The CISO Job - Getting It, and Keeping It

Featuring Craig Shumard, Marcus Ranum, and Todd Bearman
A Politics of Information Security Webcast

Over the last decade, the Chief Information Security Officer (CISO) has emerged as the job in IT risk management. But for many, it's a high-risk career move. Average tenures in the role remain mired at just a few years. But success is possible — join our expert panel to learn how you can get, and keep, the CISO job.

You'll learn:

How to Get the CISO Job:
- Who gets to the top of the shortlist
- Whether certifications play a role
- How experience in other parts of the organization can help your bid

And Then, How to Keep It:
- How to deal with senior management
- Establishing governance frameworks to guide your activities
- Advice on balancing tactical vs. strategic efforts
- Positioning yourself as an enabler, not a blocker
- Staying ahead by meeting all important audit and regulatory requirements


Featured Speakers:
- Craig Shumard, Principal, Shumard and Associates, LLC, retired CISO, Cigna
- Marcus Ranum, CSO, Tenable Network Security
- Todd Bearman, CISO, Towers Watson
May 31 2012
63 mins
The CISO Job - Getting It, and Keeping It
CISO Careers
More from this community:

IT Security

Webinars and videos

  • Live and recorded (2597)
  • Upcoming (175)
  • Date
  • Rating
  • Views
  • By 2014, 60% of global companies are expected to pilot, deploy or expand their BYOD programs (RainKing). As BYOD has become a fixture in the workplace, with 72% of employees clamoring to have their personal devices work-enabled, the IT industry has watched as the familiar “perimeter" model has become untenable. Data is going to more places, and ending up on a wider variety of devices, than ever before. A new model for protecting data has become a necessity. Organizations have tried to do so in a multitude of ways: extending policies to cover mobile devices, monitoring usage, MDM solutions, and even NAC; all have been methods used to try and create the most stable environment for mobile technology. Let Integralis security expert Mike Gabriel explain how to best balance mobile productivity and security in this Security Talks installment.

    Why Attend?

    1.Discover how your peers are trying to protect mobile data.
    2.See how the perimeter is being sculpted (or not) by the IT industry.
    3.Find out what the future holds for BYOD in the workplace.
  • Over the years true MSPs have had to work diligently to differentiate themselves from companies that are at best, not true MSPs and at worst, are shady fly-by-night operators. This is where the Unified Certification Standard or (UCS) for Cloud & Managed Service Providers comes in.

    The UCS was created by a team of dedicated MSPs to address the shortfalls of existing standards like ISO 27001, ITIL, CoBIT, SSAE 16, which were never intended for managed services organizations and offered little in the way of consumer protection.

    CASE IN POINT: Many MSPs do NOT fail because of technical deficiencies, but due to financial risk. Because of this, customers have very little insight into the service provider's business practices and financial strengths and capabilities.

    Attend this webcast and you will hear from real MSP executives on how the UCS certification and audit has helped them to:

    - Win new business
    - Provide needed transparency to customers
    - Achieve compliance objectives
    - Quickly develop trust with customers and prospects
    - Provide documentation on how those MSPs deliver their services
    - And much more...

    Both Cloud and Managed Service Providers should attend this webcast and at least begin to follow the standards necessary to achieve managed services and cloud computing excellence.
  • Doug Turner, CEO of Mantis Technology Group, talks about how his team built Pulse Analytics, a sentiment analysis solution using text analytics tool running on SAP HANA One. Hear how his team strengthened the capabilities of this solution while simplifying their data architecture by replacing 20 servers with only 1 SAP HANA One instance.
  • Most SMB's use a single point product for each of the different perceived security threats. This has worked in the past, but a far better approach is layering multiple products in a stouter defense.
  • APIs are a hot topic in all sectors of IT - they have gone from being niche solutions provided by big players like Amazon and Google, to being almost as ubiquitous as corporate websites. Ad hoc API development & evangelism without a formal program can leave real revenue on the table, can unintentionally leak sensitive data, and can tarnish the corporate brand with the development community. Today, developers and partners expect to be engaged with first class API programs, while businesses expect real insights to know which APIs are profitable and which APIs to bring to market next. In this webinar, Intel & Mashery outline the baseline enterprise pillars for constructing a first class API program. Learn from CapitalOne how they strategized to build an API program grounded in core business objectives. All attendees to receive a new Mobile API Buyers Guide that presents how to optimize APIs for mobile apps.
  • Are you using or considering a next-generation threat protection solution? Join this webcast and learn how you can multiply the value of your investment by integrating network and endpoint security.

