<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Safelight Security Advisors &#187; Events</title>
	<atom:link href="http://safelightsecurity.com/news/category/events/feed/" rel="self" type="application/rss+xml" />
	<link>http://safelightsecurity.com</link>
	<description>Enabling organizations to proactively manage information security risks</description>
	<lastBuildDate>Wed, 01 Feb 2012 15:19:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Rob Cheyne Demonstrates Application Architecture Security Assessment</title>
		<link>http://safelightsecurity.com/news/2010/11/30/1063/</link>
		<comments>http://safelightsecurity.com/news/2010/11/30/1063/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 15:24:48 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=1063</guid>
		<description><![CDATA[Overview Date – Wednesday December 1 Time &#8211; 6:30 p.m. Location &#8211; Microsoft Offices in Waltham, MA Topic &#8211; Application Architecture Security Assessment &#8211; First Session Presenter – Rob Cheyne, Safelight Security In the December 1st session, Rob will conduct a sample architecture assessment against a real-world system, and in the process, teach participants how [...]]]></description>
			<content:encoded><![CDATA[<h2>Overview</h2>
Date – Wednesday December 1 <br/>
Time &#8211; 6:30 p.m. <br/>
Location &#8211; Microsoft Offices in Waltham, MA<br/>
Topic &#8211; Application Architecture Security Assessment &#8211; First Session<br/>
<br/>
<h2>Presenter – Rob Cheyne, Safelight Security</h2>
<p>In the December 1st session, Rob will conduct a sample architecture assessment against a real-world system, and in the process, teach participants how to conduct an architecture of their own.  Brave volunteers will be welcome to share their own architectures and have them reviewed. This is an opportunity to get free consulting that typically costs thousands of dollars.  There is limited time, so not every one will get chosen.  If you are interested in this, please contact Rob Cheyne (rcheyne@safelightsecurity.com) directly.</p>

<h2>Additional information:</h2>
<p>Penetration testing is a common way to evaluate an application&#8217;s security.  Yet a comprehensive architecture and design assessment can uncover critical security issues that often cost far less to resolve early on in a project.  Many companies overlook this element of system design.</p>

<p>Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems. </p>

<h2>Location and Directions</h2>
 
Microsoft offices at the Waltham Weston Corporate Center, 201 Jones Rd., Sixth Floor Waltham, MA]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/11/30/1063/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>John Carmichael and Rob Cheyne Featured at BASC 2010</title>
		<link>http://safelightsecurity.com/news/2010/11/15/john-carmichael-and-rob-cheyne-featured-at-basc-2010/</link>
		<comments>http://safelightsecurity.com/news/2010/11/15/john-carmichael-and-rob-cheyne-featured-at-basc-2010/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 15:21:28 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=1059</guid>
		<description><![CDATA[John Carmichael and Rob Cheyne presented to over 150 attendees of the 2010 OWASP Boston Application Security Conference. Coffee Shop Warfare:Protecting Yourself in Dark Territory Presented by: John Carmichael Time: 13:00-13:50 Track: 2 A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops [...]]]></description>
			<content:encoded><![CDATA[<strong>John Carmichael and Rob Cheyne presented to over 150 attendees of the 2010 OWASP Boston Application Security Conference.  
</strong>

<h2>Coffee Shop Warfare:Protecting Yourself in Dark Territory</h2>
Presented by: John Carmichael<br/>
Time: 13:00-13:50<br/>
Track: 2<br/>

<p>A lighthearted look at the real threats that people face in personal computing, specifically when connected to unknown network at coffee shops and airports. John will cover many of these threats and discuss tools and best practices everyone can engage in to ensure they protect their machine and information from these risks. </p>

<h2>OWASP Basics 1 and 2</h2>
Presented by: Robert Cheyne<br/>
Time: 10:00-11:50<br/>
Track: 2<br/>

