Member Login:
Username:
Password:
Email:
Remember Me!
Request My Log On ID

 

Topics:
Choose any Topic to
view Specific Content
Learn about Topics

 

Search:
Advanced

 

Specific Forum Information

Add to Calendar
View Agenda
View Report
View Report
View Report
View Report
View Report
View Report
View Report
View Presenter Bio
Back to Event List
IT Security Summit
Tue Oct 6, 2009 - Wed Oct 7, 2009
Rockville, MD

IT security threats both internal and external are evolving at a staggering pace. Keeping abreast of the issues and solutions and balancing them against decreasing budgets is a herculean task. This forum will address the challenges and best practices for information security professionals.

This meeting will hosted by IMF Member US Pharmacopeia in Rockville, MD:

The United States Pharmacopeia (USP) is an official public standards–setting authority for all prescription and over–the–counter medicines and other health care products manufactured or sold in the United States. USP's standards are recognized and used in more than 130 countries around the globe. These standards have helped to ensure public health throughout the world for close to 200 years.    

"From CISO to CIO"
What are the building blocks to a successful career in Information Technology?   Lou Magnotti, CIO of the US House of Representatives, could answer this question in a number of ways.  His extensive career in IT includes time at the Department of Defense, nine years as CISO, and as of November 2008, CIO of one of the nation's oldest institutions.  His success has not come without challenges, but Lou makes it look easy.  During this presentation, Lou will discuss his own career development and the steps and best practices that have made him the successful IT Executive he is today.
Lou Magnotti, Chief Information Officer, US House of Representatives


"The Role of the CISO"
Ron Baklarz, CISO of Amtrak, has been involved in Information Security for several years now.  He has unparalleled experience in a number of industries, including military, government, non-profit, private sector, healthcare, and transportation.  Ron will discuss his role and best practices that has made him successful in the CISO position.  He will also share insights on information security from different industry perspectives.
Ron Baklarz, CISO Amtrak

"Security as a Marketing Tool"
Paul Moran, CISSP, CISA, CGEIT, is responsible for managing the operation and effectiveness of security-related programs and initiatives.  He assesses the cost of potential threats relative to cost of solutions required to eliminate, minimize, or mitigate threats. Paul is also responsible for the development and communication of information security policies and procedures.  He works closely with all departments to ensure integrity of security procedures, systems, and policies.  He will be sharing his expertise on how security is an important role in any sales process. 
Paul Moran, Information Security Analyst Automotive Resources International

"
IT Security: When Will We Know if What We Are Doing is Working?"
Clint Kreitner is the Founding President and CEO of The Center for Internet Security. Mr. Kreitner has for the past 38 years been President and CEO of two information technology companies, Response of Hawaii, Inc. and American Information Systems, Inc, a number of hospitals, and from 2000-2008, The Center for Internet Security. He continues to serve CIS as Senior Advisor.  He will be presenting on "IT Security: When will we know if what we are doing is working?"  Discussing the need for the information security community to come to consensus on what constitutes success and how to measure it, plus the need for a feedback learning loop to enable measurable continued improvement in protecting information.
Clint Kreitner, Senior Advisor; Founding President/CEO The Center for Internet Security

"Lessons From the Sandbox"  "Leaving the Fortress"
In the first half of Dr. Greg Hanson's presentation, "Lessons From the Sandbox," Dr. Hanson will use stories from his experiences in the Air Force, NATO, the United States Senate, and in industry to illustrate the types and nature of cyber threats. In the second half of Dr. Hanson's presentation, "Leaving the Fortress," he will discuss some practical innovations for addressing the threats.
Dr. Greg Hanson, Executive Vice President Criterion Systems 

"Security Architecture"

Enterprise Security Architecture (ESA) is an elusive topic for many organizations, with only a minimal level of guidance in terms of industry sound and best practices. Dr. Brancik will discuss an on-going project he has been involved in to place a science around the topic of ESA. The primary goal of this interactive session is to engage and enable the attendees to think about the topic and to freely share their thoughts and ideas on both the theoretical and practical aspects for creating viable solutions to strengthen ESA practices. The general framework for the open discussions may include, but not be limited to the following areas of ESA risk: Architecture User Requirements and Design, Integrating governance, Risk Management and Compliance (iGRC) considerations, Cyber Security risks and controls, Threat Modeling and architectural implementations to name a few. 
Dr. Kenneth Brancik, Principal CYBER Security Architect, Advanced Technology and Quality Group Northrop Grumman

Member Spotlight: U.S. Pharmacopeia Tour

This tour will provide all attendees the opportunity to see U.S. Pharmacopeia’s headquarters, including Reference Standards Laboratory, Biologic Labs, USP’s museum, and Library.  The tour guide will discuss functions of each department and how it ensures the quality, purity, strength, and consistency of prescription and over-the-counter medicines, as well as other healthcare products manufactured and sold in the United States.

