Five Steps for Utilities to Reduce Risk Management Framework Fatigue

Patrick Miller, Security Expert
Utilities fear the specter of the NERC auditor, new security legislation on the horizon, and cyber attacks that could shut down systems and services. But risk management framework fatigue has set in, and with so many approaches they don’t know where to begin addressing risk. In this webcast, security expert Patrick Miller describes five concrete steps common to all frameworks that offer a leg up on security and compliance.
Aug 28 2012
58 mins
Five Steps for Utilities to Reduce Risk Management Framework Fatigue
More from this community:

IT Security

Webinars and videos

  • Live and recorded (2597)
  • Upcoming (175)
  • Date
  • Rating
  • Views
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Doug Turner, CEO of Mantis Technology Group, talks about how his team built Pulse Analytics, a sentiment analysis solution using text analytics tool running on SAP HANA One. Hear how his team strengthened the capabilities of this solution while simplifying their data architecture by replacing 20 servers with only 1 SAP HANA One instance.
  • Most SMB's use a single point product for each of the different perceived security threats. This has worked in the past, but a far better approach is layering multiple products in a stouter defense.
  • APIs are a hot topic in all sectors of IT - they have gone from being niche solutions provided by big players like Amazon and Google, to being almost as ubiquitous as corporate websites. Ad hoc API development & evangelism without a formal program can leave real revenue on the table, can unintentionally leak sensitive data, and can tarnish the corporate brand with the development community. Today, developers and partners expect to be engaged with first class API programs, while businesses expect real insights to know which APIs are profitable and which APIs to bring to market next. In this webinar, Intel & Mashery outline the baseline enterprise pillars for constructing a first class API program. Learn from CapitalOne how they strategized to build an API program grounded in core business objectives. All attendees to receive a new Mobile API Buyers Guide that presents how to optimize APIs for mobile apps.
  • Are you using or considering a next-generation threat protection solution? Join this webcast and learn how you can multiply the value of your investment by integrating network and endpoint security.

    During this session you’ll learn best practices for protecting your network and your endpoints and servers from today's new breed of cyber attacks. You’ll also see firsthand how the integration of network and endpoint security solutions will help you:

    ・ Automatically confirm and prioritize alerts
    ・ Provide enterprise-wide visibility of infections to speed investigation
    ・ Drive remediation
    ・ Automatically analyze files from endpoints and servers
  • In today’s socially-connected world, conducting business effectively demands easy access to information from anywhere at any time. More people need access to more data through the use of more devices than ever before.

    Join this webcast and learn how CA Technologies helps companies across the world to enable business in a secure manner. Through the use of a Cloud Identity and Access Management service, CA allows the right people have access to the right information at the right time. By seamlessly leveraging existing investments, while extending Identity and Access Management to the cloud, CA Technologies vastly reduces the time to deliver secure new business services.
  • Join us on May 22 for a complimentary webcast on how Oracle Exalogic is the simple way to deploy and upgrade your business applications. Oracle Exalogic is hardware and software engineered together to provide extreme performance, reliability and scalability for your critical applications. Hyundai Motor Company saves more than US$1 Million per year with Exalogic and related Oracle products.

    During this webcast you will hear how Oracle customers have used Exalogic to:

    • Seize new market opportunities
    • Lower business risk
    • Reduce the cost of application deployments

    “We chose Oracle Exalogic, Oracle Exadata, Oracle WebLogic Server, and Oracle WebCenter Content over their competitors as Oracle offers stable storage for petabytes of data and high processing speeds. We have cut the time spent each day on document-related work by around 85% and saved up to US$1.1 million in printing costs.” Kang Tae-jin, Manager, General Affairs Team

    If you would like to contact Tom Smith directly for more information, his email address is tom.a.smith@oracle.com
  • Ever feel like you spend more time converting security information from one format to another, than actually connecting the dots hidden within it? The Collective Intelligence Framework (CIF) is a data processor for pulling in and normalizing out all these threat intel sources into a single combined dataset.

    Learn how to...
    Get CIF up and running
    Connect intelligence sources to CIF
    Leverage CIF with your existing security controls
    Host: Conrad Constantine, Community Manager, AlienVault
    Guest: Todd Leetham, Visiting Scientist, RSA I The Security Division of EMC
    Event Date: Tuesday, May 21, 2013 at 11am PDT
  • "People are talking about doing security in the mobile space and I ask the following question: You have spent the last 13 years building up proper, compliant infrastructures inside your four walls. Now we're going mobile. Why should you implement any lesser degree of compliance in that portion of your infrastructure than you currently have?" Winn Schwartau, one of the world's top experts on security, privacy, infowar and cyber-terrorism, discusses the importance of mobile security and the implications it can have for your pre-existing infrastructure.
  • Channel
  • Channel profile
Up Down
  • I Didn't Know Tripwire Owned That! Jun 25 2013 5:00 pm UTC 45 mins
    Join Bryce Schroeder,Systems Engineer Director of Tripwire, to get an overview of the technology Tripwire recently acquired through the purchase of nCircle.

