<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.mn-issa.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Minnesota ISSA Chapter - Minnesota ISSA Chapter - Serving the Upper Midwest</title>
 <link>http://www.mn-issa.org/frontpage</link>
 <description>ISSA&#039;s mission is to enhance the education and expand the knowledge and skills of its members in the interrelated fields of information systems and data processing; to encourage a free exchange of information security techniques, approaches, and problem solving; to provide adequate communication to keep members abreast of current events in information processing and security; and to communicate to management and to systems and information processing professionals the importance of establishing controls necessary to ensure the secure organization and
utilization of information processing resources.</description>
 <language>en</language>
<item>
 <title>ISSA Meeting</title>
 <link>http://www.mn-issa.org/events/issa-meeting</link>
 <description>&lt;div class=&quot;field field-type-date field-field-date&quot;&gt;
&lt;div class=&quot;field-items&quot;&gt;
&lt;div class=&quot;field-item odd&quot;&gt;
ISSA Meeting
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;
March 16th, 2010&lt;br /&gt;
1:30 PM - 4:00 PM 
&lt;/p&gt;
&lt;p&gt;
Dorsey Ewald Conference Center
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;1000 Westgate Drive&lt;br /&gt;
St. Paul, MN 55114&lt;br /&gt;
Ph: 651-290-6260&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Directions: &lt;a href=&quot;http://www.ewald.com/displaycommon.cfm?an=1&amp;amp;subarticlenbr=54&quot;&gt;&lt;span&gt;&lt;span&gt;http://www.ewald.com/displaycommon.cfm?an=1&amp;amp;subarticlenbr=54&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Speaker:&lt;/strong&gt; Gunnar Peterson
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Title:&lt;/strong&gt; Dealing with the Wildness That Awaits&lt;br /&gt;
&lt;strong&gt;Abstract:&lt;/strong&gt; Inexactitude is a part of software development project, but the problem is which part is inexact? Finding the imperfection in the software you&#039;re building before attackers do is a laudable goal, but also a kind of guesswork. To deal with this issue, we look at the margin of safety as a software engineering tool that leverages our knowledge and skills.&lt;/p&gt;
&lt;p&gt;The fitness of the system is not decided at design time, its ability to withstand attacks is ultimately decided at runtime; but there are concrete design steps that can be taken to build systems that resist and recover from attacks. The combination of Threat Models, which show how the system may fail, and Attack Surface which show where the system is vulnerable, is a starting point for assessing Margin of Safety at design time. The output of the combined Threat Model and Attack Surface is a Countermeasure Model, which identifies and locates the Countermeasures in the system.&lt;/p&gt;
&lt;p&gt;The Countermeasure Model forms the basis of the Margin of Safety by providing testable criteria for the resiliency of both the countermeasures and the system as a whole. This has proven useful in the field for two reasons, one expected and the other more subtle. The expected reason for the utility of the Countermeasure Model is that security gets more challenging each day due to new threats, vulnerabilities, attacker skill, functionality and connectivity. The more subtle reason is that Security Countermeasures are first and foremost a systems integration problem, meaning the resultant Countermeasures, such as access control systems, require architecture, planning, prioritization, and detailed design to effectively integrate with system’s applications, network channels, messages and other constituents. Suffice to say, this is not a linear process, and frequently decisions are not based on technical merits.&lt;/p&gt;
&lt;p&gt;The Margin of Safety concept is used to provide the team with a framework to:&lt;/p&gt;
&lt;p&gt;·   Make security architecture decisions&lt;br /&gt;
·   Communicate security architecture decisions&lt;br /&gt;
·   Provide a concrete basis for building the security architecture&lt;br /&gt;
·   Measure security architecture effectiveness&lt;br /&gt;
·   Manage security architecture lifecycle&lt;/p&gt;
&lt;p&gt;In this talk we will take an end to end example of a portion of security architecture from design time (using Threat Models and Attack Surface to build a Countermeasure Model), reviewing the Margin of Safety; and then examine how these are applied in deployment and runtime policies and security mechanisms. This being a security talk, we will wrap up discussing  how this all goes wrong when the rubber meets the road, specifically what failure modes are present in current Web service implementations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;BIO: &lt;/strong&gt;Gunnar Peterson is a Managing Principal at Arctec Group. He is focused on distributed systems security for large mission critical financial, financial exchanges, healthcare, manufacturer, and insurance systems, as well as emerging start ups. Mr. Peterson is an internationally recognized software security expert, frequently published, an Associate Editor for IEEE Security &amp;amp; Privacy Journal on Building Security In, a contributor to the SEI and DHS Build Security In portal on software security, a Visiting Scientist at Carnegie Mellon Software Engineering Institute, and an in-demand speaker at security conferences. He maintains a popular information security blog at&lt;span class=&quot;Object&quot;&gt;&lt;a href=&quot;/&quot; target=&quot;_blank&quot;&gt;http://&lt;/a&gt;&lt;/span&gt;&lt;span class=&quot;Object&quot;&gt;&lt;a href=&quot;http://1raindrop.typepad.com/&quot; target=&quot;_blank&quot;&gt;1raindrop.typepad.com&lt;/a&gt;&lt;/span&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span class=&quot;Object&quot;&gt;&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Speaker:&lt;/strong&gt; Brian Tokuyoshi
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt; Title:&lt;/strong&gt; Too Many Encryption Keys
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Abstract:&lt;/strong&gt; In the effort to meet compliance goals and to encrypt more information, companies are deploying a greater number of encryption products. However, as many companies are discovering, the inconsistencies of tools and policies for managing encryption keys are creating a growing administrative problem. Could the deployment of too many encryption products and the lack of centralized policy increase the risk of data loss?