<p>Rob presents a number of scenarios that walk participants through the basics of SQL injection, XSS and CSRF, along with a few other tricks he has up his sleeve. Participants will come away with a foundation for further security learning. Those already knowledgeable on application security issues will learn some new techniques for presenting and teaching this information in a clear, concise and effective manner.</p>
]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/11/15/john-carmichael-and-rob-cheyne-featured-at-basc-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rob Cheyne presenting at OWASP Boston, October 6th</title>
		<link>http://safelightsecurity.com/news/2010/09/27/rob-cheyne-presenting-at-owasp-boston-october-6th/</link>
		<comments>http://safelightsecurity.com/news/2010/09/27/rob-cheyne-presenting-at-owasp-boston-october-6th/#comments</comments>
		<pubDate>Mon, 27 Sep 2010 19:18:57 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=1009</guid>
		<description><![CDATA[Next meeting – Wed. Oct 6. Microsoft Waltham. This is the first of a 2 part session. The second part will be Wed. Dec. 1. Overview: In this highly interactive two-part workshop, Rob Cheyne of Safelight Security will show you the basics of conducting a real-world architecture &#38; design review. This workshop draws from Safelight&#8217;s [...]]]></description>
			<content:encoded><![CDATA[Next meeting – Wed. Oct 6. Microsoft Waltham. This is the first of a 2 part session. The second part will be Wed. Dec. 1.
<p>
<strong>Overview:</strong></p>
<p>In this highly interactive two-part workshop, Rob Cheyne of Safelight Security will show you the basics of conducting a real-world architecture &amp; design review.
This workshop draws from Safelight&#8217;s Security Architecture Fundamentals training course, a two-day course frequently used to teach Fortune 500 companies how to look at their system architectures from both the hacker&#8217;s and the designer’s point of view.</p>

<p><strong>First session:</strong></p>
<p>In the first session on October 6, Rob discusses a practical approach to architecture review and threat modeling using real-world examples. This session lays the foundation for participants to participate in a real-world architecture review in the December session.</p>

<p><strong>Attendees will learn:</strong></p>
<ul>
	<li>How to holistically examine a system architecture for security issues from both the designer’s and the hacker&#8217;s point of view</li>
	<li>To identify frequently overlooked areas where security vulnerabilities commonly occur</li>

	<li>Tips for assessing a system at the host-level, network level, and application level</li>

	<li>Practical ways to apply threat modeling to help manage risk</li>

</ul>


<p><strong>Second session:</strong></p>
<p>In the December 1st session, Rob will conduct a sample architecture assessment against a real-world system, and in the process, teach participants how to conduct an architecture of their own.  Brave volunteers will be welcome to share their own architectures and have them reviewed. This is an opportunity to get free consulting that typically costs thousands of dollars.  There is limited time, so not every one will get chosen.  If you are interested in this, please contact Rob Cheyne (rcheyne@safelightsecurity.com) directly.</p>

<p><strong>Who should attend?</strong></p>
<p>Anyone can participate and learn from the discussion in this accessible and dynamic workshop.  Whether you are an architect, a developer, or a manager, there will be something here for you.  Come learn to challenge your assumptions.</p>

<p><strong>Additional information:</strong></p>
<p>Penetration testing is a common way to evaluate an application&#8217;s security.  Yet a comprehensive architecture and design assessment can uncover critical security issues that often cost far less to resolve early on in a project.  Many companies overlook this element of system design.
Rob was one of a select few at security consulting company @stake who regularly led and conducted full-blown enterprise-level architecture assessments for Fortune 500 companies.  Drawing from his experience with dozens of real-world architecture assessments over the past 12 years, and his 20 years as a software developer, architect, and consultant, Rob teaches students to challenge assumptions that frequently lead to long-term security and reliability problems.</p>
<p>http://www.owasp.org/index.php/Boston</p>

We will still have a November meeting, featuring <strong>Pravir Chandra</strong>, project leader for OWASP Open SAMM.

http://www.owasp.org/index.php/Category:Software_Assurance_Maturity_Model#tab=Main
]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/09/27/rob-cheyne-presenting-at-owasp-boston-october-6th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP Boston Lighting Talk:  Cross Site Scripting, Reflected and Persistent</title>
		<link>http://safelightsecurity.com/news/2010/05/28/owasp-boston-lighting-talk-cross-site-scripting-reflected-and-persistent/</link>
		<comments>http://safelightsecurity.com/news/2010/05/28/owasp-boston-lighting-talk-cross-site-scripting-reflected-and-persistent/#comments</comments>
		<pubDate>Fri, 28 May 2010 17:12:06 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=462</guid>
		<description><![CDATA[In the second installment of Safelight’s Lightning Talk series, Rob Cheyne will present the basics of cross-site scripting (XSS) at OWASP Boston. He will cover the two primary methods of XSS attack, reflected and persistent, as well as provide detailed demonstrations that show how an attacker would use these methods in the real world.  As [...]]]></description>
			<content:encoded><![CDATA[<p>In the second installment of Safelight’s Lightning Talk series, Rob Cheyne will present the basics of cross-site scripting (XSS) at <a href="http://www.owasp.org/index.php/Boston" target="blank">OWASP Boston</a>.

