September 14th 2010

Chris Merkel, Director of Information Security for Brunswick Corporation

Topic: Launching a budget-conscious security awareness program

3-5 PM

New Berlin Ale House
16000 W. Cleveland Ave.
New Berlin, WI
Directions
 

 

Previous Meetings

August 10th 2010

John Parkinson, SVP Global Program Office, Axis Capital Group

Topic: Are the bad guys winning? Information Security Strategies for an evolving landscape of cyber threats

June 8th 2010

Jason Prost, Central Region Solutions Engineer for Accuvant, Inc.

Topic:  Redefining the Perimeter: Today's End Point Security Landscape 

May 19th & 20th 2010

InfraGARD SuperConference 

April 13th 2010

NAC Solution Bake Off

Representives from McAfee, Symantec, Bradford Networks, Juniper and Cisco will be there.

Dan Pinnecker will lead the questioning as the top NAC vendors get a chance to compare their solutions against their leading competitors.  This should be an informative and entertaining discussion.  Come armed with questions!

  Sponsored by Fishnet Security 

March 9th 2010
Dan Swartwood, Director of Information Safeguarding at Disney

Location:

New Berlin Ale House
16000 W. Cleveland Ave.
New Berlin, WI
Directions

February 9th 2010

Weather cancellation

January 2010

Andre Robitaille, IS Consultant, ISSA Milwaukee Chapter Member

 Topic: Phishing vs. Web Gateways Demo: How hackers are bypassing your $50k perimeter

 Sponsored by Meridian IT

December 2009

Weather cancellation

November 2009

Nickolas Roedel, Information Security Analyst at Metavante

Website vulnerability and hacking demonstration.

 

Tuesday, April 14, 2009
3-5 p.m.

Topic: Rats in the Cellar and Bats in the Attic

This will be a facilitated discussion led by Mark Chapman, President/CEO of Chapman Technology Group, Inc., covering vulnerability scanning, penetration testing, social engineering. Bring your personal experiences and preferences along for discussion.

Outline:
  * Planning - Scoping Keep me out of jail!
  * Discovery - Mapping what there is.
  * Analysis - Vulnerability review, anything to attack?
  * Penetration - Can I get in? (Human Firewall, Technical Firewall, Monitoring Systems)
  * Reporting - Tell Management about it!

Mark Chapman, President/CEO of Chapman Technology Group, Inc.

Mark T. Chapman, CISSP CISM, holds a Masters Degree in Computer Science from the University of Wisconsin Milwaukee in the area of Cryptography and Data Security. Mark has over 19 years of experience providing information security, information technology and risk management solutions to a wide variety of organizations from community banks to multinational institutions. He is the president and founder of Chapman Technology Group, Inc. -- a Wisconsin-based information security and data analysis solution provider specializing in risk management methods and tools.

SynerComm
3265 Gateway Road, Suite 650
Brookfield, WI 53045
Directions

 

 

Tuesday, March 10th, 2009
3-5 p.m.

Topic: Risk & Regulatory Intelligence - Getting to the Head of the Class

Bombarded with an array of risks and regulations impacting every phase of business operations, global organizations have much to manage. Resilient and agile organizations manage risk and regulations proactively to stay abreast of dynamic environments, risks, regulations, and case law across multiple jurisdictions. Staying alert to a diverse and dynamic world has become a competitive advantage. This presentation looks at the processes, technologies, and content needed for an organization to stay informed in dynamic risk and regulatory environments.

Michael Rasmussen CISSP - President & Business Research Analyst, Corporate Integrity, LLC

Michael Rasmussen is the foremost authority in understanding Governance, Risk, and Compliance (GRC). He is a sought after keynote speaker, author, and collaborator on GRC issues around the world and is noted for being the first analyst to define and model the GRC market for products and professional services. With more than 15 years of experience, Michael's objective is to assist organizations in defining GRC processes that are sustainable, consistent, efficient, and transparent.

Michael currently serves on the Leadership Council and Steering Committee of the Open Compliance and Ethics Group. Michael is a frequent conference keynote on topics related to GRC and has been quoted extensively in the press around the world and has appeared several times on television news channels providing insight into current events. In the June 2007 issue of Treasury & Risk, Michael was recognized as among the top 100 most influential people in finance with specific accolades noting his work in "Governance and Compliance: Saving the Planet and the Corporation."

