Hi [[ session.user.profile.firstName ]]

SDLC Meets PCI Compliance: Securing Applications From the Inside Out

For individuals tasked with ensuring their organizations are PCI complaint, challenges are ever present. The delicate balance of achieving PCI Compliance while ensuring there is no disturbance in day to day operations of a security program is what separates experts from practitioners. This web seminar will give attendees the expert’s guide to reviewing PCI requirements for secure application development and will detail how HP helps partners not only meet these requirements but to also solidify the future of a security program by securing applications from the inside out.
Recorded May 22 2012 58 mins
Your place is confirmed,
we'll send you email reminders
Presented by
Rick Dunnam, Principal Consultant, Application Security HP
Presentation preview: SDLC Meets PCI Compliance: Securing Applications From the Inside Out

Network with like-minded attendees

  • [[ session.user.profile.displayName ]]
    Add a photo
    • [[ session.user.profile.displayName ]]
    • [[ session.user.profile.jobTitle ]]
    • [[ session.user.profile.companyName ]]
    • [[ userProfileTemplateHelper.getLocation(session.user.profile) ]]
  • [[ card.displayName ]]
    • [[ card.displayName ]]
    • [[ card.jobTitle ]]
    • [[ card.companyName ]]
    • [[ userProfileTemplateHelper.getLocation(card) ]]
  • Channel
  • Channel profile
  • Trends in Cyber Attacks and Breaches Dec 11 2018 1:00 pm UTC 45 mins
    Steve Durbin, Managing Director, ISF LTD
    As the scale, sophistication, and targeting of cyber-attacks increase, organisations need to manage risk in ways beyond those traditionally handled by the information security function.

    In this webinar, Steve Durbin, Managing Director at the ISF will offer his insights into how security and business teams across the entire organisation can work together to minimise the impact of a breach, in order to protect organisations from damaging shareholder value and business reputation.


    About the presenter

    Steve Durbin is Managing Director of the Information Security Forum (ISF). His main areas of specialism include strategy, information technology, cybersecurity and the emerging security threat landscape across both the corporate and personal environments.
  • Security in the Golden Age of Cloud Oct 23 2018 12:00 pm UTC 45 mins
    Emma Bickerstaffe, Senior Research Analyst, ISF LTD
    Demand for cloud services continues to increase as the benefits of cloud services change the way organisation manage their data and use of IT.

    However, while these services can be implemented quickly and easily, with increased legislation and data privacy, the threat of cyber theft is on the increase and organisations must have a clear understanding of where their information is stored and how reliant these services are.

    In this webinar, Steve Durbin, Managing Director of the ISF will discuss the risks associated with cloud computing and how to manage them, as well as how to maximise the benefits.

    About the presenter

    Steve Durbin is Managing Director of the Information Security Forum (ISF). His main areas of specialism include strategy, information technology, cybersecurity and the emerging security threat landscape across both the corporate and personal environments.
  • [Earn 1 CPE] Compliance vs Risk: Aligning Priorities & Prioritizing Threats Sep 27 2018 5:00 pm UTC 75 mins
    Colin Whittaker, Moderator. Stephen Boyer, CTO & Co-Founder, BitSight
    Compliance is a fundamental pillar to effective risk management at any company. However, simply complying with laws and regulations without considering the broader threat landscape can result in disaster. Certainly, a balance between compliance and risk is necessary. Ensuring compliance represents an organization's starting point, not the endgame, should be a priority.

    In a dynamic threat environment, forward-thinking organizations have concluded that the goal of total protection is elusive and that a risk-based approach to governance and management of cybersecurity is necessary. That is easier said than done, as the way most information security professionals measure risk today fails to quantify threats in terms the business can understand and use. In this CPE accredited webinar, our panel of experts will discuss:

    - Aligning risk and compliance metrics and controls across functional domains.
    - Benchmarking existing process for managing the risks identified by stakeholders.
    - Creating a transparent 'system of record' and collaborative process life-cycle management system.
    - Prioritizing control efforts accordingly.
    - Aligning compliance investments with compliance risk ratings and business priorities.
  • Beyond the Breach: Recommendations for Effective Response Sep 19 2018 5:00 pm UTC 60 mins
    Heather Stratford-Geibel (Stronger.tech) | Sushila Nair (NTT DATA)
    Discover the latest trends in cyber crime, your organization's vulnerabilities, and how to go about preventing, detecting and responding to a breach.

    Join this interactive Q&A panel with top security experts across the ecosystem to learn more about:
    - Trends in breaches and cyber attacks
    - What to do (and not to do) after a breach
    - What's new on the threatscape
    - Best practices and recommendations for improving your security posture

    Speakers:
    - Heather Stratford-Geibel, CEO of Stronger.tech
    - Sushila Nair, Sr. Director, NTT DATA Services
    - Others TBA
  • Next Generation Data Protection and Security: The Blockchain Advantage Sep 19 2018 3:00 pm UTC 60 mins
    Joseph Pindar (Gemalto), Ulf Mattsson (TokenEx) + Panel of experts
    How can Blockchain improve trust, security, and compliance? Can the decentralised nature of this technology be the missing piece in solving cybersecurity challenges?

