Incident Materiality and the SEC Guidance

Steven F. Fox, U.S. Dept of the Treasury
October 13, 2011 saw the release of the Securities and Exchange Commission's guidance on the reporting of material cyber security breaches. Consistent with regulations which address financial reporting, this guidance calls for publicly-traded companies to disclose breach information to current and prospective investors. Such disclosure may include discussion of service providers associated with the event.

This session will summarize the disclosure guidance and discuss its implications to both the business and the incident response team. A collaboration model will be discussed wherein a business representative can work with the IR team to evaluate incident materiality, allowing the business to address this guidance efficiently. The implications of of the Dodd-Frank Act in light on this guidance will also be discussed.
May 23 2012
38 mins
Incident Materiality and the SEC Guidance
SEC compliance GRC
More from this community:

IT Service Management

Webinars and videos

  • Live and recorded (1090)
  • Upcoming (42)
  • Date
  • Rating
  • Views
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Join Klaus Feldam of PBD Worldwide and Liaison Technologies’ Phil Ifkovits who will discuss specific B2B integration challenges and how Liaison solutions allowed PBD to focus on more important areas including innovation and strategy.
  • Peeush Bajpai, Director of Professional Services EMEA at Kaseya gives his views on the current challenges for IT Service Management professionals.
  • Get a leg up on intermittent problems, watch this webinar to learn how OptiView XG v10 can inject test traffic to measure network performance, examine the traffic's impact on infrastructure, spot ongoing problems, expose intermittent issues, and map out exactly where problems are located.
  • When a business rolls out IT systems to run its operations, the basic foundation on which the system is built is the network that carries the traffic. To be able to solve problems in such a complex environment, it's vitally important to know what is happening on the network. Whether it's the behavior of the applications, behavior of the users or rogue elements that interfere with application delivery, knowing what is going on is half the battle of solving the problem.

    This short video will discuss why having a well-designed workflow for identifying suspect traffic patterns and finding even the smallest volume of interesting data can make the difference in finding the culprit of pesky performance problems.
  • According to a recent survey by MobileIron, 81% of companies accommodate personal mobile devices in the workplace and more than 50% have formal BYOD (“Bring Your Own Device”) programs in place. Another survey from iPass found that nearly half of IT managers in organizations implementing enterprise mobility strategies believe their company’s approach to be insufficient. Register for this webinar and discover how to avoid missteps on your path to mobility.

    •How can you quickly and securely mobilize your workforce?
    •What controls should be available to IT for a BYOD initiative?
    •How do innovative companies collaborate in a mobile-first world?

    Get your questions answered and explore the latest integrated solution from Box and MobileIron. Over 150,000 companies around the world, including 92% of Fortune 500, use Box for content sharing that both users and IT love and adopt. MobileIron is a Box partner and recognized leader in the Gartner Magic Quadrant for Mobile Device Management.
  • Did you know that natural disasters, such as hurricane or flood only account for approximately 2% of all business disasters while hardware failures and human error account for more than 70%?

    Let’s face it: as an IT professional, anything that interrupts normal business operations could form the basis of disaster for you. Just remember: whatever the cause of your interruption, how you prepare to respond that will decide the fate of your business.

    So, are you prepared?

    In this session, Senior Sales Engineer Chris Brightwell from Kaseya will discuss what a state of the art backup and disaster recovery solution looks like, how you should plan ahead to prevent or mitigate the risks of a disaster and explains the difference between good and bad backup and disaster recovery strategies based on real-life examples.
  • Automating your data center is the easiest way to free up your IT department's time to work on more strategic projects. Tune in to this webinar as Jeff Hart from M2 Technology discusses how automation can be the key to increase efficiency while reducing your IT costs.
  • The mega-trends of SaaS, mobile and Big Data are converging, generating a new wave of business opportunity for enterprises. The convergence demands a new kind of platform – one that connects and takes advantage of the explosion of endpoints and data caused by organizations each choosing a uniquely diverse set of best-of-breed applications to power their business. Ross Mason will discuss his vision for this new platform and demonstrate how MuleSoft’s solutions are making it a reality.

    Questions to be discussed include:

    How will SaaS and mobility impact my business?
    Is SOA really dead?
    Does my business need an API strategy? Where should we start?
    Can the Anypoint platform help me secure a competitive advantage?
  • Channel
  • Channel profile
Up Down
  • Big Data: NASA's Perspective and Initiatives Recorded: Mar 13 2013 42 mins
    Dr. Sasi Pillay, the CTO of NASA, will discuss how NASA is using big data from their thousands of missions they run every year as well as how big data has impacted their data center infrastructure.
  • DHS Strategy and Resources Addressing Software Assurance Recorded: Feb 20 2013 44 mins
    Vulnerabilities in software put at risk the Nation’s critical infrastructure. The risk is compounded by software size and complexity, the use of software produced by unvetted suppliers, and the interdependence of software systems. Software assurance deals with the root of the problem by improving software security.
  • VDI or RDS? Balancing Security, Budget, Performance and Mobility Recorded: Feb 13 2013 47 mins
    There are key pressures driving IT today: budget, security threats, consumerization of IT, end-user needs and expectations. In response, IT is turning to virtualization to relieve these pressures but which is the best solution?