During his career, Michael has worked in the market analyst, consulting, and enterprise sectors. Prior to founding Corporate Integrity, Michael was a Vice-President and top analyst at Forrester Research, Inc. Before Forrester, he led the risk consulting practice at a professional services firm in the Midwest. Earlier, his career included industry experience in healthcare as well as manufacturing.

Michael's educational experience consists of a B.S. in business from the University of Phoenix. Michael has previously studied theology and is currently pursuing a Juris Doctorate from the Oakbrook College of Law and Government Policy.

SynerComm
3265 Gateway Road, Suite 650
Brookfield, WI 53045
Directions

 

Tuesday, February 10th, 2009
3-5 p.m.

Topic: E-discovery
As technology advances, sophisticated litigators are gaining a better understanding of the information they can obtain from e-mail messages, databases, software applications, computer logs, and metadata. Adopting sound information management to emerging electronic practice is a big challenge. IT professionals are being called upon to ensure a systemized approach to electronic record management that conforms to state and federal legal requirements. IT departments must understand how to more efficiently locate, preserve, and review information in order to support in-house and external counsel. Learn about the changes to the Federal Rules of Civil Procedure and the impact on release and access of electronic information. How should you prepare your department and organization for E-Discovery?
Where do you begin?

Thomas Shorter

Thomas N. Shorter is a shareholder in the Employment and Health Care Practice Groups in Godfrey & Kahn, S.C.'s Madison office.

Tom represents health care and educational institutions, providing counsel in labor and employment and regulatory matters such as collective bargaining, FMLA compliance, discrimination issues, discipline and discharge, ADA, HIPAA, EMTALA, Stark, and Anti-Kickback issues. His heath care practice includes working with hospitals, physicians groups, research institutions and other health care organizations. He is a Vice-Chair of the American Health Lawyers Association Labor & Employment Practice Group.

SynerComm
3265 Gateway Road, Suite 650
Brookfield, WI 53045
Directions

 

Tuesday, January 13th, 2009
2-5 p.m.

Topic: How Might Your Next Security Breach Occur?

Learn about recent trends and case studies in forensics and how you can mitigate risk in the face of the increasing number of breaches. The discussion will provide in depth views of incidents and both effective and ineffective response efforts across multiple industries.

This forum will offer a behind the scenes look at the following topics:

The Latest Incident Trends

The Business of Converting Stolen Data to Cash

Investigative Response Case Studies and Discussion

The Fundamental Components of an Effective Response Capability

Chris Novak

Christopher Novak is a Principal Consultant within Verizon Business' Investigative Response Unit and has more than 10 years experience in the security arena providing industry-leading services and support for both commercial and government customers. Christopher is a senior investigator, having taken the lead in more than 50 tactical response cases over the past 18 months involving both civil and criminal scenarios. In addition, Mr. Novak responds to incidents on a global basis and has worked significantly with foreign governments and institutions to identify and prosecute international criminals.

Mr. Novak has also been instrumental in Verizon Business' PCI and related compliance services. He maintains accreditations with all of the major payment brands to perform their respective compliance assessments and provides guidance to merchants, service providers and payment vendors on the topics of achieving and maintaining compliance with the PCI DSS.

Mr. Novak has been published on a number of security-related topics, holds many security-specific industry certifications, and has presented at numerous public conferences as well as private seminars.

SynerComm
3265 Gateway Road, Suite 650
Brookfield, WI 53045
Directions

 

Tuesday, December 9th, 2008
2-5 p.m.

Topic: Risk & Regulatory Intelligence - Getting to the Head of the Class
Bombarded with an array of risks and regulations impacting every phase of business operations, global organizations have much to manage. Resilient and agile organizations manage risk and regulations proactively to stay abreast of dynamic environments, risks, regulations, and case law across multiple jurisdictions. Staying alert to a diverse and dynamic world has become a competitive advantage. This presentation looks at the processes, technologies, and content needed for an organization to stay informed in dynamic risk and regulatory environments.

