Security Forum : Storage and Security

22-Jan-2009

On January 22nd 2009, LSEC organized its 4th Information Security Forum a conference that brings together some international experts from around the world to exchange ideas on the evolution and future of Information Security. This year the focus theme was on Storage Security. Not only from a technical perspective, but also from a business and a management perspective we’ve tried to understand the evolutions of both worlds and where they meet up on a strategic level.

It was our aim to present to a number of business leaders and Information Security professionals the changes and potential impacts for their business of these technologies that support the business operations on a day to day life, gaining increased importance.
Leading technology companies such as EMC, IBM and Symantec have been making major acquisitions and have been spending quite an enormous amount of development on either security or storage technologies. From a business perspective, after a couple of years of operations, the business would like to get a better understanding of the evolutions of those developments and how the joined technologies can improve their business and operations.

Final Program

10.30 : Registration & Welcome

11.00 : Introduction of the day by Ulrich Seldeslachts, CEO LSEC

11.15 : Opening address : outlining the issues on Storage and Security
By Jim Hughes, SUN Microsystems Fellow and Vice President.

Being the chair of the IEEE Forum on Storage Security, and within his role within SUN Microsystems, Jim has the key to enlighten us on the frameworks of both worlds, where they meet and how technology is evolving to support key business processes such as real-time massive storage access.
During this opening address, Jim will set the scene and outline some of the issues, returning in the later part of the afternoon and evening on how to handle some of these concerns.
From a technology perspective some of the following themes will be addressed : Cryptographic Algorithms for Storage, Key Management for Sector and File based Storage Systems, Balancing Usability, Performance and Security concerns, Unintended Data Recovery, Attacks on Storage Area Networks and Storage, Insider Attack Countermeasures, Security for Mobile Storage, Defining and Defending Trust Boundaries in Storage, Long-term storage, …)

12.00 :  Sandwich Lunch

12.30 : Storage Security Best Practices,
by Gordon K. Arnold Product Manager, STSM
(Technical Strategy Security and Storage Software)

With optimization of storage resources based upon pooling of networked storage comes a number of vulnerabilities to your data. However, there are best practices for protecting your data in a cost-effective manner. This session surveys the techniques used to mitigate threats to your data and meet the requirements for auditing of storage operations. Innovative self-encrypting storage media and key management will be highlighted, including new full disk encrypting product announcements.
Three keys elements that you will walk away with:
1. What are the biggest threats to my data with networked storage?
2. What are the best practices for securing my data?
3. What are the practical lessons learned to make storage security cost-effective?

About : Gordon Arnold is the strategy lead for encryption key management for IBM.  Gordon defines strategy and roadmaps for storage security, encryption and key management.  Gordon joined IBM through acquisition in 1994.  Prior to joining IBM he worked in a variety of technical and development management positions for e-mail and directory integration company Soft-Switch.  His focus in IBM has been on large scale Internet deployments, security, and for the last 6 years storage.  He was part of the core team which brought to market our storage virtualization offerings. Gordon has a BA in Liberal Arts and Sciences from the University of Illinois, over 25 years experience in IT products development, and holds the Senior Technical Staff Member grade in IBM.  He is currently chair of the Storage Security Industry Forum of SNIA.

13.30 : Service as a Security Feature
By Stephan Haux, Senior Product Manager EMEA, Iron Mountain Digital

Every week we read about a data breach throughout Europe. It seems like a contradiction having the rapidly developing security technologies on the one hand and the more frequent and more severe data losses on the other hand. Looking closer into the incidents, you find that humans, processes and coincidence are causing them rather than technologies. “as a Service” does provide a more comprehensive approach into protecting information against theft, loss or breach.
• Exceptional case studies presenting data loss caused by employees, bad processes and pure coincidence.
• The varying needs for protection throughout the life of information
• 360 degree promise of service – not only technology, but processes executed by professionals.
• Examples of how only a service can secure information fully.

About : Stephan Haux is a Senior Product Manager for EMEA at Iron Mountain Digital. Haux oversees EMEA activities for determining market requirements for going to market across Iron Mountain Digital’s product and service portfolio. Haux frequently speaks at events, briefs journalists and engages with the analyst community in all parts of the world. Before Haux joined Iron Mountain, he held various international positions with SAS, including Team Leader and Product Manager. With more than 20 years experience in IT and Marketing, covering areas from ERP, CRM, Business Intelligence and Performance Management, Haux is embarked for the ultimate challenge: Protecting the world’s information by Storage as a Service.
14.30 : Coffee Break
15.00 : Storage Security Best Practices
By ir. Erik R. van Zuuren MBA is Senior Manager at Deloitte Enterprise Risk Services
Organizations have become dependent on (the storage of) their electronic data and on (the processing of) their electronic transactions. This dependence and the need for protection of this data and the transactions is getting every day higher on the agenda, hence this seminar. 
However, data centers represent the central hubs for this data storage, information exchange and transaction processing. Therefore they are not to be forgotten in the context of an organization’s data & information storage- & security-strategy.
Data center security is not solely focused on preventing data breaches. The security of a data center must protect the confidentiality, integrity, and availability of process and functions that depend on the data center. The security of the data center must address each type of threat, including those posed from humans, electronic data, and nature (i.e., the environment).  This expose will give an overview of the risk management & security-aspects which are required to sustain normal business operations and protect the business from harm.

About : ir. Erik R. van Zuuren MBA is Senior Manager at Deloitte Enterprise Risk Services and has an extensive experience in Information Security Governance and Risk Management related disciplines, both at strategic and tactical level and has an extensive experience at C-level in the private sector and management- / cabinet-level in the public sector. ir. Erik R. van Zuuren MBA is active as consultant since over 10 years and since participated in and led a broad range of strategic and tactical projects mostly in Belgium and The Netherlands.

