Enterprise Preparedness Using Our National Preparedness Standard

Donald Schmidt; Preparedness, LLC, CEO
Business continuity and disaster recovery planning are important elements of an enterprise preparedness program, but they are not the only elements. This presentation, by the chair of the technical committee that writes NFPA 1600 “Standard on Disaster/Emergency Management and Business Continuity Programs,” will identify the essential elements of an enterprise preparedness program. The discussion will focus on NFPA 1600’s current edition and the upcoming 2010 edition.
Oct 6 2009
42 mins
Enterprise Preparedness Using Our National Preparedness Standard

Webinars and videos

  • Live and recorded (1009)
  • Upcoming (31)
  • Date
  • Rating
  • Views
  • In this session, we look at the issues with testing and audit. This is the base causes of why we fail to secure systems and how we can more effectively create methodologies that actually find flaws. Penetration tests and audit each have major failings, but when done correctly and with the right incentives, they can help make us more secure. When done poorly, we all suffer.
  • Zac Streelman, Manager, Information Technology at Leupold and Stevens was looking for a disaster recovery (DR) solution that would extend the flexibility of virtualization to his DR environment. The solution had to deliver enterprise-class support for his mission critical applications: Oracle, Microsoft SQL Server and SharePoint and various CAD programs. The board of directors was specifically asking what the current solution was and what service levels could the infrastructure deliver.
    Zerto Virtual Replication installed seamlessly into their existing infrastructure, did not require any data center updates and is fully integrated into VMware vCenter.

    With Zerto Virtual Replication he was able to:
    - Realize very aggressive service levels – recovery point objectives of seconds and recovery time objectives of minutes
    - Deliver a better ROI with a DR solution that is hardware agnostic
    - Increase team productivity with a very simple solution
    - Quickly cross-train additional staff on DR processes and procedures
    - Optimize flexibility as changes to the environment required changes to the DR strategy
    - Test and validate the DR failover process without taking primary production systems offline

    Join Zac Streelman, Manager, Information Technology at Leupold and Stevens and Jennifer Gill, Director of Product Marketing at Zerto, to hear from your peers and learn about Zerto Virtual Replication.
  • Zac Streelman, Manager, Information Technology at Leupold and Stevens was looking for a disaster recovery (DR) solution that would extend the flexibility of virtualization to his DR environment. The solution had to deliver enterprise-class support for his mission critical applications: Oracle, Microsoft SQL Server and SharePoint and various CAD programs. The board of directors was specifically asking what the current solution was and what service levels could the infrastructure deliver.
    Zerto Virtual Replication installed seamlessly into their existing infrastructure, did not require any data center updates and is fully integrated into VMware vCenter.

    With Zerto Virtual Replication he was able to:
    - Realize very aggressive service levels – recovery point objectives of seconds and recovery time objectives of minutes
    - Deliver a better ROI with a DR solution that is hardware agnostic
    - Increase team productivity with a very simple solution
    - Quickly cross-train additional staff on DR processes and procedures
    - Optimize flexibility as changes to the environment required changes to the DR strategy
    - Test and validate the DR failover process without taking primary production systems offline

    Join Zac Streelman, Manager, Information Technology at Leupold and Stevens and Jennifer Gill, Director of Product Marketing at Zerto, to hear from your peers and learn about Zerto Virtual Replication.
  • Join us as top security experts look at some of the latest security challenges and provide strategies for defense, including how to quickly implement a robust solution that provides the protection you need without impacting your network performance or reducing employee productivity. You will learn how to better protect your networks from the inside as well as the outside, with solutions that reduce work for IT and security teams.

    You will learn about:
    •The malware menace – latest stats and facts
    •Third party industry firewall comparison results: which firewall is best for you?
    •Best and easiest practices for securing end points
    •How a customer implemented a solution—step-by-step
    •And much more…
  • The data center is changing in an era of applications and automation, but how do you get there? OST, an expert in crafting automation for large-scale public clouds and developing new provisioning models for enterprise technology and in-application development, has experience in bringing data centers into the 21st century.

