Dan Kaplan, a senior editor at SC Magazine, wrote an excellent piece on the evolving role of the security manager and the value of security certification and training, in this month's "20th Anniversary" issue of SC Magazine. Dan included some of my comments, as well as those of other security leaders and innovators. Worth a read.
[Read the SC Magazine Article here.] [2nd Link]
The commentary of a security heretic, skeptic and wayward scientist.
For my part I know nothing with any certainty, but the sight of the stars makes me dream. -Vincent Van Gogh
Showing posts with label 2009. Show all posts
Showing posts with label 2009. Show all posts
Friday, November 20, 2009
Tuesday, October 20, 2009
Friday, July 17, 2009
Preparing for Black Hat 2009

The Black Hat USA 2009 conference begins in less than two weeks. I'm excited, but have a lot of preparation to do! I will be on a panel on Tuesday, and the executive briefings and then I am on a panel Wednesday morning.
I'm planning on a long week, and since I'm staying the weekend, I'll have time to relax and enjoy myself. There are lots of interesting topics for Black Hat and DEFCON. If you're going to be there, drop me a line!
Monday, April 27, 2009
RSA Conference 2009

I was just reading this article (LINK) about the 2009 RSA Conference, held in San Francisco last week. I haven't spoken to my friends, who organize the the conference yet (OFFICIAL SITE), but it seems that numbers were somewhat down as expected this week, due to the economy.
I spent the last week here, in Moline, at my desk. As it turns out, I have a huge number of projects going on that need me here, and so our new travel policy (not to travel) made sense to me. I was happy to stay here, keep working (and keep my job!) But, I must say, I was a bit nostalgic, since this would have been my 10th conference. I think having missed this year, 2010 will be even better. I can only hope that the economy improves and that this great venue for information security doesn't dry up and fade away! We probably can't ever have things the way they were five or ten years ago, but for many of us, this is the one chance we get to meet up with all of our friends, catch up and review what's new in the security industry.
Friday, March 13, 2009
Security & Privacy - In the Cloud
I am posting the slides from my Cloud Computing talk today. A slide show that you can view, and if you want my full deck you just have to email me or Tweet, with your version of PowerPoint or format choice.
I finished up the slides, and added the Larry Ellison audio last night at midnight, so I got to bed after 1am and then got about three hours of sleep before driving the 3 hours to Springfield (IL). This was for the Infragard conference on data protection (see below). We had about 160 people turn out, from all industry sectors. Including: police, federal, agriculture, banking, schools and colleges... Our keynote speaker was excellent (John Bace, of Gartner). We wrapped up around 4pm and I just got back from the return drive. I'm heading off for a nap, and may comment more later. For now, my eyes are bugging out from writing these slides up in one marathon session yesterday. I thought my talk went well, I hope you find the slides somewhat useful.
Click here for the slides. [2.8Mb - 2007 compatible]

I finished up the slides, and added the Larry Ellison audio last night at midnight, so I got to bed after 1am and then got about three hours of sleep before driving the 3 hours to Springfield (IL). This was for the Infragard conference on data protection (see below). We had about 160 people turn out, from all industry sectors. Including: police, federal, agriculture, banking, schools and colleges... Our keynote speaker was excellent (John Bace, of Gartner). We wrapped up around 4pm and I just got back from the return drive. I'm heading off for a nap, and may comment more later. For now, my eyes are bugging out from writing these slides up in one marathon session yesterday. I thought my talk went well, I hope you find the slides somewhat useful.

