Day One: Tuesday 6 September 2005
|
| 08.30 | Registration and morning coffee
|
| |
|
| 09.00 | Opening remarks from the chair
|
| |
|
| THE REAL WORLD: MORE THAN JUST SECURITY |
|
| 09.10 | Keynote Address:
The future of information security
- Current trends in technology and their implications for security
- Why today's solutions will fail to meet tomorrow's challenges
- What organisations must do now to survive the next decade
- How the next ten years are likely to unfold
|
| | David Lacey, Director of Information Security, Royal Mail Group, UK
|
| 09.50 | Featured presentation:
Don’t sacrifice growth for security
Historically, companies have implemented identity management programs out of fear of what would happen if they didn't. And while the ability to manage who accesses your system is paramount to mitigating risk and complying with regulations, there's a brighter side.
An effective identity management program will cover your security bases while also providing the freedom to grow as quickly as your business will allow.
|
| | Sara Gates, Vice President, Identity Management, Suns Microsystems USA
|
| 10.20 | Morning coffee and exhibition viewing
|
| |
|
| THE CULTURE OF SECURITY - PEOPLE AND CHANGE |
|
| 11.00 | IT Security as a business risk management discipline
- Is IT, and IT Security in particular, really different from my other business risk issues?
- How much spending is enough for my business? Am I spending enough, or too much, and how can I tell?
- Is IT Security really "everyone's responsibility"? What should the business expect from IT in this area?
- How can we all keep our focus on the main (business) game?
- What has AMP done to position IT Security in our business risk context, and to develop an organisational culture to support risk / compliance / governance activities as part of "the way we do things around here"?
|
| |
|
| 11.20 | Case Study:
Aligning security policies to the business
- Ensuring security policies meets business strategies
- Adapting security policies to meet the needs of changing business models
- Addressing the security needs of an extended enterprise
- Developing security governance in an outsourced environment
|
| |
|
| 11.40 | Panel Discussion
Proven tactics to guarantee internal policy compliance
- Learn how to craft concise, effective policies
- Communicate policies to the right people
- Leverage automated tools for policy enforcement
- Assess policy effectiveness and make adjustments
|
| |
|
| 12.20 | Luncheon
|
| |
|
| TECHNOLOGY DYNAMICS: EMAIL SECURITY AND ONLINE CRIME |
|
| 13.50 | Keynote address:
The enterprise and online fraud: assessing response strategies
- Identifying the latest international and national trends in online fraud
- Corporate responses – what eBay is doing
- Assessing the way forward
|
| |
|
| 14.20 | Spam – Taking out the trash in email
- Existing mechanism for dealing with spam and why they are only partially effective
- Risks associated with spam and delayed email
- Counteracting high volumes of incoming bad mail
- Steps to take now to protect your email systems
|
| |
|
| 14.40 | Case study:
Making authentication simple, secure and self-funding
- Maximising returns on investment using web-based systems
- Examining the use of one device for accessing all information and areas
- Using one device for securely authenticating and storing applications
- Assessing an organisation’s unique real world identity management requirement
- Developing a customised authentication solution
|
| |
|
| 15.00 | Speed Networking

Speed networking This exclusive Terrapinn innovation facilitates a quick introduction and business card exchange during a light and fast-paced session.
|
| |
|
| 15.40 | Afternoon tea and exhibition viewing
|
| |
|
| MANAGING YOUR RISK |
|
| 16.10 | Case Study
Your database: The Aladdin’s cave of the new millennium fraudster
Assessing ubiquitous nature of databases in business
- Highlighting links to identity fraud
- Examining professional data theft
- Limiting exposure to global data thieves
- Protecting account information
- Will government legislate for data base security?
|
| |
|
| 16.30 | Panel discussion:
Who are you? Corporate identity and online crime
The emergence of increasingly sophisticated attacks
- Examining various strategies for user authentication
- Strategising a combined industry approach
- Keeping your customer’s trust
|
| | Moderator: Jason Hart, Head of Information Security Services, WhiteHat Consultancy (UK) Ltd David Lacey, Director of Information Security, Royal Mail Group, UK
|
| 17.10 | Closing remarks from Chair and close of Day One
|
| |
|
| 17.20 | Cocktail Reception
Sponsored by Sun Microsystems

|
| |
|
|
Day Two, Wednesday 7 September 2005
|
| 08.30 | Welcome coffee
|
| |
|
| 09.00 | Opening remarks from the chair
|
| | Vijay Varadharajan, Director, Information & Networked Security Research, Macquarie University
|
| INNOVATION: PLANNING FOR TOMORROW’S THREATS |
|
| 09.10 | International keynote address:
Secrets of Super-spies: Cost effective programs for your organisation
Spies are unstoppable geniuses who can steal any information they want. You are at their mercy. Then there are the spy wannabes such as criminals, hackers, and even your employees, all with similar diabolical reputations. However, as good as spies are in stealing your information, they are as good as protecting their information. Using actual cases of espionage, including those that he committed, Ira will demonstrate the most cost effective security programs for your organization. |
| |
|
| 10.00 | Keynote address:
Information security is not just about IT!