Michael Rasmussen CISSP - President & Business Research Analyst, Corporate Integrity, LLC

Michael Rasmussen is the foremost authority in understanding Governance, Risk, and Compliance (GRC). He is a sought after keynote speaker, author, and collaborator on GRC issues around the world and is noted for being the first analyst to define and model the GRC market for products and professional services. With more than 15 years of experience, Michael's objective is to assist organizations in defining GRC processes that are sustainable, consistent, efficient, and transparent. His thought leadership spans industry verticals and GRC domains on a global basis, and involves:

Educating and collaborating with GRC professionals -- such as compliance, risk, legal, audit, finance, corporate social responsibility, and IT -- to identify, understand, and analyze GRC strategies, drivers, trends, and best practices; Working with technology and solution providers to align their products to meet the needs and requirements of GRC professionals; and, advising professional service firms on their portfolio of GRC service offerings so they are better equipped to consult and define GRC processes for their respective clients. Considered one of the foremost authorities in understanding the broad view and impact of risk and compliance standards, frameworks, regulations, and legislation, Michael has worked closely with large organizations and government agencies. His involvement in government initiatives has included leading roles in defining public policy and legislation on risk and compliance with contributions to US Congressional reports, boards, and committees.

Michael currently serves on the Leadership Council and Steering Committee of the Open Compliance and Ethics Group. Michael is a frequent conference keynote on topics related to GRC and has been quoted extensively in the press around the world and has appeared several times on television news channels providing insight into current events. In the June 2007 issue of Treasury & Risk, Michael was recognized as among the top 100 most influential people in finance with specific accolades noting his work in "Governance and Compliance: Saving the Planet and the Corporation."

During his career, Michael has worked in the market analyst, consulting, and enterprise sectors. Prior to founding Corporate Integrity, Michael was a Vice-President and top analyst at Forrester Research, Inc. Before Forrester, he led the risk consulting practice at a professional services firm in the Midwest. Earlier, his career included industry experience in healthcare as well as manufacturing.

Michael's educational experience consists of a B.S. in business from the University of Phoenix. Michael has previously studied theology and is currently pursuing a Juris Doctorate from the Oakbrook College of Law and Government Policy.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, November 11th, 2008
2-5 p.m.

Topic: Emerging Threats - A Discussion of Current and Future Threat Environments

Mike Belton, CISSP

Mike is a CISSP-certified security engineer and has been working professionally with information systems security for over 10 years.

During that time Mike has worked directly with most aspects of information security, both as an engineer and in managerial roles.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, October 14th, 2008
2-5 p.m.

Topic: FBI Cyber Cases, an Insiders View from a Former FBI Special Agent

This will be a presentation and discussion on how the FBI handles Cyber cases from the perspective of a former FBI Special Agent. The presentation will be based on real life case examples worked by Craig while in the FBI. The information presented will be on cases that have gone public through the media. Primarily the presentation will deal with a large scale international intrusion case that targeted the federal government, private sector, and numerous universities. Other case topics to be covered include internal employee hackings, computer child porn cases, and Internet auction fraud. The presentation will give you an appreciation of what would happen if your corporation needed to contact the FBI in response to a Cyber incident.

Craig Adams, MCSE, CCA, CNA, ITIL has ten plus years experience as a Systems Engineer. He has a Bachelor of Science with a double major in computer science and criminal justice from the University of WI Oshkosh. Craig is a former FBI Special Agent who investigated Cyber (computer) crimes for the FBI in addition to assisting on terrorism and foreign counter intelligence cases.

Primarily Craig worked on international computer intrusion cases for the FBI, but he also worked on cases of traditional crime that have migrated to the Cyber realm. Craig also spearheaded efforts within the FBI to build public private partnerships between universities, private corporations, and the FBI in an attempt to better be able to react to emerging Cyber threats. In 2006 Craig spoke in Turin Italy as a subject matter expert on computer intrusions in preparation for Italy's hosting of the Winter Olympics.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, September 9th, 2008
2-5 p.m.

Topic: Security and Risk 

Jeffrey Wheatman is is a research director for Information Security and Privacy. As an analyst within the Gartner Group for IT Leaders' Security & Risk Management program, he works with senior security executives to help them address security risks within their environments.