    Join this webinar to learn which technology: VDI, RDS or both that you should turn to for help. This presentation will cover use cases to help determine best fit, how the addition of the PCoIP protocol to RDS can improve performance, and a first hand account of how and why Gypsum Management and Supply, a national distributor of construction supplies, implemented a desktop virtualization solution replacing aging PCs.

    About the Presenter:
    Mike Fodor is a customer-focused product management professional with over 20 years of experience in technology, six of which have spent in the desktop virtualization space. Mike began his career in Southern California as a technology manager for Walt Disney Feature Animation.  He has spent more than a decade in Silicon Valley, holding management posts at NetIQ, Peoplesoft and Pano Logic before joining Teradici.
  • Case Study: Department of Homeland Security's Public and Private Cloud Recorded: Oct 16 2012 48 mins
    Creating your IT strategy with a combination of public and private cloud services can improve the efficiency and reduce costs of your infrastructure. Join Keith Trippie, Executive Director for Enterprise System Development Office for the U.S. Department of Homeland Security (DHS) as he explains:

    - The DHS's public and private cloud services
    - Data security in their cloud
    - The benefits they've seen
    - Challenges and lessons learned
  • Incident Materiality and the SEC Guidance Recorded: May 23 2012 38 mins
    October 13, 2011 saw the release of the Securities and Exchange Commission's guidance on the reporting of material cyber security breaches. Consistent with regulations which address financial reporting, this guidance calls for publicly-traded companies to disclose breach information to current and prospective investors. Such disclosure may include discussion of service providers associated with the event.

    This session will summarize the disclosure guidance and discuss its implications to both the business and the incident response team. A collaboration model will be discussed wherein a business representative can work with the IR team to evaluate incident materiality, allowing the business to address this guidance efficiently. The implications of of the Dodd-Frank Act in light on this guidance will also be discussed.
  • Our Service Catalog Journey at the National Institutes of Health Recorded: May 17 2012 48 mins
    As an ITSM professional with over 30 years experience in IT, Mike will discuss the importance of collaboration and coordination among all work groups in the creation of a Service Catalog and share the challenges he faced as a Process Owner.

    In this session, Mike will cover:

    - Why management support is essential
    - The process of establishing an effective team
    - How to utilize project management principles
    - Defining services: Taking the time needed to do it right
    - How a maturity model was used in his process
    - Tool selection: Consider all options
    - How to keep the momentum going
  • Desktop Virtualization: Doing More with Less in State and Local Government Recorded: Mar 15 2012 48 mins
    Virtualization provides the opportunity for organizations to utilize existing resources to create new and innovative ways to achieve higher availability, better reliability and an overall better user experience -- all while not breaking the bank. In this webinar, you will learn how Alex Musicante, System Security Architect, leveraged virtualization to improve the City of Pittsburgh's infrastructure, and explore his thoughts on the what the desktop market can and will bring in the future.
  • How to Create Social Illusions: A Social Engineering Case Study Recorded: Feb 8 2012 49 mins
    Social engineering is the art of creating social illusions that result in the sharing of sensitive information or physical access to secured areas. This webinar will review the psychological framework that informs a social engineer's reconnaissance, pretext formulation, and social exploit activities. A case study will illustrate the use of the Social Engineer's Toolkit, Maltego, and Google Hacking to collect information that contributed to a successful engagement. Attendees will learn to identify social illusions and respond to protect their personal and professional data. They will also learn how to frustrate the efforts of social engineers.
  • Evolving From A Help Desk To An ITIL Service Desk Recorded: Jan 18 2012 49 mins
    The National Institutes of Health (NIH) is a very large, multi-faceted organization with a significant IT presence. A ten year veteran of the IT customer support industry, Phil will discuss his organization’s challenges, trials and tribulations, and successes as they evolved from a Help Desk to an IT Service Management focused Service Desk.

    Phil’s presentation covers: the transformation of their very large internal organization – what was the “before” picture and how they determined what needed to change; how they articulated a vision and set objectives; the process of creating buy-in from skeptical IT service partners and customers in adopting the necessary ITIL processes – what worked and why; the process used to select and implement the right tools to support the objectives; steps taken to “cement” a service-based climate and a summary of major improvements made that radically changed IT support.
  • US Government Driven Cloud Computing Standards Recorded: Mar 2 2011 55 mins
    This session will look at the use cases developed by the US National Institute of Standards and Technology (NIST) in collaboration with the public to drive interoperability, portability and security of cloud computing. A panel of key representatives from NIST as well as several industry standards organizations, including the DMTF, SNIA and the Cloud Security Alliance will discuss their work as it pertains to these use cases. The discussion will cover portable workloads and standardized interfaces for cloud computing. The goal of cloud standards is to improve cloud consumer agility and define a set of architectural semantics that unify the interoperable management of workloads and resources between enterprises of all sizes and cloud computing infrastructures.

