PDF Download August 22, 2012 Agenda (PDF)

CISO Chicago Summit Agenda
August 22, 2012

Agenda Key
 

Networking Opportunities & Session Breaks

 

Executive Exchange

 

CISO Keynote Presentation

 

CISO Focus Group

 

A visionary speaker addresses the entire summit audience on a topic determined by the CIO Content Committee.

 

Led by a vendor, these sessions allow executives to discuss business drivers within a particular area of technology. Presentations are 15-20 minutes followed by 10-15 minutes of Q&A.

 

CISO Executive Visions

 

Analyst Q&A Session

 

A panel of IT executives has an in-depth discussion on a critical IT business topic. Audience members have an opportunity to pose questions to the panelists and moderator.

 

A high-impact, open-forum session covering the latest technology research and led by a member of our analyst partner community.

 

CISO Thought Leadership

 

Vendor Showcase

 

Led by a member of the vendor community, these sessions will provide an overview of cutting edge technology topics and pressing business concerns.

 

Presented by a member of the vendor community, these sessions are divided into three 10-minute long elevator pitches on the newest technology solutions and services.

 

CISO Think Tank

 

CISO Case Study

 

Focusing on a specific topic or initiative, these interactive, open-forum style sessions allow the attending 15-20 executives to discuss best practices and have lively debates.

 

Learn about recent technology implementations from the IT executives who drove the projects at their organizations. Presentations are followed by Q&A sessions.

 

CISO/CTO Roundtable

 

CISO Open Forum Luncheon

 

An interactive, focused session led by either an analyst, industry expert or member of the vendor community.

 

Led by a moderator, these sessions allow attendees to have informal discussions on pre-determined technology topics.

CISO Chicago Summit

7:00am - 8:00am

Registration & Greeting to the CISO Chicago Summit
Networking Breakfast

Part 1: Making Innovation Real

8:10am - 8:50am

Opening CISO Keynote Presentation

Securing the Mobile Enterprise

Everyday individuals make technology decisions on behalf of their organization by implementing tools that solve their real business problems. Employees are easily adopting unsanctioned services from a number of sources, where they are storing, sharing and managing internal company data. This new paradigm poses a major security challenge for today's enterprises: how can we let technology run rampant through our organizations - technology that is fundamentally improving business outcomes - while still maintaining a coherent IT security strategy?

  • Understand the mobile landscape and where the market is heading
  • Learn how to manage and secure iPhones, Android, webOS and other new devices in your organization
  • Develop an enterprise plan that future proofs your investment

9:00am - 9:30am

Executive Exchange

CISO Thought Leadership

Data Security & Integrity - Gaining Control & Protecting Your Information

Enterprise data security has become a critical issue for business decision-makers when the control over the information is at stake. What can organizations do to secure enterprise data and applications? What strategies and methods can they use to maintain control over who has access to what?

Topics to be discussed:

  • Mechanisms for protecting data
  • Desktop/laptop encryption - benefits and management challenges
  • Privileged Access Management (PAM)
  • HIDS/NIDS (Host Intrusion Detection/Network Intrusion Detection) - how hackers circumvent NIDS.
  • Managing your logs - log correlation
  • Email encryption - manual vs. automated solutions
  • Data Loss Prevention (DLP) - trace your electronic leaks
  • Areas of infrastructure concerns and weak spots
  • Cloud computing and the race to use ASPs - evaluating their security before you jump

9:35am - 10:05am

Executive Exchange

CISO Think Tank

The Business of Cloud Security

As your organization migrates business processes, transactions and assets to the cloud, security and privacy concerns may surface. Knowledge is critical to supporting your business and your client-side demands. This session will provide insights into how to leverage existing practices and incorporate requirements to support transitioning to the cloud, while understanding potential risks, implementing continuous compliance, gaining visibility and realizing the benefits of 24/7 access, reporting, industry expertise, and on-demand flexibility of cloud services.

CISO Think Tank

Myths and Reality of Affordable Storage and Secure Accessibility

Adding storage capacity and lowering costs - do these seems like mutually exclusive propositions? As you evaluate new archiving approaches to address the high cost of storage, such as hosted storage, and new sharing technologies to enable enterprise data - security and privacy will be key considerations.

This session will discuss accelerating enterprise data growth trends and key reasons why many industry leaders are evaluating cost-effective and secure archiving and sharing alternatives.

10:05am - 10:20am

Networking Break

Part 2: Raising the ROI of IT
10:25am - 10:55am Executive Exchange

CISO Thought Leadership

A Guide to Managing Cyber Security Risk

As the U.S. energy infrastructure becomes more advanced it must meet and address cybersecurity challenges along the way. Enterprises will need to research, develop and commercialize a comprehensive range of cybersecurity solutions to strengthen the energy infrastructure against cyber intrusion and assist owners and operators in complying with cybersecurity regulations.