<p>He will cover the two primary methods of XSS attack, reflected and persistent, as well as provide detailed demonstrations that show how an attacker would use these methods in the real world.</p> 
<p>As part of the demo, Rob will go beyond proof of concept and present an example of a &#8220;weaponized&#8221; JavaScript that could be used to steal another user&#8217;s session information.</p> 
<p>Rob will also offer practical tips for defending against cross-site scripting flaws in your own applications.</p>
 
<p>When: June 2, 2010</p>

<p>Time: 6:30 p.m.</p>

<p>Where: Microsoft offices at the Waltham Weston Corporate Center, 201 Jones Rd., Sixth Floor Waltham, MA<p>

]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/05/28/owasp-boston-lighting-talk-cross-site-scripting-reflected-and-persistent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safelight Headlines OWASP Boston with Monthly Lightning Talk Series</title>
		<link>http://safelightsecurity.com/news/2010/05/05/safelight-headlines-owasp-boston-with-monthly-lightning-talk-series/</link>
		<comments>http://safelightsecurity.com/news/2010/05/05/safelight-headlines-owasp-boston-with-monthly-lightning-talk-series/#comments</comments>
		<pubDate>Wed, 05 May 2010 19:33:01 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=404</guid>
		<description><![CDATA[IT Security Education Key to Defending Against OWASP Top 10 Most Critical Web Application Vulnerabilities In the first of the Safelight Security Advisors Lightning Talk Series, CEO Rob Cheyne will discuss “An Introduction to SQL Injection,” at the Open Web Application Security Project (OWASP) Boston chapter meeting, Monday, May 3. Rob will cover the methodology [...]]]></description>
			<content:encoded><![CDATA[<p><em>IT Security Education Key to Defending Against 
OWASP Top 10 Most Critical Web Application Vulnerabilities</p></em>


<p>In the first of the Safelight Security Advisors Lightning Talk Series, CEO Rob Cheyne will discuss “An Introduction to SQL Injection,” at the Open Web Application Security Project (OWASP) Boston chapter meeting, Monday, May 3.</p>  

<p>Rob will cover the methodology used by professional attackers, along with detailed demonstrations of one of the most common and dangerous OWASP Top 10 issues.</p>

<p>After demonstrating how SQL injection can be used to run system commands and gain root access on a database server, Rob will provide practical tips for defending against SQL injection flaws.</p>

<p>Safelight’s Lightning talks are designed for members newer to OWASP interested in understanding the basics of web application security, although everyone should feel free to attend.</p>

<p>When: 	
May 3, 2010, with subsequent meetings typically the first Wednesday of the month<p>
6:30 – 7:00 p.m. Networking
7:00 – 9:00 p.m. Main Presentations
<a href="https://lists.owasp.org/mailman/listinfo/owasp-boston" target="_blank">Join the Boston mailing list.</a> <p>


]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/05/05/safelight-headlines-owasp-boston-with-monthly-lightning-talk-series/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join Us at the RSA 2010 Conference</title>
		<link>http://safelightsecurity.com/news/2010/02/19/join-us-at-the-rsa-2010-conference/</link>
		<comments>http://safelightsecurity.com/news/2010/02/19/join-us-at-the-rsa-2010-conference/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 17:21:54 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=184</guid>
		<description><![CDATA[RSA 2010 Conference March 1-3 Moscone Center San Francisco, CA Join Safelight at Booth #2058 to see the latest in information security training, including our newest online learning programs. Attend our customer presentation, Banking on Security Education with State Street Bank’s Vice President Jeff Richard, and cocktail reception from 6:00 -8:00 p.m. at The St. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://rsaconference.com/2010/usa/" target="blank">RSA 2010 Conference</a></p>
<p>March 1-3</p>
<p>Moscone Center</p>
<p>San Francisco, CA</p>