    Panelists:
    Lee Badger, Computer Scientist, NIST
    Mark Johnson, Co-Chair, DMTF Cloud Management Working Group
    Mark Carlson, Vice Chair, SNIA Cloud Storage Initiative
    Becky Swain, Risk & Compliance Mgmt, Corporate Security Programs Organization (CSPO), Cisco

    Moderator:
    Winston Bumpus, President, DMTF
  • Building the Cloud at Los Alamos National Lab Recorded: Nov 10 2010 44 mins
    Organizations are faced with dwindling IT budgets and pressure to deliver more with less; sophisticated data centers can help meet this challenge. By embracing technologies such as virtualization, IT can deliver increased compute capacity, reduce its footprint and even enhance its green IT posture. Los Alamos National Laboratory has evolved its successful technology investment in virtualization into a self service Infrastructure-as-a-Service (IaaS) private cloud, providing compute resources on demand to users and bringing the cloud into our data center.

    Participants will learn:
    • LANL's journey into virtualization
    • The steps LANL took to deploy an Infrastructure-as-a-Service (IaaS) private cloud, “Infrastructure on Demand”
  • Marine Corps Desktop Virtualization Vision and Strategy Recorded: Aug 25 2010 45 mins
    The Marine Corps has had tremendous success in virtualizing IT infrastructure to improve utilization and availability while reducing the cost of hardware and manpower associated with managing servers. Desktop virtualization is the next logical step to continue this momentum. The Marine Corps is interested in reducing the touch labor costs with managing desktops, improving security, and providing disaster recovery. This presentation will focus on the vision and strategy, describe a notional desktop architecture with use cases and provide lessons learned from ongoing virtual desktop proof of concept deployments.
  • Energy Efficiency Tune-up of a Legacy Data Center Recorded: Apr 21 2010 48 mins
    The data center in LBNL’s Building 50, Room 1275 has a long and interesting history that stretches back several decades. The center originally housed large, air-cooled IBM computers. It was later reconfigured to support LBNLs’ payroll and other miscellaneous computing needs. In 1996, the National Energy Research Scientific Computing Center (NERSC) was located in this center that used water-cooled Cray C-90 computers. In 1999, the Cray computers were replaced with new air-cooled computers. By July of 2007, the data center had two types of datacom equipment: approximately 250kW of high density research computing clusters and approximately 90kW of “back-of-house” IT equipment.
    A baseline energy-use assessment, and subsequent energy-efficiency retrofit analyses, began in July 2007. This assessment confirmed a baseline IT load approximate of 330 kW. With a cooling system capacity of 140 tons (nominal), it only just kept the servers cool. However, during the assessment period while some retrofit measures were being installed, the facility operators added approximately 100 kW of IT load. To further complicate matters, the IT staff was contemplating installing an additional 120 kW of IT load in the near future that would bring the total connected IT load to 550 kW.
    With chiller capacity “maxed out” and no additional space to locate additional cooling system capacity, installing efficiency measures (EEMs) to increase the center’s effective cooling capacity were the only option for the LBNL staff. Three main EEM upgrades were identified that resulted in reduced energy waste in the data center, effectively increasing the existing system’s cooling capacity as follows:
    Retrofit Tune-up Summary
    1. Airflow Optimization
    2. Wireless temperature sensors
    3. Server rear-door heat exchangers
  • Save Energy Now in Data Centers, A Case Study at the LBNL Recorded: Jul 30 2009 46 mins
    Save Energy Now in Data Centers, A Case Study at the Lawrence Berkeley National Laboratory

    Mr. Dale Sartor from the Lawrence Berkeley National Lab (LBNL) specializes in the energy efficiency of buildings for high-tech industries. He will describe trends and issues relative to energy consumption in data centers, and will focus his talk on lessons learned improving the efficiency of LBNL’s own data centers.

    LBNL has benchmarked dozens of data centers. The results of that benchmarking, as well as high level performances metrics and tools will be presented. Further benchmarking helps identify opportunities and best practices. The best practices adopted at LBNL will be described. Topics will include: air management, right sizing, plant optimization, liquid cooling, “free” cooling, humidity control, the electrical power chain, and design and operational practices.

    Finally Mr. Sartor will describe some of the resources available to improve energy efficiency in data centers.
Exploring the latest technology for federal, state & local government
Tune into the webinars in this BrightTALK Channel for the latest best practices and analysis of information technology. The content is specifically created for public sector IT professionals and administrators.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Incident Materiality and the SEC Guidance
  • Live at: May 23 2012 7:00 pm
  • Presented by: Steven F. Fox, U.S. Dept of the Treasury
  • From:
Your email has been sent.
or close
You must be logged in to email this