    During this session you’ll learn best practices for protecting your network and your endpoints and servers from today's new breed of cyber attacks. You’ll also see firsthand how the integration of network and endpoint security solutions will help you:

    ・ Automatically confirm and prioritize alerts
    ・ Provide enterprise-wide visibility of infections to speed investigation
    ・ Drive remediation
    ・ Automatically analyze files from endpoints and servers
  • In today’s socially-connected world, conducting business effectively demands easy access to information from anywhere at any time. More people need access to more data through the use of more devices than ever before.

    Join this webcast and learn how CA Technologies helps companies across the world to enable business in a secure manner. Through the use of a Cloud Identity and Access Management service, CA allows the right people have access to the right information at the right time. By seamlessly leveraging existing investments, while extending Identity and Access Management to the cloud, CA Technologies vastly reduces the time to deliver secure new business services.
  • Join us on May 22 for a complimentary webcast on how Oracle Exalogic is the simple way to deploy and upgrade your business applications. Oracle Exalogic is hardware and software engineered together to provide extreme performance, reliability and scalability for your critical applications. Hyundai Motor Company saves more than US$1 Million per year with Exalogic and related Oracle products.

    During this webcast you will hear how Oracle customers have used Exalogic to:

    • Seize new market opportunities
    • Lower business risk
    • Reduce the cost of application deployments

    “We chose Oracle Exalogic, Oracle Exadata, Oracle WebLogic Server, and Oracle WebCenter Content over their competitors as Oracle offers stable storage for petabytes of data and high processing speeds. We have cut the time spent each day on document-related work by around 85% and saved up to US$1.1 million in printing costs.” Kang Tae-jin, Manager, General Affairs Team

    If you would like to contact Tom Smith directly for more information, his email address is tom.a.smith@oracle.com
  • Ever feel like you spend more time converting security information from one format to another, than actually connecting the dots hidden within it? The Collective Intelligence Framework (CIF) is a data processor for pulling in and normalizing out all these threat intel sources into a single combined dataset.

    Learn how to...
    Get CIF up and running
    Connect intelligence sources to CIF
    Leverage CIF with your existing security controls
    Host: Conrad Constantine, Community Manager, AlienVault
    Guest: Todd Leetham, Visiting Scientist, RSA I The Security Division of EMC
    Event Date: Tuesday, May 21, 2013 at 11am PDT
  • "People are talking about doing security in the mobile space and I ask the following question: You have spent the last 13 years building up proper, compliant infrastructures inside your four walls. Now we're going mobile. Why should you implement any lesser degree of compliance in that portion of your infrastructure than you currently have?" Winn Schwartau, one of the world's top experts on security, privacy, infowar and cyber-terrorism, discusses the importance of mobile security and the implications it can have for your pre-existing infrastructure.
  • Channel
  • Channel profile
Up Down
  • Geeking Out with Marcus Ranum - Malware Response Jun 4 2013 6:00 pm UTC 60 mins
    Within the past five years, we have seen an escalating strategic use of malware and its negative impact on organizations. The TTPs (tactics, techniques, and procedures) of various threat actors have caused not only a demand for incident response capabilities, but also the need for in-house reverse engineering and malware response skills to aid incident response and forensic activities.

    Please join Marcus Ranum and special guest, Joel Yonts, on Tuesday, June 4 at 2PM EST for an interactive conversation on malware response programs and their importance and role in today’s enterprise security operations.

