contributions while at DARPA. Anup was named to the Naval Studies Board for a National Academies Study in 2008 on Information Assurance for Network-Centric Naval Forces and currently sits on a number of advisory boards informing the future of American cyber-defenses.

 

Topic:

Addressing User Targeted Attacks At The Endpoint - Killing Apts And 0Days With Behavioral Based Detection.

Your organization is under a state of constant and sustained attack, and every employee represents a potential point of weakness in your security strategy. Innovation in endpoint security is a critical need. New approaches to insulate the employee against these attacks are required. Today's most successful and common attack vector is to spear-phish your employees with email containing links to malicious sites and weaponized attachments. The adversary is getting onto your networks by tricking your employees into becoming accomplices to network breach every time they click on a link in a spear-phish or open its attachments.

The techniques used by your adversaries include:

  • Spear-phishing emails that deliver the employee to malicious websites that run drive-by download exploits or include weaponized document attachments
  • Hijacking legitimate trusted sites to push malware to unsuspecting users
  • Poisoning search results behind trending news items on popular engines, such as Google, Yahoo!, and Bing
  • Pushing malware through popular social networks such as Twitter and Facebook

This presentation will focus on new approaches, without the need of signatures or lists, to fight against Zero Day Attacks.

Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Monday, 04 March 2013 18:08
 
January 2013 - Software Security for the 99%: Realistic Approaches PDF Print E-mail
Saturday, 29 December 2012 23:38
Time:RSVP:
Date:1/15/2012
11:30 - 1:30
http://survey.constantcontact.com/survey/a07e6vkt6cshbn2z47b/start
Speaker:John Dickson – Denim Group

Bio:

John Dickson is a Principal at Denim Group, Ltd, a 20-year career security professional, an entrepreneur, and a serial volunteer. John is Past President and Founder of the Alamo Chapter of the ISSA, which won the Chapter of the Year award in 2011. John’s background includes hands-on experience with network security, intrusion detection systems and software security. He helps Chief Security Officers of Fortune 500 and federal organizations launch software initiatives. He is currently the honorary commander of the 67th Network Warfare Wing, which organizes, trains and equips cyberspace forces to conduct network defense, attack and exploitation.

John has a strong history of non-profit leadership outside the ISSA and security worlds. In addition to being a full-time security professional and running Denim Group, John is currently President Elect of the Texas Lyceum, a statewide leadership group which includes well-known alumni such as President George W. Bush and Governor Rick Perry. He is also a Past Chairman of the North San Antonio Chamber of Commerce, and past Chairman of the San Antonio Technology Accelerator Initiative, a community-wide advocating technology businesses in the region.

 

Topic:

Software Security for the 99%: Realistic Approaches

Industry conferences and professional literature give examples of successful software security programs, but those examples are usually of the largest, most security-conscious companies in the marketplace. These Wall Street banks and independent software vendors, such as Microsoft and Adobe, have mature software security programs that have been in place for years and have driven best practices for developing more secure code. Benchmarking tools capture successes of these companies, but leave most organizations wondering, “What about us? How can we build a software security program on a limited budget, with little resources?” Unfortunately, the state of software security outside these top companies is vastly different. In many organizations, software security champions still struggle to justify resources and head count, and find themselves substantially behind their more sophisticated companies. What can a security leader reasonably do to build a successful software security program in the small enterprise or upper mid-market space? What can they do to build more secure code when regulatory scrutiny or the publicity of product breaches is not yet a business consideration? This presentation will represent what these companies are doing, and what one can do to define success.

Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Monday, 04 February 2013 17:58
 
November 2012 - Identity Context: The Missing Link for Security Intelligence PDF Print E-mail
Tuesday, 27 November 2012 11:30
Date: Tuesday, November 27th, 2012
Time: 11:30 AM - 1:30 PM
Speaker:

Christopher Williams – Business Solutions Manager – Aveksa Inc.

Topic:

Identity Context: The Missing Link for Security Intelligence

In this session, we will discuss how changes to the threat and compliance landscape are driving a need for broader scope and incorporation of identity context into other areas of security intelligence. The discussion will cover the advantages and best practices when adopting an identity context approach to Security Information and Event Management (SIEM).

Bio:

Christopher is a leading voice in the convergence of operational IT practices and Identity, Audit, and Compliance programs. His career features 15 years as a practicing manager of data centers, operations & technical services teams for fortune 500 companies and DODcontractors – and 16 years of technical services, consulting, and product / marketing management.

Christopher now serves as the Business Solutions Manager for the industry’s leading Identity and Access Governance firm, Aveksa. In this role Christopher continues to assist organizations around the world to define and achieve their goals through process workshops, mentoring seminars, and numerous publications.

RSVP: http://survey.constantcontact.com/survey/a07e6juo4syh8opk1jl/start
Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Friday, 30 November 2012 16:51
 
October 2012 - Why Your Enterprise Should Be Managing Its Certificates PDF Print E-mail
Tuesday, 16 October 2012 11:30
Date: Tuesday, October 16th, 2012
Time: 11:30 AM - 1:30 PM
Speaker:

Paul Turner, VP of Products

Topic:

Why Your Enterprise Should Be Managing Its Certificates

This presentation goes deeper into just what the root causes of key and certificate encryption risks are and what actions to take to manage these risks. The Flame Virus, weak key management policies, and ongoing attacks on certificate infrastructure have all heightened the requirement for more robust management of encryption keys and certificates. Learn what Enterprise Key and Certificate Management Policies are recommended as a best practice to help you manage keys and certificates and mitigate your risks.

Bio:

As vice president of products at Venafi, Turner is responsible for engineering, quality assurance, and product management. Prior to Venafi, Turner held various roles at Novell, including leading their resource management, identity management, collaboration, and Internet products businesses. Turner also served as vice president of products at CertCo, a provider of PKI and security products for the financial services market. He holds a bachelors in Electrical Engineering.

Last Updated on Wednesday, 24 October 2012 18:40
 
September 2012 - CI vs A – The Relationship Between the CIO and Information Security PDF Print E-mail
Tuesday, 18 September 2012 11:00
Date: Tuesday, September 18st, 2012
Time: 11:30 AM - 1:30 PM
Speaker: Panel

Topic:

CI vs A – The Relationship Between the CIO and Information Security

Information security is all about CIA – confidentiality, integrity and availability. For the CIO, the most important component is availability while confidentiality and integrity are secondary concerns. For the information security team, integrity and confidentiality are the primary concerns while availability is secondary. Please join us for this opportunity to discuss this balancing act with the CIOs who are at the tip of the fulcrum.

Bio:

 

RSVP: http://survey.constantcontact.com/survey/a07e6df3fw4h6zbtsty/start
Location: McAfee
2821 Mission College Blvd,
Santa Clara, CA 95054


View Larger Map
Last Updated on Tuesday, 09 October 2012 20:31
 
<< Start < Prev 1 2 3 4 5 6 Next > End >>

Page 1 of 6