<p>Join Safelight at <a href="http://www.mapyourshow.com/shows/index.cfm?Show_ID=RSA10" target="_blank">Booth #2058</a> to see the latest in information security training, including our newest online learning programs.  Attend our customer presentation, <a href="http://securityadvisors.com/rsaevent" target="_blank">Banking on Security Education</a> with State Street Bank’s Vice President Jeff Richard, and cocktail reception from 6:00 -8:00 p.m. at The St. Regis Hotel to hear how this leading financial institution rolled out a comprehensive security training program for thousands of developers worldwide.  You must <a href="http://securityadvisors.com/rsaevent">register for this event</a> in advance in order to attend.]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/02/19/join-us-at-the-rsa-2010-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webcast: &#8220;New Technology Wearing Hand-Me-Down Vulns&#8221;</title>
		<link>http://safelightsecurity.com/news/2010/02/10/webcast-new-technology-wearing-hand-me-down-vulns/</link>
		<comments>http://safelightsecurity.com/news/2010/02/10/webcast-new-technology-wearing-hand-me-down-vulns/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 21:51:17 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=115</guid>
		<description><![CDATA[Safelight’s CEO Rob Cheyne will present a webcast for the Microsoft SDL Pro Network community on “New Technology Wearing Hand-Me-Down Vulns,” February 25, 2010 from 1:00-1:30 p.m. EDT. Using a web service as an example, Rob will demonstrate how classic vulnerabilities can crop up in new technologies and how applying SDL principles can help build [...]]]></description>
			<content:encoded><![CDATA[Safelight’s CEO Rob Cheyne will present a webcast for the Microsoft SDL Pro Network community on “New Technology Wearing Hand-Me-Down Vulns,” February 25, 2010 from 1:00-1:30 p.m. EDT.</p>  

<p>Using a web service as an example, Rob will demonstrate how classic vulnerabilities can crop up in new technologies and how applying SDL principles can help build secure systems.  <a href="https://www2.gotomeeting.com/register/469030554">Register</a> for the Webcast.  

]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/02/10/webcast-new-technology-wearing-hand-me-down-vulns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safelight Named Member of Microsoft SDL Pro Network</title>
		<link>http://safelightsecurity.com/news/2010/02/02/safelight-named-member-of-microsoft-sdl-pro-network/</link>
		<comments>http://safelightsecurity.com/news/2010/02/02/safelight-named-member-of-microsoft-sdl-pro-network/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 14:30:38 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=104</guid>
		<description><![CDATA[At BlackHat DC 2010, Safelight Security Advisors today became a training member of Microsoft’s Security Development Lifecycle (SDL) Pro Network. Microsoft created the SDL Pro Network to help development organizations adopt the SDL and address the challenges of embedding security and privacy into their software and development culture. As one of seven new members and [...]]]></description>
			<content:encoded><![CDATA[At <a href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-home.html" target="_blank">BlackHat DC 2010</a>, Safelight Security Advisors today became a training member of Microsoft’s Security Development Lifecycle (SDL) Pro Network. Microsoft created the <a href="http://www.microsoft.com/security/sdl/getstarted/pronetwork.aspx" target="_blank">SDL Pro Network</a> to help development organizations adopt the SDL and address the challenges of embedding security and privacy into their software and development culture. As one of seven new members and the only training company selected among the latest group, Safelight joins a select network of industry leaders specializing in application security with significant experience in secure development lifecycle methodologies.</p>

<p>“Microsoft is happy to have SafeLight join the SDL Pro Network.  We believe training is a cornerstone to the SDL and SafeLight can help train developers on secure coding practices,” said David Ladd, Principal Security Program Manager, Microsoft’s Trustworthy Computing Group.</p>

<p>As part of the SDL Pro Network, Safelight looks forward to continuing the mission of training students on a disciplined process that’s proven to reduce vulnerabilities and lower the total cost of development. Safelight’s instructor-led and online learning programs helps companies incorporate security best practices into their development initiatives, offering security education courses that cover all phases of the SDL:
<ul>
	<li>Introduction to the Microsoft Development Lifecycle</li>
	<li>Application Security Fundamentals</li>
	<li>Architecting Secure Systems</li>
	<li>Language-Specific &amp; Language-Agnostic Secure Coding</li>
	<li>Testing for Secure Systems</li>
	<li>Managing a SDL (for project managers and team leaders)</li>
	<li>Risks of Insecure Applications (for business owners and executives)</li>
</ul>
Visit Safelight’s SDL Pro Network page at <a href="http://securityadvisors.com/sdl" target="_blank">http://securityadvisors.com/sdl</a> to learn more about our offerings.</p>