    Hear why hardware and software discovery is the foundational control to understanding your attack surface and how nCircle's market leading Vulnerability management solutions can help reduce the risk of breach within your infrastructure.

    This 30 minute presentation will include an overview of the extended product portfolio, key advantages to the technology and why the nCircle acquisition complements Tripwire’s portfolio.
  • I Didn't Know Tripwire Owned That! Jun 18 2013 9:00 am UTC 45 mins
    Join Gavin Millard, EMEA Technical Systems Director of Tripwire, to get an overview of the technology Tripwire recently acquired through the purchase of nCircle.

    Hear why hardware and software discovery is the foundational control to understanding your attack surface and how nCircle's market leading Vulnerability management solutions can help reduce the risk of breach within your infrastructure.

    This 30 minute presentation will include an overview of the extended product portfolio, key advantages to the technology and why the nCircle acquisition complements Tripwire’s portfolio.
  • Passing NERC CIP Audits with Tripwire Jun 11 2013 5:00 pm UTC 60 mins
    This presentation will provide attendees with the keys to achieving and maintaining NERC CIP compliance using Tripwire solutions. Jeff Simon, Tripwire Director of Services Solutions, and Jason Iler, Principal Services Engineer, will discuss their experiences in working with registered entities to reduce the time and effort required to pass NERC CIP audits through the appropriate use of automation.

    Webcast highlights include:
    -CIP requirements most likely to cause audit findings
    -Examples of successful – and unsuccessful – approaches to achieving compliance
    -Using Tripwire products, services and NERC-specific extensions to meet CIP standards
    -Live demonstration of using Tripwire to address specific NERC CIP requirements
    Join us for this informative webcast!
  • Tripwire Announcement Recorded: Mar 20 2013 19 mins
    Tripwire general announcement to customers
  • SCM for Dummies Recorded: Feb 20 2013 32 mins
    Join us for a live preview of "Security Configuration Management For Dummies," a new book by Wiley Publishing sponsored by Tripwire. In this webcast, we'll outline how to:
    •Harden systems against attack,
    •Rapidly repair configuration drift, and
    •Provide objective and actionable assessments of your organization’s security and compliance postures.

    Qualified attendees will receive a complimentary download of the ebook!
  • 10 Steps to Risk-Based Security Management Recorded: Dec 4 2012 59 mins
    Despite the belief of many security professionals in the value of a risk-based approach to information security, many organizations still act in ways that do not reflect this commitment. This dichotomy often leads to misplaced effort, spending and risk treatment. It is also reflected in the disconnect between executive management and those tasked with protecting the information security assets of an organization.

    This webcast will provide a simple framework for executing a risk based security management program. This framework is based on some basic tenants about risk based security management:

    It creates an environment of informed choice
    It strives to reduce uncertainty and eliminate conjecture
    It is best achieved through a plethora of relevant data
    It is based on analysis of frequency of threats and vulnerabilities
    It is a cyclical process involving feedback loops and explicit challenges to assumptions
    This webcast will not only offer you actions you can take but also provide guidance on identifying your progress towards a risk based security program.
  • IANS Webcast: Calculating Your Return on Security Investment with Tripwire Recorded: Oct 9 2012 41 mins
    In the world of security, you know first-hand how difficult it can be to quantify the advantages of solutions when there are so many variables at play. Join us and listen in to Diana Kelley, IANS faculty member and analyst and Tripwire customer, Francis Ballares, IT Systems and Infrastructure Manager at a large accounting and advisory services firm as they discuss how to assess the return on security investment with Tripwire solutions.
  • Connecting Security to the Business Recorded: Sep 14 2012 3 mins
    Information security has entered the boardroom. So, how can CISOs show value to their organization in meaningful ways? In this video we outline the growing problem and Tripwire's solution.
  • Five Steps for Utilities to Reduce Risk Management Framework Fatigue Recorded: Aug 28 2012 58 mins
    Utilities fear the specter of the NERC auditor, new security legislation on the horizon, and cyber attacks that could shut down systems and services. But risk management framework fatigue has set in, and with so many approaches they don’t know where to begin addressing risk. In this webcast, security expert Patrick Miller describes five concrete steps common to all frameworks that offer a leg up on security and compliance.
  • 2012 Ponemon Report on Risk-based Security Management: Are Organizations... Recorded: Jun 27 2012 60 mins
    Risk-based security management (RBSM) is rapidly gaining acceptance as an essential security practice. But how far along are organizations with it? Ponemon Institute and Tripwire teamed up to explore the state of risk management. In this webcast, hear the study’s key findings, including a strong commitment to the practice by most respondents, but little action to back it up.
  • 2012 Ponemon Report on Risk-based Security Management: Are Organizations... Recorded: Jun 26 2012 61 mins
    Risk-based security management (RBSM) is rapidly gaining acceptance as an essential security practice. But how far along are organizations with it? Ponemon Institute and Tripwire teamed up to explore the state of risk management. In this webcast, hear the study’s key findings, including a strong commitment to the practice by most respondents, but little action to back it up.
  • 10 Steps to Better Security Incident Detection Recorded: May 22 2012 37 mins
    Organisations invest heavily in their security defenses, yet many still get breached. Sadly, they frequently find out about it from a third party. So why can’t security teams detect incidents early? In this webcast, information security expert Brian Honan describes why this happens and gives advice on resources you can use and steps to take to quickly identify a potential breach.
  • Achieving Continuous Monitoring Easily with Security Automation Recorded: May 17 2012 47 mins
    With complex, distributed government information systems increasingly under attack from rogue nations, terrorists and cause-driven groups, IT security teams need to get a lead on the state of their systems. In this webcast, learn about an approach to continuous monitoring that offers strong protection against these threats, then see this approach with a demo.
  • 10 Steps to Better Security Incident Detection Recorded: May 2 2012 61 mins
    Organizations invest heavily in their security defenses, yet many still get breached. Sadly, they frequently find out about it from a third party. So why can’t security teams detect incidents early? In this webcast, information security expert Brian Honan describes why this happens and gives advice on resources you can use and steps to take to quickly identify a potential breach.
  • Get more out of SIEM with Change and Configuration Data Recorded: Mar 27 2012 24 mins
    Join us for this Lunch and Learn Webcast:

    Most organizations capture log data that could indicate a breach occurred. Yet not a single breach investigated in the Verizon Data Breach Investigation Report was detected through log analysis or review. Change and configuration data provides valuable insight around the security events that matter, allowing you to identify and react quickly to potential threats. Gavin Millard will talk through the common misconceptions around the limitations of SIEM solutions and how best to leverage this increasing operational efficiency.
  • From Compliance To Security: Making PCI Earn Its Keep Recorded: Mar 21 2012 41 mins
    Your File Integrity Monitoring (FIM) solution has been taking it easy. Doing the bare minimum to meet PCI Requirement 11.5. Like a prima donna that just shows its face and expects to be applauded. Nobody in IT security gets to do that, so why should FIM? Learn how it can do a lot more to improve security. Put it to work as a host intrusion detection system (HIDS) that catches the bad guys well beyond point-of-sale systems and in-scope assets.
  • The Metamorphosis: Extracting Business Intelligence from IT Security Data Recorded: Mar 15 2012 44 mins
    It’s been a long time coming: businesses really care about the organization’s state of security. But to make it relevant to business executives, they need up-leveled views of raw security data that don’t require a deep understanding of IT and security. Tripwire CTO Dwayne Melancon explains three keys to making that possible.
  • IT-Security Controls in Deutschland 2011 Recorded: Mar 14 2012 61 mins
    IT-Security-Verantwortliche in deutschen Unternehmen wissen, welche Daten sie schützen müssen und kennen die Folgen einer Datenschutzverletzung: Umsatzeinbußen, Reputations- und sogar Jobverlust. Dennoch sind die meisten der Meinung, irgendwann Opfer einer Kompromittierung zu werden oder bereits gewesen zu sein. Der optimale Einsatz der richtigen IT-Security Controls kann hier entscheidend sein. Im Webinar erfahren Sie mehr über die Ergebnisse der IDC-Studie und wie starke IT-Security Controls Ihr Unternehmen positiv beeinflussen.
  • Secure on Two Fronts: Increased Control to Protect Your Business Recorded: Feb 16 2012 23 mins
    Securing today’s organization is a daunting task. Gartner’s Mark Nicolett explains why and describes key compliance and security drivers, how to secure your organization, and criteria for selecting a security and compliance technology provider. Tripwire’s Dwayne Melancon adds his perspective, including a smart approach to selecting controls.
  • Where, When and How to Use Real-Time Monitoring Recorded: Dec 15 2011 30 mins
    It's clear to most IT security practitioners that if you only monitor for change through periodic scans, you are probably missing changes that can introduce risk or cause non-compliance. Real-time monitoring seems to offer the panacea by allowing you to detect every change that happens, as it happens. But given the number of devices in the average enterprise IT infrastructure, you may be capturing so much data that you can't possibly see the changes that actually spell trouble.

    In this webcast, Gavin Millard, Technical Director, EMEA of Tripwire uses his experience working with numerous customers to answer critical questions about real-time change monitoring, including:

    - Which parts of your IT infrastructure are suitable for real-time monitoring?
    - How do your monitor the IT estate without overloading the system?
    - What benefits should you expect to gain from real-time monitoring?

    If you are interested in learning more about best practices for implementing a real-time monitoring solution, register for this webcast and tune in to learn from someone with firsthand, practical knowledge of what works and what doesn't.
Leading Provider of IT Security and Compliance Automation Solutions
Tripwire’s powerful IT security and compliance automation solutions help businesses and government agencies take control of their IT infrastructure.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Five Steps for Utilities to Reduce Risk Management Framework Fatigue
  • Live at: Aug 28 2012 5:00 pm
  • Presented by: Patrick Miller, Security Expert
  • From:
Your email has been sent.
or close
You must be logged in to email this