&lt;/p&gt;
&lt;p&gt;
In this session, learn about the ins &amp;amp; outs of key management. Brian will discuss the problem of too many encryption keys, dig into the architectures behind enterprise key management, and go over strategies to get the problem under control for better centralized management in the future.
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;BIO:&lt;/strong&gt; Brian Tokuyoshi is a Solution Manager for PGP Corporation, overseeing the server products. He has a 14 years of expertise in data encryption, identity management, smart cards and enterprise messaging. Prior to PGP, Brian served as Product Marketing Manager for ActivIdentity, where he oversaw the smart card management systems and strong authentication solutions.  He was part of the team that launched the Sun Identity Management platform, and also served as the senior market analyst for The Radicati Group, covering the PKI and directory server markets.
&lt;/p&gt;
&lt;p&gt;&lt;/span&gt;&lt;/p&gt;
</description>
 <category domain="http://www.mn-issa.org/taxonomy/term/3">Meetings</category>
 <pubDate>Fri, 22 Jan 2010 16:00:49 -0600</pubDate>
 <dc:creator>lalamri</dc:creator>
 <guid isPermaLink="false">289 at http://www.mn-issa.org</guid>
</item>
<item>
 <title>View Open Positions</title>
 <link>http://www.mn-issa.org/resources/career-area/view-open-positions/view-open-positions</link>
 <description>&lt;p&gt;
Members of MN-ISSA and Sponsors are able to post resumes or open positions within their organization on the Minnesota ISSA web site.  If you are interested in doing so, please submit your resume / open position to the &lt;a href=&quot;mailto:webmaster@mn-issa.org&quot;&gt;webmaster&lt;/a&gt;.  
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;/sites/mn-issa.org/files/Fortify%20Pre-Sales%20Software%20Security%20Consultant.pdf&quot;&gt;Pre-Sales Security Consultant - Fortify Software&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;/resources/career-area/view-open-positions/rsa-the-security-division-of-emc-associate-technology-cons&quot;&gt;RSA, The Security Division of EMC - Associate Technology Consultant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;/resources/career-area/view-open-positions/information-security-solution-architect/information-securi&quot;&gt;Information Security Solution Architect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;/resources/career-area/view-open-positions/senior-security-sales-engineer/senior-security-sales-engin&quot;&gt;Senior Sales Engineer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;/resources/career-area/view-open-positions/security-architect-des-moines/security-architect-des-moine&quot;&gt;Security Architect&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
 <pubDate>Wed, 24 Dec 2008 12:48:35 -0600</pubDate>
 <dc:creator>sstaubin</dc:creator>
 <guid isPermaLink="false">154 at http://www.mn-issa.org</guid>
</item>
<item>
 <title>Speaking Opportunities</title>
 <link>http://www.mn-issa.org/resources/speaking-oportunities/speaking-opportunities</link>
 <description>&lt;p&gt;
Feedback is obtained at each meeting as to what topics are of interest.  Below are the top requests:
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;PCI requirements / solutions&lt;/li&gt;
&lt;li&gt;Forensics&lt;/li&gt;
&lt;li&gt;Attack methods / defense&lt;/li&gt;
&lt;li&gt;Database security and best practices&lt;/li&gt;
&lt;li&gt;Application Security&lt;/li&gt;
&lt;li&gt;Awareness&lt;/li&gt;
&lt;li&gt;Penetration testing&lt;/li&gt;
&lt;li&gt;Data loss prevention&lt;/li&gt;
&lt;li&gt;Security architecture&lt;/li&gt;
&lt;li&gt;End-point intelligence&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you are able to present on any of the above topics, please contact the &lt;a href=&quot;mailto:program-director@mn-issa.org&quot;&gt;program director&lt;/a&gt;.&lt;/p&gt;
</description>
 <pubDate>Fri, 05 Sep 2008 11:34:18 -0500</pubDate>
 <dc:creator>sstaubin</dc:creator>
 <guid isPermaLink="false">102 at http://www.mn-issa.org</guid>
</item>
</channel>
</rss>