Read Microsoft’s announcement on the new SDL Pro Network members in their <a href="http://www.microsoft.com/presspass/events/blackhat" target="_blank">press room.</a>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/02/02/safelight-named-member-of-microsoft-sdl-pro-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rob Cheyne Presenting at CSI 2009</title>
		<link>http://safelightsecurity.com/news/2009/08/31/rob-cheyne-presenting-at-csi-2009/</link>
		<comments>http://safelightsecurity.com/news/2009/08/31/rob-cheyne-presenting-at-csi-2009/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 20:52:05 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=57</guid>
		<description><![CDATA[Safelight’s CEO Rob Cheyne will present, “Banking on Education: A Case Study on Developer Security” at CSI 2009 on Tuesday, October 27, 2009 from 9:45-10:45 a.m. Learn how Safelight Security Advisors helped a major U.S. bank create security training for its internal developers: both employees and contractors located in multiple countries. Attendees will learn ways [...]]]></description>
			<content:encoded><![CDATA[<p>Safelight’s CEO Rob Cheyne will present, “<a href="https://www.cmpevents.com/CSI36/a.asp?option=C&amp;V=11&amp;SessID=9826">Banking on Education: A Case Study on Developer Security</a>” at CSI 2009 on Tuesday, October 27, 2009 from 9:45-10:45 a.m.</p>

<p>Learn how Safelight Security Advisors helped a major U.S. bank create security training for its internal developers: both employees and contractors located in multiple countries. Attendees will learn ways to shift the mindset of this critical audience, leaving with ideas they can start to implement themselves.</p>

<p>CSI 2009 features a comprehensive program, covering 18 main topic areas, to provide the security knowledge needed to succeed in today&#8217;s environment. To attend, visit <a href="http://csiannual.com/">http://csiannual.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/08/31/rob-cheyne-presenting-at-csi-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business vs. Security: Let&#8217;s get ready to rumble!!!</title>
		<link>http://safelightsecurity.com/news/2009/03/09/business-vs-security-lets-get-ready-to-rumble/</link>
		<comments>http://safelightsecurity.com/news/2009/03/09/business-vs-security-lets-get-ready-to-rumble/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 13:36:35 +0000</pubDate>
		<dc:creator>Rob Cheyne, Safelight CEO</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[community]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[questions]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[source]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=50</guid>
		<description><![CDATA[I am currently preparing for the Business vs. Security panel that I am moderating at the Source:Boston conference on Wednesday, March 11th from 4:15-5:30pm. You can read about it here . Click the link that says &#34;The end of our rope: the ongoing tug-o-war between business and security&#34;, The gist is that we get two [...]]]></description>
			<content:encoded><![CDATA[<p>I am currently preparing for the Business vs. Security panel that I am moderating at the <a title="Source:Boston" href="http://sourceconference.com" target="_blank" title="Source:Boston">Source:Boston</a> conference on Wednesday, March 11th from 4:15-5:30pm.</p>

<p>You can read about it <a title="here" href="http://sourceconference.com/index.php/source-boston-2009/boston-2009-sessions" target="_blank" title="here">here</a> .  Click the link that says &quot;The end of our rope: the ongoing tug-o-war between business and security&quot;, The gist is that we get two business people and two security people together, and they discuss the finer points of managing business and security requirements in real-world environments.  Many of us have been there.  Security people have a notoriously difficult time convincing the business that security is important, and business folks are just trying to run the company and often view security as a speed bump.</p>

<p>I&#8217;m very excited to moderate this panel two years in a row.  It is relatively rare to get security and business people together at one table with the sole purpose of discussing how security impacts real-world decisions.  As they say on TV, &quot;Let&#8217;s get ready to rumble!&quot;</p>

<h2>How you can help</h2>
<p>Below are some examples of questions I could ask the panelists.  I have a much longer list, but I think it would be much more interesting to open this up to the security community.  So, given this opportunity, what questions would YOU like me to ask the panelists?</p>

Sample questions:
<ul>
	<li>When you are &#8216;selling&#8217; security, how do you get appropriate attention when you are talking about what MIGHT happen instead of things that ARE happening?  You are essentially asking people to spend money on a problem that &quot;THEY DON&#8217;T HAVE&quot;.  How do you justify the expense?</li>
	<li>Whose responsibility IS it to manage security?</li>
	<li>With security, it is possible to spend an unknown amount of money on an intangible problem.  What is the right amount to spend?</li>
	<li>As an industry, security people tend to NOT be very good at communicating security concepts to NON security people.   How do you communicate technical security concepts to business people in a way that they get it?</li>
</ul>

<p>See you at the conference!<br />
&#8211;rob</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/03/09/business-vs-security-lets-get-ready-to-rumble/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

