The CISO Executive Summit stands out for the open collaboration and sharing it enables among peers. It is truly a unique format that allows security leaders an opportunity to make each other better.
Dr. Peter Tippett, an information security pioneer and inventor of the program that became Norton AntiVirus, explains where security professionals should put their time and money in order to effectively and efficiently protect their data. Using results from the Verizon 2009 Data Breach Investigations Report (a comprehensive review on forensics and computer crime investigations, gathered from more than 600 cases over five years), Dr. Tippett will share real data and fresh insight into day-to-day security and compliance struggles within the enterprise.
Session discovery topics: • What are the best methods to mitigate security vulnerabilities • How can organizations protect themselves from increasingly sophisticated cybercrime techniques • Who are these data thieves and what kind of companies do they target • Which poses the bigger danger — insider threats or partner companies
IT risk management projects compete for dollars with projects that deliver functionality to grow the business. Drawing upon lessons learned at Nationwide from developing a revised risk model, Mathews Thomas and Lisa Hodkinson will discuss how business leaders assess whether they’re spending too little or too much to mitigate risks.
Session discovery topics: • Indentifying pitfalls of qualitative labels • Quantifying risks — moving from labeling to estimating expected dollar value for information risks • Utilizing risk modeling to show level of risk the business is assuming • Taking the next step — defining limits and risk correlations
Increased commoditization of virtualized computing coupled with a heightened demand for real-time capabilities are creating an entirely new market and service experience for the enterprise to contend with. In order to help shape and guide technology selection and behaviors, these elements must first be understood in a business context. In this session, Richard Puckett will illustrate many of the organic externalization drivers underway in the industry, ranging from cloud, collaboration and social networking trends, while highlighting leading challenges, risks and benefits.
Securing mobile technologies at the enterprise level has surfaced as a leading objective for IT security organizations. Burdened with a myriad of security challenges, the task of rolling out a successful, effective and secure mobility program is an intricate and intimidating process. In the working stages of securing a mobile technology platform, Steve Collignon will share best practices and lessons learned as Cardinal Health heads towards a significant consumerization implementation: bring your own PC.
Session discovery topics: • Identifying business needs — impact of the evolution of technology • Considering cost pressures • Analyzing key policy decisions — challenges and successes • Visioning the end-goal — what’s next
With security perimeters expanding into an environment where data and internet access are always available, the risk landscape is quickly evolving. The need to revisit fundamental building blocks for a data security strategy should be a priority for security organizations to facilitate the implementation of data loss prevention solutions. Join Stacy Mill as she outlines her four “E” strategy to developing a thoughtful and decisive data security program.
Session discovery topics:
• Educate — understanding internet and data presence • Enable — implementing proper controls • Enforce — moving towards a renewed DLP strategy • Evolve — transforming posture to meet business needs
The role of information security is continually shifting, bringing the CISO along for the ride. Driving a mobility strategy is the next big mountain to climb for many security organizations. The consumerization of IT has required CISOs to face the task of developing an agile program that delivers business value.
Additionally, the marketing initiatives and hype surrounding cloud computing shows little sign of diminishing. Understanding challenges, identifying security benefits and exploring third-party options that coincide with your company’s objectives is essential to a successful migration to cloud environments.
Utilizing diversified perspectives from the attendees, Leo Cronin, Edward McMillan, Mathews Thomas and Greg Zimmerman will lead interactive roundtable discussions addressing these top-of-mind topics.
The steady collaboration between law enforcement and public and private sectors is integral to maintaining awareness and control over cyber crime. As threats to IT security infrastructures increase, understanding the FBI’s protocols and involvement is more relevant than ever before. Special Agents Daniel Kilbourne and Corey Collins will discuss the nature of information sharing and the processes through which they lead efforts to diminish and mitigate security breaches.
Session discovery topics: • Methods of distributing and receiving information — how is information utilized • Steps taken when a possible crime is reported • Myths surrounding the FBI’s interaction with private industries
The golden arches of McDonald’s represent one of the most recognized brands in history. Serving more than 60 million customers daily in 117 countries, consumer confidence is critical to the McDonald’s brand. As such, IT security can have a huge impact on brand confidence and protecting shareholder value, and no one knows this more than Marc Varner, CISO for McDonald’s Corporation. What Varner also understands is that McDonald’s size — an estimated 1.7 million employees — represents a great deal of information security risks. To combat these risks, Varner has implemented a governance plan which is helping to drive a global strategy and direction. In this session, Varner will share prior experience concerning brand and reputational loss, the speed at which these circumstances can occur, and what he’s doing to ensure that McDonald’s customers, shareholders and employees are never affected by such events.