15.45 Keynote - Virtual IT: A Strategy For Thriving In The Information Economy
A holistic view on the future of storage and security by EMC.
by Hans Timmerman, Technology Officer EMC Netherlands

In this keynote by EMC, the leading Storage company it will become clear why they have acquired RSA with the specific goal in mind of Security and Storage. Include VM Ware to the table and a whole new paradigm presents itself what the future of Information Technology could look like. Learn about the view on the future by EMC/RSA.
• The Need For Information Governance
• New Focus on Information Risk Management
• The Rise of Social Computing
• The New Knowledge Worker
• The Demand For Personal Information Control
• The Deconstruction and Reconstruction of IT

About : Prior to joining EMC The Netherlands beginning 2002, Hans was active in the Dutch Aerospace industry. He lead many years the manufacturing development at Fokker Aircraft after which he held several management and director roles. During his career he has been a guest professor at several universities and was involved in various international IT and standardization projects. At EMC after having been responsible for the Professional Services and Pre-Sales, Hans today is Country Technology Officer and responsible for the ONE EMC view - for development and empowerment of both EMC’s local business development as for the existing Strategic Alliances and partnerships.

17.10 : Welcome note to the evening sessions participants, Ulrich Seldeslachts, CEO LSEC

17.15 : Keynote : Cross Border Data & Information Storage & Security

by Erik Luysterborg, Partner Deloite ERS

When you are storing, hosting, processing etc. (personal) data you need to consider how to appropriately to manage the requirements and risks of applicable data protection and privacy laws, regulations and internal policy/contractual requirements. All of this needs to be done while ensuring that from a technical and procedural point of view the necessary tools are in place to protect and share such data efficiently. What are the key parameters in order to achieve such a balance ? How is it that implementation/usage of technology tools is often not sufficient to obtain data privacy ? What impact do data protection laws and regulations/contracts have on issues such as data leakage, data retention, data access etc .? What is this so-called security/privacy paradox and why is it relevant to storing/processing (personal) data in a (international) data centre ?  During this presentation we will shed some light on the above issues and how to manage them in a pragmatic manner. We will share with you some experiences and thoughts and suggest a “real life” checklist for dealing with a number of the major implications of these data protection issues and requirements.

About : Erik Luysterborg is a partner of Deloitte Enterprise Risk Services, operating out of the Brussels office. In his cross-functional client role, he heads up Deloitte’s data protection and privacy services both in Belgium and for the EMEA region. He also acts as the global Chief Privacy Officer for Deloitte Touche Thomatsu worldwide. He is a lawyer by training but runs an integrated team of both lawyers and security & privacy experts who are specialized in ICT and data protection related ICT and regulatory compliance services.  Erik is an active member of several global data privacy steering committees and has extensive experience in assisting clients regarding the cross border aspects of data protection including the outsourcing aspects thereof. He has a specific focus on both designing and implementing a pragmatic data protection strategy as well as providing hands on privacy solutions and advice on setting up manageable and auditable compliance structures within international organizations.

18.15 : Closing Keynote : the future of storage and security explained

By Jim Hughes, SUN Microsystems Fellow and Vice President.
A glimpse in the future of storage and security and the world of information technology and systems. Jim will bring some of the key learning of the day and expands that into a view of technological developments in close contact with tomorrow’s business requirements. A view from the leading companies in technology of the world …
19.15 : Closing Notes & LSEC activities in 2009 by Ulrich Seldeslachts, CEO of LSEC
19.30 : Reception, Walking Dinner, Networking and Fun Activities
22.00 : Close of Event

Practical Details

LSEC Security Forum – Storage & Security, LSEC New Years Event
Brussels, Claridge

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< September 2010 >>

S M T W T F S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 1 2

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Bluekrypt

Security Expert in Crypto, Information Security and Training

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: arrowUp

arrowUp - member of the Lykos Group

Expert: Research In Motion - RIM - Blackberry

Research In Motion - RIM - Blackberry

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: Traxion

Traxion - Identity Management - cornerstone for your company

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: Approach

Approach specializes in Application Security, Identity Management and financial transactions.

Expert: Global Knowledge

Global Knowledge is the worldwide leader in IT and business training.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Novell

Comprehensive Identity, Security and Systems Management Solutions.

Expert: Exclusive Networks

Value added Distributor specialized in information security. Operational in Belgium, France, Switzerland and Luxemburg.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: D Soft

D Soft is an expert in electronic distribution of digital documents.

Expert: Scanit

Scanit is an IT security boutique specializing in ethical hacking, penetration testing, vulnerability assessments and security configuration reviews.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: Microsoft

At Microsoft, we're motivated and inspired every day by how our customers use our software to find creative solutions to business problems.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: Intesi

Intesi Belgium is the R&D competence center of Intesi Group, focusing on Internet Security, using state-of-the-art ICT technologies.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Cisco

Cisco Internet Protocol (IP)-based networking solutions are the foundation of the Internet.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: BT - British Telecom

One of the world's leading providers of communications solutions.

Expert: Alcatel Lucent

Alcatel provides communications solutions to telecommunication carriers, Internet service providers and enterprises for voice, data and video.

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: IBM

A world leader in Information Technology with a large professional organization in Belgium and a series of security experts.

Expert: Norkom Technologies

Norkom is a market-leading provider of innovative financial crime and compliance solutions to the global financial services industry.

Expert: Telindus

Telindus has expertise in all aspects of modern telecommunications technology, including LAN, WAN, Internet and e-networking, network access and security, VOIP (Voice over Internet Protocol), VPN, fixed and mobile communications.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.