    Topics covered:
    •Strategy and objectives for developing a malware response process
    •How to build a malware analysis team
    •What tools to employ for malware response, and other related topics
  • Managing Vulnerabilities in Virtualized and Cloud-based Deployments May 30 2013 6:00 pm UTC 60 mins
    Technologies such as virtualization and cloud-delivered services offer organizations the benefits of hardware consolidation and rapid provisioning and deployment. However, they also bring security and compliance challenges that break traditional vulnerability management solutions by allowing un-scanned and unpatched systems to become active in any part of the organization. A new model that offers real-time identification and assessment of these technologies is required to mitigate the risks. Find out more about it in this webcast…
  • Cyber Threats News and APT Defenses - A Politics of Security Webcast May 23 2013 6:00 pm UTC 60 mins
    There has been a lot of press lately on the escalating cyber threats especially from China. A panel of security experts and practitioners will discuss focus on how this press coverage has changed how organizations think about these cyber threats and what countermeasures they need or plan to implement to address escalating crimes, espionage, or warfare cyber risks.
  • Is your Network Infrastructure Adequately Protected? Recorded: May 15 2013 63 mins
    Network devices including firewalls and routers are the gatekeepers to “endpoint” resources and are increasingly using complex software components. These devices are often remotely accessible and whose configuration changes regularly, making them susceptible to vulnerabilities and misconfigurations. To add to this, network and security teams are often separate parts of an organization often leading to incomplete understanding of vulnerable infrastructure. In this webcast, we examine how to identify vulnerable devices and communicate them across multiple teams and ultimately fortify these devices from configuration and security issues.
  • Increase Security Effectiveness with the 20 Critical Security Controls Recorded: May 1 2013 64 mins
    Automating the 20 Critical Security Controls has demonstrated reduction in risk by over 90%. Tenable is the first vendor to offer an integrated real-time risk management solution to help organizations easily implement these controls.
  • How Will CDM Impact Your Organization? Recorded: Apr 10 2013 59 mins
    DHS' CDM program combines the valuable lessons learned from the existing implementation of FISMA mandates, the strides made by the Cyberscope program, and the proven results of the State Department’s iPOST program. During this webinar, we will discuss:

    - Current challenges in enterprise continuous monitoring
    - How to move your program from periodic system state analysis to real-time monitoring
    - A glimpse into the future: DHS CDM and it's affect on security and regulatory compliance
  • Geeking Out with Marcus Ranum - Take 2 Recorded: Apr 3 2013 60 mins
    Defining "normal" is one of the hardest things we do in security (the other is trying to get people to write perfect code!), but there are a few tricks that work. In this second session, Marcus Ranum and Ron Dilley will be talking about detection algorithms and the problem of defining "normal" network activity.
  • Geeking Out with Marcus Ranum - Security Data Aggregation Recorded: Feb 19 2013 52 mins
    Big data and security analytics have become the buzz of the industry. It is true organizations are collecting more and more data each year with the intention of getting better network telemetry and enterprise-wide visibility to solve complex security problems. One of the main challenges is collecting the necessary data that lives dispersed across an organization to build an effective security model.

    The first part of this series is a lively discussion between Marcus Ranum, CSO of Tenable Network Security, and special guest, Ron Dilley.
  • The Politics of Stakeholders within the CISO world Recorded: Jan 31 2013 56 mins
    CISOs must deal with several stakeholders within the organization. These stakeholders range from BOD members, C-Level management, peer compliance stakeholders (e.g. Legal, Privacy Office), vendors, and the IT organization itself.

    This session will focus on critical success factors to dealing with this wide array of stakeholders and success case studies.

    Specifically, this session will discuss the politics of getting alignment and buy in with the many stakeholders within the organizations such as:
    •Board of Directors and C-Level management
    •Natural allies such as compliance, privacy, audit, enterprise risk management
    •Potential contentious relationships with line or business unit management
    •IT organization strategic and tactical delivery goals and objectives

    Speakers include:
    •Craig Shumard, Principal, Shumard and Associates, LLC, Emeritus CISO, Cigna
    •Tom Doughty, VP & CISO,Prudential
    •Larry Brock, CISO emeritus, Dupont
    •Bob Hillmer, Director, Enterprise Information Security and Directory Services
    •Marcus Ranum, CSO, Tenable Network Security
  • Outcome Based Security Monitoring in a Continuous Monitoring World Recorded: Jan 23 2013 57 mins
    Data from continuous monitoring is in turn enabling “Outcome based” security for identifying trends before they are problems, making better policies, and making asset owners more accountable for the systems they are managing.

