The most trusted source for computer security training, certification and research.



select a course
San Jose, CA - December 4 - 9, 2006
Global Information Assurance Certification

The information presented is priceless!
-Nehal Parmar, North Fork Bank

Faculty for SANS Silicon Valley 2006

Jonathan Ham
Jonathan is an independent consultant who specializes in large-scale enterprise security issues, from policy and procedure, through staffing and training, to scalable prevention, detection, and response technology and techniques. With a keen understanding of ROI and TCO (and an emphasis on process over products), he has helped his clients achieve greater success for over 12 years, advising in both the public and private sectors, from small upstarts to the Fortune 500. He's been commissioned to teach NCIS investigators how to use Snort, performed packet analysis from a facility more than 2000 feet underground, and chartered and trained the CIRT for one of the largest U.S. civilian Federal agencies. He currently holds the CISSP, GSEC, GCIA, and GCIH certifications, and is a member of the GIAC Advisory Board. A former combat medic, Jonathan still spends some of his time practicing a different kind of emergency response, volunteering and teaching for both the National Ski Patrol and the American Red Cross.
James Manico
Jim is the VP of Software Engineering for CodeMagi Inc., a service firm specializing in cutting edge web application development. Jim brings ten years of web-based database-driven software development and analysis experience to client engagements. CodeMagi Inc. has recently provided service for SUN Microsystems, Fox Media, the Golden State Warriors and Architecture for Humanity. In addition, Jim has expertise working with a wide variety of technologies including web-based development with J2EE, thick-client and applet-based Java applications, hybrid applications using Java, C++ and Flash, web-based PHP applications using Drupal 4.7, rich-media web applications using advanced Ajax techniques, and Database technology using Oracle, MySQL and Postgres. Jim's office is located on the beautiful island of Kauai, HI and hosts a bi-weekly call-in computer talk radio show for KKCR, Kauai's community radio station. Jim previously served as the Director of Vendor Relations with the SANS Institute. Jim often volunteers his time fixing and tuning his neighbors computers, the only cost to them is being lectured at regarding the importance of backup and security.
David Rice

David Rice is an internationally recognized cyber security expert, consulting director for policy reform at the U.S. Cyber Consequences Unit, and author of the critically acclaimed book Geekonomics: The Real Cost of Insecure Software. Mr. Rice is a key figure shaping the discussion of cyber security, and his work impacts both U.S. and European cyber security policy. As director of The Monterey Group, a private consulting firm, Mr. Rice advises a variety of clients on a range of issues, including cyber strategy development and execution, corporate cyber risk management, cyber security metrics, identity management, and secure software development practices.

William Stearns
Bill is a Senior Research Engineer at Dartmouth's Institute for Security Technology Studies, working on Honeypot development and other network security projects. He is a content author and faculty member at the SANS Institute. His background is in network and operating system security; he was the chief architect of a commercial firewall and is an active contributor to the Linux development effort. His spare time is spent coordinating and maintaining an antispam blacklist. Bill's articles and tools can be found in SysAdmin magazine, online journals, and at http://www.stearns.org.
John Strand
John Strand currently is the owner and senior security researcher with Black Hills Information Security, and a consultant with Argotek, Inc for TS/SCI programs. As a certified SANS instructor he teaches: 504 "Hacker Techniques, Exploits and Incident Handling," 517, "Cutting Edge Hacking Techniques," and 560 "Network Penetration Testing." He is a contributing author of Nagios 3 Enterprise Network Monitoring, and a regular contributor to SearchSecurity's "Ask the Expert" series on the latest information security threats. He also regularly posts videos demonstrating the latest computer attacks and defenses at vimeo.com/album/26207. He started the practice of computer security with Accenture Consulting in the areas of intrusion detection, incident response, and vulnerability assessment/penetration testing. John then moved on to Northrop Grumman specializing in DCID 6/3 PL3-PL5 (multi-level security solutions), security architectures, and program certification and accreditation. He has a master's degree from Denver University and is currently also a professor at Denver University. In his spare time he writes loud rock music and makes various futile attempts at fly-fishing.