Topics to be discussed include:

  • Pinpoint pressure points for IT security in the utilities industry
  • Discover how to tailor your security compliance strategy through increased awareness
  • Optimize operational security within hostile environments through accurate risk assessment and constructive dialogue
  • Develop cutting-edge intelligence strategies to maximize protection against evolving business security threats

11:00am - 11:30am

Executive Exchange

CISO Thought Leadership

Designing a Strategy for Database Access and Secure Data Access

A relational database management system (RDBMS) is a database management system that is based on the relational model. While relational database systems remain the dominant choice for both transactional and analytical applications, newer structures are competing with RDBMSs in data warehouse applications including column-oriented and correlation database systems. Recently, many organizations are beginning to move to web-based services due to increasing internet reliability, data storage efficiency, and the lack of a need for dedicated IT staff to manage the hardware. This session will discuss the best practices for CISOs when designing a database access strategy.

11:35am - 12:05pm Executive Exchange

CISO Think Tank

Mobility Killed the Desktop Star

Smartphones, tablet computers and other personal devices are connecting to an increasing number of corporate networks and the trend continues to gain momentum. With employers and employees alike expecting 24/7 access to company data, ease of access and convenience need to be balanced with industry, security, and compliance requirements.

The days of corporate IT departments distributing and mandating the technology that employees use are being challenged by a new generation of Bring Your Own Technology (BYOT) workers who want to decide what technology they utilize. The lines between personal and business computing blur, as employees want a single mobile device to meet all of their needs. While most users focus on the 'simplicity' and 'ease of use' of new devices, they rarely understand the associated complex regulatory and legal concerns. PCI, SOX, HIPAA, GLBA mean little to employees, but are a constant focus for IT executives charged with keeping their computing environment secure and compliant.

This interactive discussion will highlight some industry trends and then launch into a candid discussion of how your peers are confronting these challenges. We'll focus on how to enable technology as a competitive advantage, while being mindful of the responsibility of having control over the flow of data.

CISO Think Tank

Power Security and Protection

Smart grid information security and power transmission protection has aspects of both Industrial Control Systems (ICS) as well as Information Technology (IT) Systems. The threat profiles precedes all other security services and differ significantly from threat profiles of other IT functions such as utility customer billing, where confidentiality is a greater concern.

This session will discuss the fact that although both ICS and IT systems require information security services, the specifics of how these services are used for the power grid depend upon appropriate risk assessment and risk control.

12:10pm - 1:10pm

CISO Networking Luncheon

Part 3: Expanding Business Impact

1:15pm - 1:45pm

Executive Exchange

CISO Thought Leadership

Tactical Application Security: Increase Your Security Intelligence and Enterprise Compliance

Too many organizations respond to persistent security threats and burdensome compliance requirements by investing in reactive perimeter controls and implementing tactical application security testing programs that may satisfy regulators, but fall short of consistently protecting the assets and information that are the lifeblood of the business. As these assets are moved to the cloud, there is an even greater need for a more strategic approach to securing the critical applications and data; with all of the benefits of the cloud come new challenges inherent to relinquishing some of the infrastructure and security controls that might exist in your own data center.

Some progressive organizations have begun to adopt software security assurance as a more strategic approach to securing their applications wherever they may originate or reside. Software security assurance is a comprehensive discipline that provides a systematic way to secure applications by delivering the application security intelligence necessary to manage risk in context with the business.

1:50pm - 2:20pm

Executive Exchange

CISO/CTO Roundtable



CISO/CTO Roundtable



CISO/CTO Roundtable



2:25pm - 2:55pm

Executive Exchange

CISO Think Tank

Risk Management and Cost Optimization

Beyond just reacting to the latest security threats, the CIO need to approach security from the standpoint of risk management, at the same time as growth remains a top priority for most enterprises and IT executives are challenged to provide sustainable management support to increasingly complex business models. When addressing the challenges becomes a survivor factor, it is crucial for IT leaders to be more effective. Developing an IT organization that successful can deliver innovative solutions, efficient risk management and pervasive cost optimization, is a key success factor for any operator.

CISO Think Tank

Safe-Cracking the Cloud

A view on architectural cloud strategies for improving IT efficiency and security. Where are the weak spots of the service and what can be done do to prevent illegal access? Are current security systems, integrated with enterprise single-sign-on and Identity Management, enough to secure the cloud?

3:00pm - 4:00pm

CISO Executive Visions

Security, Identity Management and Fraud: Future Proofing the Enterprise IT System

American enterprises are facing a new and unprecedented range of risks. The challenges of the current economic climate are not enough, organizations are under pressure to assure the control and protection of sensitive client and employee information. Factors such as increasingly sophisticated security threats and the sheer pace of technology innovation raise the bar substantially, while longstanding questions about trust and confidence must be asked in a new light. In a time of economic constraint that has affected North American organizations more than many others, how do we deal with these challenges - and how do we prepare for what is yet to come?

Topics to be discussed in this insightful executive panel session:

  • Assuring control of customer information
  • Securing the mobile worker
  • Regulatory compliance
  • Internal risks in light of both internal and external threats
  • Securing SaaS and Cloud Computing environments
  • Data Loss Prevention and related initiatives

4:00pm - 4:15pm

Closing Remarks