    Register for this webinar to learn:
    •How to develop core disciplines of application development and automation in the IT department
    •How to provide business-responsive services without compromising quality
    •How to prepare your data center for the future
  • Le taux d’équipement en périphériques mobiles (PC, tablettes, smarphones) dépassant maintenant celui des PCs fixes, il n’est pas surprenant que la tendance se poursuive en entreprises. Hors la mobilité va de pair avec le Cloud en tant que nouvelle plateforme de collaboration d’où un échange des informations bien au-delà du traditionnel périmètre.
    Lors de ce webcast, nous vous proposons de mieux comprendre comment protéger vos données stockées dans le Cloud, tout en garantissant une facilité d’expérience aux utilisateurs.
    Découvrez :
    -Comment développer, gérer et mettre en œuvre des politiques de sécurité renforcées dans le Cloud
    -Comment sécuriser les communications emails échangées entre terminaux mobiles
    -Comment Symantec peut vous aider à résoudre des problématiques de conformité grâce au DLP et au chiffrement
  • La convergence des infrastructures IT apporte un surcroit de complexité, de coûts et de risques dans la gestion, le stockage et la protection des informations dans les entreprises.
    Au cours de cette session, nous vous proposons de faire le point sur les enjeux actuels des infrastructures (virtualisation, croissance des données, stockage…) et vous présenterons une solution moderne de protection des données pour réduire la complexité et les coûts : l’appliance Symantec Backup Exec 3600.
  • Organizations outsourcing card data to the cloud face significant security risks. As soon as an organization adds other players to the offsite card-management mix, ensuring compliance with the PCI Data Security Standard becomes increasingly challenging. Cloud users and cloud service providers need to understand what their roles and responsibilities are when it comes to protecting this data. Storing, processing and transmitting cardholder data in the cloud brings the cloud environment into scope for PCI-DSS.

    Organizations need to know where their data is at all times. A lot of cloud clients have limited or no control over cardholder data storage. Organizations should be concerned about collecting and correlating access logs and other information from cloud vendors to ensure they are maintaining security compliance. Where's the data being stored? Is it stored in multiple locations? These are all things that you have to take into consideration when you're thinking about outsourcing to a cloud provider. Join this webcast as we address the compliance challanges in the cloud, and gain new insights on:

    - Emerging PCI security risks in the cloud
    - Understand the role of cloud entities
    - Processes for assessing risk when card data could potentially be stored in multiple locations
    - Structuring planning controls to deal with PCI DSS changes
    - Recommendations for achieving PCI compliance across virtual environments
  • Enterprise IT implementations and upgrades often come with business disruption, unexpected costs and lengthy delays. What if there were a way to avoid those risks?

    Please join us for an informative webinar spotlighting a unique alternative to traditional onsite technology integration. Take a look inside FusionStorm’s Integration Center and see how our expert configuration, staging and logistics services enable on-time, plug-and-play installation of multivendor solutions anywhere in the world.

    Detailed case study examples will show you how to cut deployment time and disruption for:
    •rollouts of customized technology solutions to multiple locations
    •repetitive deployments of standardized equipment

