Register for Network Security-Vegas by Sept. 3 for $250 discount. >> More Info
the most trusted source for computer security training, certification and research


select a course
Las Vegas, NV - September 28 - 30, 2006
Global Information Assurance Certification

Real life - real solutions changed the way I look at security.
-Richard B. Williams, US Army ALTESS

Participating Vendors:



ArcSight, Inc. Mu Security
Sensage HP
Mu Security

Vendor Hospitality Suites

Friday, September 29th: 5:00pm - 8:00pm, Palace Tower Promenade Level
Join the vendors for the opportunity to discuss the latest in SCADA security tools while enjoying an evening of food, drinks, and networking. You will meet industry leaders who are interested in you thoughts regarding new and future developments. In addition, you will be able to speak with their customers and learn how they are leveraging products to improve SCADA Security.
Mu Security - Genoa Room
Please join Mu Security for Superior Cocktails and Delectable Appetizers as well as insightful discussions with users already benefiting from the automation and operationalization of the often challenging Security, Test, and Evaluation (ST&E) portion of the Certification and Accreditation (C&A) processes. PNNL's Mark Hadley will discuss his top 5 SCADA security issues and what PNNL and industry requires to fix these over the next couple of years.
You can also learn more about how the newly created Security Analyzer system essentially automates the ST&E process with standardized security testing and results. Mu Security is already working with SCADA experts to analyze both 0-day and published vulnerabilities. In addition, Designated Approval Authorities (DAA) are working with the Mu-4000 to ensure they receive accreditation packages that have the highest assurance that IP-enabled technology does not inadvertently introduce weaknesses into critical infrastructure.
Don't miss the chance to win a SONY PS2 and fabulous games at 6:30!
Mu Security offers a new class of security analysis system, delivering a rigorous and streamlined methodology for verifying the robustness and security readiness of any IP-based product or application. Founded by the pioneers of intrusion detection and prevention technology, Mu Security is backed by preeminent venture capital firms that include Accel Partners, Benchmark Capital and DAG Ventures. The company is headquartered in Sunnyvale, CA. For more information, visit the company's website at www.musecurity.com.
Arcsight - Capri Room

Refuel at ArcSight's Margaritaville

After a long day of sessions, it.s time to give your brain a break.and ArcSight.s Margaritaville is just the place to kick back with a nice cold one. If you relax best with a little techtalk, we.ll be showing a product demo of how ArcSight addresses the needs of the energy sector and how our SIM solution is being applied to SCADA and process control networks. No matter what, make sure you.re in Margaritaville by 7:30pm for your chance to win a Apple iPod video!

ArcSight, a leader in Enterprise Security Management, provides solutions that serve as the mission control center for real-time threat management, compliance reporting and automated network response. By comprehensively collecting, analyzing and managing security data, ArcSight solutions centrally manage and mitigate information risk for security, insider threat and compliance. ArcSight has a blue-chip customer base of over 200 enterprises, government agencies and MSSPs along with a rich partner eco-system. The company has received numerous awards and recognition including Network Computing.s Editor.s Choice award for two consecutive years and Network World.s Best of Tests award. For more information, visit www.arcsight.com

Symantec - Pompeian I

Join Symantec for a discussion of real-world SCADA and DCS security risks, the top 10 common vulnerabilities, and effective practices for protection. We will also discuss compliance with regulations and standards (such as NERC CIP and Sarbanes Oxley) for process control environments.

Symantec offers a comprehensive set of industry-specific solutions to help power and energy companies ensure business continuity, achieve standards and regulatory readiness, and avoid costly disruptions associated with cyber security incidents. Together with our partners, Symantec delivers best practices, products and services to ensure the security, availability and integrity of power and energy companies - both in the areas of IT and Operations. To learn more about Symantec's power and energy solutions, visit: http://ses.symantec.com/power_2 or email us at Industry_Solutions@symantec.com

HP / SenSage - Pompeian II

Visit the HP/SenSage SCADA suite and have a sneak peak at an integrated NERC CIP 002-009 Compliance solution from HP, powered by SenSage. Get into the Vegas spirit with food, drink and our "I'm All In" game chances to win cool shirts or a HP Photosmart 10 MP camera.

HP is a technology solutions provider to consumers, businesses and Institution's globally. It is estimated that more than 65 percent of the World's power is controlled by systems from HP and its partners. HP will preview advanced security and scalable event data management technologies that transform the intent to comply with the NERC CIP 002-009 requirements into plans, controls, processes and records.