Members at this event will receive continuing education credits from the following organization:
  IMF has partnered with  (ISC)2, an organization recognized as Gold Standard for certifying Information Security professionals. This Forum can be used to obtain credits toward Continuing Professional Education (CPE) points needed to ensure certification remains in good standing. Credits can be earned for the following certifications:   SSCP, CAP, CISSP, ISSAP, ISSEP, and ISSMP. 

 

 


Location Information

Location Name: Hilton Washington DC/Rockville Executive Meeting Center
Address: Rockville, MD 20852
(301) 468-1100
Map it!
Description

Located within walking distance from USP headquarters. Accessible to Twinbrook Metro Station. Request U.S. Pharmacopeia's group rate when booking rooms.

Presenter Information
Paul Moran Bio

Paul Moran, CISSP, CISA, CGEIT, is responsible for managing the operation and effectiveness of security-related programs and initiatives. He assesses the cost of potential threats relative to cost of solutions required to eliminate, minimize, or mitigate threats. Paul is also responsible for the development and communication of information security policies and procedures. He works closely with all departments to ensure integrity of security procedures, systems, and policies.

Before joining ARI, Paul was the Senior Information Security Risk Analyst at Independence Blue Cross. Before that he served as the Division Security Administrator at CIGNA. He also spent twelve years at CGU Insurance Company (formerly General Accident) where he held various positions including Security Administrator, Help Desk Specialist, and Actuarial Programmer.

Paul has served on the board of the Information Systems Security Association (ISSA) for the last seven years. He has been the Vice President of that organization for the last two years. Paul and his wife Carolyn have four children. They range in ages from 9 to 17 years old. Besides his work, Paul enjoys spending time with his family.

Clint Kreitner Bio

After serving in the U.S. Navy as Director of Computer-Aided Ship Design at the Bureau of Ships and Design Superintendent at the Pearl Harbor Naval Shipyard, Mr. Kreitner has for 38 years been President and CEO of two information technology companies, Response of Hawaii, Inc. and American Information Systems, Inc (1971-89), a number of hospitals (1989-2000), and The Center for Internet Security.

From 1989-2000, he was President and CEO of the Reading Rehabilitation Hospital and President/CEO of the Southeastern Region of the Adventist Health System, with responsibility for seven acute care hospitals in four states. He was a Board Member of the parent company and Chairman of the Board of several of the hospitals.

Mr. Kreitner is the Founding President and CEO of The Center for Internet Security, serving in that capacity from 2000-2008. He is currently serving CIS as Senior Advisor. He earned an undergraduate degree from the U.S. Naval Academy and graduate degrees from Webb Institute and American University.

Greg Hanson Bio

Dr. J. Greg Hanson brings nearly 32 years of technology leadership experience to Criterion Systems, Inc., a management consulting and technology services organization led by world-class senior executives.  Prior to joining Criterion, Dr. Hanson served as Chief Information Officer for the United States Senate where he was responsible for the technology vision and strategy.  Dr. Hanson's focus at Criterion is on all aspects of strategic decision making, operations, and innovative technology solutions for key Government customers.  Dr.  Hanson is a respected international lecturer and author with numerous awards for leadership and professional excellence including two FED 100 Awards and an AFFIRM Leadership Award. He has been an active member of the Air Traffic Control Association (ATCA), Armed Forces Communications and Electronics Association (AFCEA), Greater Washington Board of Trade, and Northern Virginia Technology Council. Dr. Hanson earned his Ph.D. in Computer Science from the University of Central Florida, a Master’s of Science degree in Information Systems from the U.S. Air Force Institute of Technology, and a Bachelor of Science from the U.S. Air Force Academy. He is also an Adjunct Full Professor, teaching graduate computer science courses for the University of Maryland University College.

Ken Brancik Bio

Dr. Brancik is an INFOSEC luminary who has worked over the past quarter of a century within the Information Assurance space evaluating integrated Governance, Risk Management and Compliance (iGRC) activities for both the public and private sectors. Additionally, he has spent a number of years conducting technical IT infrastructure and application audits and examinations within the Federal Government and the private sector.

