Security Management 2010

Become a member of the site to sign up for this event.

25-Oct-2010

In 2008, LSEC organized a seminar on Information Security Management Standards and the impact and interest for organizations interested in applying those. Two years later, we would like to understand what the current level of expertise, typical organizational structure, challenges, facilities and interests are of organizations, both enterprise and government in managing information security.

Security Management Seminar 2010

The aim for this seminar was not only to understand the current market situation, by means of best practices and real cases; but also in an attempt to find sufficient expertise to demonstrate the level of professionalism in this domain, and to present to companies and people challenged with the day to day operations a further guidance to professionalize their activities.

By means of presentations on IT and Information Security Management, a panel with respective CSO-CISO-CIO explaining their professional experiences, presentations on best practice guides and standards, cases and discussions; we had liked to gather an indication of the situation in Belgium.
Simultaneously, we are planning an industry-wide survey on the current market situation in Belgium on the responsibilities of Security within organizations.

This seminar “Security Management in 2010 – A Day On Security Management” offered the opportunity to listen to expert presentations, participate in panel discussions, sharing your expertise with peers , or any other type of witness, … during ,

Some of the following topics have been highlighted:
- Information Security Management, a good practice
- Information and IT Security, part of Risk Management, Information Management, Security Management, or an expert practice
- Panel discussion with CIO’s, CISO’s and CSO’s : the search for the white rabbet
- The CISO/IT Security Manager in Belgium and abroad
- The typical Information Security Organization
- A budgetary approach to Security Management
- Good Cop – Bad Cop : Security Manager – Audit & Controller : who’s who
- In- or Out? Should IT & Information Security Management
- Theory & Practice : Risk-IT, ISO27000, …
- …


Final Program


9.00 : Welcome & Registration

9.45 : Opening Notes & Introduction by Ulrich Seldeslachts, CEO LSEC

10.00 :  Six lessons learned for effective security management, by Ward Duchamps - Vinti-Q
A collection of best practices from more than 10 years experience in the field on security management, collected in 45 minutes.

Or visit : http://sixlessons.vinti-q.com/

Abstract : Despite all standardization efforts, Information Security Management remains - just like any other management discipline - a subjective matter. In this presentation Ward will reflect on some lessons learned that he collected during 10 years of field experience. Starting from “the art of getting things done through people”, this session puts business, people, standards and daily operations in a cohesive perspective that may inspire security practitioners to think about their management approach.

About : Ward is cofounder of VintiQ, a new company of senior security consultants that specialize in convincing the C-suite and business leaders to think positively about the risks related to information processing. With his in depth specialist knowledge combined with management capabilities and business insight he enabled several blue chip companies to manage information security in an effective and efficient manner. Ward is certified as CISM, CISSP, CISA, CGEIT and ISO27001 Lead Auditor. He holds a Master in Engineering and is in the process of obtaining the degree of MSc Information Security at the Royal Holloway University of London

11.00 : Risk-IT and COBIT in practice, by Dirk Steuperaert - IT In Balance

Abstract: Risk IT provides an end-to-end, comprehensive view of all risks related to the use of IT and a similarly thorough treatment of risk management, from the tone and culture at the top, to operational issues. Risk IT is a framework based on a set of guiding principles for effective management of IT risk. The framework complements COBIT, a comprehensive framework for the governance and control of business-driven, IT-based solutions and services.

While COBIT provides a set of controls to mitigate IT risk, Risk IT provides a framework for enterprises to identify, govern and manage IT risk. Simply put, COBIT provides the means of risk management; Risk IT provides the ends. Enterprises who have adopted (or are planning to adopt) COBIT as their IT governance framework can use Risk IT to enhance risk management.

Being one of the authors of both COBIT and Risk-IT, Dirk was also part of the Development Team of the “Risk IT Practitioner Guide”, a 135p guide published in 2009 on Risk Universe, Appetite and Tolerance;
Risk Awareness, Communication and Reporting; Expressing and Describing Risk, Risk Scenarios; Risk Responses and Prioritisation; Using COBIT® and Val ITTM

With all of this background and his personal experiences as both auditor and guiding companies in their efforts on implementing COBIT and Risk IT, Dirk is a unique expert in Belgium.

About : Dirk is Managing Director of IT In Balance BVBA, - delivering consulting services on IT Governance issues, focussing on COBIT and related frameworks, and including COBIT related training.
Dirk used to be steering committee member for COBIT within ISACA, the association for the development, adoption and use of globally accepted industry-leading knowledge and practices for information systems. He provided consulting support to ISACA as project manager of the development team for the new Risk IT framework and is currently performing a similar role for the new COBIT® 5.0 research initiative. Since 1997, Dirk has been active within PricewaterhouseCoopers (PwC), as a Director responsible for IT governance services. Earlier, Dirk has worked with ING and SWIFT, as engineer and IT auditor. Dirk has been studying Electronics Engineering at the university of Ghent and mastered in Computer Auditing at the Management School of the Antwerp University.

12.00 : Sandwich Lunch, snacks soft drinks & Coffee

13.00 : Security Management, a challenging metier?, by Olaf Jonkers, Belgacom ICT - Telindus

Abstract : Security Management is without a doubt a challenging “métier”, where different areas of conflict come together. In different market segments, the challenges seem to be different from a business point of view, whereas the IT-service implications often boil down to quite similar issues and solutions. From their longstanding IT-Service outsourcing contracts Belgacom provides insights on these issues, and how contractual obligations are enforced throughout an IT-Service catalogue and towards subcontractors. For this presentation, Security Managers from these contracts provided their insights, issues and solutions in order to manage security across an ICT Services Catalogue, and a complex delivery organisation

About : Olaf has been active in the field of Information and ICT Security for over 12 years. His roots lie within the field of PKI and cryptography, but his knowledge also covers network-specific as well as system-based security technology and tools. The processes governing the management of information security, including risk assessment methods, have been the centerpoint of the more recent years at Belgacom ICT, where he worked as a business consultant, focussing on ICT / information Security.”

