|
IDC's IT Security, Storage & Business Continuity Roadshow 2008
Secure your Business in an Uncertain World
IDC's IT Security Roadshow has become the seminal annual event for
CIOs and IT managers looking for the latest information on IT security
trends and wanting to meet IT security gurus and industry professionals.
The growing complexity of IT systems and their security has created
multiple challenges for CIOs and IT managers across the CEMA region.
They must address the explosion in the number of access points,
communication technologies convergence, human behavior, company leaders
still thinking in terms of antivirus software and firewalls, limited
resources, and flat or even decreasing budgets. While basics remain
essential, CIOs and IT security managers must also handle evolving
authentication methods, well financed corporate espionage agents and
cyberterrorists, as well as employee awareness.
Here is a brief of the IDC conference this year,
Nokia solutions:
They have been in the market for 12 years providing
hardware for network security, they are good with 3G HSDPA and high speed
mobile communication that can provide a virtual office in your nokia handset,
even you can connect your office ip telephony to it.
Juniper Networks:
Talked about network evolution and virtualization is
impacting the industry.
Tipping Point:
They test web applications then instantly create digital
program and insert it in front of your application to protect it rather than
give report to developer and take long time to fix and create new release.
MacAfee:
Talked about
- compliance and privacy laws and how it differ from
country to another.
- How portability affect loss ability.
- Highlighted the PEBKAC effect (Problem events between
keyboard and Chair) which is the solution for most of the issues.
- Encourage every IT department to put a Data usage
policy,
- understand your data.
- work on user awareness of policy.
Secure computing:
Said that with WEB2.0 the webmaster is in control, and
that web2.0 downloads things through your browser without your permission
-common practice to coded website without including the
secured approach, make it work then secure it.
- Active X, Java plug-ins exposed to HDD.
- 68% of new malware steal data not destructing, work
silently not to be detected to collect and send
- Whaling and spear phishing scams target executives CIO
CTO CSO.
- encourage browsers without ACTIVEX
- Transparent Attacks
- None transparent Attacks.
- Russian business network
- social engineering
- behavior analysis
Fortinet
-Has UTM become an Arabian Stallion
- threats from web email, ftp, Msn, Yahoo msg, et
- to protect you need firewall, then IDS, then IPS Then
VPN then antispam etc..
- add latency if one fails all fail.
- standby plan means double firewall, double IDS double
IPS double VPN double equipments double boxes
- try to manage then report if boxes different brands
cisco not cisco etc...
- Human & People is the weakest link
- UTM unified Threat Management
- core center to separate departments from other when
infected.
Kaspersky lab.
- ING direct
- bank solutions
- smart tokens very expensive solution
- secure virtual keyboard
- PDM productive defense module
- Registry Guard
- Detection
- life demonstration how Trojan can take screen shots of
you clicking on the virtual keyboard and arrow indicating which key was
pressed. And that Trojan evolutes to movie capture rather than screen shoots
with cheap disk space.
Blue Coat Systems:
- byte caching, if you working on a document and sending
forth and backward, byte caching will send only the changed bytes of a file not
the whole file between the sender and receiver,
Smart isn't it :)
Trend:
- PCI-DSS.
- PCI section 6.5 details
BT:
-Risk of convergence
Phion:
- Secure communication
- ICAP content filtering
All the presenations of the conference are in the download section of this website, please register and download if needed.
You can see me in the conference talking to GOPA in the fourth last image.
http://www.idc-cema.com/?showproduct=31349&content_lang=ENG&action=Photogallery
Only registered users can write comments. Please login or register. Powered by AkoComment 2.2 |