    Mark your calendar and join us for an inside look at the best practices and nimble processes that enable rapid turnaround of complex projects with less risk.
  • Channel
  • Channel profile
Up Down
  • Incident Response 2.0 - Triage, Containment, & Remediation for Evolving Threats Jun 6 2013 6:00 pm UTC 45 mins
    Colby Clark will present a rapid incident response methodology used by the FishNet Security Incident Management team utilizing a combination of best-of-breed solutions to rapidly facilitate all phases of an IR investigation of evolving threats. The methodology begins with identification from network indicators with NetWitness, triage and containment using FireAmp, and in-depth forensic investigations on system artifacts (memory, volatile data, and file system) using EnCase Enterprise.
  • Targeted Attacks 101 - Eight Incident Response Steps Jun 6 2013 5:00 pm UTC 45 mins
    Is your business safe from malware and targeted attacks? Sophisticated attacks now leverage social engineering techniques and malware to compromise those individuals already on the inside of your enterprise, and then target your data. This session covers the basics of how this continues to happen, despite more money than ever being spent on perimeter and endpoint defenses. We’ll present an eight step incident response model to help prevent, detect and respond to these attacks.
  • Incident Response - Reimagining the Modern Enterprise Security Paradigm Jun 6 2013 4:00 pm UTC 55 mins
    Today's accepted wisdom is that there are only two types of organizations, those that have been breached and know it and those that have been breached and don't. With this new vision comes the realization that building perimeter defenses is no longer enough, but that remediation, situational awareness and fast response time are what separate well secured organizations from the rest.

    Join this panel as they discuss the transition to an incident response world and the important operational and philosophical battles that will define it - from the federal and commercial perspectives to using forensics for risk analysis and IT investment and the attribution debate.

    Panel:

    Tom Field, Vice President, Editorial, Information Security Media Group (moderator)
    Bill Hau, VP of FireEye Labs,
    Pete Allor, Steering Committee member of FIRST
    Vernon Habersetzer, IR Team Lead, Walmart
  • Lifecycle of a Breach – 6 Steps Toward Better Security Jun 6 2013 1:00 pm UTC 45 mins
    This webinar will review the methodology lifecycle of a breach at an organization and highlight best-practices and efficiencies that can help your organization learn from breaches and continually strengthen your security posture.
  • Why are Simple Deployment and Management Key to SMB Security? Jun 5 2013 5:00 pm UTC 60 mins
    Your business needs security solutions that are easy to live with and run on a daily basis. ESET has the best solution from this perspective. This webcast will highlight 2-3 specific atributes and focus the ease of management and implementation.
  • Detecting File Execution: What Runs but Never Walks Jun 5 2013 5:00 pm UTC 45 mins
    In this webinar, I will begin with a brief discussion of the different types of attackers, and show how all threat actors are not equal. Then, I will discuss four main ways attackers execute code in a Windows environment. Reviewing real cases of recent attacks, I will show how to detect file execution using static, dynamic, and advanced analysis techniques. I will show how to use artifacts such as the Windows registry, logs, prefetch files, and network data to determine whether an attacker executed files. Finally, there will be a discussion of tools used for forensic analysis, including free tools such as the ShimCacheParser and MANDIANT Redline.
  • Full Security Visibility For Effective Incident Response Jun 5 2013 4:00 pm UTC 45 mins
    Despite significant time and effort deploying multiple security solutions, incident responders know more than anyone that existing signature-based, “set it and forget it” security technologies have not stopped the advanced persistent threat. Signature- and rule-based technologies are easily evaded with today’s advanced targeted attacks, morphing malware and zero-day threats. Tools like FireEye’s Malware Analysis System are effective in dealing with zero-day malware, but being able to detect this threat does not mean complete resolution.

    In addition, sophisticated attackers employ social engineering or take advantage of misconfigurations in security technologies to breach networks – without using any malware at all. Incident responders need full visibility of everything that is going through the network to understand the nature of how a threat originated, see what attackers actually did to take control over the network, and to answer the questions of what they did after they compromised systems. This session will provide an overview of Big Data Security Intelligence and Analytics and how full security visibility can answer the toughest post-breach questions so you can quickly determine the full source, scope and material impact of an incident.
  • Top 10 Mistakes Incident Response Teams Make Jun 5 2013 3:00 pm UTC 45 mins
    When it comes to organizations experiencing some form of cyber-attack, the adage still rings true: it’s not a question of if but when. Advanced malware, zero-day exploits, and targeted advanced persistent threats (APTs) have kept organizations on their heels and searching for ways to protect themselves. Incident Response teams are being forced to re-examine their existing IT security defenses and attempt to stay ahead of the attack curve. Surprisingly, many incident response teams aren’t doing themselves any favors with practices they have implemented.