Mr. Wheatman is a seasoned information security practitioner with significant expertise as a hands-on technologist as well as extensive background in strategy and program development. He has over nine years experience in consulting for Fortune 500 and Global 200 organizations in numerous vertical markets where he has managed teams responsible for architecting, deploying and managing security programs and solutions.

During his nine years in consulting, Jeffrey was responsible for successfully developing and managing information security consulting practices for several regional professional services providers in the northeast United States.

Jeffrey has significant hands-on experience in multiple areas within technology and security including network operations, end-user support, network architecture, telecommunications and systems analysis.

Jeffrey has an MBA in management of information systems from the Zicklin School of Business in NYC. His business acumen complemented by technical background prepared him for his current role at Gartner where he regularly advises senior security executives on aligning information security and risk management with business goals and objectives.

When global corporations have questions about information security and risk management, they need answers and invariably they get those answers from Gartner.

Years of Experience
2 years with Gartner
17 years in IT industry

Professional Background
Gotham Technology Group, Security Practice Manager, 2 years
Brute Force Security, CSO, Principal Consultant, 1 years
Martha Stewart Living, AVP, Network & Information Security, 3 years

Education
MBA, Computer Information Systems - Zicklin School of Business
BA, Economics - Queens College

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, August 12th, 2008
2-5 p.m.

Topic: Fraud: how it works, where it's been, and where it's going 

Steve Fried, CISSP, CISM is the Vice President of Information Security at the Metavante Corporation with responsibility for ensuring the confidentiality, integrity, availability, and privacy of Metavante's information assets and those of its customers. He is a seasoned information security professional with over 20 years experience in information technology.

For the past ten years Stephen has concentrated his efforts on providing effective information security leadership to large organizations. Stephen has led the creation of security programs for two Fortune 500 companies and has extensive background in such diverse security issues as risk assessment and management, security policy development, security architecture, infrastructure and perimeter security design, outsource relationship security, offshore development, intellectual property protection, security technology development, business continuity, secure e-business design, and information technology auditing. A frequent speaker at conferences, Stephen is also active in many security industry organizations. He is a contributing author to the Information Security Management Handbook and has also been quoted in Secure Enterprise and CIO Decisions Magazines.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, June 17th, 2008
2-5 p.m.

Topic: Professor Schmidt spoke on a range of Information Security topics.

Professor Howard A. Schmidt, CISSP, CISM is the President of ISSA International.

A noted speaker and author, Howard Schmidt has had a long and distinguished career in defense, law enforcement and corporate security spanning almost 40 years. He has served as a cyber security advisor to the White House, Vice President and Chief Information Security Officer and Chief Security Strategist for eBay, and Chief Security Officer for Microsoft. He most recently served in the position of Chief Security Strategist for the US CERT Partners Program for the National Cyber Security Division, Department of Homeland Security.

Marcus Palladium
770 N. Springdale Road
Brookfield, WI 53186
Directions

 

May 14 and 15, 2008

2008 InfraGard SuperConference 

Kalahari Resort in Wisconsin Dells

 

Tuesday, April 8th, 2008
3-5 p.m.

Topic: Security Governance: The 13 Questions the CEO, CIO, and CISO Must ask each other.

Todd Fitzgerald, CISSP, CISA, CISM serves as a Medicare Systems Security Officer for National Government Services, LLC (NGS), Milwaukee, WI which is the nation's largest processor of Medicare claims, and subsidiary of WellPoint, Inc. (NYSE:WLP) the nation's largest health insurer.

