header image
Gary McGraw on Building Security In Maturity Model
Written by Webmaster Rob   
Feb 01, 2010 at 10:44 AM

On Tuesday February 23rd at 6 PM, Gary McGraw will be holding a public
lecture on the Building Security In Maturity Model (BSIMM -
http://bsi-mm.com). The lecture is organized jointly by secappdev.org
and the Leuven Center on Information and Communication Technology
(LICT), a K.U. Leuven multi-disciplinary research center.

The lecture will describe the observation-based BSIMM maturity model,
drawing examples from many real software security programs in leading
companies. A maturity model is appropriate because improving software
security almost always means changing the way an organization works.
While not all organizations need to achieve the same security goals, all
successful large scale software security initiatives share common ideas
and approaches. BSIMM can be used as a yardstick to determine where one
stands and what kind of software security strategy will work best in a
specific case.

The lecture will be held in ESAT's auditorium A in Heverlee and is free
of charge. However, registration is required by February 15th at
http://www.esat.kuleuven.be/LICT/ - follow the link for upcoming new
activities in the right margin. Sandwiches will be provided before the
lecture. The lecture, including a Q&A session, will take approximately
90 minutes, but those who feel like continuing the discussion, are
welcome to join the SecAppDev 2010 pub crawl afterwards.

Gary McGraw will go into more depth about his BSIMM work at SecAppDev
2010. In particular, he will highlight the results from the European
study
and how they compare to the North-American sample. He will also
speak in more depth about the practices found to be most successful by
the participants in the study.

Unfortunately, Richard Clayton had to drop out of this year's faculty.
We believe his colleague Steven Murdoch will prove to be a worthy
replacement. Steven has been grabbing headlines these last few days for
his work on Visa's 3DS. I am sure that his lecture on banking security
architectures will prove to be one of the highlights of this year's
course.

In the meantime, the program for SecAppDev 2010 is being finalized
(http://secappdev.org/pages/8). Check out the other exciting speakers
who will be ensuring that SecAppDev remains at the vanguard of secure
software engineering. There are still some places left at SecAppDev
2010, but do not delay registration. I am looking forward to your
comments and hope to see you soon.

Johan Peeters Program Director http://secappdev.org

VMware Security Professional Training: How Hackers enter our virtual environment
Written by Webmaster Rob   
Feb 01, 2010 at 10:44 AM

VMware Security Professional Training: “How Hackers enter our virtual environment”

Lancelot Institute trainer Aman Bhar (Malaysia) will teach students how easy it is to hack into virtual environments and best practices on how to protect the organization.

This is a 5 day, in- depth and 60% hands on training for security professionals, architects and VMware engineers. The training prepares for certification.

ISSA- members receive a 10% discount on this training. For more information:
http://www.lancelotinstitute.com/$id_608/

combined OWASP ISSA event
Written by Webmaster Rob   
Feb 01, 2010 at 10:41 AM

Dear ISSA-BE Member,
Dear Security Professional,

ISSA-BE would like to inform you about the following events and member benefits

OWASP Belgium Chapter meeting, together with ISSA Belgium

There are only 100 seats available (first register, first serve)!

WHAT

The Open Web Application Security Project (
www.owasp.org) Belgium Chapter organizes their next Chapter meeting. OWASP's all-volunteer participants produce free, professional quality, open-source documentation, tools, and standards on application security. An example of this is the famous OWASP top ten of most critical web application security flaws. The OWASP community facilitates conferences, local chapters, articles, and message forums. Participation in OWASP is free and open to all, as are all the materials we produce.

WHEN

Monday, February 1th, 2010 (18h00pm-21h00pm), together with ISSA Belgium.

WHERE

Location is sponsored by Ernst&Young's Information Security Team.
address: De Kleetlaan 2, 1831 Diegem (
Route + Google Maps)

PROGRAM

    * 18h00 - 18h30: Welcome & Refreshments
    * 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, Zenitel, OWASP Board)
    * 18h45 - 19h00: ISSA Update (by tbd, ISSA)
    * 19h00 - 20h00: GreenSQL: an Open Source database firewall (by Yuli Stremovsky, VP of Research and Development at GreenSQL)
    * 20h00 - 20h15: Break
    * 20h15 - 21h15: Mobile malware now and in the future (by Mikko Hypponen, Chief Research Officer at F-Secure Corp)

More information can be found at
http://www.owasp.org/index.php/Belgium#tab=Chapter_Meetings .

REGISTRATION


There are only 100 seats available (first register, first serve)!

Please send a mail to
if you plan to attend, so we can size the venue appropriately and keep you updated on last-minute changes.

Please forward to anyone you feel would have an interest in these events.

<< Start < Previous 1 2 3 Next > End >>

Just as we hit the Infosecurity.be fair, and as a small reminder for all of you, check out a brief overview of current additional benefits you get when becoming a member of ISSA-BE.

Fill out the forms at booth 08C100 !

 

 

Polls
What kind of topic would you like to see next year?
  
Who's Online
We have 11 guests online