    Register for this new webcast to learn about how data from continuous monitoring is enabling "Outcome Based" security.
  • The Politics of Risk Tolerance Recorded: Dec 13 2012 52 mins
    A Politics of Information Security Webcast.

    This webcast will focus on how risk tolerance is decided within an organization and the processes and politics of risks assumption. Topics to be covered include:

    - How risk tolerance is decided within an organization
    -- Informal to formal risk tolerance model
    - How and who can assume risk
    - Risk assessment and risk assumption linkages
    - Competing Drivers
    -- Business unit versus enterprise risk

    Presenters include:
    - Craig Shumard, Principal, Shumard and Associates, retired CISO, Cigna
    - Dennis Brixius, VP of risk management and CSO, McGraw Hill
    - Catherine Rees, CISO, Dow Jones & Company
    - Marcus J. Ranum, CSO, Tenable Network Security
  • IPv6 Requires Fundamental Change to Vulnerability Management Programs Recorded: Dec 4 2012 63 mins
    Learn how new upgrades to Tenable’s SecurityCenter CV™ identify vulnerabilities in devices that could be located in any of 18,446,744,073,709,551,614 (18 quintillion!) IPv6 addresses, the /64 space recommended for a “typical” organization.

    Register for Tenable’s webcast on Dec 4 at 2PM EST to hear about the Newest version of SecurityCenter Continuous View™ (SC CV). This is the first solution designed to manage risk across IPv6 networks, the next generation of Internet address spaces.

    Speakers include:
    - Ron Gula, Tenable Co-founder and CEO
    - Jack Daniel, Tenable technical product manager
    - Allan Carey, Tenable product marketing manager
  • The CISO Job - Getting and Keeping It Part II Recorded: Sep 25 2012 58 mins
    A Politics of Information Security Webcast
    Earlier this year, a panel of Chief Security Officers from some of the nation’s highest profile companies met to talk about how to get and keep the CISO job. The response was tremendous – over 1,000 people have participated in the session. But that talk only scratched the surface – our team of panelists has much more information to share. Join us for Part II of the discussion where we’ll dig into some of the questions that didn’t get answered in the initial discussion, and cover more ground on topics like working with senior management.
    You'll learn:
    How to Get the CISO Job:
    - How to deal with senior management
    - Establishing governance frameworks to guide your activities
    - Advice on balancing tactical vs. strategic efforts
    - Positioning yourself as an enabler, not a blocker
    - Staying ahead by meeting all important audit and regulatory requirements
    Featured Speakers:
    - Craig Shumard, Principal, Shumard and Associates, LLC, retired CISO, Cigna
    - Marcus Ranum, CSO, Tenable Network Security
    - Todd Bearman, CISO, Towers Watson
    - Vas Rajan, CISO, ING Direct
    - John Masserini, Chief Security Officer of Miami International Holdings and the Miami International Securities Exchange (MIAX)
  • Malware Defenses for 2012 and Beyond Recorded: Jul 31 2012 60 mins
    Organizations everywhere are deep in the grips of “malware madness.” Industry estimates of the number of unique malware variants are pegged in the hundreds-of-millions, and it’s rapidly growing. Faced with increasing stealth and sophistication, and an ever-broadening selection of worthy targets, security teams must not only invest in dedicated anti-malware products, but also take advantage of every tool in their arsenal capable of helping combat the problem.

    Join AimPoint Group Founder and Principal Analyst Mark Bouchard and Tenable CEO and CTO Ron Gula to learn:

    • What’s driving the malware problem and how extensive it is
    • Strategies for building effective, long-term malware defenses
    • The benefits of a next-generation vulnerability management solution with integrated malware defense capabilities
  • No More Checkboxes: Vulnerability Management Evolves Recorded: Jun 26 2012 67 mins
    Vulnerability management is growing in strategic importance as organizations seek to optimize the efficiency of their security teams, and to better understand and manage risk. As managers struggle to make sense of a deluge of vulnerability data, vulnerability scanners are evolving to address these needs. As a result, they’re emerging as a much more strategic component of the security infrastructure. Join Securosis analyst and president Mike Rothman as he discusses critical findings around this market shift – including an examination of underlying drivers and detailed insights into the capabilities and features you’ll need to move to next-generation vulnerability management and begin reaping the rewards. Mike will be joined by Jack Daniel, Tenable Network Security product manager and security blogger, who’ll provide insights into how organizations are achieving these gains today with Tenable products and technologies.