- The importance of being business savvy, not just tech savvy
- Integrating technology issues with management priorities
- Dealing with tighter board scrutiny and increasingly rigorous cost controls
- Implementing the right management practices from the board down to the operational level
|
| |
|
| 10.40 | Morning coffee and exhibition viewing
|
| |
|
| 11.20 | Case Study
Mobile devices – your next big threat?
- Addressing intrusion detection and integrity management
- Contingency plans for an eminent attack
- Developing a variety of tactics to counter malicious viruses
- Maximising protection of information on devices and in transit
- Supporting the distribution, management and enforcement of policies on mobile devices
|
| |
|
| APPLICATIONS: THE NUTS AND BOLTS OF SECURITY |
|
| 11.40 | Stopping SPAM before it attacks your network
- Presented through two client case studies - COX COMMUNICATIONS & BAPTIST HEALTH CARE
- Reputation systems are the only way to stop new SPAM attack techniques
SPAM volumes are overwhelming current EMAIL systems resulting in high cost and maintenance
- Connection Control techniques eliminate a requirement for new email servers
- Company and Government regulations require OUTBOUND handling and filtering
- Automatic detection of sensitive outbound messages and protecting them with encryption
- Establishing outbound policy and training of systems must be simple and easy
|
| | Paul Serrano, Senior Marketing Director - Asia Pacific,, CipherTrust
|
| 12.10 | International panel discussion-
Making the case : open vs proprietary software environments
- Debates the merits of using proprietary and open source software
- Highlights the number of reported vulnerabilities and their severities
- Considers the requirements on hardware and security when operating on different platforms
- Addresses the economic and security benefits of using proprietary and open source software
|
| | Moderator: Vijay Varadharajan, Director, Information & Networked Security Research, Macquarie University David Lacey, Director of Information Security, Royal Mail Group, UK David McCaskill, Section Manager, Information Security Solutions, Procter and Gamble , USA
|
| 12.50 | Luncheon
|
| |
|
| 14.10 | Presentation
Breaking down walls – A layered defence approach
- What is de-perimeterisation?
- Changing perimeter requirements
- Developing B-2-B networking for virtual organisations
- Overcoming architectural & technology challenges
- Addressing governance and alignment to the business
|
| |
|
| EVALUATING PROCESS IMPROVEMENTS |
|
| 14.30 | Roundtable discussion
Each delegate will be asked to join a table of their choice to discuss and network with like-minded individuals facing similar challenges, led by an industry expert.
|
| |
|
| Roundtable discussion 1:
The insider threat |
Led by: Ira Winkler, Industry Expert and Author, “Spies Among Us”, USA
|
| Roundtable discussion 2:
ID management |
Led by: Sara Gates, Vice President, Identity Management, Sun Microsystems USA
|
| Roundtable discussion 3:
Mobile devices |
Led by: Paul Osmond, Director of Asia Pacific, Blackberry Research in Motion
|
| Roundtable discussion 4:
De-perimeterisation – Discussing the global trend towards information security |
Led by: David Lacey, Director of Information Security, Royal Mail Group UK
|
| Roundtable discussion 5:
Standards and regulations |
Led by: Andrew Caswell , Project Manager, Standards Australia
|
| 15.10 | Afternoon tea and exhibition viewing
|
| |
|
| 15.40 | Case Study:
Developments in Information Security Standards
- Progress of the NCSS (National Centre for Security Standards)
- Information security risk management guidelines
- Fraud and corruption control
- Whistleblower protection programmes for business entities
|
| |
|
| 16.10 | Technology Discussion:
Technology roundup
- Examining and evaluating the effectiveness of each security component
- Assessing the critical security components
- Essential ingredients for effective security architecture
- Getting a handle on which solutions to deploy and where
- Structuring your architecture for success
- The latest technology you need to know about
|
| | Moderator: Vijay Varadharajan, Director, Information & Networked Security Research, Macquarie University
|
| 17.00 | Closing remarks from the Chair and end of conference
|
| | Vijay Varadharajan, Director, Information & Networked Security Research, Macquarie University
|