Todd co-authored the 2008 ISC2 Press Book Entitled CISO Leadership: Essential Principles For Success. Todd was named as a finalist for the 2005 Midwest Information Security Executive (ISE) of the Year Award, nominee for the national award, Judge for the 2006/08 central region awards, Master of Ceremonies for the 2006 West awards, and has moderated several Executive Alliance Information Security Executive Roundtables. Todd has authored articles on Information Security for The 2007 Official ISC2 Guide to the CISSP Exam, The Information Security Handbook Series (2003-2008), The HIPAA Program Reference Book, Managing an Information Security and Privacy Awareness and Training Program, and several other security-related publications. Todd is also a member of the Editorial Board for ISC2 Journal/Information Systems Security Magazine and Darkreading.com security publication and is frequently called upon to present at international, national, and local conferences such as the Computer Security Institute (CSI) and Management Information Systems Training Institute (MISTI). Todd serves on the Board of Directors for the HIPAA Collaborative of Wisconsin, and is an active leader, participant and presenter in multiple industry associations such as Information Systems Security Association (ISSA), Blue Cross Blue Shield Information Security Advisory Group, CMS/Gartner Security Best Practices Group, Workgroup for Electronic Data Interchange (WEDI), Information Systems Audit and Control Association (ISACA), and others.

Todd has 29 years of Information Technology experience, including 20 years of management. Prior to joining NGS, Todd held various broad-based senior Information Technology management positions for Fortune 500 organizations such as American Airlines, IMS Health, Zeneca (subsidiary of AstraZeneca Pharmaceuticals), Syngenta, as well as prior positions with Blue Cross Blue Shield of Wisconsin.

Todd holds a B.S. in Business Administration from the University of Wisconsin-Lacrosse, serves as an advisor to the College of Business Administration, and holds a MBA with highest honors from Oklahoma State University.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, March 11th, 2008
3-5 p.m.

Topic: Security Products and Vendor Satisfaction Moderated Discussion on the latest security measures implemented, products used, and vendor satisfaction. Please be prepared to talk about solutions used at your companies.

Scott Ried CISSP, VP, and CSO for The Ziegler Companies

Scott has developed a Security Program including Improved Security Measures, Identity Theft Management, and Security Awareness.

Scott is also the Milwaukee ISSA Chapter Secretary.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, February 12th, 2008
3-5 p.m.

Topic: Protecting Enterprise Mobile Data Portable intelligent devices, including laptops, PDAs, and smartphones, promise to enhance productivity, but also come with security liabilities. Lost or stolen equipment can leak sensitive personal information and other confidential data, provide entry points for intruders into the corporate network, and be costly to replace, both to buy and to restore configurations and data.
We will review the latest technologies for protecting mobile data, locating and recovering lost or stolen equipment, and rendering devices that can't be recovered harmless. We also discussed our own experiences, successful or not, in keeping these devices working and in friendly hands.

Mark Chapman's Mobile Device Security Presentation

Mark Chapman CISSP, CISM
Chapman Technology Group

SPEAKER BIO: Mark Chapman holds a Masters Degree in Computer Science from the University of Wisconsin Milwaukee in the area of Cryptography and Data Security. Mark has published several papers and has presented research at conferences in the U.S., Asia and Europe. Mark is a CISSP, CISM and is certified in the National Security Agency's Information Assurance Methodology. He is a member of the executive planning committee for the Eastern Wisconsin Chapter of the FBI InfraGARD. He published the chapter on wireless security in the 2004 Information Security Management Handbook and has spoken at many information-security-related venues. Mark has lectured at WCTC, UWM, Marquette University and has presented risk-related topics to the FFIEC/FDIC and NASA Glenn Research Center. He is the founder of Chapman Technology Group, Inc. - a Wisconsin-based risk management, information security and data analysis solution provider.

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions

 

Tuesday, January 8th, 2008
3-5 p.m.

Topic: "MODERATED ROUNDTABLE DISCUSSION: Security and Audit Standards and Controls." Come join a lively discussion around the different security and audit standards, methodologies and guidelines. Bring your favorite standard and justification for why it is the best. Be sure to attend this meeting in order to receive copies of any handouts or sample mapping models that have been done of various standards, COBIT to ITIL to NIST and so on that may be shared at the meeting. Ken Shaurette, TRM Engagement Manager with Jefferson Wells will facilitate the discussion and encourages everyone to join in a fun and information packed meeting.

Ken Shaurette's COBIT V Standards Presentation

Ken Shaurette is the TRM Engagement Manager with Jefferson Wells

Also, please join us for the Vice Presidential and Secretarial Elections. 

Wipfli
10000 Innovation Drive, Suite 250
Milwaukee, WI 53226
Directions