RSA Conference 2012

USA 2012

February 27 - March 2

Moscone Center

San Francisco

Monday Events

RSA Conference Events

Association Events

Seminars

return to top

RSA® Conference offers a full day of seminars at no additional charge to full Conference delegates.

SEM-001 – Security Basics Seminar - 3 Years or Less Experience - Full Day
8:30 AM - 5 PM

Overview:
Security Basics is a day long course that explains some of the most important security principles and technologies. The program is designed for practitioners with less than three years of information security experience or those new to the field. It is engineered to lay a foundation of essential concepts that will enhance your understanding of the more advanced security issues that will be discussed during RSA Conference week. Taught by some of the top RSA Conference speakers and leaders in the space, this is a true jump start to the week. Sessions will be 35 minutes with 10 minutes for Q&A. Topics include:

  • Business of Security
  • Crypto 101/Encryption Basics, SSL & Certificates
  • Authentication Technologies
  • Application Security
  • Viruses, Malware and Threats
  • Mobile Security
  • Governance, Risk and Compliance
  • Firewalls and Perimeter Protection
  • Professional Development
View Agenda
close

8:30 - 9:30 AM Introduction & The Business of Security
SPEAKER: Hugh Thompson, Chief Security Strategist, People Security

9:30 - 10:15 AM Crypto 101/Encryption Basics, SSL & Certificates
SPEAKER: Ben Jun, VP of Technology, Cryptography Research Inc.

10:15 - 10.30 AM Break

10:30 - 11:15 AM Authentication Technologies
SPEAKER: Bill Duane, Distinguished Engineer, Office of the CTO, RSA, The Security Division of EMC

11:15 AM - 12:00 PM Application Security
SPEAKER:
Jason Rouse, Principal Consultant, Cigital, Inc.

12 - 1 PM  Break for Lunch

1 - 1:45 PM Viruses, Malware and Threats
SPEAKERS: Dawn Cappelli, Technical Manager, CERT Insider Threat Center, Software Engineering Institute CERT Program; Juan Montelibano, Team Lead, Insider Threat Technical Solutions and Standards at Carnegie Mellon University

1:45 - 2:30 PM Mobile Security
SPEAKER: Alex Stamos, Founding Partner, iSEC Partners

2:30 - 3:15 PM Governance, Risk and Compliance
SPEAKER: Justin Peavey, Chief Information Security Officer, Omgeo (A DTCC I Thomson Reuters Company)

3:15 - 3:30 PM Break

3:30 - 4:15 PM Firewalls and Perimeter Protection
SPEAKER: Christofer Hoff, Senior Director, Juniper Networks

4:15 - 5 PM Professional Development
SPEAKER: Mike Gentile, Founder & CEO, Delphiis

Back to Top

SEM-002 – Improving Application Security Seminar - Full Day
8:30 AM - 4:30 PM

Sponsored by

HP

Overview:
Building security into applications is a much less expensive proposition than trying to add security late in the software development lifecycle. Through demonstration and lecture, you will learn about a broad variety of security issues as well as prevention techniques/countermeasures.

View Agenda
close

8:30 - 8:40 AM Truth or Fiction: The rise of software vulnerabilities and the impact the vulnerabilities have on organizations
SPEAKER: Kathy Kriese, Principal Product Manager, Symantec Corporation

8:40 - 9:30 AM Security in the Software Development Lifecycle: For each lifecycle stage, what are the activities and responsibilities?
SPEAKER: Brad Arkin, Senior Director, Product Security and Privacy, Adobe

9:30 - 10:15 AM Secure Design Principles: Defense in depth, least privilege, compartmentalization, guest/tenant isolation, reduction of attack surface, fail-secure, no reliance on client-enforced security, secure interoperability, secure-by-default
SPEAKER: Paco Hope, Technical Manager, Cigital, Inc.