14.00 : Information Security Governance in Practice, by Peter Houtmeyers - Consultant, TITANS Consulting

Abstract: Peter will be focusing on using the ISO 27000 family of standards to guide us through ways of governing Information Security in practice. From the various drivers to the choice of a good standard, understanding the changing shift in Information Security and by showing some concrete case examples on how to get to real implementations. He will walk us through the different steps of assessment, choice, implementation, certification up until audit, a practical guide for future Information Security Management practitioners.
About : Peter is a highly qualified senior level Information Security and Security Governance expert holding various certifications, including CISSP, CISA, CISM, CGEIT and ISO 27001Lead Auditor. After his career as an information security specialist at a leading inter-banking and financial telecommunications company, Peter joined as a senior security advisor in a distinguished security consultancy company in which he gained a considerable amount of experience in Incident Response Management, Compliance Auditing, Information Security Policy Implementation and the development and implementation of Corporate Security Governance frameworks. As an Information Security Advisor Peter was active as an advisor and consultant in the Information Security Governance practice, mainly delivering professional services for governmental, military, financial companies and automotive institutions on Information Security Management related projects. With a bachelor’s degree in informatics, Peter applies a structured and methodological approach in combination with clear and direct communication to deliver pragmatic high-quality results in line with client expectations. Peter lectures at various business schools and institutions in Belgium such as UAMS, Solvay Brussels School of Economics and Management and ISACA. In his spare time, Peter is a basketball enthusiast, and loves books related to IT and security. Prior to joining Branswijck, Peter had worked with ACROSS Technology as Principal Consultant, at Belgacom ICT - Telindus as Senior Consultant Information Security and as Senior Security Advisor with Uniskill. Prior to that, Peter was Security Administrator at SWIFT.

15.00 : Coffee Break

15.30 : Practical Experiences with implementing Security Management, Pierre Dewez, Devoteam

About : Married and happy father of four children, active in the field of information technologies for 13 years and member of the executive board of directors within Devoteam Belgium for global security and education related matters, Pierre has been Lead Auditor for management systems (quality, information security, IT service management and business continuity) and advisor in IT risk management for many financial, insurance or service delivery companies in Belgium and abroad (Germany, France, Luxembourg, Netherlands, Canada). Member of the Belgian federation of the technological enterprises (Agoria) and the JTC1/sc27 sub-committee, Pierre takes part as an international ITSMS, ISMS and risk management expert while contributing to the elaboration of recommendations intended to improve the contents and the relevance as of these international standards (ISO 20000, ISO 27001, BS 25999, ...) towards the market. Trainer and author of various articles and operational support tools relating to the information security audit and the IT service management, Pierre collaborates with other international trainers to the continuous improvement of the courses contents, audit activities and seminars associated with these practices around Europe and Canada.

16.15 : Panel discussion : the role of the Security Manager, CSIO and CSO in 2010

17.00 : Closing Notes

17.30 : Reception & Networking

18.30 : Special Evening activity : The future of internet networks and security by Nir Zuk, CTO PaloAltoNetworks

20.30 : Close of Seminar

Practical Details

Monday, October 25th 2010.

Day Seminar, from 9 am onwards, with closing special event from 17.30h onwards.
SAP Lounge, Vilvoorde
Participation : free to attend, if registered prior to October 20th. Afterwards : 150 € (excl vat) participation fee or cancellation fee. Free to attend for LSEC, VICTOR, EEMA, AGORIA, ISACA, ISSA, TeleTrusT, Systematic & SITC Members.

Become a member of the site to sign up for this event.

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< February 2012 >>

S M T W T F S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 1 2 3

Expert: Oracle

Oracle Belgium & Luxemburg

Expert: Option

Wireless data security enablers

Expert: TNO

TNO Research and Innovation

Expert: Control & Process

Automatisering SCADA, PLC; Meettoestellen en brandbeveiliging

Expert: Thales Group

Thales Group

Expert: On2It

Smart IT Security We Are On To It

Expert: Mobco

Mobile Fleet Management

Expert: TITANS

TITANS ICT Consulting

Expert: G Data

G Data Anti Virus Solutions

Expert: Outpost 24 - Vulnerability Management Made Easy

Outpost 24 - Vulnerability Management Made Easy

Expert: Regify - Trusted and Binding Secure eMail

Regify - Trusted and Binding Secure eMail

Expert: Mobila - Mobile Enterprise Applications

Mobile Enterprise & Applicatinos

Expert: Lancelot Institute

Lancelot Institute - Training in Information Security, IT- Risk & IT - Auditing

Expert: CSI Tools

CSI tools is an expert software solution provider specialized in powerful tools for IT architects and auditors who are focused on maximizing GRC project development efficiency in SAP environments.

Expert: Intrinsic-ID

Content Protection, Unique Device Identification, Key Storage, PUF Physical Unclonable Functions

Expert: Belgacom ICT

Belgacom ICT Security Solutions for Large, Medium and Small Enterprises

Expert: Qualys

On Demand Vulnerability Management and Policy Compliance

Expert: Trend Micro

Securing your web world

Expert: Egemin

Egemin provides process and handling automation engineering and Secures Industry Automation

Expert: AEP Networks

More than 60 countries ... protected by AEP Networks

Expert: Palo Alto Networks

Next Generation Firewalls

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: Ascure

World class information risk management services!

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.