|
|
Upstate SC ISSA
The Global Voice of Information Security
|
|
|
Upcoming Events
|
Next Chapter Meeting - Friday, May 15th, 2009 - 11:00AM to 12:30PM |
- Presentation:
Establishing a Vulnerability Management Program
- Today's environments are continually plagued by security risk and Security Professionals and System Administrators alike must establish the appropriate processes for proactively identifying and managing risk throughout their environments. Come join this important and lively discussion on how to implement the various aspects of a successful Vulnerability Management Program within your own organization!
- Door prizes to include a $50 Amazon gift card and other items!
- Bootable Live DVD versions of the latest beta version of BackTrack will be made available to attendees.
- Please RSVP for the event by sending an Email to webmaster@upstate-issa.org.
- Catered box lunches will be provided at a nominal cost of $10 per person. If you'd like to eat lunch with us, please make sure to RSVP to webmaster@upstate-issa.org at least 24 hours prior to the meeting. Also, please include any type of drink you would like to have.
- AGENDA - April 17th, 2008 - 11AM to 12:30PM
- 11:00 - 11:15 Lunch/Networking
- 11:15 - 11:30 Introductions/Announcements
- 11:30 - 12:20 Presentation
- 12:20 - 12:30 Q&A/Door Prizes/Wrap-up
- DIRECTIONS
|
|
The 2009 TECHNO SECURITY Conference - May 31 - June 3, 2009 at Myrtle Beach, SC |
- Presentation:
The Eleventh Annual International Techno Security Conference
This conference promises to be THE international meeting place for IT Security
professionals from around the world. The conference will feature some of the top speakers in the industry, and will
raise international awareness towards increased education and ethics in IT security.
- Held at the Myrtle Beach Marriott Resort at Myrtle Beach, South Carolina
http://www.myrtlebeachmarriottresort.com
- Schedule of Events, additional information
http://www.techsec.com/html/Techno2009.html
|
| |
|
| |
|
|
Study Sessions – CISSP & Security+!
Studying for your CISSP, Security+ or other Information Security
certifications? Let us know if you’re looking for help! The Upstate SC
ISSA Chapter has more than a few certified individuals willing to help
you pass!
For more information on upcoming study sessions, please contact
webmaster@upstate-issa.org.
Past Events
04/17/09 - April Meeting - eDiscovery & Digital Forensics - The New Corporate Tools - As a follow-up to our February meeting discussion which began to address Data Forensics, Clay Boswell, Information Security Director at Sealed Air & our Chapter Vice President, will be looking at the wide variety of tools used in an enterprise's eDisovery and Digital Forensics program. Also, we'll be providing a preview of the new BackTrack 4 Beta penetrationtesting platform.
03/20/09 - March Meeting - Cyber Threat - Underground Economy - The Symantec Report on the Underground Economy
is a survey of cybercrime activity in the underground economy. It includes a discussion of some of the more notable groups
involved, as well as an examination of some of the major advertisers and the most popular goods and services available.
It also includes an overview of the servers and channels that have been identified as hosts for trading, and a snapshot
of software piracy using a file-sharing protocol in the public domain.
03/17/09 - 03/18/09 - - ATLANTA SECUREWORLD Conference- Conference topics include, Security Policy Conmpliance, Defense Against Dark Bots, Risk Assessment,
and Informatin Risk Leadership.
01/14/09 - January Meeting - Hack the Flag! - Each four hour session is designed for both the experienced security
professional and those new to the field of penetration testing. We'll cover performing network reconnaissance, along with
a wide variety of pen testing techniques and ultimately gaining control over resources in a typical Windows & Cisco based
environment seen implemented in most SMB environments today.
10/17/08 - October Meeting - You're Compliant - But Are You Secure? - Dan Ramaswami, Senior Security Engineer with Sourcefire
(www.sourcefire.com), will discuss the importance of creating a security program that protects your enterprise and produces compliance as
a by-product. Any compliance effort that focuses strictly on a given set of requirements to check off will not produce long-lasting success.
If security is built into your operations, and your mindset, you will be better able to handle changes in existing rules and new regulations
that come up. As we know they will.
09/19/08 - September Meeting - Web Application Hacking for Web Developers How safe are your web
applications? You’ll think twice after seeing how Foundstone security
experts dig into their hacker's toolbox and rip open web applications
by exploiting simple software bugs. Common problems such as Cross-Site
Scripting (XSS) and SQL Injection will be demonstrated and explained,
along with more subtle vulnerabilities including privilege escalation,
data tampering, and Cross-Site Request Forgery. Even if you've seen
XSS and SQL Injection before, advanced techniques will be presented
that can slip through many protections. As a finale, the holy grail of
web security will be broken with a Man-In-The-Middle attack on SSL.
Countermeasures to prevent mistakes will then be shared. Join us for
this guaranteed informative discussion with Dean Saxe, Managing
Consultant with Foundstone Professional Services (www.foundstone.com).
08/18/08 - August Meeting - Jeff Busby from Sapphire Technologies will be discussing successful strategies for new and established members of the Information Security field. What value do security certifications truly hold? How do certifications compare to degrees? What's the overall outlook on the job market place today for InfoSec professionals? Bring all of your career questions for Jeff for what should be a lively discussion!
07/18/08 - July Meeting - IBM's Information Security Systems (ISS) Linda from ISS presented on the various threats that present risk against environments today and explained how the current threat environment has evolved over the years.
06/20/08 - June
Meeting - Chris Knox, Stalwart Systems Chris Knox, Security Engineer for Stalwary Systems, provided an overview of conducting a vulnerability assessment for a company. Chris also shared various penetration testing techniques along with his interesting experiences.
05/16/08 - May
Meeting - Robert Hamod, Federal Bureau of
Investigation Robert Hamod
of the FBI came to discuss Information Security
today with special "Notes from the Field". We'll
also discussed how the private sector can work
more closely with government agencies like the
Federal Bureau of Investigation in cyber
security matters, taking advantage of great
resources like the Infragard organization
(http://www.infragard.net/).
04/18/08 - April
Meeting - Uncovering Secret Botnet
Communication and Evil Botnet
Herders John Fraizer, Network
Security Engineer for NuVox, presented an
overview of some of the law enforcement online
and private individual efforts in infiltrating
botnets in an effort to identity their creators
and eliminate the risks presented by these
individuals and their zombie
networks.
03/28/08 - March Meeting -
Penetration Testing with the Metasploit
Framework Mike Holcomb, Chapter President
and Network Security Engineer for NuVox,
presented an overview of the Metasploit
Framework and it's unique features in aiding
penetration efforts and validating discovered
vulnerabilities.
02/22/08 - February Meeting
- Vulnerability Assessment Process with
BackTrack
Mike Holcomb, Network Security Engineer for NuVox, presented an overview of the Penetration Testing process and introduced the BackTrack Live CD with its collection of security testing tools.
SLIDES
|
| |
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|