10:15 - 10:30 AM Break

10:30 AM- 12 PM Secure Coding: Demonstrate issues and illustrate prevention/remediation techniques.
SPEAKERS: Alexander Hoole, Principal Security Researcher, Fortify, an HP Company; Jacob West, Director of Security Research, Fortify, an HP Company

12 - 1 PM Break for Lunch

1 - 2 PM Secure Coding: Demonstrate issues and illustrate prevention/remediation techniques.
SPEAKERS: Alexander Hoole, Principal Security Researcher, Fortify, an HP Company; Jacob West, Director of Security Research, Fortify, an HP Company

2 - 3:10 PM Security Testing: Fuzzing, threat modeling, benefits/limitations of testing techniques, source code scanning, vulnerability scanners.
SPEAKER: Chris Eng, Vice President of Research, Veracode, Inc.

3:10 - 3:25 PM Break

3:25 - 4:10 PM Vulnerability Response: Representatives for defined roles, third-party tracking, regression testing, root cause analysis, patches - creation and communication.
SPEAKER: Katie Moussouris, Senior Security Strategist Lead, Microsoft Corporation

4:10 - 4:30 PM Security Resources: CERT, NIST, RSA Labs, RSA Share Community, (ISC)2 and more.
SPEAKER: Kathy Kriese, Principal Product Manager, Symantec Corporation

Back to Top

SEM-003 – Information Security Leadership Development: Surviving as a Security Leader Seminar - Half Day
8:30 - 11:30 AM

Overview:
In traditional security training, there are few opportunities to learn how to develop and direct a successful information security program. Experienced security leaders deliver a morning seminar focused on bridging this gap.

Topics include:

  • Building Blocks of a Security Program
    • 20/20 Hindsight
    • Assessing the Program’s Maturity
    • Presenting Metrics to the Executive Team
  • Security Program Strategy
    • Establishing a Program Roadmap
    • Sneaking Security In
  • CISO Roundtable: Tearing Down the Security Empire
View Agenda
close

8:30 - 9:50 AM Building Blocks of a Security Program

  • 20/20 Hindsight
    The morning starts off with a review of various experiences leading a large security program with a focus on key lessons learned along the way. The best way to prepare you to lead a security program is to observe several different approaches to the role, and benefit from successes and failures of others. Learn how to keep the agenda of the security program moving forward while avoiding the common pitfalls that can threaten a new information security officer. Join these long-time security leaders as they share their tips for managing a successful program through the lens of their own experiences.
  • Speaker: Dennis Devlin, Assistant Vice President, Information Security and Compliance Services, The George Washington University; Joseph Hammer, Managing Director of Technology and Information Risk, Morgan Stanley
  • Assessing the Program’s Maturity
    Building a program from scratch can be difficult, but more often new security leaders will inherit an existing program in various stages of maturity.  Dealing with this baggage of previous decisions and directions that may not align well with the business can be very challenging.  Learn from the experience of successful security leaders how to first assess the various aspects of the existing program, and decide where to focus your resources.  The desire to fix previous directional mistakes needs to be balanced with the turmoil that too many changes can have on an organization.
  • Speaker: Mark Clancy, CISO, Depository Trust & Clearing Corporation (DTCC)
  • Presenting Metrics to the Executive Team
    Everyone talks about security metrics, but deciding which metrics will be meaningful to senior management can be difficult.  Good metrics can demonstrate the value of a security program through a reduction in risk exposure and cost savings, and the right metrics can also highlight the urgency of certain focus areas or drive process improvements. This session covers how to generate and package meaningful security metrics that are appropriate for executive management or board level presentations.
  • Speaker: John Johnson, Global Security Program Manager, John Deere

9:50 - 10:30 AM - Security Program Strategy

  • Establishing a Program Roadmap
    Now that you know what not to do, the seminar focuses on a roadmap that will guide you during the first few years of your new program.  Often, security leaders will have two plans: one that they share with the organization in general terms, and one that they keep to themselves with milestones for the program’s growth and success.  In this session attendees will learn how to balance the objectives and strategies that you share with the organization, versus those you should keep close to the chest as you influence and shape the culture of the organization.
  • Speaker: Justin Peavey, CISO, Omgeo (A DTCC I Thomson Reuters Company)
  • Sneaking Security In
    So often information security is one of the most visible programs in an organization through the various controls, assessments, awareness efforts, and this is intentional.  This session presents several strategies for relieving some of the perceived burden of information security within the organization by leveraging existing business activities to meet security objectives.  Perception is everything, and it is amazing what can be accomplished without ever invoking the dreaded security or compliance mandates.
    • Speaker: Evan Wheeler, Director InfoSec, Omgeo (A DTCC I Thomson Reuters Company)