Wednesday, February 11, 2009
Teaching in 2009
Is it common for security professionals to have their (corporate) day job, and teach/write/speak in their spare time? I have my teaching schedule pretty well laid out for 2009. I will be teaching astronomy (16-week, 4 credit) in the Spring and Fall semesters for Scott Community College, and shorter Summer semester courses for SCC and St. Ambrose. The St. Ambrose course is 8 nights over 8 weeks, starting at the beginning of May, for 3 credits.
In addition, I am in discussions with a company in India to design two graduate security courses for an online university. The titles are, "Information Security Challenges and Solutions (3 sem. cr.)" and "Information Security Governance (3 sem. cr.)". If the timeline and price is agreeable, I may start on those yet this month.
Besides teaching, I will be giving an hour talk at the "Springfield Infragard Conference" on March 13th, in Springfield, Illinois on the topic of "Security, Privacy and Cloud Computing". (Yet to be written.) So, I should be kept pretty busy through the summer at least, which is a consolation since my company has decided to cut back on travel this year, and I won't be attending the 2009 RSA Conference in San Francisco. That's an excellent conference, and I will miss it, but I do plan on attending Black Hat Briefings in Las Vegas, in early August. I will be on a pre-conference panel, and I'll pay my own way if I have to.
In addition, I am in discussions with a company in India to design two graduate security courses for an online university. The titles are, "Information Security Challenges and Solutions (3 sem. cr.)" and "Information Security Governance (3 sem. cr.)". If the timeline and price is agreeable, I may start on those yet this month.
Besides teaching, I will be giving an hour talk at the "Springfield Infragard Conference" on March 13th, in Springfield, Illinois on the topic of "Security, Privacy and Cloud Computing". (Yet to be written.) So, I should be kept pretty busy through the summer at least, which is a consolation since my company has decided to cut back on travel this year, and I won't be attending the 2009 RSA Conference in San Francisco. That's an excellent conference, and I will miss it, but I do plan on attending Black Hat Briefings in Las Vegas, in early August. I will be on a pre-conference panel, and I'll pay my own way if I have to.
Thursday, October 16, 2008
Security Goals for 2009
I was caught off-guard today by the announcement that the RSA Conference submission deadline is coming up in a week! I need to decide if I will submit any of the successful (interesting? timely?) projects I have worked on in the past year for consideration. I would love to present at the April 2009 conference in San Francisco. I was sick this past year, and kind of bounced around dosed up on Nyquil all week!
Besides this great conference, I was involved in the Black Hat 2008 conference in Las Vegas this past summer. It was good to serve on a panel for the executive briefings. So, if I can't get a paper submitted (my employer isn't always keen on discussing projects publicly), maybe I will be able to serve on a committee or panel. I was on the RSA Conference organizing committee this past year, and it was a great experience.
I finish my year as chariman of the IA-IL IEEE Section in January, and become past-chair. I still remain active in the Quad Cities Engineering and Science Council, and I am working on bringing in a speaker for the local Putnam Museum in November. I am also working on starting a "Computer Society" chapter for IEEE locally. If all works out, I will have a meeting in November at St. Ambrose University to kick that off!
For the coming year, I am serving as treasurer for the FBI Infragard board (Springfield Chapter). I am also the education chair for the IEEE for Region 4 (midwest). I think these things will keep me pretty busy. I have enjoyed my involvement with IEEE the past several years, as a board member, and it was great to spend a week in Quebec City in September for our Sections Congress. In addition to computer security, it is a great opportunity to promote general science and engineering, and critical thinking skills with K-12 and all members of the local community.
That's my update. I will try to use this space as my "professional" blog, and keep it updated with events I am participating in, and my commentary on topics related to computer security.
Besides this great conference, I was involved in the Black Hat 2008 conference in Las Vegas this past summer. It was good to serve on a panel for the executive briefings. So, if I can't get a paper submitted (my employer isn't always keen on discussing projects publicly), maybe I will be able to serve on a committee or panel. I was on the RSA Conference organizing committee this past year, and it was a great experience.
I finish my year as chariman of the IA-IL IEEE Section in January, and become past-chair. I still remain active in the Quad Cities Engineering and Science Council, and I am working on bringing in a speaker for the local Putnam Museum in November. I am also working on starting a "Computer Society" chapter for IEEE locally. If all works out, I will have a meeting in November at St. Ambrose University to kick that off!
For the coming year, I am serving as treasurer for the FBI Infragard board (Springfield Chapter). I am also the education chair for the IEEE for Region 4 (midwest). I think these things will keep me pretty busy. I have enjoyed my involvement with IEEE the past several years, as a board member, and it was great to spend a week in Quebec City in September for our Sections Congress. In addition to computer security, it is a great opportunity to promote general science and engineering, and critical thinking skills with K-12 and all members of the local community.
That's my update. I will try to use this space as my "professional" blog, and keep it updated with events I am participating in, and my commentary on topics related to computer security.
Subscribe to:
Posts (Atom)