    Listen in to this panel of security luminaries where they will discuss:
    -Key considerations for leveraging the blockchain in the age of GDPR
    -What sort of infrastructure must be in place to ensure a secure environment?
    -Is the blockchain itself secure?
    -How do you build a trust network around the blockchain?
    -What are some of the cybersecurity challenges that can be mitigated and managed by the blockchain?
  • Trends in Data Breaches and Comprehensive Response Sep 19 2018 12:00 pm UTC 60 mins
    Michelle Drolet (Towerwall) | David Klein (GuardiCore)
    Does your organization have a data breach response plan? Discover the best practices for breach response and how to strengthen your organization's cyber resilience.

    Join this interactive Q&A panel with top security experts as they discuss:
    - The latest trends in data breach protection
    - Who's most at risk
    - How to detect breaches faster
    - What to do and not to do when it comes to breach response
    - Recommendations for CISOs for improving security

    Speakers:
    - Michelle Drolet, CEO, Towerwall
    - David Klein, Sr. Director Engineering & Architecture, GuardiCore
  • A Data Breach Prevention, Detection & Response Strategy to Combat Today' Threats Sep 18 2018 12:00 pm UTC 45 mins
    Nick Frost, Principal Consultant, ISF LTD
    With the ever-increasing frequency and sophistication of security threats to organisations, business leaders need to have a comprehensive data security strategy to protect themselves. Information security practitioners have to think and plan beyond existing protection capabilities that are aimed at preventing threats only. Today's cyber security strategies need to protect an organisations mission critical assets in a way that is:

    ‒ balanced, providing a mixture of informative, preventative and detective security controls that complement each other
    ‒ comprehensive, providing protection before, during and after threat events materialise into security incidents
    ‒ end-to-end, covering the complete information life cycle.

    This will enable organisations to match the protection provided with the sophistication of threats to such mission critical information assets. This webinar will look at past and present models and share ideas on how organisations can ‘future proof’ their strategies to combat next generation threats.

    In particular in this webinar, Nick Frost, Principal Consultant at the ISF will discuss what actions can be taken to identify your most critical information assets, and how a modern day cyber security model needs to focus on prevention and detection of a data breach, and how to respond to a breach in order to reduce damage to brand and reputation.
  • GDPR 101: Compliance Maintenance After the Deadline Aug 28 2018 5:00 pm UTC 75 mins
    Kelley Vick, IT GRC Forum, Dr. Branden Williams, MUFG Union Bank; TrustArc, Online Business Systems, DXC Technology
    The European Union’s new General Data Privacy Regulation (GDPR) came into force on May 25th, and began immediately reshaping the digital universe. According to IDC's 2017 GDPR Readiness Survey, 80% of companies were not prepared, and tech giants have already been sued for violating the terms, while major newspapers have been forced to restrict EU access to their websites for fear of noncompliance. Now two months after deadline, it's clear that large scale enterprises and their employees, are still not sure about what they need to do to comply.

    In this CPE accredited webinar, our panel of experts will discuss how to adhere to the GDPR and boost the security and compliance foundations of your organization by managing the data risk.

    Learning Objectives:

    - Find out what your organization needs to uncover data risks and avoid fines.
    - Discover the latest techniques to protect data and remediate breaches.
    - Learn how handle data in cloud and ensure only the right people have access.
    - Clarify the requirements for your enterprise to become compliant with GDPR.
  • [Ep.18] Founders Spotlight: Paul Kurtz, Co-founder & CEO of TruSTAR Aug 21 2018 5:00 pm UTC 45 mins
    Paul Kurtz, Co-founder & CEO of TruSTAR
    This webinar is part of BrightTALK's Founders Spotlight Series, where each week we feature inspiring founders and entrepreneurs from across industries.

    In this episode, Paul Kurtz, an internationally recognized expert on cybersecurity and the co-founder and CEO of TruSTAR Technology, will share his insight and expertise into the threat intelligence and security industry.
    - What it means to found and run a security start up
    - Where is the industry headed in the age of cyber attacks and high-profile breaches
    - How to scale and grow a business in this hi-tech industry

    Paul will be taking questions from the live audience so this session will be an excellent opportunity for any entrepreneurs or security professionals out there to have their questions answered.