SenSage Inc., the leading provider of scalable event data management solutions, empowers companies to respond to business-critical threats, conduct thorough investigations, and maintain compliant operations.

Vendor Sponsored Lunch & Learns

Vendor Lunch and Learn Sessions are an opportunity to evaluate vendor tools in an interactive environment to increase your effectiveness, productivity and knowledge gained from the summit while enjoying a light lunch.

Friday, September 29, 12:10 PM . 1:20 PM
Arcsight - Pompeian I Room, Palace Tower Promenade Level

Come lunch and learn how SCADA principles are now being applied to security systems. With a centralized security information management system to monitor, correlate, and alert on all network, application, and other security data, organizations can amplify their security posture and more efficiently respond to threats. Join us to learn how the SCADA practices allow you to combat cyber terrorists and improve your organization's security posture.

Glen Sharlun, Director, Strategic Application Solutions, ArcSight
Glen is responsible for the rapid development and delivery of "Strategic Solutions" to ArcSight.s customers. Building on his years of experience of global network operations as the lead executive for the protection of the U.S. Marine Corps. world-wide network, he has the operational mind-set and experience to identify and then deliver immediate value to ArcSight.s customers. Having been responsible for all budgetary, personnel and operational prioritization; 24/7 global monitoring, response & forensics; and being the Certification/Compliance Authority before that, Glen has a well rounded view of effective operations. He has been regularly taking these experiences to the market space since 2001 as faculty for SANS, at select CSO events and the Pentagon Security Forum. Glen is a graduate of the U.S. Naval Academy and the Naval Postgraduate School (MS, Info Tech Mgmt), and has (& instructs) numerous certifications from ISC2, SANS and the NSA.

HP / SenSage - Pompeian II Room, Palace Tower Promenade Level

SCADA Compliance Information Management - Pitfalls, Obligations and Practices Hewlett-Packard, the leading provider of IT solutions and services for the energy market and SenSage, the leader provider of scalable log management and analytics solutions, have teamed to expose the latest obligations, best practices and audit objectives to consider for SCADA compliance. This informative session will explore what's needed, what works, what Pitfalls to avoid, how to size implementation and what audit proofs should be on-hand. Attendees will also get a glimpse of an integrated solution to automate event data collection, protected retention, rapid response and audit documentation that support SCADA obligations and reduce security risks. In the spirit of Vegas - lunch, shirts and the chance to win a HP Photosmart 10 MP camera will be provided.

James Hansen, Sensage Senior Tehcnical Product Manager, has more than 9 years of security enterprise software deployment and management experience. As the Director of Professional Services for SenSage, James developed the methodologies and approaches used by SenSage to successfully enable customers to meet their compliance and regulation goals. As Sr. Technical Product Manager he is responsible for the growth of the SenSage product suite.

Jeff Kalibjian is a Senior Security Architect in Hewlett Packards Atalla Security Products organization. HP Atalla has been the leader in hardware based security for over thirty years. Jeff is lead architect for HPs new energy compliance product, the Trusted Compliance Solution for Energy. He has been in senior management for two security start-ups (TriStrata and CounterSign Software), and has had led his own security consulting company. Prior to joining the public sector, Jeff spent twelve years at the Lawrence Livermore National Laboratory where he did pioneering work in missile defense, automated design and manufacture, and electronic commerce. He has a BS in Electrical Engineering and Computer Science from UC Berkeley and is Chairman of the IEEE East Bay Computer Society.

Saturday, September 30th, 12:10 PM - 1:20 PM
Mu Security - Pompeian I, Palace Tower Promenade Level

Kowsik Guruswamy, CTO and Co-founder
Security Analysis ROI

End users and product developers use Security Analyzers for creating & automating security readiness metrics for networked hardware or software product. Mu Security will discuss Security Analyzer usage scenarios including product quality, configuration validation, comparative security analysis and threat assessment to identify and expedite remediation of vulnerabilities before malicious exploits.

Kowsik Guruswamy is Mu Security's co-founder. Prior to founding Mu, he was a Distinguished Engineer at Juniper and the Chief Architect for Intrusion Prevention products, joining through the acquisition of NetScreen/OneSecure. He holds 8 networking and security patents and a MS in Computer Science from the University of Louisiana.