    Attend this webinar to learn the top 10 mistakes that Incident Response teams make and what you can do to make sure you aren’t making them yourselves.
  • Don’t Ask, Don’t Tell: The (In)Security of Vendor-Supplied Software May 30 2013 4:00 pm UTC 45 mins
    What vulnerabilities threaten the integrity of your software supply chain and data? Can your enterprise really influence software vendors to meet your most important security policies and remediate insecure software?

    Action is needed, and urgently. An alarming 62 percent of all applications fail to reach compliance on their first submission, according to a study recently conducted by Veracode, Enterprise Testing of the Software Supply Chain. While few enterprises now have formal third-party testing programs, those that do find they dramatically improve vendor compliance while meeting industry standards.

    Join this webcast with Chris Eng, Veracode's Vice President of Research, and you will learn:

    •How leading enterprises now test their software supply chains.
    •Analytics drawn from code-level analyses of thousands of third-party applications that support global enterprises.
  • 5 Essential Steps for SMB's to Build a Layered Security Solution. May 22 2013 5:00 pm UTC 60 mins
    Most SMB's use a single point product for each of the different perceived security threats. This has worked in the past, but a far better approach is layering multiple products in a stouter defense.
  • Today's Advanced Threats Require Next-Generation Protection May 22 2013 5:00 pm UTC 45 mins
    Are you using or considering a next-generation threat protection solution? Join this webcast and learn how you can multiply the value of your investment by integrating network and endpoint security.

    During this session you’ll learn best practices for protecting your network and your endpoints and servers from today's new breed of cyber attacks. You’ll also see firsthand how the integration of network and endpoint security solutions will help you:

    ・ Automatically confirm and prioritize alerts
    ・ Provide enterprise-wide visibility of infections to speed investigation
    ・ Drive remediation
    ・ Automatically analyze files from endpoints and servers
  • How To Simplify Your Data Center With Network Automation and Orchestration May 21 2013 3:00 pm UTC 47 mins
    Join 3 network specialists as they cover:

    - the need for networks to evolve
    - reducing human latency
    - simplifying the network
    - simplifying operations
  • Securing the Agile Cloud: Automating Security and Compliance for IaaS Recorded: May 16 2013 45 mins
    Companies are eager to adopt infrastructure-as-a-service services in both public providers and private datacenters because of the business agility that IaaS enables. Full IT automation, self-service provisioning, and metered usage billing helps companies accelerate the development of their products and services, and improves organizational efficiency. Unfortunately, many companies are struggling to accelerate the most important parts of their business due to the challenges of securing these highly dynamic environments. In this talk Rand Wacker, VP of Products for CloudPassage will describe the challenges of security and compliance in a truly automated cloud and critical topics that you need to be aware of when planning to adopt cloud services in either public or private environments.
  • Why Your Cloud Provider Security Logo Doesn’t Mean a Thing Recorded: May 16 2013 49 mins
    As more applications have moved to the cloud, the industry has seen a proliferation of application security issues. In 2012, several cloud service providers were breached as a direct result of application security vulnerabilities. Before you choose a cloud service provider, make sure that it answers the series of security questions created by the Cloud Security Alliance (CSA). CSA has created a checklist of industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings – creating more transparency for enterprises. The speakers will walk attendees through this blueprint, helping them to become more adept at identifying service provider security readiness. They'll also discuss some of the most common application vulnerabilities, including unencrypted passwords, SQL Injection, and those that impact poorly architected mobile apps.
  • Panel: Securing Your Enterprise Cloud Recorded: May 16 2013 59 mins
    As the cloud model continues to disrupt and enhance the modern enterprise IT teams are facing new challenges retaining security and control in these new environments. This panel will explore a multifaceted approach to the cloud that looks at the importance of integrating the right tech solutions and deployments while negotiating and understanding your relationship with cloud providers.