    About the Speaker:
    Paul began working on cybersecurity at the White House in the late 1990s. He served in senior positions relating to critical infrastructure and counterterrorism on the White House's National Security and Homeland Security Councils under Presidents Clinton and Bush. After leaving government, Paul has held numerous private sector cybersecurity positions including founding the Cyber Security Industry Alliance (Acquired by Tech America), Executive Director of SAFECode, Managing Partner of Good Harbor Consulting in Abu Dhabi, and CISO of CyberPoint International.

    Paul’s work in intelligence analysis, counterterrorism, critical infrastructure protection, and non-proliferation of weapons of mass destruction influenced his approach to cybersecurity. Specifically, the fields highlighted the need to build an exchange platform which addresses barriers to sharing information--bureaucratic, legal, and market risk and concerns--while providing immediate value to operators defending networks.
  • The SNIA Persistent Memory Security Threat Model Aug 21 2018 5:00 pm UTC 75 mins
    Doug Voigt, Co-Chair, SNIA NVM Programming TWG and Distinguished Technologist, HPE
    What new security requirements apply to Persistent Memory (PM)? While many existing security practices such as access control, encryption, multi-tenancy and key management apply to persistent memory, new security threats may result from the differences between PM and storage technologies. The SNIA PM security threat model provides a starting place for exposing system behavior, protocol and implementation security gaps that are specific to PM. This in turn motivates industry groups such as TCG and JEDEC to standardize methods of completing the PM security solution space.
  • How to Build a Robust Incident Response Capability for Financial Institutions Aug 16 2018 12:00 pm UTC 45 mins
    Michelle Drolet, CEO, Towerwall, Inc.
    Michelle Drolet CEO of Towerwall will be discussing the need for developing a solid Incident Response Program and doing Tabletop exercise throughout the year. An Incident Response Plan (IRP) will ensure information security incidents, once identified, will be handled and communicated appropriately. Consistency of how incidents are handled and communicated is paramount to a successful incident response.

    The IRP provides a quick, organized, and effective response to computer-related and physical security incidents. The IRP’s mission is to prevent a serious loss of information, information assets, property, and customer confidence by providing an immediate, effective, and informed response to any event involving your information systems, networks, workplace, or data.

    Security incident response is an organized approach to address and manage activities during and after a security breach. The goal of security incident response is to handle any information security incident in an organized and effective manner that limits damage to the organization and reduces recovery time and cost.
  • [Webcam Panel] Trends Discussed at Black Hat 2018 Aug 15 2018 5:00 pm UTC 60 mins
    Charles Tendell (The Charles Tendell Show) | Eddie Lamb (6point6) | Other Panelists TBA
    Join this post-Black Hat panel as we look at the biggest trends and cyber threats covered during the Black Hat Conference 2018 in Las Vegas.

    Tune in for an interactive Q&A panel with industry experts across the security ecosystem as they discuss:
    - What are the biggest threats to security in 2018?
    - Key steps to take today to better secure your critical data assets
    - Top technological advancements powering security
    - CISO strategy in the age of breaches

    Speakers:
    - Charles Tendell, Renown Cybersecurity Expert, Certified Ethical Hacker & Host of "The Charles Tendell Show"
    - Eddie Lamb, Managing Director, Cyber Security at 6point6
    - Other Panelists TBA

    The session is being brought to you in partnership with ITSPmagazine.
  • Disrupt Nothing: Cybersecurity for Inflexible Healthcare Working Environments Aug 15 2018 3:00 pm UTC 60 mins
    Ian Schmertzler, President & CFO of Dispel
    How do you go about defending a community that instinctively resists change and has the power to thwart you? You can try to alter human behavior, approach the problem through unobtrusive methods, or step aside and let a calamity educate the workforce. Since the last option isn’t really on the table while you are on the clock, a combination of the first two is the most likely approach. In this talk, we go through some readily implementable methods for narrowing the attack surface of your healthcare institution.

    About the Speaker:
    Ian Schmertzler is the President and CFO of Dispel, a cyberdefense firm that specializes in building traceless, encrypted communications networks within which teams and datasets can operate free from targeted attack. He also has a sense of humor, which is a necessity in cyberdefense. Ian holds an MSc. in Industrial Engineering from Georgia Tech, and a BA from Yale.
  • How to Manage Cyber Risks in a Regulatory Environment with Security Analytics Aug 14 2018 3:00 pm UTC 45 mins
    Ashwin Chaudhary, Accedere Inc
    With increased security and privacy regulations such as the new EU GDPR, it is becoming more important to reduce the dwell time of incidents to be able to report those breaches in the required time. For example GDPR requires you to report them in 72 hours.

    In this webinar, we will discuss how Security Analytics can help you do that including getting you ready for preventing, detecting and responding to breaches.

    Join us to know how Security Analytics as a Service can give you a better insight to your threats as well as optimize your compliance costs.
  • [Webcam Panel] What to Expect at Black Hat 2018 Jul 31 2018 5:00 pm UTC 60 mins
    Sean Martin (ITSPmagazine) | Eddie Lamb (6point6) | Other Panelists TBA
    Join this panel of industry experts as they share their experiences and thoughts on one of biggest security conferences in the world, Black Hat in Las Vegas, along with their expectations from this year's event.