10:30 - 10:40 AM Break  

10:40 - 11:10 AM Leadership Roundtable: Tearing Down the Security Empire
Many security programs get caught up in the mode of ever expanding the security team to take on every aspect of information security across the organization.  Then inevitably it will go through some level of reorganization to better align these activities with similar functions in other teams.  The security team may grow, then be broken up and dispersed, and then sometime reformed.  Join this panel of experienced security leaders as they debate how to balance the growing responsibilities of information security as a function with the desire to manage a lean and mean security team that is focused on oversight and guiding strategy.  The pros and cons of several approaches will be discussed, including outsourcing security functions and decentralizing security responsibilities to better leverage capabilities in other teams.

  • Moderator: Evan Wheeler, Director InfoSec, Omgeo (A DTCC I Thomson Reuters Company)
  • Panelist: Dennis Devlin, Assistant Vice President, Information Security and Compliance Services, The George Washington University; John Johnson, Global Security Program Manager, John Deere; Justin Peavey, CISO, Omgeo (A DTCC I Thomson Reuters Company); Mark Clancy, CISO, Depository Trust & Clearing Corporation (DTCC); Joseph Hammer, Managing Director of Technology and Information Risk, Morgan Stanley

11:10 - 11:30 AM Questions & Answers

Back to Top

Professional Development Track Sessions

return to top

RSA® Conference offers the Professional Development track at no additional charge to full Conference delegates.

PROF-001 – Stress and Burnout in the Information Security Community
12:30 - 1:40 PM

Moderator: Jack Daniel, Product Manager, Tenable Network Security, Inc.
Panelists: Joshua Corman, Director, Security Intelligence, Akamai Technologies; Martin McKeay, Security Evangelist, Akamai Technologies, Gal Shpantzer, Information Security Consultant, Independent Consultant; Stacy Thayer, Field Consultant, Veracode, Inc.

Abstract: Stress, burnout, rage, despair- all common experiences to many in the information security community. This panel will discuss the issues, compare and contrast them to other industries including releasing survey data to compare stress levels in infosec to other professions. We will also discuss how to recognize stress in ourselves and others, and steps that can be taken to combat it.

PROF-002 – Smart Investments: Workforce Development Programs Working for You
2 - 2:50 PM

Speaker: Rosa Ayer, IT Specialist, Department of Veterans Affairs; Angela Seal-Guinn, Supervising Program Lead, Department of Veterans Affairs

Abstract: An information security professional's work never ends. With constant demands of new technology, sophisticated threats, and a challenging economy how do you stay current and keep up with work demands? Learn about the U.S. Department of Veterans Affairs' professional development program that provides clear career paths and 24/7 training to support 400 information security officers nationwide.

PROF-003 – Making a Career Move, Developing Your Approach
3:10 - 4 PM

Speaker: Jeff Combs , Director, Acumin US

Abstract: Starting a job search can be a daunting task and many job seekers don't know how to put their best foot forward. This session will give an overview on how hiring managers and recruiters evaluate candidates, help candidates define the qualities that make them stand out and provide insights on how to "product manage" one's professional assets.

PROF-004 – Becoming a Change Agent in a World Where Change Never Ends
4:20 - 5:30 PM

Moderator: Lisa Lee, IT Examiner, Office of the Comptroller of the Currency
Panelists: Michelle Dennedy, Founder, iDennedy Project; Aimee Larsen Kirkpatrick, Director of Communications & Outreach, National Cyber Security Alliance; Patricia Titus, VP and CISO, Symantec Corporation; Pamela Warren, Independent Consultant, Independent Consultant

Abstract: What we have been doing in security isn't working. A paradigm shift is needed to recognize how integral security, privacy and risk management should be in business decisions. Security and privacy practitioners need a battle plan for becoming change agents to drive this shift in thinking. Discover strategies that foster sustainable excellence in a world of constant change.