    Panel:

    Bill Brenner, Managing Editor, CSO Magazine (moderator)
    Nataraj Nagaratnam, Ph.D., IBM Distinguished Engineer, IBM Master Inventor
    Chris Farrow, Information Security Specialist, Compassion International
    Jason Mendenhall, EVP Cloud, Switch
  • End Point to Perimeter: Network protection that’s inside out and outside in Recorded: May 16 2013 55 mins
    Join us as top security experts look at some of the latest security challenges and provide strategies for defense, including how to quickly implement a robust solution that provides the protection you need without impacting your network performance or reducing employee productivity. You will learn how to better protect your networks from the inside as well as the outside, with solutions that reduce work for IT and security teams.

    You will learn about:
    •The malware menace – latest stats and facts
    •Third party industry firewall comparison results: which firewall is best for you?
    •Best and easiest practices for securing end points
    •How a customer implemented a solution—step-by-step
    •And much more…
  • Not Going Quietly; Gracefully Losing Control & Adapting to Cloud and Mobility Recorded: May 16 2013 48 mins
    Cloud, virtualization, mobility, and consumerization have greatly changed how IT assets are owned and operated. Rather than focusing on loss of security control, the path forward is cultural change that finds serenity and harnesses the control we’ve kept. The Control Quotient is a model based on control and trust, allowing proper application of security controls, even in challenging environments.
  • Active Defense: How to Think Outside the Box Recorded: May 16 2013 48 mins
    Synopsis:
    This webinar will define the concept of active defense or "hack back”. During his talk, David will explore the legal issues, reveal how it can be accomplished without breaching any laws, and show you how active defense will actually improve your security posture.

    About the speaker:
    David is a leading authority in cyber security and the law. He is a licensed attorney in NY, CT, and CO, and owner of Titan Info Security Group, a Risk Management and Cyber Security law firm. David is a retired Army JAG officer. During his 20 years in the Army he provided legal advice in computer network operations, information security and international law to the DoD and NSA and was the legal advisor for what is now CYBERCOM. He holds the CISSP & Security + certifications and has two LLM’s in International Law and in Intellectual Property law. He is a VP of his local ISSA chapter and a member of InfraGard.
  • Next Generation Access and Identity Management For a Multi-Perimeter World Recorded: May 15 2013 47 mins
    In today's open and interconnected enterprise, traditional perimeters are being extended to adopt mobile, cloud, social access and information interactions. To make matters worse, many organizations face the growing risk and burden of managing multiple identity and access controls without the required security intelligence to address those challenges. They need the ability to secure identity and access across the wide variety of enterprise and internet resources from any device, any service and any source. In this session, join IBM to review the emerging needs, the next generation access and identity management solutions available today to enable secure and rapid adoption of mobile, cloud, and social transformation.
  • 12 Steps to a Successful & Secure Cloud Recorded: May 15 2013 39 mins
    Some would like to have you believe that everything should be moved to the Cloud. How do you know if you should move to the Cloud? To move it safely and successfully takes insight and planning. To move it to a Secure Cloud takes investigation beyond “is the cloud vendor secure”. As so many others have learned, it can be done in 12 steps.
The latest trends and best practice advice from the leading experts
This channel features presentations by leading experts in the field of information security. From application, computer, network and Internet security to access control management, data privacy and other hot topics, you will walk away with practical advice for your strategic and tactical information security initiatives.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Enterprise Preparedness Using Our National Preparedness Standard
  • Live at: Oct 6 2009 7:00 pm
  • Presented by: Donald Schmidt; Preparedness, LLC, CEO
  • From:
Your email has been sent.
or close
You must be logged in to email this