    Tune in for an interactive Q&A panel with some of the biggest names in infosecurity to learn more about:
    - What can security professionals learn during Black Hat / DEF CON week
    - Must-attend events and why
    - What's new on the cyber threatscape
    - Advances in technology
    - AI: Hype vs Reality
    - Common sense advice for CISOs
    - How to keep your employees cyber safe

    Speakers:
    - Sean Martin, Co-Founder and Editor-in-Chief, ITSPmagazine
    - Eddie Lamb, Managing Director, Cyber Security at 6point6
    - Other Panelists TBA

    The session is being brought to you in partnership with ITSPmagazine.
  • [Earn 1 CPE] Post-GDPR: Key Steps to GRC Integration Jul 26 2018 5:00 pm UTC 75 mins
    Moderator: Colin Whitaker. Panel: Sooji Seo, RSA; Quin Rodriguez, Riskonnect; Gabriel Gumbs, STEALTHbits; Tim Hill, Centrify
    Data protection laws such as the General Data Protection Regulation (GDPR) are complex, and can impact a broad range of business roles, including legal, audit, HR and finance, not just IT. In achieving GDPR compliance, organizations should focus on getting these roles to work together in ongoing efforts to ensure governance, risk and compliance (GRC) across an organization, and not be distracted by the noise in the marketplace. Through the process of integrating GRC practices real value can be achieved, as long as all stakeholders work with one another and take practical, measured steps toward integration. Join our panel of experts on this CPE accredited webinar to learn how your organization can achieve this.

    Learning Objectives

    - Find out how to align risk management with enterprise performance management under the GDPR.
    - Learn how to work with stakeholders to effectively integrate compliance activities, and gain transparency, efficiency and agility for process operations.
    - Discover how to identify and manage the digital risks that matter, and which risk functions need to transform.
  • Threat Hunting - An In-depth Explanation Jul 23 2018 4:00 pm UTC 60 mins
    Juanita Koilpillai, Mark Rasch, Andrew Johnston and David Morris
    Threat Hunting is a complicated and often misunderstood cybersecurity activity that if properly used can add tremendous value to your cybersecurity posture.

    In this session you will learn:
    What is Threat Hunting?
    When do I use it?
    What will it tell me?
    How do I use it?
    What are the legal implications?

    Learn from the following leading experts:
    Juanita Koilpillai: Chief Technology Advisor, Digital Risk Management Institute
    Mark Rasch: Chief Legal Council,Digital Risk Management Institute
    Andrew Johnston: Associate Consultant,Mandiant
  • Zero to Hero: Blissfully Ignorant to Risk Focused Recorded: Jul 19 2018 36 mins
    Casey Reid, Principal Security Engineer, Tenable
    Innovation is the key to survival in today's Digital economy. Providing fresh content in new ways to broader markets is expanding the attack surface. The adoption of DevOps, cloud proliferation and enterprise IoT has added significant challenges to understanding your Cyber Risk.

    In this webinar Casey Reid, Principal Security Engineer at Tenable will talk about:
    - Why there no such thing as "Secure"
    - How the "Race to Zero" is killing your productivity and increasing your Cyber Risk
    - How "Chasing the Zero Day" could be a big waste of time
    - What it takes to be Risk focused: Going from Zero to Hero

    About the Speaker:
    Casey Reid is a Principal Security Engineer at Tenable, responsible for helping enterprise customers reduce their Cyber Exposure and strengthen their Vulnerability Management program. He is an energetic, outspoken, problem solver and hobby hacker with over 15 years of diverse technical experience. When he's not learning new technologies or hacking in his lab, he is competing at local CrossFit competitions and Obstacle Course Races such as the World's Toughest Mudder.
  • Two Companies Walk into a Bar: Cyber Risk for the C-Suite Recorded: Jul 19 2018 51 mins
    Cynthia Wright, CEO at Synthus
    It's become a truism among cybersecurity professionals that there are two types of companies: those that have been hacked and those that will be. If cyber incidents are inevitable, what can organizations do to pro-actively minimize the impact on their operations? This session addresses considerations for organizations addressing cyber-risk at the strategic level.
The latest trends and best practice advice from the leading experts
This channel features presentations by leading experts in the field of information security. From application, computer, network and Internet security to access control management, data privacy and other hot topics, you will walk away with practical advice for your strategic and tactical information security initiatives.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: SDLC Meets PCI Compliance: Securing Applications From the Inside Out
  • Live at: May 22 2012 8:00 pm
  • Presented by: Rick Dunnam, Principal Consultant, Application Security HP
  • From:
Your email has been sent.
or close