event
24 January 2012 - 8am PST / 11am EST / 4pm GMT

Information Protection and Authentication

Emerging technologies such as mobile devices, online payments and Web applications have not only made accessing personal and corporate data convenient for users, but also for hackers. Securing data has become more than just creating a complex password, as attacks are becoming increasingly sophisticated and one incident of security breach can have a huge impact on an organization. Learn how to prevent cybercrime and improve security posture with authentication and other solutions from leading industry experts.

3
6 Recorded Webcasts


Program
24 January 2012 - 8am PST / 11am EST / 4pm GMT
Opening Remarks - Moderator



Brandon Dunlap
Brandon Dunlap
Managing Director, Research
Brightfly

24 January 2012 - 8am PST / 11am EST / 4pm GMT
Overview of SSL Authentication

To make an environment secure, you must be sure that any communication is with "trusted" sites whose identity you can be sure of. Transport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL), are cryptographic protocols that provide communication security over the Internet. TLS and SSL encrypt the segments of network connections above the Transport Layer, using asymmetric cryptography for key exchange, symmetric encryption for privacy and message authentication codes for message integrity. Several versions of the protocols are in widespread use in applications such as web browsing, electronic mail, Internet faxing, instant messaging and voice-over-IP (VoIP). This presentation will provide an overview of the history/development of the protocol, applications that are used, the security measures including overview of TLS handshakes, implementations, and recent security issues with the protocol.


Edward Ray
Edward Ray
Chief Information Security Officer
MMICMAN, LLC

24 January 2012 - 9am PST / 12pm EST / 5pm GMT
The Mistakes Commonly Made with SSL and How to Avoid Them

SSL can provide powerful security when configured correctly, but errors and laziness are frighteningly common. Thanks to a project of the EFF (Electronic Frontier Foundation) we can see which errors are most common. They scanned the Internet for SSL certificates and examined them. Many servers use weak or broken keys. Many had invalid signatures from certificate authorities. Some signed invalid host names. Quite a few were expired. Errors such as these could mean weakened protection for your site and your users. They could cause errors on the user end and engender distrust. Learn from these examples how to do SSL right.


Larry Seltzer
Larry Seltzer
Security Analyst

24 January 2012 - 10am PST / 1pm EST / 6pm GMT
Identification and Authentication

Identification and Authentication (I&A) methods and activities have dramatically expanded over the past 5 years, after being relatively the same for the previous 15 years. We examine the basics of I&A and see what is new in the field in this talk.


Leighton Johnson III
Leighton Johnson III
COO & Senior Security Engineer
ISFMT

24 January 2012 - 11am PST / 2pm EST / 7pm GMT
Closing Comments by Aleese Eckenrode



Aleese Eckenrode
Aleese Eckenrode
Education Coordinator
ISACA

24 January 2012
CPE Quiz