Dr. Brancik recently authored a book through Auerbach publications based on his Doctoral dissertation entitled “Insider Computer Fraud – An In-Depth Framework for Detecting and Defending Against Insider IT Attacks”. 

Dr. Brancik has functioned as a Principal Architect for Information Security within the newly created Advanced Technology Group (ATG) and reports directly to NGIT’s CTO. Prior to this role he accepted an interim full-time assignment within the Corporate Civilian Cyber Security Campaign, where he worked as a Director of their Security Governance, Risk Management and Compliance (iGRC) activities and as NGC’s lead Technical Security Architect within the Cyber Security Integration Group (CSIG).

Dr. Brancik also worked for VerizonBusiness Security Solutions Group, where he functioned as their Director and Trusted Security Advisor and Senior Executive Security Consultant. Dr. Brancik worked for The Federal Reserve Bank of New York for approximately three and a half years, where he functioned as a Senior IT Analyst within the Emerging Technologies group. Dr. Brancik functioned as a VP and Officer at CITIGROUP within the Audit and Risk Review (ARR) department. Dr. Brancik learned about project management and software development activities when he functioned in a similar capacity while working for Merrill Lynch and Company. Dr. Brancik was recruited by PricewaterhouseCoopers, LLP to serve as their Manager within their Federal Service practice Assurance and Business Advisory Service (ABAS) line of service. Dr. Brancik served within The United States Treasury Department’s Office of the Comptroller of the Currency (OCC) for over eleven years, where he was appointed as a National Bank Examiner performing both financial and technology related audits.

Lou Magnotti Bio

Lou Magnotti is the Chief Information Officer (CIO) for House Information Resources (HIR) within the Chief Administrative Office of the U.S. House of Representatives. After nine years as the House Chief Information Security Officer, Lou accepted the role of CIO in November 2008.   HIR consists of a dynamic team of over 300 information technology (IT) professionals responsible for infrastructure, messaging, security, communications, business applications, Green IT and Member support. Lou advocates for all aspects of IT as a value-added business for the House and his team identifies opportunities, provides solutions and delivers quality customer service for the House community.

Lou is a member of the CIO Executive Council, Chairs the Legislative Branch CIO Committee, a member of the (ISC)² Government Advisory Board for Cyber Security, a member of the Information Systems Security Association, the ASIS Information Asset Protection Committee and on the Board of Advisors to the Security Executive Council. He earned a Master of Science degree in computer science from James Madison University and has over 28 years of government and industry experience.

Ron Baklarz Bio

Ron Baklarz CISSP, CISA, CISM, NSA-IAM/IEM

Ron Baklarz has over twenty years in the Information Security field developing “first-of-a-kind” information security programs within government, military, and private sector organizations including the Naval Nuclear Program, U.S. House of Representatives, Prudential Insurance Company, MedStar Health, and Amtrak.

Ron is currently the Chief Information Security Officer at Amtrak and he has held various information security management, consulting, technical, and operational positions throughout his career.  In 1997, his work as the first security manager at the House of Representatives was ranked by InfoWorld magazine as 19th of the top 100 innovative computing projects in American business. In 2008, he was the recipient of CSO Magazine’s Compass Award “The Complete CSO”. He is currently a member of GFIRST (Government – Forum of Incident Response and Security Teams) and has developed and led a number of incident response and network monitoring teams.

Ron holds an MS degree in Information Science and a Certificate of Advanced Study in Telecommunications, both from the University of Pittsburgh. He has successfully completed certifications in cyberforensics and is a Certified Information Systems Security Professional (CISSP), Certified Information System Auditor (CISA), Certified Information Security Manager (CISM), and National Security Agency certified in INFOSEC Assurance Methodology (IAM) and INFOSEC Evaluation Methodology (IEM).  His professional affiliations include the International Information Systems Security Certification Consortium (ISC2), Information Systems Audit and Control Association (ISACA), The American Society for Industrial Security (ASIS) and International Association of Privacy Professionals (IAPP), and Institute of Electrical and Electronics Engineers (IEEE).

Mr. Baklarz is a frequent speaker and author on information warfare and security management topics. His books and articles include The Art of Information Warfare and the essay "The Enemy Within- Y2K Issues Below the Application Level" in the award-winning IS Audit & Control Journal, Volume III, 1998. He has also appeared on BBC radio and CNN television.

Home | Reports | Forums | Web Forums | Benchmarking | Connects | Resource Center | About IMF | Membership | Site Map | Contact Us



© 2010 Information Management Forum, LLC
10896 Crabapple Road, Roswell, GA 30075
770-455-0070 Fax: 770-455-0082