SIEM 2009 - Security and Information Event Management Seminar

08-Sep-2009

The truth is out there

But how much do you know from it? Do you know how effective your firewall, NAC, UTM, IPS, … and maybe many more devices and applications that prevent security threat incidents are?


Their activities are extremely important, but are you able to manage them thoroughly? During this afternoon seminar, you’ll be able to find out from the experts what they are doing with all of this information.


Part of the Global Security Week, LSEC has organized the following seminar on SIEM (Security Information and Event Management). Many companies have installed a variety of complex security mechanisms that flash on a day by day basis, but most are only reporting basic information coming out of the standard reporting engines of these devices and tools.
In some cases this logged data is not stored at all, and just erased from the perspective of reducing the processing power and disk space. Whilst perimeter security is in most large organizations largely being considered, only in rare occasions it is properly taken care for. In smaller organizations typically, the situation is even worse. On top, no consideration is paid to threats coming from the inside.




SIEM Seminar 2009 in Leuven, Fabian Libeau from ArcSight



SIEM technology can be deployed to support three primary use cases: compliance reporting/log management, threat management, or a SIEM deployment that covers both use cases. Most organizations require a general SIEM deployment that implements capabilities in all three areas, but there is variation in use case priority and capability requirements Companies from a variety of industries (financial institutions & insurances companies, process manufacturing, chemicals, pharmaceuticals, government institutions and others ) are welcome to attend these expert presentations and participate in the discussions on how to to deal with sensitive information coming from and going to business partners and customers.




Learn from the expertise and experiences of some of our best experts.

Final Program

12.00h Registrations & Sandwich Lunch

12.20h Welcome & Introduction by LSEC

12.30h SIEM : a critical component of Information Risk Management
by Stefaan Hinderyckx, Dimension Data

About : Stefaan Hinderyckx heads Dimension Data’s Security business in Europe. He has worked for Dimension Data in European and global positions for nearly 4 years, where he oversaw security sales operations and new business development as well as maintained and created relationships with Dimension Data’s security technology partners.
Prior to working at Dimension Data, Stefaan worked as Sales Director for Symantec, and as Vice President Sales at Verizon Business Security Solutions. Stefaan has 19 years experience in the networking, security and application industry. He fluently speaks four languages, and holds a B.Mathematics, M.Computer Science and M.Business Administration, all from the University of Leuven, Belgium

13.10h SEM SIM SIEM ... just more technology or truly adding value?
by Bart Vansevenant, Cybertrust - Verizon Business

About : prior to his current function, Bart was responsible for the Managed Security Services and Vulnerability Management offerings of Cybertrust worldwide. Prior to acquisition of Verizon Business and the merger of Betrusted/Ubizen and TruSecure, he was Ubizen’s executive vice president of marketing, managing the company’s marketing communications, public relations and analyst relations. Before joining Ubizen in January 2001, Vansevenant led the internet product management department at cable operator Telenet. Previously, Bart had served as account manager and business development manager at Oracle. As one of the founding members of LSEC, Verizon - Cybertrust wanted to contribute to the initiative to gather companies offering security products, services and expertise to increase security awareness in the Belgian market, to internationally promote the security expertise present in Belgium and stimulate collaborations between different security players in the market

13.50h Human Nature or a Few Bad Apples
by Riaz Khan, European Director, WildPackets

Network & Application Performance Analysis, Protocol Analysis, VoIP Monitoring and Troubleshooting Solutions
What are the challenges for Network Forensics, what questions need to be answered and how can you answer them? One of the problems is that there are many things happening on your networks at the same time.
Trying to find the critical packet is like looking for the needle in the haystack. An integrated approach and some forensic analysis tips could help in dark times.

About : Riaz Khan has over 20 years of IT experience gained in mission-critical networking environments such as those of DEC, Compaq, and Cisco Systems. He holds a Certified Business Critical Consultant diploma from the British Computer Society, and has been certified by the Industrial Society in Management in Computing and Management practices. Khan spent 2 years auditing Software, Network and Security Domains advising customers on how to improve business processes which support IT. He specializes in enterprise solutions across diverse market verticals

14.30h VoIP Security Management, threat detection and control
by Peter Cox, CEO UMLabs
About : Peter Cox CEO, has 30 years experience of IT systems and software development including more than 20 years experience of IP networking and security. Peter was a co-founder of Borderware Technologies, a pioneer of IP security and developer of one of the first commercial firewall products.
While at Borderware, Peter focused on application specific security gateways including Email, IM and VoIP products. Peter also navigated Borderware’s products through a total of 3 Common Criteria EAL4+ Security certifications. Common Criteria is a international security certification standard sponsored by over 20 countries.