Back to Top

Innovation Sandbox

return to top

1 - 6 PM

Overview:
Innovation Sandbox is an exciting half-day program where you can explore the new technologies that promise to transform the information security industry, now and in the future. Innovation Sandbox will feature sessions such as:

  • Demonstrations from information security’s new rising stars
  • The “Most Innovative Company at RSA Conference 2012” contest, judged by a panel of industry experts and thought leaders
  • Interactive whiteboard sessions on tomorrow’s security challenges, facilitated by industry experts
  • Our Start-up Speed Dating session: here’s your chance to sit face-to-face with venture capitalists and angel investors to pitch your company’s innovative technologies, share your vision and summarize your business plan
  • Talk to labs staff and see what lies ahead

Open to Delegate and Expo Plus registrants only.

More Info

Back to Top

Association Events

return to top
CSA-001 – Cloud Security Alliance Summit 2012
9 AM - 1 PM

Speakers: Baber Amin, Senior Director of Product Management, CA Technologies; Dave Asprey, Vice President of Cloud Security, Trend Micro; Philippe Courtot, Chairman and CEO, Qualys, Inc.; Marc S. Crandall, JD, CIPP, Senior Manager of Global Compliance, Enterprise, Google; Don Godfrey, Security Consultant, Humana; Patrick Harding, CTO, Ping Identity; Steve Herrod, CTO and Senior VP of R&D, VMware; Ron Huddleston, Senior Vice President, ISV Alliances, salesforce.com; Matt Johansen, Threat Research Center Manager, WhiteHat Security; Girish Juneja, Director of Application Security and Identity Products, Intel; Ashvin Kamaraju, VP Product Development, Vormetric; Chris Kemp, Founder and CEO, Nebula Inc., former CTO, NASA; David Lingenfelter, Information Security Officer, Fiberlink; Tim Mather, Advisory Director, KPMG; Mike McConnell, Vice Chairman of Booz Allen Hamilton and former Director of National Intelligence & former Director of the National Security Agency; Chris Wysopal, CTO, Veracode.

Abstract:
The global compute utility is coming sooner than forecasted, promising to disrupt IT and information security entirely. The CSA Summit 2012 will once again rock RSA Conference with new research and compelling keynotes from thought leaders in industry and government. Several exclusive announcements will be made at CSA Summit 2012 regarding new research, provider certification, standards and pragmatic lessons learned from leading cloud customers.

The CSA Summit 2012 provides a fantastic opportunity for you to ask questions and learn from experts who are designing and implementing cloud security technologies.

Back to Top

TCG-001 – The Paradox of Security: Is the Status Quo Acceptable?
10 AM - 2 PM

Speakers: Leslie Anderson, General Dyamics; Paul Bartock, NSA; James Clifford, Las Alamos National Laboratory; Jason Cox, Seagate; James Greene, Intel Corporation; Steve Hanna, Juniper Networks; Thi-Nugyen Huu, WinMagic; David Lennon, Lumeta Corporation; Rick Kagan, Infoblox; Shawn Mullen, IBM; Steve Orrin, Intel Corporation; Nicolas Ponsini, Trusted Logic Mobility; Michael Willett, Samsung

Abstract:
The market of security is in a state of misshapen chaos. In a world where users sign end-user license agreements that give away their personal identity and will buy a "cool" device that limits user choice on what they can do with that device, TCG and its members provide industry accepted security solutions to any platform. Learn how to use a hardware root of trust as an anchor for data leak and malware prevention; platform integrity; device and user identity; and network access.

Back to Top

Remember to join the conversation:

About

Registration

Agenda & Sessions

Expo

Sponsors

Travel & Venue

For Speakers

FAQs

Join the Mailing List

Contact Us