    Topics to be covered include:

    •What core features are essential in today’s more complex networking environments

    •The increasing importance of assessing the application layer

    •How to expand capabilities by incorporating value-add technologies to your deployment

    •The unique requirements of the enterprise

    •Deciding whether you can work with the tools you have – and how to replace them if new technologies are needed
  • The Case for Integral Attack Path Analysis Recorded: Jun 19 2012 63 mins
    Taking Vulnerability Management to the Next Level:
    The Case for Integral Attack Path Analysis

    Are your high-value servers and the data they contain really safe from attack, even with multiple countermeasures in place? Given today’s highly motivated attackers and the increasingly sophisticated threats they are generating it is not surprising that patching, firewalls, intrusion prevention systems and other commonly deployed defenses are no longer sufficient. Unfortunately, all it takes is a single, seemingly unimportant system to provide skilled attackers with a beachhead they can use to work their way through and around your defenses. Tenable’s next-generation vulnerability management, with integrated attack path analysis capabilities provides the answer, delivering the tools, insights, and intelligence organizations need to identify and close off otherwise overlooked attack paths – while simplifying infrastructure and streamlining operations in the process.

    Join AimPoint Group Founder and Principal Analyst Mark Bouchard and Tenable CEO Ron Gula and learn:

    • Why traditional vulnerability management fails to measure up
    • What’s needed to efficiently identify and close common attack paths
    • Processes, tips and techniques for conducting attack path analysis
    • The benefits that can be derived from a next-generation vulnerability management solution with integral attack path analysis capabilities
  • The CISO Job - Getting It, and Keeping It Recorded: May 31 2012 63 mins
    A Politics of Information Security Webcast

    Over the last decade, the Chief Information Security Officer (CISO) has emerged as the job in IT risk management. But for many, it's a high-risk career move. Average tenures in the role remain mired at just a few years. But success is possible — join our expert panel to learn how you can get, and keep, the CISO job.

    You'll learn:

    How to Get the CISO Job:
    - Who gets to the top of the shortlist
    - Whether certifications play a role
    - How experience in other parts of the organization can help your bid

    And Then, How to Keep It:
    - How to deal with senior management
    - Establishing governance frameworks to guide your activities
    - Advice on balancing tactical vs. strategic efforts
    - Positioning yourself as an enabler, not a blocker
    - Staying ahead by meeting all important audit and regulatory requirements


    Featured Speakers:
    - Craig Shumard, Principal, Shumard and Associates, LLC, retired CISO, Cigna
    - Marcus Ranum, CSO, Tenable Network Security
    - Todd Bearman, CISO, Towers Watson
  • A Layered Approach to Mobile Security Recorded: May 22 2012 64 mins
    70% of security professionals agree mobile device vulnerability management is very important, but 67% of enterprises report they have no or few mobile controls deployed. Despite the bleak outlook, it is possible to reassert control over this rapidly growing security exposure. Join AimPoint Group Founder and Principal Analyst Mark Bouchard and Tenable CEO Ron Gula and learn how to apply a layered approach to mobile device security to regain control, evaluate risks, and establish essential policies.

    You’ll learn:

    •Why mobile devices are inherently difficult to track, evaluate, and assess
    •The four essential layers of an effective mobile device security strategy
    •How to prioritize mobile device security activities
    •Why scanning technologies need to change to assure effective vulnerability assessment of mobile devices
Industry-expert insights on overcoming critical security challenges
Tenable Network Security brings you critical, timely insights and advice on how to protect your IT infrastructure from the latest threats and ensure compliance and clean audits, while effectively understanding and communicating risk. With guests including renowned technical experts and specialists, senior executives, and industry leaders, you’ll gain multiple perspectives on how to address IT security challenges — along with the practical, hands-on advice you need to stay ahead of threats.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: The CISO Job - Getting It, and Keeping It
  • Live at: May 31 2012 6:00 pm
  • Presented by: Featuring Craig Shumard, Marcus Ranum, and Todd Bearman
  • From:
Your email has been sent.
or close
You must be logged in to email this