15.10h Coffee Break, Refreshments & Networking

15.40h SIEM City. A general technological and market perspective of SIM / SEM = SIEM
Luc Dooms, C-Cure

About : Luc Dooms has a Masters degree in Physics (1985) from the University of Antwerp and a Masters degree in Computer
Sciences from the University of Brussels. After doing fundamental research at the KU Leuven in the area of theoretical physics, Luc
finds his way in the IT world: software engineer at Dynamic Engineering and knowledge engineer at Kredietbank. In 1991 he
starts working for BIM, an innovative Belgian IT company, doing UNIX and TCP/IP long before market recognition. At BIM, Luc
progressively gets interested in IT security and is involved in the early internet security projects in Belgium. In 1996, Luc decides to
be active as an independent consultant in the area of internet security.
In 1998, he co-founds C-CURE, a Belgian company specialized in design, implementation and management of corporate
perimeters and internal networks. As CEO he has guided this company from an innovative start up to the trusted security
partner C-CURE is today.

16.20h SIEM evolution, a day in the life of a Security Architect
by Stijn Vande Casteele, Senior Security Architect, Telindus - Belgacom ICT

The business case for a SIEM that was initiated in 2003 has evolved quite significantly. This session will share the different tooling migrations, the different evolutions from an architecture, security operations, services and content evolution perspective. Especially for for Application developers, Architects, SOC employees, Business consultants, Program managers this session highlights the various hands-on experiences from a Security Architect’s perspective.

About : Stijn has spent the last 8 years helping organizations solve information security puzzles. He is currently lead expert for the Security Management offerings within the Telindus Belgacom ICT organization and program responsible for the SIEM multi-tier platforms based on ArcSight ESM and Logger technologies. Stijn received his MSc in Information Security from Royal Hollow, University of London and holds a CISSP certification.

17.00 Beyond IP Addresses. Monitoring Security Risks in Business Processes
by Fabian Libeau, ArcSight

About : Fabian Libeau, EMEA Marketing Director, ArcSight
Fabian has more than 12 years IT security experience and is working in the SIEM space for nine years now. For the last five years Fabian is working for ArcSight in EMEA, first as Principal Architect, now as Marketing Director. Before joining ArcSight, Fabian worked at CA as Principal Architect and VP for SIM solutions in EMEA. Recognized as an expert in the field of IT Security, Fabian is a frequent speaker at security conferences and has worked with global IT companies on major security solution roll-outs. Fabian has a certification as CISSP and ITIL and a master in Physics.

17.30 SIEM Experience and practical implementations in Belgium and Luxemburg
by Dominique Dessy, RSA the Security Division of EMC

About : Dominique (CISSP) has a degree in Computer Science from the Brussels Free University. Worked in various IT positions in companies such as Sun Microsystems, AT&T, SGI, DAD. Started 9 years ago witrh EMC, doing Presales for Enterprise. Moved moved to RSA as BeLux Sales Engineer.

18.10h Experiences from the field and lessons learned. Best Practices in SIEM correlations
By Fabian Libeau, ArcSight

18.30h Panel Discussion & Closing Notes

18.45h Cocktail Reception & Networking

20.00h Close of Event



During this seminar you could learn about some of the following key steps to success : 1. baseline understanding of your security events; 2. “start slowly” tackle perimeter security; 3. deal with alerts. 4. Make sure executives are onboard and have them endorse it. You need all your governance issues clearly laid out before you start deployment.

Next Opportunity

If you like to participate in a future SIEM Seminar, as a speaker or participant, send an email to siem at lsec.be with SIEM interest in the subject line. You will be contacted personally.

Thanks to RSA for supporting this event!


Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< September 2010 >>

S M T W T F S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 1 2

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Bluekrypt

Security Expert in Crypto, Information Security and Training

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: arrowUp

arrowUp - member of the Lykos Group

Expert: Research In Motion - RIM - Blackberry

Research In Motion - RIM - Blackberry

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: Traxion

Traxion - Identity Management - cornerstone for your company

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: Approach

Approach specializes in Application Security, Identity Management and financial transactions.

Expert: Global Knowledge

Global Knowledge is the worldwide leader in IT and business training.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Novell

Comprehensive Identity, Security and Systems Management Solutions.

Expert: Exclusive Networks

Value added Distributor specialized in information security. Operational in Belgium, France, Switzerland and Luxemburg.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: D Soft

D Soft is an expert in electronic distribution of digital documents.

Expert: Scanit

Scanit is an IT security boutique specializing in ethical hacking, penetration testing, vulnerability assessments and security configuration reviews.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: Microsoft

At Microsoft, we're motivated and inspired every day by how our customers use our software to find creative solutions to business problems.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: Intesi

Intesi Belgium is the R&D competence center of Intesi Group, focusing on Internet Security, using state-of-the-art ICT technologies.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Cisco

Cisco Internet Protocol (IP)-based networking solutions are the foundation of the Internet.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: BT - British Telecom

One of the world's leading providers of communications solutions.

Expert: Alcatel Lucent

Alcatel provides communications solutions to telecommunication carriers, Internet service providers and enterprises for voice, data and video.

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: IBM

A world leader in Information Technology with a large professional organization in Belgium and a series of security experts.

Expert: Norkom Technologies

Norkom is a market-leading provider of innovative financial crime and compliance solutions to the global financial services industry.

Expert: Telindus

Telindus has expertise in all aspects of modern telecommunications technology, including LAN, WAN, Internet and e-networking, network access and security, VOIP (Voice over Internet Protocol), VPN, fixed and mobile communications.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.